From d042bd7bdc0ede3367e3701b0831cd6f48110e77 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 8 May 2026 14:25:21 -0400 Subject: [PATCH] Add reusable CI workflows for Python/SAM and TypeScript/CDK repos (#9) Parameterized workflows that each repo calls via a thin 3-5 line caller. All lint, test, and validate steps are toggleable so repos can adopt incrementally. Covers Python SAM, Python CDK, TypeScript CDK, and Node.js SAM stacks. --- .github/workflows/ci-python-sam.yaml | 65 +++++++++++++++++++ .github/workflows/ci-typescript-cdk.yaml | 72 +++++++++++++++++++++ README.md | 81 +++++++++++++++++++++++- 3 files changed, 217 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/ci-python-sam.yaml create mode 100644 .github/workflows/ci-typescript-cdk.yaml diff --git a/.github/workflows/ci-python-sam.yaml b/.github/workflows/ci-python-sam.yaml new file mode 100644 index 0000000..045924d --- /dev/null +++ b/.github/workflows/ci-python-sam.yaml @@ -0,0 +1,65 @@ +name: CI — Python / SAM + +on: + workflow_call: + inputs: + python-version: + description: "Python version to use" + type: string + default: "3.12" + source-dirs: + description: "Space-separated directories for ruff (default: repo root)" + type: string + default: "." + run-tests: + description: "Run pytest" + type: boolean + default: false + run-sam-validate: + description: "Run sam validate --lint" + type: boolean + default: true + sam-template: + description: "Path to SAM template file" + type: string + default: "template.yaml" + +jobs: + ci: + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@v4 + + - uses: actions/setup-python@v5 + with: + python-version: ${{ inputs.python-version }} + + - name: Install ruff + run: pip install ruff + + - name: Ruff check + run: ruff check ${{ inputs.source-dirs }} + + - name: Ruff format check + run: ruff format --check ${{ inputs.source-dirs }} + + - name: Install test dependencies + if: ${{ inputs.run-tests }} + run: | + pip install pytest + for req in $(find . -name requirements.txt -not -path './.aws-sam/*'); do + pip install -r "$req" + done + + - name: Run tests + if: ${{ inputs.run-tests }} + run: pytest + + - name: Setup SAM CLI + if: ${{ inputs.run-sam-validate }} + uses: aws-actions/setup-sam@v2 + + - name: SAM validate + if: ${{ inputs.run-sam-validate }} + run: sam validate --lint --template ${{ inputs.sam-template }} diff --git a/.github/workflows/ci-typescript-cdk.yaml b/.github/workflows/ci-typescript-cdk.yaml new file mode 100644 index 0000000..c0ba138 --- /dev/null +++ b/.github/workflows/ci-typescript-cdk.yaml @@ -0,0 +1,72 @@ +name: CI — TypeScript / CDK + +on: + workflow_call: + inputs: + node-version: + description: "Node.js version to use" + type: string + default: "22" + run-typecheck: + description: "Run tsc --noEmit" + type: boolean + default: true + run-lint: + description: "Run ESLint (requires eslint config in repo)" + type: boolean + default: false + run-tests: + description: "Run Jest" + type: boolean + default: false + run-cdk-synth: + description: "Run cdk synth" + type: boolean + default: true + run-sam-validate: + description: "Run sam validate --lint (for Node.js SAM repos)" + type: boolean + default: false + sam-template: + description: "Path to SAM template file" + type: string + default: "template.yaml" + +jobs: + ci: + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@v4 + + - uses: actions/setup-node@v4 + with: + node-version: ${{ inputs.node-version }} + cache: npm + + - name: Install dependencies + run: npm ci + + - name: Type check + if: ${{ inputs.run-typecheck }} + run: npx tsc --noEmit + + - name: Lint + if: ${{ inputs.run-lint }} + run: npx eslint . + + - name: Run tests + if: ${{ inputs.run-tests }} + run: npx jest + + - name: CDK synth + if: ${{ inputs.run-cdk-synth }} + run: npx cdk synth --quiet + + - name: Setup SAM CLI + if: ${{ inputs.run-sam-validate }} + uses: aws-actions/setup-sam@v2 + + - name: SAM validate + if: ${{ inputs.run-sam-validate }} + run: sam validate --lint --template ${{ inputs.sam-template }} diff --git a/README.md b/README.md index fd36bf2..5748a81 100644 --- a/README.md +++ b/README.md @@ -6,6 +6,10 @@ Organization-level GitHub configuration for Sea Haven Industries. ### Reusable Workflows +**`.github/workflows/ci-python-sam.yaml`** — Reusable CI workflow for Python / SAM repos. Runs `ruff check` + `ruff format --check`, optional `pytest`, and optional `sam validate --lint`. Also usable for Python CDK repos by disabling SAM validate. + +**`.github/workflows/ci-typescript-cdk.yaml`** — Reusable CI workflow for TypeScript / CDK repos. Runs `npm ci` + optional `tsc --noEmit`, optional ESLint, optional Jest, and optional `cdk synth`. Also supports Node.js SAM repos via an optional `sam validate` step. + **`.github/workflows/claude-code-review.yaml`** — Reusable PR review workflow powered by Claude Code. Individual repos call this via a thin wrapper workflow. Reviews for code correctness, security issues, and Sea Haven conventions (kebab-case, secrets placement, Lambda defaults). **`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`. @@ -48,7 +52,82 @@ Go to **Organization Settings > Secrets and variables > Actions** and add: | `CLAUDE_CI_APP_ID` | The App ID from step 1 | | `CLAUDE_CI_APP_PRIVATE_KEY` | The full contents of the `.pem` file from step 1 | -### 4. Roll out PR reviews to repos +### 4. Add CI to a repo + +Create `.github/workflows/ci.yaml` in the target repo. Examples: + +**Python SAM repo** (e.g., afterhours-shift-manager, expense-approval-bot): + +```yaml +name: CI +on: + pull_request: + branches: [main] + +jobs: + ci: + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main +``` + +**TypeScript CDK repo** (e.g., seahaven-door-unlock-api, seahaven-slack-bot): + +```yaml +name: CI +on: + pull_request: + branches: [main] + +jobs: + ci: + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main +``` + +**Node.js SAM repo** (e.g., payments-dashboard): + +```yaml +name: CI +on: + pull_request: + branches: [main] + +jobs: + ci: + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main + with: + run-typecheck: false + run-cdk-synth: false + run-sam-validate: true +``` + +**Mixed stack** (e.g., exec-aide — TypeScript CDK + Python Lambdas): + +```yaml +name: CI +on: + pull_request: + branches: [main] + +jobs: + python: + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main + with: + source-dirs: "src" + run-sam-validate: false + typescript: + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main +``` + +Enable optional steps as repos adopt them: + +| Input | Default | Turn on when... | +|-------|---------|-----------------| +| `run-tests` | `false` | Repo has `pytest` tests or Jest tests | +| `run-lint` | `false` | Repo has an ESLint config | +| `run-typecheck` | `true` | Repo has `tsconfig.json` | +| `run-cdk-synth` | `true` | Repo is CDK-based | +| `run-sam-validate` | `true` (Python) / `false` (TS) | Repo has a SAM template | + +### 5. Roll out PR reviews to repos ```bash ./scripts/rollout-review-workflow.sh