* Add QEMU support to CI CDK workflow for cross-platform Docker builds Mirrors the enable-qemu input from cd-cdk.yaml. Required when CDK stacks use PythonFunction or other Docker-bundled constructs targeting arm64 Lambda on x86 CI runners. * Increase CI timeout for QEMU CDK builds * Bump default Node.js version to 24 across all reusable workflows npm 11 (Node 24) generates lockfileVersion 3 which breaks npm ci on Node 22's npm 10 for repos with aws-cdk-lib bundled deps. * Add lightweight conventions check to CI workflows Validates README exists, .env in .gitignore, arm64 architecture, and log retention in synthesized templates. Runs by default, opt-out via run-conventions-check: false. * Add pre-flight stack status checks to CD workflows Blocks deploy if the CloudFormation stack is in ROLLBACK_COMPLETE, FAILED, or IN_PROGRESS state. Prevents wasted deploy attempts on stacks that need manual intervention. * Add post-deploy health checks to CD workflows Verifies stack status after deploy, prints outputs, and runs project-specific scripts/health-check.sh if present. --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> |
||
|---|---|---|
| .github/workflows | ||
| scripts | ||
| .gitignore | ||
| oidc-deploy-roles.yaml | ||
| README.md | ||
.github
Organization-level GitHub configuration for Sea Haven Industries.
What's in here
Reusable Workflows
.github/workflows/ci-python-sam.yaml — Reusable CI workflow for Python / SAM repos. Runs ruff check + ruff format --check, optional pytest, and optional sam validate --lint. Also usable for Python CDK repos by disabling SAM validate.
.github/workflows/ci-typescript-cdk.yaml — Reusable CI workflow for TypeScript / CDK repos. Runs npm ci + optional tsc --noEmit, optional ESLint, optional Jest, and optional cdk synth. Also supports Node.js SAM repos via an optional sam validate step.
.github/workflows/cd-sam.yaml — Reusable CD workflow for SAM repos. Runs sam build + sam deploy with OIDC credentials and a CloudFormation execution role. Triggers via workflow_call from per-repo deploy.yaml on push to main.
.github/workflows/cd-cdk.yaml — Reusable CD workflow for CDK repos (TypeScript and Python). Runs cdk deploy --all with OIDC credentials. Supports optional Python setup for Python CDK repos and QEMU emulation for cross-platform Docker builds.
.github/workflows/claude-code-review.yaml — Reusable PR review workflow powered by Claude Code. Individual repos call this via a thin wrapper workflow. Reviews for code correctness, security issues, and Sea Haven conventions (kebab-case, secrets placement, Lambda defaults).
.github/workflows/compliance-audit.yaml — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via workflow_dispatch.
Scripts
scripts/rollout-review-workflow.sh — One-time script to push the thin PR review wrapper workflow to all org repos via the GitHub API. Creates a branch and PR on each repo.
Setup
1. Create a GitHub App
- Go to Organization Settings > Developer settings > GitHub Apps > New GitHub App
- Name it
claude-code-ci(or similar) - Set Homepage URL to your org URL
- Disable Webhook (uncheck "Active")
- Set these Repository permissions:
- Contents: Read and write
- Issues: Read and write
- Metadata: Read-only
- Pull requests: Read and write
- Set Where can this app be installed? to "Only on this account"
- Click Create GitHub App
- Note the App ID from the app's settings page
- Under Private keys, click Generate a private key — save the
.pemfile
2. Install the App
- From the app's settings page, click Install App
- Select
Sea-Haven-Industries - Choose All repositories
3. Add org-level secrets
Go to Organization Settings > Secrets and variables > Actions and add:
| Secret | Value |
|---|---|
ANTHROPIC_API_KEY |
Your Claude API key |
CLAUDE_CI_APP_ID |
The App ID from step 1 |
CLAUDE_CI_APP_PRIVATE_KEY |
The full contents of the .pem file from step 1 |
4. Add CI to a repo
Create .github/workflows/ci.yaml in the target repo. Examples:
Python SAM repo (e.g., afterhours-shift-manager, expense-approval-bot):
name: CI
on:
pull_request:
branches: [main]
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main
TypeScript CDK repo (e.g., seahaven-door-unlock-api, seahaven-slack-bot):
name: CI
on:
pull_request:
branches: [main]
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
Node.js SAM repo (e.g., payments-dashboard):
name: CI
on:
pull_request:
branches: [main]
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
with:
run-typecheck: false
run-cdk-synth: false
run-sam-validate: true
Mixed stack (e.g., exec-aide — TypeScript CDK + Python Lambdas):
name: CI
on:
pull_request:
branches: [main]
jobs:
python:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main
with:
source-dirs: "src"
run-sam-validate: false
typescript:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
5. Add CD to a repo
Create .github/workflows/deploy.yaml in the target repo. Requires AWS_DEPLOY_ROLE_ARN repo secret.
SAM repo (e.g., afterhours-shift-manager):
name: Deploy
on:
push:
branches: [main]
jobs:
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@main
with:
stack-name: afterhours-shift-manager
cfn-role-arn: arn:aws:iam::328440206208:role/github-cfn-execution-role
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
TypeScript CDK repo (e.g., seahaven-door-unlock-api):
name: Deploy
on:
push:
branches: [main]
jobs:
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
Python CDK repo (e.g., po-ingest):
name: Deploy
on:
push:
branches: [main]
jobs:
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
with:
python-version: "3.12"
cdk-dir: cdk
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
CDK repo with arm64 Docker builds (e.g., exec-aide):
name: Deploy
on:
push:
branches: [main]
jobs:
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
with:
enable-qemu: true
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
Enable optional steps as repos adopt them:
| Input | Default | Turn on when... |
|---|---|---|
run-tests |
false |
Repo has pytest tests or Jest tests |
run-lint |
false |
Repo has an ESLint config |
run-typecheck |
true |
Repo has tsconfig.json |
run-cdk-synth |
true |
Repo is CDK-based |
run-sam-validate |
true (Python) / false (TS) |
Repo has a SAM template |
6. Roll out PR reviews to repos
./scripts/rollout-review-workflow.sh
This creates a PR on each repo adding the thin wrapper workflow. Review and merge them, then delete the add-claude-review branches.