* ci: emit ci-complete from self-CI for the CI complete ruleset
* fix(ci): keep a temporary ci / ci alias until the ruleset cutover
* revert: drop the temporary ci / ci alias; the ruleset cutover landed
* feat(cd): add Python HCP Lambda zip deploy reusable (PLAT-251)
cd-hcp-lambda-python.yaml mirrors cd-hcp-lambda.yaml for repos whose
packager is a shell script. The caller provides
scripts/package_lambdas.sh --git-sha --out-dir --only <key>, which writes
build/packages/<key>.zip with build_info.py carrying the commit. The
ship-gate step is unchanged.
After update-function-code settles, each function's CodeSha256 must equal
the base64 SHA-256 of the local zip and LastUpdateStatus must be Successful.
These functions have no health URL, so the digest is the live-state check.
* chore(ci): retrigger checks after the GitHub Actions incident
Optional inputs so a matrix caller can publish small static trees that have
no index page. Defaults keep the current seahaven-site behavior: the build
runs npm ci --ignore-scripts && npm run build, index.html is required, and
the served hash of / is polled after invalidation.
- build-command runs under bash -euo pipefail
- index-required: false skips the local and bucket index.html checks
- verify-path picks the local file and served URL used for the hash poll;
a trailing slash means index.html, and .. is rejected
- header documents a matrix caller keyed on ssm-prefix
* ci(terraform): fail mixed app and Terraform changes
* fix(ci): count deletions and honor the Terraform working directory
Deleted paths were excluded from the isolation diff, so a mixed change could pass. The checker now treats working-directory as the Terraform prefix.
* fix(ci): load the isolation checker from this workflow's commit
The second checkout used the caller's SHA and the caller's token, so a private clone of this repo could not resolve the script. The checker is now a composite action referenced with $/.
Pull request tokens use repo:ORG/seahaven-org-baseline:pull_request.
Merge queue tokens use the gh-readonly-queue ref. The previous
refs/pull/* subject never matched either.
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
Drops the management-account deploy roles for front-integrations,
afi-backup-monitor, exec-aide, seahaven-door-unlock-api, and
apm-wo-analysis. CloudTrail showed no successful mutation for 14 days.
Deploying this stack deletes those roles. This change does not deploy it.
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* feat(iam): add org-baseline Access Analyzer CI role (PLAT-234)
Adds githubdeploy-seahaven-org-baseline-policy-check with only
ValidatePolicy and CheckNoNewAccess, trusted for main and pull_request.
The deploy role stays limited to main and CDK assume.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* docs(iam): point the policy-check role at its CI job (PLAT-234)
The Access Analyzer checks live in seahaven-org-baseline pull request 160.
This role is only the principal that job assumes.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* fix(iam): match the default pull request OIDC subject (PLAT-234)
Trust refs/pull/* so seahaven-org-baseline pull request tokens can assume
the policy-check role. The immutable subject claim is not enabled.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
Collect-only and subproject-tests were unused on most callers. Pytest stays a caller-owned job. The reusable now emits lint plus the ci / ci aggregator.
* feat(ci): add HCP reusable workflows and drop Mergify
Callers can pin org Fargate/SPA CD and parallel CI instead of copying per-repo deploy jobs.
* chore(ci): remove deprecated PR policy reusable
policy / pr is no longer a required check. Drop the callable, its unit tests, and the setup docs so callers stop pinning a retired gate.
Mutable tags and the dependency-review v5 branch executed inside every consumer, including OIDC deploy jobs. SHA pins with version comments match the policy scanner and let Renovate advance them.
* ci: expand labeler globs and skip dependabot pr policy
.NET product paths never matched app, so backend PRs stayed unlabeled. Dependabot PRs still ran commit-subject and pin checks on generated titles. Skip those PRs in the reusable policy job.
* fix(labeler): match nested elastic beanstalk config paths
Root-only .ebextensions and .platform globs miss api/.ebextensions in monorepos. Mirror the Dockerfile nested form.