Commit graph

196 commits

Author SHA1 Message Date
Adam Moussa
73b98a66ac
chore(ci): bump actions/checkout to v6 (#34)
Bump all actions/checkout references to @v6 (org target). v4 runs on a
node runtime version that is being deprecated; v6 is the verified org
standard alongside configure-aws-credentials@v6.

Ref: engineering-handbook cicd.md (workflow standardization).
2026-06-05 12:11:44 -04:00
Adam Moussa
81189e6476
Add org-wide default CODEOWNERS (#37)
Set @amoussa1229 as the default owner for all paths so the new
required code-owner review rule on the org main-branch ruleset has
a reviewer to resolve against. The .github repo CODEOWNERS acts as
the org-wide fallback for repos without their own file.
2026-06-05 12:11:40 -04:00
Adam Moussa
3f4bf4f54d
Add dependency-review workflow and Sea Haven PR checklist (#36)
Add a reusable callable-dependency-review workflow that runs
actions/dependency-review-action with fail-on-severity: high, and
append a Sea Haven checklist to the PR template covering infra,
secrets, PITR, Slack, Confluence, memory, and cross-review.
2026-06-05 12:11:36 -04:00
Adam Moussa
204958e8d9 Add org-wide pull request template
Codifies the handbook PR description format (Summary/Validation/Tests/
Notes) as the default template GitHub prefills for every repo in the org
that lacks its own. Hidden hint comments carry the title, scope, and Jira
linking conventions so contributors fill in structure instead of a blank
box.
2026-06-02 19:49:22 -04:00
Adam Moussa
2381907236
Grant wafv2 to github-cfn-execution-role for WAF associations (audit M-17) (#33)
Adds read + (dis)associate wafv2 actions so SAM/CFN deploys can attach the shared
seahaven-app-waf CloudFront WebACL to app distributions (meal-order orders).
Without it, the WebACL association fails 'Unable to verify read permissions on
Web ACL'. IAM cross-reviewed (no BLOCK). Not wafv2:* — scoped to read +
associate. Same manual-changeset deploy path as the H-16 change.
2026-06-02 17:19:48 -04:00
Adam Moussa
7eda38e41b
Fix conventions check false-positive on Secrets Manager env var names (#32)
The SAM template secret check grepped the 5 lines after `Environment:` for
API_KEY|SECRET|TOKEN|PASSWORD|WEBHOOK. That flags env var *names* like
`SLACK_BOT_TOKEN_SECRET: my-app/slack-token`, whose value is a Secrets
Manager id — i.e. the recommended pattern — so any well-architected
template failed CI.

Match on the value's shape instead: known inline secret formats (Slack
xox* tokens, AWS AKIA keys, GitHub gh*_/PAT tokens, sk- keys, PEM private
keys). Secrets Manager references and intrinsic functions no longer trip
it, while pasted real secrets still fail the build.
2026-06-01 18:59:44 -04:00
Adam Moussa
f5e93b7933
Add seahaven-account-baseline deploy role; codify cfn-exec cloudfront/ssm (audit H-16) (#31)
- New githubdeploy-seahaven-account-baseline OIDC role (CDK pattern: assumes
  cdk-hnb659fds-*, scoped to the repo's main branch). Wires CD for the shared
  account-baseline repo (CloudTrail C-1 + AWS Backup C-7).
- Codify cloudfront:* and ssm:* on github-cfn-execution-role to reconcile
  out-of-band drift (audit H-16). These are needed by live SAM deploys
  (meal-order CloudFront; afterhours/payments/meal-order SSM params).

Deployed via change set wire-account-baseline-and-h16; stack now IN_SYNC.
IAM cross-review completed (new role confirmed; cfn-exec breadth documented).
2026-05-29 18:28:00 -04:00
Adam Moussa
87318ac8dd Guard npm ci on a lockfile so Python CDK repos (npx) don't fail deploy 2026-05-29 15:42:44 -04:00
Adam Moussa
6db9f44a47 Add githubdeploy-apm-wo-analysis OIDC deploy role
Mirrors the existing per-repo deploy roles (StringLike sub claim, scoped to
repo:<org>/apm-wo-analysis:ref:refs/heads/main, sts:AssumeRole on
cdk-hnb659fds-* only). Cross-reviewed (cross_reviewer): additive, no existing
role modified; the one flagged item (StringLike->StringEquals) was a false
positive — all 8 existing roles use StringLike, so this is consistent.
2026-05-29 13:35:25 -04:00
Adam Moussa
333a9613b5 Add enable-qemu input to CI workflow for arm64 cdk synth bundling 2026-05-29 13:33:00 -04:00
Adam Moussa
c040bfaa22 Update runner to macos-26 for Xcode 26 / iOS 26 SDK requirement 2026-05-19 19:32:19 -04:00
Adam Moussa
dbe7d25bc4
Add monorepo support to reusable workflows (#30)
Extend ci-typescript-cdk and cd-cdk with working-directory,
dotnet pre-build, and post-deploy script inputs. Add new
ci-dotnet and cd-mobile-ios reusable workflows.
2026-05-18 19:10:18 +00:00
Adam Moussa
814b8d4ba5 Fix .env gitignore check regex in CI workflows
Double backslash in single quotes makes ERE match a literal
backslash instead of a dot. No .gitignore entry could pass
this check. Affects both CDK and SAM CI workflows.
2026-05-15 17:53:14 -04:00
Adam Moussa
937e4d8daa
Add QEMU, Node 24, conventions check, pre-flight, and health checks to workflows (#29)
* Add QEMU support to CI CDK workflow for cross-platform Docker builds

Mirrors the enable-qemu input from cd-cdk.yaml. Required when CDK
stacks use PythonFunction or other Docker-bundled constructs targeting
arm64 Lambda on x86 CI runners.

* Increase CI timeout for QEMU CDK builds

* Bump default Node.js version to 24 across all reusable workflows

npm 11 (Node 24) generates lockfileVersion 3 which breaks npm ci
on Node 22's npm 10 for repos with aws-cdk-lib bundled deps.

* Add lightweight conventions check to CI workflows

Validates README exists, .env in .gitignore, arm64 architecture,
and log retention in synthesized templates. Runs by default,
opt-out via run-conventions-check: false.

* Add pre-flight stack status checks to CD workflows

Blocks deploy if the CloudFormation stack is in ROLLBACK_COMPLETE,
FAILED, or IN_PROGRESS state. Prevents wasted deploy attempts on
stacks that need manual intervention.

* Add post-deploy health checks to CD workflows

Verifies stack status after deploy, prints outputs, and runs
project-specific scripts/health-check.sh if present.

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-05-14 18:39:10 -04:00
Adam Moussa
7e03d635fb
Add QEMU support to CI CDK workflow for cross-platform Docker builds (#28)
Mirrors the enable-qemu input from cd-cdk.yaml. Required when CDK
stacks use PythonFunction or other Docker-bundled constructs targeting
arm64 Lambda on x86 CI runners.
2026-05-13 22:08:58 +00:00
Adam Moussa
58447f6d86
Remove custom Claude Code Review workflow (#27)
Replaced by the official Claude Code GitHub App, which handles
@claude mentions, review requests, and PR triggers natively.
2026-05-13 17:40:17 -04:00
Adam Moussa
6b896eb463
Add cross-repo dispatch to Claude Code Review (#26)
Use GitHub App token (CLAUDE_CI_APP_ID) for cross-repo access when
dispatching reviews via workflow_dispatch. Remove issue_comment,
pull_request_review_comment, and review_requested triggers since
org-level workflows don't propagate those events to other repos.
2026-05-13 17:20:29 -04:00
Adam Moussa
5d0349dfa3
Change Claude Code review to on-demand triggers (#25)
* Change Claude Code review to on-demand via @claude or review request

Replace automatic PR triggers (opened, ready_for_review) with on-demand
triggers: @claude mentions in PR comments, inline review comments, and
review requests from the 'claude' team.

* Remove unreachable workflow_call event check

workflow_call invocations inherit the caller's event_name, so
github.event_name == 'workflow_call' never matches. The caller's
event context passes through and is handled by the existing
issue_comment/review_requested conditions.

* Fix workflow_call invocations being silently skipped

Add a direct_call boolean input (defaults to true) to workflow_call
so reusable workflow callers bypass the event-specific filtering gate.
Without this, callers triggered by e.g. pull_request opened would
hit the pull_request branch which requires requested_team.slug == 'claude',
causing a silent no-op.
2026-05-13 16:27:18 -04:00
Adam Moussa
b1b341afe5
Remove stale OIDC roles and add procurement-ingest role (#24)
Deleted roles for archived repos (ring-scheduler-3cx,
workorder-ingest) and renamed po-ingest role to match
the current procurement-ingest repo name.
2026-05-13 14:06:09 -04:00
Adam Moussa
565058ce7a
Remove expense-approval-bot OIDC deploy role (#23)
Expense bot merged into payments-dashboard (PR #28). The standalone
stack and repo are being archived.
2026-05-12 14:04:03 -04:00
Adam Moussa
bcbfd8ebfa
Add OIDC deploy role for front-integrations (#22)
Consolidates front-sla-monitor and google-user-sync into a single
SAM deploy role for the new front-integrations repo.
2026-05-12 13:37:04 -04:00
Adam Moussa
2cab51d032
Fix compliance audit and source standards from handbook (#20)
* Fix compliance audit workflow and source standards from handbook

- Add missing permissions (id-token, contents, issues) for OIDC auth
  and issue creation
- Fix direct_prompt → prompt (direct_prompt is not a valid input)
- Check out engineering-handbook repo as authoritative standards source
  instead of hardcoding the checklist in the workflow
- Create compliance label on-the-fly if it doesn't exist in target repo

* Fix compliance audit violation detection

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-05-11 16:50:59 -04:00
Adam Moussa
6b40091a2b
Update GitHub App token action to v3 (#19)
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-05-11 16:07:50 -04:00
Adam Moussa
e19e455870
Remove profile README — moved to .github-private (#17)
Org profile README only renders from a public .github repo or a
private .github-private repo. Moved there in a788a82.
2026-05-08 18:33:02 -04:00
Adam Moussa
bc67e528bf
Add organization profile README (#16)
Public-facing org landing page with tech stack, active project
catalog, and link to engineering-handbook conventions.
2026-05-08 22:21:22 +00:00
Adam Moussa
fc0cd54b3f
Increase CDK deploy timeout to 30 minutes (#15) 2026-05-08 17:29:28 -04:00
Adam Moussa
ac9bdb3e4d
Move parameter-overrides from input to secret in cd-sam workflow (#14) 2026-05-08 17:22:27 -04:00
Adam Moussa
e00a7c567e
Add SQS/EC2/SNS to CFN execution role and parameter overrides to cd-sam (#13)
- SQS/EC2/SNS as inline policy (managed policy quota is 10)
- cd-sam.yaml now accepts optional parameter-overrides input for
  SAM templates with required parameters
2026-05-08 17:19:02 -04:00
Adam Moussa
b273e5cd5c
Fix CFN execution role transform permission and pip install path (#12)
- Add cloudformation:CreateChangeSet on aws:transform/* to the shared
  CFN execution role (required for SAM's Serverless transform)
- Remove working-directory from pip install step so it finds
  requirements.txt at repo root (not just cdk-dir)
2026-05-08 17:12:03 -04:00
Adam Moussa
9a8d1f7736
Add reusable CD workflows and OIDC deploy roles template (#11)
Two reusable deploy workflows (cd-sam.yaml, cd-cdk.yaml) for
GitHub Actions OIDC-based deployments. CloudFormation template
provisions per-repo deploy roles for all 10 deployable repos.
2026-05-08 16:45:57 -04:00
Adam Moussa
f92ac07ce6
Add optional CDK synth support to Python CI workflow (#10)
Enables Python CDK repos (po-ingest, workorder-ingest) to use the
same reusable workflow. Adds run-cdk-synth, cdk-dir, and node-version
inputs. Refactors dependency install to be shared between pytest and
cdk synth paths.
2026-05-08 15:38:30 -04:00
Adam Moussa
d042bd7bdc
Add reusable CI workflows for Python/SAM and TypeScript/CDK repos (#9)
Parameterized workflows that each repo calls via a thin 3-5 line
caller. All lint, test, and validate steps are toggleable so repos
can adopt incrementally. Covers Python SAM, Python CDK, TypeScript
CDK, and Node.js SAM stacks.
2026-05-08 14:25:21 -04:00
Adam Moussa
086c6e1341
Update Claude review: tighter prompt, tool restrictions, manual dispatch (#8)
* Update Claude review: tighter prompt, tool restrictions, manual dispatch

* Add draft PR guard to skip reviews on draft PRs
2026-05-08 11:09:47 -04:00
Adam Moussa
e8305b3666
Allow all bots to trigger Claude code review (#7)
Bot-initiated PRs (Cursor, Dependabot, etc.) were being rejected by
claude-code-action. Set allowed_bots to '*' so all bot PRs get reviewed.
2026-05-07 20:17:12 -04:00
Adam Moussa
4d816d6a9a
Add Dependabot auto-merge workflow (#6) 2026-05-07 18:45:22 -04:00
Adam Moussa
e431c74f71
Merge pull request #5 from Sea-Haven-Industries/feature/add-pr-trigger
Add pull_request trigger for required workflow ruleset
2026-05-06 20:08:05 -04:00
Adam Moussa
b305a4a887 Add pull_request trigger for required workflow ruleset
Required workflows via rulesets need a pull_request trigger directly.
Falls back to org secret when not called via workflow_call.
2026-05-06 20:01:41 -04:00
Adam Moussa
0da9b01905
Merge pull request #4 from Sea-Haven-Industries/feature/add-id-token-permission
Add id-token permission for claude-code-action
2026-05-06 19:45:00 -04:00
Adam Moussa
0889d0f4e4 Add id-token: write permission for claude-code-action
The action requires OIDC token access even when using an API key directly.
Also updates the rollout script template for future repos.
2026-05-06 19:44:35 -04:00
Adam Moussa
2323416ba8
Merge pull request #3 from Sea-Haven-Industries/feature/fix-workflow-inputs
Fix claude-code-action input names
2026-05-06 19:42:04 -04:00
Adam Moussa
6ab1889bb8 Fix claude-code-action input names
direct_prompt and review_comments are not valid inputs for
claude-code-action@v1. Use prompt instead.
2026-05-06 19:40:31 -04:00
Adam Moussa
4a1d53aca2
Merge pull request #2 from Sea-Haven-Industries/feature/fix-rollout-script
Fix false-positive existence check in rollout script
2026-05-06 18:09:55 -04:00
Adam Moussa
b7502a3bf8 Fix false-positive existence check in rollout script
gh api returns error JSON on 404, which made the variable non-empty.
Check exit code instead of output content.
2026-05-06 18:07:29 -04:00
Adam Moussa
5d3aed93c3
Merge pull request #1 from Sea-Haven-Industries/feature/exclude-shoc-repos
Exclude shoc-frontend-new and shoc-backend from workflows
2026-05-06 18:00:48 -04:00
Adam Moussa
0f166a5a6f Exclude shoc-frontend-new and shoc-backend from review and audit workflows 2026-05-06 17:34:29 -04:00
Adam Moussa
e24004415e Add Claude Code review and compliance audit workflows
- Reusable PR review workflow (repos call via thin wrapper)
- Weekly compliance audit across all org repos
- Rollout script to push wrapper workflow to all repos
- Uses GitHub App tokens for cross-repo auth (no PAT rotation needed)
2026-05-06 15:10:48 -04:00