INFRA-58 INFRA-59: org starter workflows + issue templates (#43)

* INFRA-59: add org issue templates (bug, feature, infra-change) + config

Adds .github/ISSUE_TEMPLATE/ with bug_report.md, feature_request.md,
infra-change.md (change-control: impact, rollback plan, affected stacks),
and config.yml disabling blank issues + routing ops to INFRA Jira.

* INFRA-58: add org starter workflows wrapping reusable workflows

Adds workflow-templates/ with starters + .properties.json for:
ci-node, ci-python, cdk-deploy, sam-deploy, dependency-review, labeler,
triage. CI/CD starters call the org reusable workflows in
.github/.github/workflows/ at @main with their required inputs/secrets.
This commit is contained in:
Adam Moussa 2026-06-05 17:26:16 -04:00 • committed by GitHub
parent 23584a53c8
commit 7f84f9cfde
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
18 changed files with 233 additions and 0 deletions

27
.github/ISSUE_TEMPLATE/bug_report.md vendored Normal file
View file

@ -0,0 +1,27 @@
---
name: Bug report
about: Report a defect in a Sea Haven service
title: "[Bug] "
labels: [bug, needs-triage]
assignees: amoussa1229
---
## What's wrong
<!-- Clear description of the bug. -->
## Expected behavior
<!-- What should happen instead. -->
## Steps to reproduce
1.
2.
3.
## Environment / blast radius
- Repo / service:
- CFN stack affected:
- Lambda(s) affected:
- Region: us-east-1 (account 328440206208)
## Logs / evidence
<!-- CloudWatch log group + timestamp, request IDs, screenshots. -->

5
.github/ISSUE_TEMPLATE/config.yml vendored Normal file
View file

@ -0,0 +1,5 @@
blank_issues_enabled: false
contact_links:
- name: Internal IT support
url: https://seahaven.atlassian.net/jira/software/projects/INFRA
about: For operational issues, file an INFRA Jira ticket instead.

View file

@ -0,0 +1,21 @@
---
name: Feature request
about: Propose new functionality for a Sea Haven service
title: "[Feature] "
labels: [enhancement, needs-triage]
assignees: amoussa1229
---
## Problem / motivation
<!-- What operational pain or gap does this address? -->
## Proposed solution
<!-- What you want to build. -->
## AWS / integration impact
- New or changed AWS resources (Lambda, DynamoDB, S3, API Gateway):
- Slack app(s) involved:
- Confluence Architecture Map update needed: yes / no
## Alternatives considered
<!-- Other approaches and why they were rejected. -->

26
.github/ISSUE_TEMPLATE/infra-change.md vendored Normal file
View file

@ -0,0 +1,26 @@
---
name: Infrastructure change
about: Track a change to AWS infrastructure or integrations (change control)
title: "[Infra] "
labels: [infra, needs-triage]
assignees: amoussa1229
---
## Change summary
<!-- What is changing and why. -->
## Impact assessment
- **CFN stack affected:**
- **Lambda(s) affected (handler signature change? Y/N):**
- **DynamoDB table(s) affected (PITR verified? Y/N):**
- **S3 bucket(s) / SES rules affected:**
- **Slack app affected:**
- **IAM role / policy changes (requires cross-review? Y/N):**
## Rollback plan
<!-- Exact steps to revert: prior stack version, DeletionPolicy considerations, data restore. -->
## Documentation
- [ ] Confluence Architecture Map (id 1540098) update queued
- [ ] README updated in same PR
- [ ] Project memory entry queued

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — Deploy (CDK)",
"description": "Deploys a CDK stack to AWS (account 328440206208, us-east-1) via OIDC on push to main, using the org reusable cd-cdk workflow.",
"iconName": "octicon-rocket",
"categories": ["Deployment", "TypeScript", "Python"],
"filePatterns": ["cdk\\.json$"]
}

View file

@ -0,0 +1,10 @@
name: Deploy (CDK)
on:
push:
branches: [main]
jobs:
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — CI (Node / TypeScript / CDK)",
"description": "Runs npm ci, tsc --noEmit, optional ESLint/Jest, and cdk synth via the org reusable workflow.",
"iconName": "octicon-checklist",
"categories": ["TypeScript", "JavaScript", "Continuous integration"],
"filePatterns": ["package\\.json$", "tsconfig\\.json$", "cdk\\.json$"]
}

View file

@ -0,0 +1,8 @@
name: CI (Node / TypeScript)
on:
pull_request:
branches: [main]
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — CI (Python / SAM)",
"description": "Runs ruff check, ruff format --check, pytest, and sam validate --lint via the org reusable workflow.",
"iconName": "octicon-checklist",
"categories": ["Python", "Continuous integration"],
"filePatterns": ["requirements.*\\.txt$", "template\\.ya?ml$", "pyproject\\.toml$"]
}

View file

@ -0,0 +1,10 @@
name: CI (Python / SAM)
on:
pull_request:
branches: [main]
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main
with:
run-tests: true

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — Dependency Review",
"description": "Scans PRs for vulnerable or newly-introduced dependencies, failing on high severity. Requires Dependency Graph (GHAS on private repos).",
"iconName": "octicon-shield-check",
"categories": ["Security", "Dependency management"],
"filePatterns": ["package\\.json$", "requirements.*\\.txt$", "pyproject\\.toml$"]
}

View file

@ -0,0 +1,20 @@
name: Dependency Review
on:
pull_request:
branches: [main]
permissions:
contents: read
pull-requests: write
jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v6
- name: Dependency Review
uses: actions/dependency-review-action@v4
with:
fail-on-severity: high
comment-summary-in-pr: on-failure

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — PR Labeler",
"description": "Auto-labels PRs by changed paths (infra / lambda / ci / docs). Requires a .github/labeler.yml config.",
"iconName": "octicon-tag",
"categories": ["Automation", "Pull requests"],
"filePatterns": [".github/labeler\\.ya?ml$"]
}

View file

@ -0,0 +1,20 @@
name: Labeler
on: [pull_request_target]
permissions:
contents: read
pull-requests: write
jobs:
label:
runs-on: ubuntu-latest
steps:
# Requires .github/labeler.yml in this repo, e.g.:
# infra: [ 'cdk/**', 'template.yaml', 'oidc-deploy-roles.yaml' ]
# lambda: [ 'lambdas/**', 'src/**', 'functions/**' ]
# ci: [ '.github/workflows/**' ]
# docs: [ '**/*.md' ]
- uses: actions/labeler@v5
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
sync-labels: true

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — Deploy (SAM)",
"description": "Deploys a SAM stack to AWS (account 328440206208, us-east-1) via OIDC on push to main, using the org reusable cd-sam workflow. Set stack-name and cfn-role-arn before enabling.",
"iconName": "octicon-rocket",
"categories": ["Deployment", "Python"],
"filePatterns": ["template\\.ya?ml$", "samconfig\\.toml$"]
}

View file

@ -0,0 +1,15 @@
name: Deploy (SAM)
on:
push:
branches: [main]
jobs:
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@main
with:
# Required: the CloudFormation stack name (kebab-case, matches repo name).
stack-name: $default-branch
# Required: the CloudFormation execution role ARN for this stack.
cfn-role-arn: arn:aws:iam::328440206208:role/REPLACE-ME-cfn-exec-role
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — Issue Triage",
"description": "Labels newly opened/reopened issues with needs-triage for weekly review.",
"iconName": "octicon-inbox",
"categories": ["Automation", "Issues"],
"filePatterns": []
}

View file

@ -0,0 +1,22 @@
name: Triage
on:
issues:
types: [opened, reopened]
permissions:
issues: write
jobs:
triage:
runs-on: ubuntu-latest
steps:
- name: Add needs-triage label
uses: actions/github-script@v7
with:
script: |
await github.rest.issues.addLabels({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.issue.number,
labels: ['needs-triage']
});