Adds read + (dis)associate wafv2 actions so SAM/CFN deploys can attach the shared
seahaven-app-waf CloudFront WebACL to app distributions (meal-order orders).
Without it, the WebACL association fails 'Unable to verify read permissions on
Web ACL'. IAM cross-reviewed (no BLOCK). Not wafv2:* — scoped to read +
associate. Same manual-changeset deploy path as the H-16 change.
The SAM template secret check grepped the 5 lines after `Environment:` for
API_KEY|SECRET|TOKEN|PASSWORD|WEBHOOK. That flags env var *names* like
`SLACK_BOT_TOKEN_SECRET: my-app/slack-token`, whose value is a Secrets
Manager id — i.e. the recommended pattern — so any well-architected
template failed CI.
Match on the value's shape instead: known inline secret formats (Slack
xox* tokens, AWS AKIA keys, GitHub gh*_/PAT tokens, sk- keys, PEM private
keys). Secrets Manager references and intrinsic functions no longer trip
it, while pasted real secrets still fail the build.
- New githubdeploy-seahaven-account-baseline OIDC role (CDK pattern: assumes
cdk-hnb659fds-*, scoped to the repo's main branch). Wires CD for the shared
account-baseline repo (CloudTrail C-1 + AWS Backup C-7).
- Codify cloudfront:* and ssm:* on github-cfn-execution-role to reconcile
out-of-band drift (audit H-16). These are needed by live SAM deploys
(meal-order CloudFront; afterhours/payments/meal-order SSM params).
Deployed via change set wire-account-baseline-and-h16; stack now IN_SYNC.
IAM cross-review completed (new role confirmed; cfn-exec breadth documented).
Mirrors the existing per-repo deploy roles (StringLike sub claim, scoped to
repo:<org>/apm-wo-analysis:ref:refs/heads/main, sts:AssumeRole on
cdk-hnb659fds-* only). Cross-reviewed (cross_reviewer): additive, no existing
role modified; the one flagged item (StringLike->StringEquals) was a false
positive — all 8 existing roles use StringLike, so this is consistent.
Extend ci-typescript-cdk and cd-cdk with working-directory,
dotnet pre-build, and post-deploy script inputs. Add new
ci-dotnet and cd-mobile-ios reusable workflows.
Double backslash in single quotes makes ERE match a literal
backslash instead of a dot. No .gitignore entry could pass
this check. Affects both CDK and SAM CI workflows.
* Add QEMU support to CI CDK workflow for cross-platform Docker builds
Mirrors the enable-qemu input from cd-cdk.yaml. Required when CDK
stacks use PythonFunction or other Docker-bundled constructs targeting
arm64 Lambda on x86 CI runners.
* Increase CI timeout for QEMU CDK builds
* Bump default Node.js version to 24 across all reusable workflows
npm 11 (Node 24) generates lockfileVersion 3 which breaks npm ci
on Node 22's npm 10 for repos with aws-cdk-lib bundled deps.
* Add lightweight conventions check to CI workflows
Validates README exists, .env in .gitignore, arm64 architecture,
and log retention in synthesized templates. Runs by default,
opt-out via run-conventions-check: false.
* Add pre-flight stack status checks to CD workflows
Blocks deploy if the CloudFormation stack is in ROLLBACK_COMPLETE,
FAILED, or IN_PROGRESS state. Prevents wasted deploy attempts on
stacks that need manual intervention.
* Add post-deploy health checks to CD workflows
Verifies stack status after deploy, prints outputs, and runs
project-specific scripts/health-check.sh if present.
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Mirrors the enable-qemu input from cd-cdk.yaml. Required when CDK
stacks use PythonFunction or other Docker-bundled constructs targeting
arm64 Lambda on x86 CI runners.
Use GitHub App token (CLAUDE_CI_APP_ID) for cross-repo access when
dispatching reviews via workflow_dispatch. Remove issue_comment,
pull_request_review_comment, and review_requested triggers since
org-level workflows don't propagate those events to other repos.
* Change Claude Code review to on-demand via @claude or review request
Replace automatic PR triggers (opened, ready_for_review) with on-demand
triggers: @claude mentions in PR comments, inline review comments, and
review requests from the 'claude' team.
* Remove unreachable workflow_call event check
workflow_call invocations inherit the caller's event_name, so
github.event_name == 'workflow_call' never matches. The caller's
event context passes through and is handled by the existing
issue_comment/review_requested conditions.
* Fix workflow_call invocations being silently skipped
Add a direct_call boolean input (defaults to true) to workflow_call
so reusable workflow callers bypass the event-specific filtering gate.
Without this, callers triggered by e.g. pull_request opened would
hit the pull_request branch which requires requested_team.slug == 'claude',
causing a silent no-op.
* Fix compliance audit workflow and source standards from handbook
- Add missing permissions (id-token, contents, issues) for OIDC auth
and issue creation
- Fix direct_prompt → prompt (direct_prompt is not a valid input)
- Check out engineering-handbook repo as authoritative standards source
instead of hardcoding the checklist in the workflow
- Create compliance label on-the-fly if it doesn't exist in target repo
* Fix compliance audit violation detection
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
- SQS/EC2/SNS as inline policy (managed policy quota is 10)
- cd-sam.yaml now accepts optional parameter-overrides input for
SAM templates with required parameters
- Add cloudformation:CreateChangeSet on aws:transform/* to the shared
CFN execution role (required for SAM's Serverless transform)
- Remove working-directory from pip install step so it finds
requirements.txt at repo root (not just cdk-dir)
Enables Python CDK repos (po-ingest, workorder-ingest) to use the
same reusable workflow. Adds run-cdk-synth, cdk-dir, and node-version
inputs. Refactors dependency install to be shared between pytest and
cdk synth paths.
Parameterized workflows that each repo calls via a thin 3-5 line
caller. All lint, test, and validate steps are toggleable so repos
can adopt incrementally. Covers Python SAM, Python CDK, TypeScript
CDK, and Node.js SAM stacks.
- Reusable PR review workflow (repos call via thin wrapper)
- Weekly compliance audit across all org repos
- Rollout script to push wrapper workflow to all repos
- Uses GitHub App tokens for cross-repo auth (no PAT rotation needed)