chore: remove retired pr-review and compliance-audit tooling

Three pieces of tooling for retired flows were still carried in this
repo, and the README documented them as if they were current.

- `.github/workflows/compliance-audit.yaml`: deprecated 2026-06-10.
  Its schedule was already stripped, and its live state in the Actions
  API is `disabled_manually`, so it was workflow_dispatch-only and
  inert. It was also the last consumer of the `CLAUDE_CI_APP_ID` and
  `CLAUDE_CI_APP_PRIVATE_KEY` org secrets.
- `scripts/rollout-review-workflow.sh`: a one-shot script that pushed a
  per-repo wrapper calling `claude-code-review.yaml`. That reusable
  workflow was deleted on 2026-05-13 and no longer exists in this repo
  or any of the 31 org repos, so the script could only ever open PRs
  for a workflow that resolves to nothing.
- README `PR Reviews`, `Scripts`, and the `claude-code-ci` GitHub App
  setup steps, which described the same retired flows.

The `ANTHROPIC_API_KEY` org secret is deliberately kept in the setup
table: it is still read by the active `reviewer-eval.yml` workflow in
`open-swe`. The `CLAUDE_CI_APP_*` secrets are now unreferenced across
the org, but this change only removes their documentation. Neither the
secrets nor the App itself are touched.

Setup steps are renumbered 1-3 with no gap, and the `see §5` reference
in the IAM section is repointed to §3. actionlint 1.7.12 (the version
pinned in ci.yaml) passes clean over the remaining workflows.
This commit is contained in:
Adam Moussa 2026-07-28 12:34:26 -04:00
parent 2139662f5a
commit af2ee942ce
No known key found for this signature in database
3 changed files with 9 additions and 267 deletions

View file

@ -1,138 +0,0 @@
# DEPRECATED (2026-06-10): The weekly org-wide compliance audit has been retired.
# The workflow is disabled in the Actions tab (state: disabled_manually) and the
# scheduled trigger has been removed so it cannot run automatically. Repo
# compliance is now handled via the Claude Code App on pull requests and the
# engineering handbook directly. Left in place (manual-dispatch only) for
# historical reference; safe to delete in a future cleanup.
name: Compliance Audit (DEPRECATED)
on:
# schedule removed on deprecation — no longer runs weekly.
workflow_dispatch:
permissions:
id-token: write
contents: read
issues: write
jobs:
get-repos:
runs-on: ubuntu-latest
outputs:
repos: ${{ steps.list.outputs.repos }}
steps:
- name: Generate GitHub App token
id: app-token
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.CLAUDE_CI_APP_ID }}
private-key: ${{ secrets.CLAUDE_CI_APP_PRIVATE_KEY }}
owner: Sea-Haven-Industries
- name: List org repos
id: list
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
run: |
EXCLUDE="shoc-frontend-new shoc-backend"
repos=$(gh repo list Sea-Haven-Industries \
--no-archived \
--json name \
--jq "[.[].name | select(. as \$n | \"$EXCLUDE\" | split(\" \") | index(\$n) | not)] | @json" \
--limit 100)
echo "repos=$repos" >> "$GITHUB_OUTPUT"
audit:
needs: get-repos
runs-on: ubuntu-latest
timeout-minutes: 15
strategy:
fail-fast: false
max-parallel: 3
matrix:
repo: ${{ fromJson(needs.get-repos.outputs.repos) }}
steps:
- name: Generate GitHub App token
id: app-token
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.CLAUDE_CI_APP_ID }}
private-key: ${{ secrets.CLAUDE_CI_APP_PRIVATE_KEY }}
owner: Sea-Haven-Industries
repositories: ${{ matrix.repo }},engineering-handbook
- name: Checkout repo
uses: actions/checkout@v7
with:
repository: Sea-Haven-Industries/${{ matrix.repo }}
token: ${{ steps.app-token.outputs.token }}
- name: Checkout engineering handbook
uses: actions/checkout@v7
with:
repository: Sea-Haven-Industries/engineering-handbook
token: ${{ steps.app-token.outputs.token }}
path: .engineering-handbook
- name: Run compliance audit
id: audit
uses: anthropics/claude-code-action@be7b93b1907a4abad570368f3c74b6fe3807510b # v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
prompt: |
Audit this repository for Sea Haven Industries compliance.
The engineering handbook in `.engineering-handbook/` is the authoritative source for all conventions. Read every markdown file in that directory to understand the full set of standards, then audit this repo against them.
Focus on these categories:
- **Naming:** kebab-case for all resource names in IaC templates, stack name matches repo name
- **Secrets:** no secrets in Lambda env vars or SSM, secrets belong in Secrets Manager with `stack-name/secret-name` naming
- **Lambda defaults:** Python 3.12+ or Node 22.x, arm64, explicit 60-day log retention in IaC
- **CI/CD:** pipeline exists with CI on PR and CD on push to main, using reusable workflows from `.github` repo
- **Git/GitHub:** branch protection on main, PR-based workflow, repo has a description
- **SAM layout:** template.yaml at root, samconfig.toml gitignored with .example committed, src/ directory structure
- **Project hygiene:** README describes architecture, .gitignore covers .env/.aws-sam/__pycache__, CloudFormation outputs include ARNs and URLs
Return structured output with:
- `has_violations`: true only when one or more actual compliance violations are found.
- `report`: a concise markdown report with pass/fail per applicable item.
Only flag actual violations — skip items that don't apply to this repo (e.g., skip Lambda checks if no Lambdas exist).
Do not create or modify files, issues, pull requests, or comments.
claude_args: |
--json-schema '{"type":"object","properties":{"has_violations":{"type":"boolean","description":"True when one or more actual compliance violations are found."},"report":{"type":"string","description":"Concise markdown report with pass/fail per applicable compliance item."}},"required":["has_violations","report"],"additionalProperties":false}'
- name: Create issue if violations found
if: ${{ fromJSON(steps.audit.outputs.structured_output).has_violations == true }}
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
AUDIT_RESULT: ${{ steps.audit.outputs.structured_output }}
run: |
gh label create compliance \
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
--description "Weekly compliance audit" \
--color "D93F0B" 2>/dev/null || true
existing=$(gh issue list \
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
--label "compliance" \
--state open \
--json number \
--jq 'length')
if [ "$existing" -eq 0 ]; then
report=$(jq -r '.report' <<< "$AUDIT_RESULT")
body_file=$(mktemp)
{
echo "The weekly compliance audit found violations in this repo."
echo
echo "## Audit report"
echo
printf '%s\n' "$report"
echo
echo "Check the [latest audit run](https://github.com/Sea-Haven-Industries/.github/actions/workflows/compliance-audit.yaml) for details."
} > "$body_file"
gh issue create \
--repo "Sea-Haven-Industries/${{ matrix.repo }}" \
--title "Compliance audit: violations found" \
--body-file "$body_file" \
--label "compliance"
fi

View file

@ -32,8 +32,6 @@ Organization-level GitHub configuration for Sea Haven Industries.
**`.github/workflows/ci.yaml`** — Self-CI for this repo: actionlint (checksum-verified install) over all workflow files, emitting the required `ci / ci` status context.
**`.github/workflows/compliance-audit.yaml`** — **DEPRECATED (2026-06-10).** The weekly scheduled org-wide audit has been retired: the schedule was removed and the workflow is disabled in the Actions tab (manual `workflow_dispatch` only, kept for historical reference). Repo compliance is now handled by the Claude Code App on pull requests and the engineering handbook directly. Safe to delete in a future cleanup.
### Workflow templates (`workflow-templates/`)
Starter workflows offered on the org's **Actions → New workflow** page: `ci-python`, `ci-node`, `cdk-deploy`, `sam-deploy`, `dotnet-eb-deploy`, `dependency-review`, `labeler`, `triage`. Each is a thin caller of the corresponding reusable workflow above (`triage` is standalone). Every template has a paired `properties.json` (name, description, icon, `filePatterns` for auto-suggestion). Replace any `REPLACE-ME` placeholders before enabling.
@ -46,21 +44,13 @@ Third-party action refs across the org follow a tiered policy:
- **Common first-party actions** (`actions/checkout`, `actions/dependency-review-action`, `actions/github-script`) are pinned to a **major tag** (`@v7`, `@v5`, …) and kept current by Dependabot version updates gated by CI.
- **Org reusable workflows** are referenced at **`@main`** (`uses: Sea-Haven-Industries/.github/.github/workflows/…@main`). This is deliberate: caller and callable share one trust domain, and pinning callers to a SHA would freeze every consumer against central fixes. Templates in `workflow-templates/` follow the same `@main` convention.
### PR Reviews
PR reviews are handled by the **official Claude Code GitHub App** (installed org-wide, enabled as a required check in the org ruleset) — there is **no review workflow in this repo**. The earlier custom `claude-code-review.yaml` reusable workflow and its per-repo wrapper were retired on 2026-05-13 when the App took over.
### Scripts
**`scripts/rollout-review-workflow.sh`** — **Legacy / superseded.** One-time script that pushed the old PR-review wrapper workflow to all org repos. Obsolete since reviews moved to the official Claude Code App (2026-05-13); retained only for historical reference.
### AWS deploy roles & IAM (`oidc-deploy-roles.yaml`)
**`oidc-deploy-roles.yaml`** is a **bootstrap CloudFormation stack** (`github-oidc-deploy-roles`, us-east-1, account 328440206208) that owns the IAM the CI/CD workflows assume. It contains:
- The GitHub Actions **OIDC provider** (conditional — already exists in the account).
- One **OIDC deploy role per repo** (`githubdeploy-<repo>`), assumed by that repo's `deploy.yaml` via OIDC and passed in as `AWS_DEPLOY_ROLE_ARN`. CDK repos use these to assume the `cdk-hnb659fds-*` bootstrap roles; SAM repos use these to run `sam deploy`.
- The shared **SAM CloudFormation execution role** `github-cfn-execution-role` (`SamCfnExecutionRole`) — passed as `cfn-role-arn` by every SAM `deploy.yaml` (see §5). CloudFormation assumes it to provision the SAM stacks' resources.
- The shared **SAM CloudFormation execution role** `github-cfn-execution-role` (`SamCfnExecutionRole`) — passed as `cfn-role-arn` by every SAM `deploy.yaml` (see §3). CloudFormation assumes it to provision the SAM stacks' resources.
- The **`seahaven-lambda-execution-boundary`** managed policy.
- The **`seahaven-cfn-exec-iam-management`** managed policy (`SamCfnIamManagementPolicy`), attached to `github-cfn-execution-role`. It holds that role's boundary-gated IAM statements plus the Deny backstops that keep the permissions boundary from being detached, rewritten, or applied to the deploy substrate's own roles. It lives in a managed policy rather than inline because the role's inline policies sit at 10,006 of IAM's hard 10,240-byte per-role limit; attached managed policies have a separate 6,144-byte budget.
@ -121,39 +111,17 @@ Recovery in either case is an administrator action, not a pipeline retry: clear
## Setup
### 1. Create a GitHub App
### 1. Org-level secrets
1. Go to **Organization Settings > Developer settings > GitHub Apps > New GitHub App**
2. Name it `claude-code-ci` (or similar)
3. Set Homepage URL to your org URL
4. Disable Webhook (uncheck "Active")
5. Set these **Repository permissions:**
- **Contents:** Read and write
- **Issues:** Read and write
- **Metadata:** Read-only
- **Pull requests:** Read and write
6. Set **Where can this app be installed?** to "Only on this account"
7. Click **Create GitHub App**
8. Note the **App ID** from the app's settings page
9. Under **Private keys**, click **Generate a private key** — save the `.pem` file
Managed under **Organization Settings > Secrets and variables > Actions**. Each is set to **selected repositories** visibility — grant it to a repo before a workflow there can read it.
### 2. Install the App
| Secret | Value | Consumed by |
|--------|-------|-------------|
| `ANTHROPIC_API_KEY` | Anthropic API key | `reviewer-eval.yml` in `open-swe` |
1. From the app's settings page, click **Install App**
2. Select `Sea-Haven-Industries`
3. Choose **All repositories**
The CI and CD workflows below need no org secret — CD authenticates to AWS via OIDC using the per-repo `AWS_DEPLOY_ROLE_ARN` secret (see §3).
### 3. Add org-level secrets
Go to **Organization Settings > Secrets and variables > Actions** and add:
| Secret | Value |
|--------|-------|
| `ANTHROPIC_API_KEY` | Your Claude API key |
| `CLAUDE_CI_APP_ID` | The App ID from step 1 |
| `CLAUDE_CI_APP_PRIVATE_KEY` | The full contents of the `.pem` file from step 1 |
### 4. Add CI to a repo
### 2. Add CI to a repo
Create `.github/workflows/ci.yaml` in the target repo. Examples:
@ -218,7 +186,7 @@ jobs:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
```
### 5. Add CD to a repo
### 3. Add CD to a repo
Create `.github/workflows/deploy.yaml` in the target repo. Requires `AWS_DEPLOY_ROLE_ARN` repo secret.
@ -323,7 +291,3 @@ Enable optional steps as repos adopt them:
| `run-typecheck` | `true` | Repo has `tsconfig.json` |
| `run-cdk-synth` | `true` | Repo is CDK-based |
| `run-sam-validate` | `true` (Python) / `false` (TS) | Repo has a SAM template |
### 6. PR reviews
PR reviews run via the **official Claude Code GitHub App** — install it on the org and enable it as a required check in the ruleset. No per-repo workflow or rollout is needed; the legacy `rollout-review-workflow.sh` is retained only for historical reference.

View file

@ -1,84 +0,0 @@
#!/usr/bin/env bash
set -euo pipefail
ORG="Sea-Haven-Industries"
BRANCH="add-claude-review"
WORKFLOW_PATH=".github/workflows/claude-review.yaml"
COMMIT_MSG="Add Claude Code review workflow"
WORKFLOW_CONTENT='name: Claude Code Review
on:
pull_request:
types: [opened, synchronize]
permissions:
contents: read
pull-requests: write
id-token: write
jobs:
review:
uses: Sea-Haven-Industries/.github/.github/workflows/claude-code-review.yaml@main
secrets:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
'
SKIP_REPOS=(".github" "shoc-frontend-new" "shoc-backend")
should_skip() {
local repo="$1"
for skip in "${SKIP_REPOS[@]}"; do
if [[ "$repo" == "$skip" ]]; then
return 0
fi
done
return 1
}
echo "Fetching non-archived repos from $ORG..."
repos=$(gh repo list "$ORG" --no-archived --json name --jq '.[].name' --limit 100)
for repo in $repos; do
if should_skip "$repo"; then
echo "SKIP $repo (in skip list)"
continue
fi
echo ""
echo "--- $repo ---"
if gh api "repos/$ORG/$repo/contents/$WORKFLOW_PATH" --jq '.sha' > /dev/null 2>&1; then
echo "SKIP $repo (workflow already exists)"
continue
fi
default_branch=$(gh api "repos/$ORG/$repo" --jq '.default_branch')
encoded=$(echo -n "$WORKFLOW_CONTENT" | base64)
gh api "repos/$ORG/$repo/git/refs" \
-f "ref=refs/heads/$BRANCH" \
-f "sha=$(gh api "repos/$ORG/$repo/git/ref/heads/$default_branch" --jq '.object.sha')" \
2>/dev/null || true
gh api "repos/$ORG/$repo/contents/$WORKFLOW_PATH" \
-X PUT \
-f "message=$COMMIT_MSG" \
-f "content=$encoded" \
-f "branch=$BRANCH" \
> /dev/null
pr_url=$(gh pr create \
--repo "$ORG/$repo" \
--base "$default_branch" \
--head "$BRANCH" \
--title "$COMMIT_MSG" \
--body "Adds a thin workflow that delegates PR reviews to the central reusable workflow in \`Sea-Haven-Industries/.github\`. Requires the \`ANTHROPIC_API_KEY\` org secret to be set." \
2>/dev/null || echo "PR already exists")
echo "DONE $repo → $pr_url"
done
echo ""
echo "Rollout complete. Review and merge the PRs, then delete the feature branches."