Commit graph

6 commits

Author SHA1 Message Date
70439c3b21 Add multi-team approval gate reusable workflow
CODEOWNERS cannot require approval from two distinct teams on the same
files (multiple owners on a line is any-one/OR; separate lines are
last-match-wins). shoc-backend and shoc-frontend-new need every PR to be
approved by BOTH the external dev team and the internal-dev senior group,
so a custom gate is the only way to express that AND.

callable-required-review.yaml passes only when every team named in
all-of-teams has at least one approving review. Team membership is an org
read the default GITHUB_TOKEN cannot do, so the caller supplies a GitHub
App token (Members: read + Pull requests: read); no write scopes are
needed because the job's own pass/fail is the required status check. It
re-evaluates on pull_request and pull_request_review, and ignores author
self-reviews and non-decisive COMMENTED reviews.

Actions are SHA-pinned (Dependabot github-actions ecosystem already
covers this repo). The all-of-teams input is read via env, never
interpolated into the script body, to avoid Actions script injection.
2026-06-18 16:08:33 -04:00
Adam Moussa
e9263123c7
docs: fix README review drift + add community-health files (#48)
INFRA-69: README documented the deleted claude-code-review.yaml workflow and
its rollout as the live PR-review setup. PR reviews are handled by the official
Claude Code App (since 2026-05-13); corrected the workflow list, added a PR
Reviews note, marked the legacy rollout script, and replaced the obsolete
rollout step. Preserved the claude-code-ci App + secrets (compliance-audit
still uses them).

INFRA-68: add SECURITY.md (private vuln reporting via GitHub advisory / email)
and SUPPORT.md (Jira INFRA, handbook, security pointer).
2026-06-10 15:35:31 -04:00
Adam Moussa
b4d9c32a9c
docs: document github-oidc-deploy-roles stack + permissions boundary (#47)
The bootstrap IAM stack (oidc-deploy-roles.yaml) had no README coverage:
how to deploy it manually (no CD pipeline; >51KB needs --s3-bucket), the
scoped github-cfn-execution-role contract, and the
seahaven-lambda-execution-boundary ceiling for SAM Lambda roles.

Documents the INFRA-97 / INFRA-103 work.
2026-06-10 15:03:34 -04:00
Adam Moussa
9a8d1f7736
Add reusable CD workflows and OIDC deploy roles template (#11)
Two reusable deploy workflows (cd-sam.yaml, cd-cdk.yaml) for
GitHub Actions OIDC-based deployments. CloudFormation template
provisions per-repo deploy roles for all 10 deployable repos.
2026-05-08 16:45:57 -04:00
Adam Moussa
d042bd7bdc
Add reusable CI workflows for Python/SAM and TypeScript/CDK repos (#9)
Parameterized workflows that each repo calls via a thin 3-5 line
caller. All lint, test, and validate steps are toggleable so repos
can adopt incrementally. Covers Python SAM, Python CDK, TypeScript
CDK, and Node.js SAM stacks.
2026-05-08 14:25:21 -04:00
Adam Moussa
e24004415e Add Claude Code review and compliance audit workflows
- Reusable PR review workflow (repos call via thin wrapper)
- Weekly compliance audit across all org repos
- Rollout script to push wrapper workflow to all repos
- Uses GitHub App tokens for cross-repo auth (no PAT rotation needed)
2026-05-06 15:10:48 -04:00