Commit graph

93 commits

Author SHA1 Message Date
71447a20a7
ci: add concurrency to ci-python-app + fix sam-deploy template (INFRA-136)
Add job-level concurrency (cancel-in-progress) to all four ci-python-app
jobs, matching the ci-python-sam idiom. Per-job group keys include
github.job so the parallel jobs in a single run do not share a group.

Replace sam-deploy starter-template stack-name: $default-branch (which
GitHub substitutes to the literal branch name main) with a
REPLACE-ME-stack-name placeholder, and point cfn-role-arn at the real
shared github-cfn-execution-role.
2026-07-08 16:28:32 -04:00
Adam Moussa
fc75158c94
docs: refresh .github README and workflow-templates (INFRA-142) (#73)
- README: mark compliance-audit.yaml deprecated (2026-06-10), document all
  12 reusable workflows (was 6), add workflow-templates and action-pinning
  policy sections
- dependency-review.yml template: convert to thin caller of
  callable-dependency-review.yaml (was inlining dependency-review-action@v4,
  drifted from callable @v5)
- callable-dependency-review.yaml: preserve comment-summary-in-pr on-failure
  and grant pull-requests: write
- add labeler.yml + labeler.properties.json starter template
2026-07-08 16:21:37 -04:00
Adam Moussa
4eff8bbc6d
chore(ci): SHA-pin mutable-tag third-party actions (INFRA-118) (#72)
Some checks failed
ci / ci / ci (push) Has been cancelled
2026-07-06 18:26:29 -04:00
dependabot[bot]
fd60e4c904
Bump the minor-and-patch group with 2 updates (#71)
Some checks are pending
ci / ci / ci (push) Waiting to run
Bumps the minor-and-patch group with 2 updates: [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `ruby/setup-ruby` from 1.314.0 to 1.316.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](9eb537ca03...d45b1a4e94)

Updates `anthropics/claude-code-action` from 1.0.159 to 1.0.165
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](a92e7c70a4...558b1d6cab)

---
updated-dependencies:
- dependency-name: ruby/setup-ruby
  dependency-version: 1.316.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.165
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-06 17:31:55 -04:00
dependabot[bot]
e732e119e3
Bump anthropics/claude-code-action in the minor-and-patch group (#69)
Some checks failed
ci / ci / ci (push) Has been cancelled
Bumps the minor-and-patch group with 1 update: [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `anthropics/claude-code-action` from 1.0.153 to 1.0.159
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](2fee155104...a92e7c70a4)

---
updated-dependencies:
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.159
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 19:46:13 -04:00
Adam Moussa
49110fa9b6
Merge pull request #68 from Sea-Haven-Industries/chore/checkout-v7
Some checks failed
ci / ci / ci (push) Has been cancelled
chore(ci): bump actions/checkout v6 → v7 across reusable workflows
2026-06-25 11:50:43 -04:00
3a258918e2 chore(ci): bump actions/checkout v6 -> v7 across reusable workflows
actions/checkout v7.0.0 (2026-06-18) is internally an ESM rebuild plus
one behavioral change: it blocks checking out a fork PR head ref under
pull_request_target / workflow_run (PR #2454). No Sea Haven workflow uses
those triggers, so there is no reachable behavior change. The Node 24
runtime requirement already landed at v6, so v6 -> v7 carries no new
runner requirement. All runners here are GitHub-hosted (ubuntu, macos).

Covers all 16 checkout pins across 12 reusable/standalone workflows plus
the dependency-review workflow-template scaffold. Consumers on @main pick
this up automatically on merge.
2026-06-25 11:43:10 -04:00
Adam Moussa
09fa684b37
Merge pull request #67 from Sea-Haven-Industries/infra/ci-typescript-frontend-reusable
Some checks are pending
ci / ci / ci (push) Waiting to run
Add reusable CI workflow for TypeScript front-end apps
2026-06-24 16:45:50 -04:00
2e356920c7 Add reusable CI workflow for TypeScript front-end apps
Adds ci-typescript-frontend.yaml, a workflow_call reusable CI for bundled
TypeScript SPAs (Vite / React / Vue with vitest + Playwright). Existing
reusable CIs do not fit this shape: ci-static is for plain HTML sites and
ci-typescript-cdk targets CDK infra repos.

The workflow runs as a single `ci` job so callers emit the `ci / ci` status
context the org branch-protection rulesets require. Steps: a Sea Haven
standards gate (required npm scripts present, plus a changed-line guard for
AI-tool footers, hook bypasses, and hardcoded secrets), then format:check,
lint, build, unit tests, and an optional Playwright browser smoke. Every step
past the standards gate is individually toggleable, and string inputs are
passed through env to avoid expression injection.

Documents the workflow in the README reusable-workflows list.
2026-06-24 16:42:54 -04:00
dependabot[bot]
945f0b6021
Bump the minor-and-patch group with 2 updates (#65)
Some checks are pending
ci / ci / ci (push) Waiting to run
Bumps the minor-and-patch group with 2 updates: [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `ruby/setup-ruby` from 1.313.0 to 1.314.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](89f90524b8...9eb537ca03)

Updates `anthropics/claude-code-action` from 1.0.149 to 1.0.153
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](4d7e1f0cd8...2fee155104)

---
updated-dependencies:
- dependency-name: ruby/setup-ruby
  dependency-version: 1.314.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.153
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 15:55:42 -04:00
Adam Moussa
6714382a29
Merge pull request #63 from Sea-Haven-Industries/fix/labeler-monorepo-paths
Some checks failed
ci / ci / ci (push) Has been cancelled
fix(labeler): cover monorepo layouts + harden the reusable labeler
2026-06-18 13:43:39 -04:00
d31893d318 fix(labeler): cover monorepo layouts and harden the reusable workflow
The central label rules assumed a root-level project layout
(lib/**, bin/**, cdk/**, src/**), so monorepos that nest components
under top-level dirs (infra/, web/, mobile/, shared/) matched nothing
for those areas. PRs touching only infra/lib/** or web/** ran the
labeler green but received no label.

Label coverage:
- infra: + 'infra/**' (covers infra/lib, infra/bin, infra/cdk.json)
- app:   + 'web/**', 'mobile/**', 'shared/**'
Additions are appended to the existing root paths, so single-project
repos are unaffected; deliberately avoided blanket '**/lib/**' globs
that would mislabel web/src/lib/** as infra.

Hardening rolled in while here:
- Pin actions/labeler to a commit SHA (was the floating @v6 tag)
- Add a per-PR concurrency group with a run_id fallback for non-PR
  callers, so rapid pushes cancel superseded label runs
- Broaden 'ci' (.github/actions/**), 'dependencies'
  (Directory.Packages.props, yarn.lock, pnpm-lock.yaml, Podfile/.lock)
  and 'tests' (JS/TS .test/.spec, pytest test_*.py/conftest,
  .NET *Tests.cs, Java *Test.java, Go, Ruby) globs

Caller repos must already have any label a rule can emit; actions/labeler
does not create missing labels. The org 'infra' label was backfilled
across repos separately.
2026-06-18 13:40:18 -04:00
Adam Moussa
347558820d
Merge pull request #62 from Sea-Haven-Industries/feature/ci-python-app-reusable
Some checks are pending
ci / ci / ci (push) Waiting to run
Add ci-python-app reusable workflow
2026-06-17 17:28:00 -04:00
c36b737af7 Add ci-python-app reusable workflow
Reusable CI for plain Python apps / locally-run tooling that don't deploy via
SAM or CDK. Beyond ruff lint/format + the conventions audit, it adds a
collect-only import check for a root suite whose live run needs secrets, and an
isolated full pytest run for a self-contained subproject dir (whose tests/
package would collide with the root tests/ under one rootdir).

Emits the org-required `ci / ci` via an aggregator job keyed `ci` that gates on
every other job. actionlint-clean.
2026-06-17 17:26:16 -04:00
Adam Moussa
0442339fff
Merge pull request #60 from Sea-Haven-Industries/dependabot/github_actions/actions/setup-python-6
Some checks are pending
ci / ci / ci (push) Waiting to run
Bump actions/setup-python from 5 to 6
2026-06-16 16:00:20 -04:00
Adam Moussa
c2735defa0
Merge branch 'main' into dependabot/github_actions/actions/setup-python-6 2026-06-16 15:59:54 -04:00
Adam Moussa
cfa7512e97
Merge pull request #58 from Sea-Haven-Industries/dependabot/github_actions/minor-and-patch-02ee58b77d
Bump the minor-and-patch group across 1 directory with 2 updates
2026-06-16 15:59:08 -04:00
Adam Moussa
2ae95530c0
Merge branch 'main' into dependabot/github_actions/minor-and-patch-02ee58b77d 2026-06-16 15:58:37 -04:00
Adam Moussa
23bddc337d
Merge pull request #59 from Sea-Haven-Industries/dependabot/github_actions/aws-actions/setup-sam-3
Bump aws-actions/setup-sam from 2 to 3
2026-06-16 15:58:08 -04:00
dependabot[bot]
6333d5cc34
Bump aws-actions/setup-sam from 2 to 3
Bumps [aws-actions/setup-sam](https://github.com/aws-actions/setup-sam) from 2 to 3.
- [Release notes](https://github.com/aws-actions/setup-sam/releases)
- [Commits](https://github.com/aws-actions/setup-sam/compare/v2...v3)

---
updated-dependencies:
- dependency-name: aws-actions/setup-sam
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-16 19:57:39 +00:00
dependabot[bot]
828187d5bd
Bump the minor-and-patch group across 1 directory with 2 updates
Bumps the minor-and-patch group with 2 updates in the / directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `ruby/setup-ruby` from 1.312.0 to 1.313.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](12fd324f1d...89f90524b8)

Updates `anthropics/claude-code-action` from 1.0.144 to 1.0.149
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](0f97b95b65...4d7e1f0cd8)

---
updated-dependencies:
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.148
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ruby/setup-ruby
  dependency-version: 1.313.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-16 19:55:52 +00:00
Adam Moussa
9bdf7a4063
Merge pull request #61 from Sea-Haven-Industries/ci-actionlint-gate
Wire .github to consume its own reusables: self-CI ci/ci gate + PR labeler
2026-06-16 15:52:35 -04:00
9353a212c3 Run the org PR labeler on .github's own PRs
Add a thin caller so the .github repo invokes its own reusable
callable-labeler.yaml on pull_request, like every consumer repo does. Without a
caller the workflow_call-only labeler never runs on .github's own PRs (this is
why #61 wasn't auto-labeled). Grants the three permissions the reusable requires
(contents:read, pull-requests:write, issues:write).
2026-06-16 15:51:10 -04:00
Adam Moussa
5937ab73e6
Merge branch 'main' into ci-actionlint-gate 2026-06-16 15:46:45 -04:00
2f25ac3535 Add self-CI actionlint gate to satisfy ci/ci ruleset
The org ruleset requires the 'ci / ci' status check on every repo, but this
.github repo only houses reusable (workflow_call) workflows and emitted no such
check — so every PR sat 'Expected — Waiting for status to be reported' and was
unmergeable, including the open Dependabot bumps (#58, #59, #60).

Add a workflow that runs actionlint (pinned, checksum-verified) over the
workflow files. The ruleset matches the required check against the JOB's
check-run name, so the job is named literally 'ci / ci' to emit that exact
context (a job named 'ci' emits context 'ci', which the UI only cosmetically
shows as 'ci / ci'). shellcheck integration is disabled for now; 4 pre-existing
run-step findings are left for a separate cleanup.

Pre-existing checkov IAM findings in oidc-deploy-roles.yaml are accepted-risk
and suppressed via machine-level security-review config, intentionally NOT
committed to this repo.
2026-06-16 15:35:09 -04:00
dependabot[bot]
568a0aacad
Bump actions/setup-python from 5 to 6
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5 to 6.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-15 17:48:51 +00:00
Adam Moussa
e4e4b42ce6
Merge pull request #57 from Sea-Haven-Industries/feature/ci-static-build-support
ci-static: add build mode for templated static sites
2026-06-12 16:40:04 -04:00
e43a9cb447 ci-static: add build mode for templated static sites
Add check-dir + build-command inputs. When build-command is set, run
npm ci + the build, then validate the built output in check-dir (e.g.
_site) instead of repo source. Without this, a site that templates its
HTML (Eleventy etc.) has no source HTML and the checks pass vacuously.

Backward-compatible: defaults (check-dir='.', build-command='') preserve
source-mode behavior for existing callers. build-command is passed via
env to avoid expression injection into the run script.
2026-06-12 16:29:19 -04:00
Adam Moussa
dea18763ee
Add ci-static reusable workflow and content label rule (#56)
- ci-static.yaml: reusable CI for static HTML/CSS/JS sites (S3+CloudFront
  repos with no build framework). Job 'ci' emits the 'ci / ci' status
  context required by the org main-branch ruleset, which static sites
  previously could not satisfy (only ci-dotnet/python-sam/typescript-cdk
  existed). Checks: htmlhint, JSON-LD validity, sitemap well-formedness,
  internal-link/asset resolution, README/.gitignore conventions.
- callable-labeler.yaml: add a 'content' rule (html/css/assets/sitemap/
  robots) so static-site PRs get labeled instead of matching nothing.
2026-06-12 16:05:18 -04:00
dependabot[bot]
06cab504be
Bump actions/labeler from 5 to 6 (#55)
Bumps [actions/labeler](https://github.com/actions/labeler) from 5 to 6.
- [Release notes](https://github.com/actions/labeler/releases)
- [Commits](https://github.com/actions/labeler/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/labeler
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:33:45 -04:00
dependabot[bot]
09135e2992
Bump docker/setup-qemu-action from 3 to 4 (#54)
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 3 to 4.
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](https://github.com/docker/setup-qemu-action/compare/v3...v4)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:30:52 -04:00
dependabot[bot]
e76447c864
Bump actions/dependency-review-action from 4 to 5 (#53)
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4 to 5.
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](https://github.com/actions/dependency-review-action/compare/v4...v5)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:30:48 -04:00
dependabot[bot]
0200ef1f38
Bump actions/setup-node from 4 to 6 (#52)
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 6.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v4...v6)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:30:44 -04:00
dependabot[bot]
e6a0f25b44
Bump the minor-and-patch group with 2 updates (#51)
Bumps the minor-and-patch group with 2 updates: [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `ruby/setup-ruby` from 1.310.0 to 1.312.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](afeafc3d1a...12fd324f1d)

Updates `anthropics/claude-code-action` from 1.0.137 to 1.0.144
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](41ea7642c1...0f97b95b65)

---
updated-dependencies:
- dependency-name: ruby/setup-ruby
  dependency-version: 1.312.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.144
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:30:40 -04:00
Adam Moussa
31bb01d1e9
Add org-wide reusable PR labeler (INFRA-56) (#50)
Add callable-labeler.yaml, a reusable workflow that carries the label
rules inline as the single source of truth and writes them to the runner
at execution time, so caller repos need only a short caller workflow and
no per-repo labeler.yml. Triggered by callers on pull_request (private org
takes no fork PRs); requires contents:read + pull-requests:write +
issues:write on every caller so labeler@v5 can create missing labels.

Remove the workflow-templates/labeler.yml starter it supersedes (no
ruleset workflows-rule or compliance-audit reference depends on it).

Add the repo's own dependabot.yml (github-actions, weekly, grouped
minor+patch) to keep the action pins current per the Pinning Principle.
2026-06-11 13:34:39 -04:00
Adam Moussa
023206e695
chore: deprecate weekly compliance-audit workflow (#49)
Retire the org-wide weekly Compliance Audit. Workflow is disabled in the
Actions tab and the schedule trigger is removed so it cannot run
automatically; manual workflow_dispatch is retained for archival only.
Repo compliance now runs via the Claude Code App on PRs + the engineering
handbook. The 19 open 'Compliance audit: violations found' issues it
generated are being closed.
2026-06-10 18:33:53 -04:00
Adam Moussa
e9263123c7
docs: fix README review drift + add community-health files (#48)
INFRA-69: README documented the deleted claude-code-review.yaml workflow and
its rollout as the live PR-review setup. PR reviews are handled by the official
Claude Code App (since 2026-05-13); corrected the workflow list, added a PR
Reviews note, marked the legacy rollout script, and replaced the obsolete
rollout step. Preserved the claude-code-ci App + secrets (compliance-audit
still uses them).

INFRA-68: add SECURITY.md (private vuln reporting via GitHub advisory / email)
and SUPPORT.md (Jira INFRA, handbook, security pointer).
2026-06-10 15:35:31 -04:00
Adam Moussa
b4d9c32a9c
docs: document github-oidc-deploy-roles stack + permissions boundary (#47)
The bootstrap IAM stack (oidc-deploy-roles.yaml) had no README coverage:
how to deploy it manually (no CD pipeline; >51KB needs --s3-bucket), the
scoped github-cfn-execution-role contract, and the
seahaven-lambda-execution-boundary ceiling for SAM Lambda roles.

Documents the INFRA-97 / INFRA-103 work.
2026-06-10 15:03:34 -04:00
Adam Moussa
385f00d97a
Scope github-cfn-execution-role down from *FullAccess (#46)
The CFN execution role held IAMFullAccess + seven *FullAccess managed
policies, giving it unconstrained AWS admin access. This replaces all
of those with per-service inline statements covering exactly what the
five SAM stacks require during a CloudFormation deploy.

PRIMARY ESCALATION CONTROL: iam:CreateRole, iam:AttachRolePolicy, and
iam:PutRolePolicy are now conditioned on iam:PermissionsBoundary
StringEquals the seahaven-lambda-execution-boundary ARN. Any role the
CFN execution role creates must carry that boundary, capping its
effective permissions at the boundary's ceiling.

SAM RolePath note: AWS::Serverless::Function does not support a custom
RolePath on auto-generated execution roles. Path scoping (e.g.
/cfn-managed/) cannot be used as the escalation guard for SAM auto-roles.
The iam:PermissionsBoundary condition achieves the same security goal.

DEPLOY ORDER DEPENDENCY: the seahaven-lambda-execution-boundary policy
(INFRA-103, PR #45) MUST exist before this stack is deployed. See the
PR description for the mandatory three-step deploy sequence.

Refs: INFRA-97
2026-06-10 14:31:50 -04:00
Adam Moussa
291a62b00d
INFRA-103: Add seahaven-lambda-execution-boundary managed policy (#45)
* Add seahaven-lambda-execution-boundary managed policy

Lambda execution roles auto-generated by SAM have no ceiling today —
a misconfigured Policies block could grant excessive permissions that
persist at runtime. This boundary caps every SAM function execution
role at the union of what the five stacks actually need, so the
effective permissions are always the intersection of the role's own
policies and this document.

The policy is a deliberate superset rather than exact-minimum: being
slightly broad is safer than a boundary that breaks functions at
runtime. Per-service scoping will tighten in follow-up work.

SAM template agents: add
  PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
to Globals.Function in all five stacks after this stack deploys.

Refs: INFRA-103

* Fix boundary gaps found in GPT-4.1 cross-review

Three issues from the mandatory IAM cross-review (BLOCK/FIX):

1. Add KMS statement — PaymentsDashboard DynamoDB table and
   payments-dashboard CloudWatch log groups use CMKs. Without
   kms:Decrypt + kms:GenerateDataKey in the boundary, those Lambda
   calls fail at the KMS layer at runtime. Scoped to account keys only.

2. Add table/*/index/* to DynamoDB resource — dynamodb:Query on a GSI
   requires the index ARN; covering only table/* silently denied GSI
   queries at the boundary.

3. Fix EC2 ENI statement — remove AssignPrivateIpAddresses /
   UnassignPrivateIpAddresses (EFA-only, not part of Lambda ENI
   lifecycle); add DescribeSubnets + DescribeSecurityGroups + DescribeVpcs
   which are required by the Lambda service during VPC attachment and are
   present in AWSLambdaVPCAccessExecutionRole.

4. Add SES configuration-set/* resource — ses:SendRawEmail requires
   permission on the configuration set if one is passed at send time.

Refs: INFRA-103
2026-06-10 14:14:31 -04:00
Adam Moussa
7f84f9cfde
INFRA-58 INFRA-59: org starter workflows + issue templates (#43)
* INFRA-59: add org issue templates (bug, feature, infra-change) + config

Adds .github/ISSUE_TEMPLATE/ with bug_report.md, feature_request.md,
infra-change.md (change-control: impact, rollback plan, affected stacks),
and config.yml disabling blank issues + routing ops to INFRA Jira.

* INFRA-58: add org starter workflows wrapping reusable workflows

Adds workflow-templates/ with starters + .properties.json for:
ci-node, ci-python, cdk-deploy, sam-deploy, dependency-review, labeler,
triage. CI/CD starters call the org reusable workflows in
.github/.github/workflows/ at @main with their required inputs/secrets.
2026-06-05 17:26:16 -04:00
Adam Moussa
23584a53c8
chore(ci): remove dependabot-auto-merge workflow (#42)
The org ruleset now requires 1 approving review + code-owner review, so
auto-merge can never complete without a human approval — the workflow
only added a no-op (or erroring) check to every PR. Repo-level 'Allow
auto-merge' was also disabled on several repos, making the gh pr merge
--auto call fail benignly. The required-workflow rule referencing this
file was removed from org ruleset 15869156 first.
2026-06-05 15:28:57 -04:00
Adam Moussa
31b02e466e
fix(ci): disambiguate concurrency groups across sibling reusable-CI callers (#41)
The group key ci-${{ github.workflow }}-${{ github.ref }} resolves
identically for every job in a caller workflow (github.workflow is the
caller's name in a reusable workflow), so repos calling two reusable CI
workflows from one ci.yaml (e.g. exec-aide python + typescript) had
their jobs cancel each other on every run.

Prefix each group with the reusable workflow's own filename and append
its distinguishing input (source-dirs / working-directory) so sibling
jobs get distinct groups while superseded runs of the same job still
cancel.
2026-06-05 12:30:58 -04:00
Adam Moussa
1cc7236ef6
fix(ci): drop pull-requests write from callable-dependency-review (#40)
Callers grant no explicit permissions, so they pass the org default
read-only token. A reusable workflow cannot request more than its
caller grants, causing startup_failure on every dependency-review run.
dependency-review-action only needs contents: read when not posting
PR comments.
2026-06-05 12:19:06 -04:00
Adam Moussa
2e74e2a670
Pin third-party actions to full commit SHAs (#39)
Replace mutable v1 tag references with immutable commit SHAs so a
compromised or force-moved tag cannot inject code into reusable
workflows. Each pin keeps a # v1 comment for readability.

- claude-code-action in compliance-audit.yaml
- ruby/setup-ruby in cd-mobile-ios.yaml (v1 branch)
2026-06-05 12:13:12 -04:00
Adam Moussa
62d82eae29
Add cancel-in-progress concurrency to reusable CI (#38)
Superseded CI runs on the same ref keep consuming runners and delay
feedback on the latest push. Add a job-level concurrency group keyed
on github.workflow and github.ref so a new push cancels the in-flight
CI run for that branch.

Concurrency is set at the job level rather than the workflow level
because these are workflow_call reusable workflows: workflow-level
concurrency would resolve github.workflow against the caller's context,
collapsing unrelated callers into one group. cd-* deploy workflows are
intentionally left untouched to avoid cancelling in-flight deploys.
2026-06-05 12:12:55 -04:00
Adam Moussa
7aab740e59
chore(ci): bump configure-aws-credentials to v6 (#35)
Bump all aws-actions/configure-aws-credentials references to @v6 (org
target) across the reusable CD workflows. v6 is the verified org standard
alongside actions/checkout@v6.

Ref: engineering-handbook cicd.md (workflow standardization).
2026-06-05 12:12:30 -04:00
Adam Moussa
73b98a66ac
chore(ci): bump actions/checkout to v6 (#34)
Bump all actions/checkout references to @v6 (org target). v4 runs on a
node runtime version that is being deprecated; v6 is the verified org
standard alongside configure-aws-credentials@v6.

Ref: engineering-handbook cicd.md (workflow standardization).
2026-06-05 12:11:44 -04:00
Adam Moussa
81189e6476
Add org-wide default CODEOWNERS (#37)
Set @amoussa1229 as the default owner for all paths so the new
required code-owner review rule on the org main-branch ruleset has
a reviewer to resolve against. The .github repo CODEOWNERS acts as
the org-wide fallback for repos without their own file.
2026-06-05 12:11:40 -04:00
Adam Moussa
3f4bf4f54d
Add dependency-review workflow and Sea Haven PR checklist (#36)
Add a reusable callable-dependency-review workflow that runs
actions/dependency-review-action with fail-on-severity: high, and
append a Sea Haven checklist to the PR template covering infra,
secrets, PITR, Slack, Confluence, memory, and cross-review.
2026-06-05 12:11:36 -04:00