Commit graph

41 commits

Author SHA1 Message Date
Adam Moussa
7eda38e41b
Fix conventions check false-positive on Secrets Manager env var names (#32)
The SAM template secret check grepped the 5 lines after `Environment:` for
API_KEY|SECRET|TOKEN|PASSWORD|WEBHOOK. That flags env var *names* like
`SLACK_BOT_TOKEN_SECRET: my-app/slack-token`, whose value is a Secrets
Manager id — i.e. the recommended pattern — so any well-architected
template failed CI.

Match on the value's shape instead: known inline secret formats (Slack
xox* tokens, AWS AKIA keys, GitHub gh*_/PAT tokens, sk- keys, PEM private
keys). Secrets Manager references and intrinsic functions no longer trip
it, while pasted real secrets still fail the build.
2026-06-01 18:59:44 -04:00
Adam Moussa
f5e93b7933
Add seahaven-account-baseline deploy role; codify cfn-exec cloudfront/ssm (audit H-16) (#31)
- New githubdeploy-seahaven-account-baseline OIDC role (CDK pattern: assumes
  cdk-hnb659fds-*, scoped to the repo's main branch). Wires CD for the shared
  account-baseline repo (CloudTrail C-1 + AWS Backup C-7).
- Codify cloudfront:* and ssm:* on github-cfn-execution-role to reconcile
  out-of-band drift (audit H-16). These are needed by live SAM deploys
  (meal-order CloudFront; afterhours/payments/meal-order SSM params).

Deployed via change set wire-account-baseline-and-h16; stack now IN_SYNC.
IAM cross-review completed (new role confirmed; cfn-exec breadth documented).
2026-05-29 18:28:00 -04:00
Adam Moussa
87318ac8dd Guard npm ci on a lockfile so Python CDK repos (npx) don't fail deploy 2026-05-29 15:42:44 -04:00
Adam Moussa
6db9f44a47 Add githubdeploy-apm-wo-analysis OIDC deploy role
Mirrors the existing per-repo deploy roles (StringLike sub claim, scoped to
repo:<org>/apm-wo-analysis:ref:refs/heads/main, sts:AssumeRole on
cdk-hnb659fds-* only). Cross-reviewed (cross_reviewer): additive, no existing
role modified; the one flagged item (StringLike->StringEquals) was a false
positive — all 8 existing roles use StringLike, so this is consistent.
2026-05-29 13:35:25 -04:00
Adam Moussa
333a9613b5 Add enable-qemu input to CI workflow for arm64 cdk synth bundling 2026-05-29 13:33:00 -04:00
Adam Moussa
c040bfaa22 Update runner to macos-26 for Xcode 26 / iOS 26 SDK requirement 2026-05-19 19:32:19 -04:00
Adam Moussa
dbe7d25bc4
Add monorepo support to reusable workflows (#30)
Extend ci-typescript-cdk and cd-cdk with working-directory,
dotnet pre-build, and post-deploy script inputs. Add new
ci-dotnet and cd-mobile-ios reusable workflows.
2026-05-18 19:10:18 +00:00
Adam Moussa
814b8d4ba5 Fix .env gitignore check regex in CI workflows
Double backslash in single quotes makes ERE match a literal
backslash instead of a dot. No .gitignore entry could pass
this check. Affects both CDK and SAM CI workflows.
2026-05-15 17:53:14 -04:00
Adam Moussa
937e4d8daa
Add QEMU, Node 24, conventions check, pre-flight, and health checks to workflows (#29)
* Add QEMU support to CI CDK workflow for cross-platform Docker builds

Mirrors the enable-qemu input from cd-cdk.yaml. Required when CDK
stacks use PythonFunction or other Docker-bundled constructs targeting
arm64 Lambda on x86 CI runners.

* Increase CI timeout for QEMU CDK builds

* Bump default Node.js version to 24 across all reusable workflows

npm 11 (Node 24) generates lockfileVersion 3 which breaks npm ci
on Node 22's npm 10 for repos with aws-cdk-lib bundled deps.

* Add lightweight conventions check to CI workflows

Validates README exists, .env in .gitignore, arm64 architecture,
and log retention in synthesized templates. Runs by default,
opt-out via run-conventions-check: false.

* Add pre-flight stack status checks to CD workflows

Blocks deploy if the CloudFormation stack is in ROLLBACK_COMPLETE,
FAILED, or IN_PROGRESS state. Prevents wasted deploy attempts on
stacks that need manual intervention.

* Add post-deploy health checks to CD workflows

Verifies stack status after deploy, prints outputs, and runs
project-specific scripts/health-check.sh if present.

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-05-14 18:39:10 -04:00
Adam Moussa
7e03d635fb
Add QEMU support to CI CDK workflow for cross-platform Docker builds (#28)
Mirrors the enable-qemu input from cd-cdk.yaml. Required when CDK
stacks use PythonFunction or other Docker-bundled constructs targeting
arm64 Lambda on x86 CI runners.
2026-05-13 22:08:58 +00:00
Adam Moussa
58447f6d86
Remove custom Claude Code Review workflow (#27)
Replaced by the official Claude Code GitHub App, which handles
@claude mentions, review requests, and PR triggers natively.
2026-05-13 17:40:17 -04:00
Adam Moussa
6b896eb463
Add cross-repo dispatch to Claude Code Review (#26)
Use GitHub App token (CLAUDE_CI_APP_ID) for cross-repo access when
dispatching reviews via workflow_dispatch. Remove issue_comment,
pull_request_review_comment, and review_requested triggers since
org-level workflows don't propagate those events to other repos.
2026-05-13 17:20:29 -04:00
Adam Moussa
5d0349dfa3
Change Claude Code review to on-demand triggers (#25)
* Change Claude Code review to on-demand via @claude or review request

Replace automatic PR triggers (opened, ready_for_review) with on-demand
triggers: @claude mentions in PR comments, inline review comments, and
review requests from the 'claude' team.

* Remove unreachable workflow_call event check

workflow_call invocations inherit the caller's event_name, so
github.event_name == 'workflow_call' never matches. The caller's
event context passes through and is handled by the existing
issue_comment/review_requested conditions.

* Fix workflow_call invocations being silently skipped

Add a direct_call boolean input (defaults to true) to workflow_call
so reusable workflow callers bypass the event-specific filtering gate.
Without this, callers triggered by e.g. pull_request opened would
hit the pull_request branch which requires requested_team.slug == 'claude',
causing a silent no-op.
2026-05-13 16:27:18 -04:00
Adam Moussa
b1b341afe5
Remove stale OIDC roles and add procurement-ingest role (#24)
Deleted roles for archived repos (ring-scheduler-3cx,
workorder-ingest) and renamed po-ingest role to match
the current procurement-ingest repo name.
2026-05-13 14:06:09 -04:00
Adam Moussa
565058ce7a
Remove expense-approval-bot OIDC deploy role (#23)
Expense bot merged into payments-dashboard (PR #28). The standalone
stack and repo are being archived.
2026-05-12 14:04:03 -04:00
Adam Moussa
bcbfd8ebfa
Add OIDC deploy role for front-integrations (#22)
Consolidates front-sla-monitor and google-user-sync into a single
SAM deploy role for the new front-integrations repo.
2026-05-12 13:37:04 -04:00
Adam Moussa
2cab51d032
Fix compliance audit and source standards from handbook (#20)
* Fix compliance audit workflow and source standards from handbook

- Add missing permissions (id-token, contents, issues) for OIDC auth
  and issue creation
- Fix direct_prompt → prompt (direct_prompt is not a valid input)
- Check out engineering-handbook repo as authoritative standards source
  instead of hardcoding the checklist in the workflow
- Create compliance label on-the-fly if it doesn't exist in target repo

* Fix compliance audit violation detection

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-05-11 16:50:59 -04:00
Adam Moussa
6b40091a2b
Update GitHub App token action to v3 (#19)
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-05-11 16:07:50 -04:00
Adam Moussa
e19e455870
Remove profile README — moved to .github-private (#17)
Org profile README only renders from a public .github repo or a
private .github-private repo. Moved there in a788a82.
2026-05-08 18:33:02 -04:00
Adam Moussa
bc67e528bf
Add organization profile README (#16)
Public-facing org landing page with tech stack, active project
catalog, and link to engineering-handbook conventions.
2026-05-08 22:21:22 +00:00
Adam Moussa
fc0cd54b3f
Increase CDK deploy timeout to 30 minutes (#15) 2026-05-08 17:29:28 -04:00
Adam Moussa
ac9bdb3e4d
Move parameter-overrides from input to secret in cd-sam workflow (#14) 2026-05-08 17:22:27 -04:00
Adam Moussa
e00a7c567e
Add SQS/EC2/SNS to CFN execution role and parameter overrides to cd-sam (#13)
- SQS/EC2/SNS as inline policy (managed policy quota is 10)
- cd-sam.yaml now accepts optional parameter-overrides input for
  SAM templates with required parameters
2026-05-08 17:19:02 -04:00
Adam Moussa
b273e5cd5c
Fix CFN execution role transform permission and pip install path (#12)
- Add cloudformation:CreateChangeSet on aws:transform/* to the shared
  CFN execution role (required for SAM's Serverless transform)
- Remove working-directory from pip install step so it finds
  requirements.txt at repo root (not just cdk-dir)
2026-05-08 17:12:03 -04:00
Adam Moussa
9a8d1f7736
Add reusable CD workflows and OIDC deploy roles template (#11)
Two reusable deploy workflows (cd-sam.yaml, cd-cdk.yaml) for
GitHub Actions OIDC-based deployments. CloudFormation template
provisions per-repo deploy roles for all 10 deployable repos.
2026-05-08 16:45:57 -04:00
Adam Moussa
f92ac07ce6
Add optional CDK synth support to Python CI workflow (#10)
Enables Python CDK repos (po-ingest, workorder-ingest) to use the
same reusable workflow. Adds run-cdk-synth, cdk-dir, and node-version
inputs. Refactors dependency install to be shared between pytest and
cdk synth paths.
2026-05-08 15:38:30 -04:00
Adam Moussa
d042bd7bdc
Add reusable CI workflows for Python/SAM and TypeScript/CDK repos (#9)
Parameterized workflows that each repo calls via a thin 3-5 line
caller. All lint, test, and validate steps are toggleable so repos
can adopt incrementally. Covers Python SAM, Python CDK, TypeScript
CDK, and Node.js SAM stacks.
2026-05-08 14:25:21 -04:00
Adam Moussa
086c6e1341
Update Claude review: tighter prompt, tool restrictions, manual dispatch (#8)
* Update Claude review: tighter prompt, tool restrictions, manual dispatch

* Add draft PR guard to skip reviews on draft PRs
2026-05-08 11:09:47 -04:00
Adam Moussa
e8305b3666
Allow all bots to trigger Claude code review (#7)
Bot-initiated PRs (Cursor, Dependabot, etc.) were being rejected by
claude-code-action. Set allowed_bots to '*' so all bot PRs get reviewed.
2026-05-07 20:17:12 -04:00
Adam Moussa
4d816d6a9a
Add Dependabot auto-merge workflow (#6) 2026-05-07 18:45:22 -04:00
Adam Moussa
e431c74f71
Merge pull request #5 from Sea-Haven-Industries/feature/add-pr-trigger
Add pull_request trigger for required workflow ruleset
2026-05-06 20:08:05 -04:00
Adam Moussa
b305a4a887 Add pull_request trigger for required workflow ruleset
Required workflows via rulesets need a pull_request trigger directly.
Falls back to org secret when not called via workflow_call.
2026-05-06 20:01:41 -04:00
Adam Moussa
0da9b01905
Merge pull request #4 from Sea-Haven-Industries/feature/add-id-token-permission
Add id-token permission for claude-code-action
2026-05-06 19:45:00 -04:00
Adam Moussa
0889d0f4e4 Add id-token: write permission for claude-code-action
The action requires OIDC token access even when using an API key directly.
Also updates the rollout script template for future repos.
2026-05-06 19:44:35 -04:00
Adam Moussa
2323416ba8
Merge pull request #3 from Sea-Haven-Industries/feature/fix-workflow-inputs
Fix claude-code-action input names
2026-05-06 19:42:04 -04:00
Adam Moussa
6ab1889bb8 Fix claude-code-action input names
direct_prompt and review_comments are not valid inputs for
claude-code-action@v1. Use prompt instead.
2026-05-06 19:40:31 -04:00
Adam Moussa
4a1d53aca2
Merge pull request #2 from Sea-Haven-Industries/feature/fix-rollout-script
Fix false-positive existence check in rollout script
2026-05-06 18:09:55 -04:00
Adam Moussa
b7502a3bf8 Fix false-positive existence check in rollout script
gh api returns error JSON on 404, which made the variable non-empty.
Check exit code instead of output content.
2026-05-06 18:07:29 -04:00
Adam Moussa
5d3aed93c3
Merge pull request #1 from Sea-Haven-Industries/feature/exclude-shoc-repos
Exclude shoc-frontend-new and shoc-backend from workflows
2026-05-06 18:00:48 -04:00
Adam Moussa
0f166a5a6f Exclude shoc-frontend-new and shoc-backend from review and audit workflows 2026-05-06 17:34:29 -04:00
Adam Moussa
e24004415e Add Claude Code review and compliance audit workflows
- Reusable PR review workflow (repos call via thin wrapper)
- Weekly compliance audit across all org repos
- Rollout script to push wrapper workflow to all repos
- Uses GitHub App tokens for cross-repo auth (no PAT rotation needed)
2026-05-06 15:10:48 -04:00