Codifies the handbook PR description format (Summary/Validation/Tests/
Notes) as the default template GitHub prefills for every repo in the org
that lacks its own. Hidden hint comments carry the title, scope, and Jira
linking conventions so contributors fill in structure instead of a blank
box.
Adds read + (dis)associate wafv2 actions so SAM/CFN deploys can attach the shared
seahaven-app-waf CloudFront WebACL to app distributions (meal-order orders).
Without it, the WebACL association fails 'Unable to verify read permissions on
Web ACL'. IAM cross-reviewed (no BLOCK). Not wafv2:* — scoped to read +
associate. Same manual-changeset deploy path as the H-16 change.
The SAM template secret check grepped the 5 lines after `Environment:` for
API_KEY|SECRET|TOKEN|PASSWORD|WEBHOOK. That flags env var *names* like
`SLACK_BOT_TOKEN_SECRET: my-app/slack-token`, whose value is a Secrets
Manager id — i.e. the recommended pattern — so any well-architected
template failed CI.
Match on the value's shape instead: known inline secret formats (Slack
xox* tokens, AWS AKIA keys, GitHub gh*_/PAT tokens, sk- keys, PEM private
keys). Secrets Manager references and intrinsic functions no longer trip
it, while pasted real secrets still fail the build.
- New githubdeploy-seahaven-account-baseline OIDC role (CDK pattern: assumes
cdk-hnb659fds-*, scoped to the repo's main branch). Wires CD for the shared
account-baseline repo (CloudTrail C-1 + AWS Backup C-7).
- Codify cloudfront:* and ssm:* on github-cfn-execution-role to reconcile
out-of-band drift (audit H-16). These are needed by live SAM deploys
(meal-order CloudFront; afterhours/payments/meal-order SSM params).
Deployed via change set wire-account-baseline-and-h16; stack now IN_SYNC.
IAM cross-review completed (new role confirmed; cfn-exec breadth documented).
Mirrors the existing per-repo deploy roles (StringLike sub claim, scoped to
repo:<org>/apm-wo-analysis:ref:refs/heads/main, sts:AssumeRole on
cdk-hnb659fds-* only). Cross-reviewed (cross_reviewer): additive, no existing
role modified; the one flagged item (StringLike->StringEquals) was a false
positive — all 8 existing roles use StringLike, so this is consistent.
Extend ci-typescript-cdk and cd-cdk with working-directory,
dotnet pre-build, and post-deploy script inputs. Add new
ci-dotnet and cd-mobile-ios reusable workflows.
Double backslash in single quotes makes ERE match a literal
backslash instead of a dot. No .gitignore entry could pass
this check. Affects both CDK and SAM CI workflows.
* Add QEMU support to CI CDK workflow for cross-platform Docker builds
Mirrors the enable-qemu input from cd-cdk.yaml. Required when CDK
stacks use PythonFunction or other Docker-bundled constructs targeting
arm64 Lambda on x86 CI runners.
* Increase CI timeout for QEMU CDK builds
* Bump default Node.js version to 24 across all reusable workflows
npm 11 (Node 24) generates lockfileVersion 3 which breaks npm ci
on Node 22's npm 10 for repos with aws-cdk-lib bundled deps.
* Add lightweight conventions check to CI workflows
Validates README exists, .env in .gitignore, arm64 architecture,
and log retention in synthesized templates. Runs by default,
opt-out via run-conventions-check: false.
* Add pre-flight stack status checks to CD workflows
Blocks deploy if the CloudFormation stack is in ROLLBACK_COMPLETE,
FAILED, or IN_PROGRESS state. Prevents wasted deploy attempts on
stacks that need manual intervention.
* Add post-deploy health checks to CD workflows
Verifies stack status after deploy, prints outputs, and runs
project-specific scripts/health-check.sh if present.
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Mirrors the enable-qemu input from cd-cdk.yaml. Required when CDK
stacks use PythonFunction or other Docker-bundled constructs targeting
arm64 Lambda on x86 CI runners.
Use GitHub App token (CLAUDE_CI_APP_ID) for cross-repo access when
dispatching reviews via workflow_dispatch. Remove issue_comment,
pull_request_review_comment, and review_requested triggers since
org-level workflows don't propagate those events to other repos.
* Change Claude Code review to on-demand via @claude or review request
Replace automatic PR triggers (opened, ready_for_review) with on-demand
triggers: @claude mentions in PR comments, inline review comments, and
review requests from the 'claude' team.
* Remove unreachable workflow_call event check
workflow_call invocations inherit the caller's event_name, so
github.event_name == 'workflow_call' never matches. The caller's
event context passes through and is handled by the existing
issue_comment/review_requested conditions.
* Fix workflow_call invocations being silently skipped
Add a direct_call boolean input (defaults to true) to workflow_call
so reusable workflow callers bypass the event-specific filtering gate.
Without this, callers triggered by e.g. pull_request opened would
hit the pull_request branch which requires requested_team.slug == 'claude',
causing a silent no-op.
* Fix compliance audit workflow and source standards from handbook
- Add missing permissions (id-token, contents, issues) for OIDC auth
and issue creation
- Fix direct_prompt → prompt (direct_prompt is not a valid input)
- Check out engineering-handbook repo as authoritative standards source
instead of hardcoding the checklist in the workflow
- Create compliance label on-the-fly if it doesn't exist in target repo
* Fix compliance audit violation detection
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
- SQS/EC2/SNS as inline policy (managed policy quota is 10)
- cd-sam.yaml now accepts optional parameter-overrides input for
SAM templates with required parameters
- Add cloudformation:CreateChangeSet on aws:transform/* to the shared
CFN execution role (required for SAM's Serverless transform)
- Remove working-directory from pip install step so it finds
requirements.txt at repo root (not just cdk-dir)
Enables Python CDK repos (po-ingest, workorder-ingest) to use the
same reusable workflow. Adds run-cdk-synth, cdk-dir, and node-version
inputs. Refactors dependency install to be shared between pytest and
cdk synth paths.
Parameterized workflows that each repo calls via a thin 3-5 line
caller. All lint, test, and validate steps are toggleable so repos
can adopt incrementally. Covers Python SAM, Python CDK, TypeScript
CDK, and Node.js SAM stacks.
- Reusable PR review workflow (repos call via thin wrapper)
- Weekly compliance audit across all org repos
- Rollout script to push wrapper workflow to all repos
- Uses GitHub App tokens for cross-repo auth (no PAT rotation needed)