Commit graph

9 commits

Author SHA1 Message Date
8c3487b6bc
ci(cd-dotnet-eb): add reusable CD workflow for .NET on Elastic Beanstalk
Publishes a .NET project, packages the output as a bundle, uploads it,
creates an Elastic Beanstalk application version, and updates an
existing environment using OIDC credentials. It deploys to an
environment; it never creates one.

Two deliberate departures from the existing cd-* reusables:

- A concurrency group keyed on application+environment, with
  cancel-in-progress false, so two pushes cannot deploy over each other
  and an in-flight deploy is never aborted midway. The existing cd-*
  workflows have no concurrency group at all.
- No input or secret is interpolated into a run: body; everything goes
  through env-var indirection. The repo's actionlint runs with
  shellcheck disabled, so this is a hand-maintained property.

The post-deploy check polls rather than using the CLI waiter
"elasticbeanstalk wait environment-updated": that waiter is hardcoded to
20 attempts x 20s and the CLI cannot extend it, so a slower rolling
deploy would fail the job while the deployment was still healthy. The
timeout is an input instead. The check asserts status, health and the
running version label -- Elastic Beanstalk reports a rolled-back deploy
as a healthy Ready environment running the previous version, so without
the version assertion the job would go green over a failed deploy.

Replaces the malformed cd-dotnet-eb.yaml.yml stub (doubled extension,
empty on:/jobs:). Adds the matching starter template and README entries.
2026-07-27 17:25:23 -04:00
5a5ab684f6
ci(templates): replace hardcoded management-account role ARN with placeholder
The sam-deploy starter template pointed every new repo's cfn-role-arn at
the management account's execution role, silently landing new workloads
in an account frozen for workloads. The ARN is now a REPLACE-ME
placeholder with guidance to use the github-cfn-execution-role in the
repo's target account.
2026-07-27 16:03:25 -04:00
69b28c6f3a
ci: pin workflow-template refs to commit SHA
Per the updated handbook convention (engineering-handbook PR #18),
reusable-workflow references use full commit SHA pins with a '# main'
comment instead of the mutable @main branch ref. Templates now ship
pinned so new repos start convention-compliant; Dependabot advances
the pin after instantiation. Commented usage examples in ci-static and
ci-typescript-frontend use the <full-commit-sha> placeholder form.
2026-07-27 15:38:18 -04:00
Adam Moussa
7b34404e40
fix/dependency-review-permissions (#86)
Some checks are pending
ci / ci / ci (push) Waiting to run
* fix: drop `pull-requests: write` and 'comment-summary-in-pr: on-failure'

* fix: update dependency-review.yml template to match callable permissions
2026-07-23 11:54:59 -04:00
Adam Moussa
9fa0a71564
ci: add concurrency to ci-python-app + fix sam-deploy template (INFRA-136) (#74)
Some checks failed
ci / ci / ci (push) Has been cancelled
Add job-level concurrency (cancel-in-progress) to all four ci-python-app
jobs, matching the ci-python-sam idiom. Per-job group keys include
github.job so the parallel jobs in a single run do not share a group.

Replace sam-deploy starter-template stack-name: $default-branch (which
GitHub substitutes to the literal branch name main) with a
REPLACE-ME-stack-name placeholder, and point cfn-role-arn at the real
shared github-cfn-execution-role.
2026-07-08 16:32:40 -04:00
Adam Moussa
fc75158c94
docs: refresh .github README and workflow-templates (INFRA-142) (#73)
- README: mark compliance-audit.yaml deprecated (2026-06-10), document all
  12 reusable workflows (was 6), add workflow-templates and action-pinning
  policy sections
- dependency-review.yml template: convert to thin caller of
  callable-dependency-review.yaml (was inlining dependency-review-action@v4,
  drifted from callable @v5)
- callable-dependency-review.yaml: preserve comment-summary-in-pr on-failure
  and grant pull-requests: write
- add labeler.yml + labeler.properties.json starter template
2026-07-08 16:21:37 -04:00
3a258918e2 chore(ci): bump actions/checkout v6 -> v7 across reusable workflows
actions/checkout v7.0.0 (2026-06-18) is internally an ESM rebuild plus
one behavioral change: it blocks checking out a fork PR head ref under
pull_request_target / workflow_run (PR #2454). No Sea Haven workflow uses
those triggers, so there is no reachable behavior change. The Node 24
runtime requirement already landed at v6, so v6 -> v7 carries no new
runner requirement. All runners here are GitHub-hosted (ubuntu, macos).

Covers all 16 checkout pins across 12 reusable/standalone workflows plus
the dependency-review workflow-template scaffold. Consumers on @main pick
this up automatically on merge.
2026-06-25 11:43:10 -04:00
Adam Moussa
31bb01d1e9
Add org-wide reusable PR labeler (INFRA-56) (#50)
Add callable-labeler.yaml, a reusable workflow that carries the label
rules inline as the single source of truth and writes them to the runner
at execution time, so caller repos need only a short caller workflow and
no per-repo labeler.yml. Triggered by callers on pull_request (private org
takes no fork PRs); requires contents:read + pull-requests:write +
issues:write on every caller so labeler@v5 can create missing labels.

Remove the workflow-templates/labeler.yml starter it supersedes (no
ruleset workflows-rule or compliance-audit reference depends on it).

Add the repo's own dependabot.yml (github-actions, weekly, grouped
minor+patch) to keep the action pins current per the Pinning Principle.
2026-06-11 13:34:39 -04:00
Adam Moussa
7f84f9cfde
INFRA-58 INFRA-59: org starter workflows + issue templates (#43)
* INFRA-59: add org issue templates (bug, feature, infra-change) + config

Adds .github/ISSUE_TEMPLATE/ with bug_report.md, feature_request.md,
infra-change.md (change-control: impact, rollback plan, affected stacks),
and config.yml disabling blank issues + routing ops to INFRA Jira.

* INFRA-58: add org starter workflows wrapping reusable workflows

Adds workflow-templates/ with starters + .properties.json for:
ci-node, ci-python, cdk-deploy, sam-deploy, dependency-review, labeler,
triage. CI/CD starters call the org reusable workflows in
.github/.github/workflows/ at @main with their required inputs/secrets.
2026-06-05 17:26:16 -04:00