Add reusable CI workflows for Python/SAM and TypeScript/CDK repos (#9)

Parameterized workflows that each repo calls via a thin 3-5 line
caller. All lint, test, and validate steps are toggleable so repos
can adopt incrementally. Covers Python SAM, Python CDK, TypeScript
CDK, and Node.js SAM stacks.
This commit is contained in:
Adam Moussa 2026-05-08 14:25:21 -04:00 • committed by GitHub
parent 086c6e1341
commit d042bd7bdc
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 217 additions and 1 deletions

65
.github/workflows/ci-python-sam.yaml vendored Normal file
View file

@ -0,0 +1,65 @@
name: CI — Python / SAM
on:
workflow_call:
inputs:
python-version:
description: "Python version to use"
type: string
default: "3.12"
source-dirs:
description: "Space-separated directories for ruff (default: repo root)"
type: string
default: "."
run-tests:
description: "Run pytest"
type: boolean
default: false
run-sam-validate:
description: "Run sam validate --lint"
type: boolean
default: true
sam-template:
description: "Path to SAM template file"
type: string
default: "template.yaml"
jobs:
ci:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: ${{ inputs.python-version }}
- name: Install ruff
run: pip install ruff
- name: Ruff check
run: ruff check ${{ inputs.source-dirs }}
- name: Ruff format check
run: ruff format --check ${{ inputs.source-dirs }}
- name: Install test dependencies
if: ${{ inputs.run-tests }}
run: |
pip install pytest
for req in $(find . -name requirements.txt -not -path './.aws-sam/*'); do
pip install -r "$req"
done
- name: Run tests
if: ${{ inputs.run-tests }}
run: pytest
- name: Setup SAM CLI
if: ${{ inputs.run-sam-validate }}
uses: aws-actions/setup-sam@v2
- name: SAM validate
if: ${{ inputs.run-sam-validate }}
run: sam validate --lint --template ${{ inputs.sam-template }}

View file

@ -0,0 +1,72 @@
name: CI — TypeScript / CDK
on:
workflow_call:
inputs:
node-version:
description: "Node.js version to use"
type: string
default: "22"
run-typecheck:
description: "Run tsc --noEmit"
type: boolean
default: true
run-lint:
description: "Run ESLint (requires eslint config in repo)"
type: boolean
default: false
run-tests:
description: "Run Jest"
type: boolean
default: false
run-cdk-synth:
description: "Run cdk synth"
type: boolean
default: true
run-sam-validate:
description: "Run sam validate --lint (for Node.js SAM repos)"
type: boolean
default: false
sam-template:
description: "Path to SAM template file"
type: string
default: "template.yaml"
jobs:
ci:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: ${{ inputs.node-version }}
cache: npm
- name: Install dependencies
run: npm ci
- name: Type check
if: ${{ inputs.run-typecheck }}
run: npx tsc --noEmit
- name: Lint
if: ${{ inputs.run-lint }}
run: npx eslint .
- name: Run tests
if: ${{ inputs.run-tests }}
run: npx jest
- name: CDK synth
if: ${{ inputs.run-cdk-synth }}
run: npx cdk synth --quiet
- name: Setup SAM CLI
if: ${{ inputs.run-sam-validate }}
uses: aws-actions/setup-sam@v2
- name: SAM validate
if: ${{ inputs.run-sam-validate }}
run: sam validate --lint --template ${{ inputs.sam-template }}

View file

@ -6,6 +6,10 @@ Organization-level GitHub configuration for Sea Haven Industries.
### Reusable Workflows
**`.github/workflows/ci-python-sam.yaml`** — Reusable CI workflow for Python / SAM repos. Runs `ruff check` + `ruff format --check`, optional `pytest`, and optional `sam validate --lint`. Also usable for Python CDK repos by disabling SAM validate.
**`.github/workflows/ci-typescript-cdk.yaml`** — Reusable CI workflow for TypeScript / CDK repos. Runs `npm ci` + optional `tsc --noEmit`, optional ESLint, optional Jest, and optional `cdk synth`. Also supports Node.js SAM repos via an optional `sam validate` step.
**`.github/workflows/claude-code-review.yaml`** — Reusable PR review workflow powered by Claude Code. Individual repos call this via a thin wrapper workflow. Reviews for code correctness, security issues, and Sea Haven conventions (kebab-case, secrets placement, Lambda defaults).
**`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`.
@ -48,7 +52,82 @@ Go to **Organization Settings > Secrets and variables > Actions** and add:
| `CLAUDE_CI_APP_ID` | The App ID from step 1 |
| `CLAUDE_CI_APP_PRIVATE_KEY` | The full contents of the `.pem` file from step 1 |
### 4. Roll out PR reviews to repos
### 4. Add CI to a repo
Create `.github/workflows/ci.yaml` in the target repo. Examples:
**Python SAM repo** (e.g., afterhours-shift-manager, expense-approval-bot):
```yaml
name: CI
on:
pull_request:
branches: [main]
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main
```
**TypeScript CDK repo** (e.g., seahaven-door-unlock-api, seahaven-slack-bot):
```yaml
name: CI
on:
pull_request:
branches: [main]
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
```
**Node.js SAM repo** (e.g., payments-dashboard):
```yaml
name: CI
on:
pull_request:
branches: [main]
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
with:
run-typecheck: false
run-cdk-synth: false
run-sam-validate: true
```
**Mixed stack** (e.g., exec-aide — TypeScript CDK + Python Lambdas):
```yaml
name: CI
on:
pull_request:
branches: [main]
jobs:
python:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main
with:
source-dirs: "src"
run-sam-validate: false
typescript:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
```
Enable optional steps as repos adopt them:
| Input | Default | Turn on when... |
|-------|---------|-----------------|
| `run-tests` | `false` | Repo has `pytest` tests or Jest tests |
| `run-lint` | `false` | Repo has an ESLint config |
| `run-typecheck` | `true` | Repo has `tsconfig.json` |
| `run-cdk-synth` | `true` | Repo is CDK-based |
| `run-sam-validate` | `true` (Python) / `false` (TS) | Repo has a SAM template |
### 5. Roll out PR reviews to repos
```bash
./scripts/rollout-review-workflow.sh