From a36e1501483c139d5ed0cbcaf957fc9df4cfa5dc Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Tue, 14 Jul 2026 19:24:08 -0400 Subject: [PATCH] docs: repoint cross-family review to security-review cross_review.py (orchestrator archived) (#31) --- .claude/agents/classifier-engineer.md | 2 +- CLAUDE.md | 4 ++-- docs/BUILD.md | 6 +++--- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.claude/agents/classifier-engineer.md b/.claude/agents/classifier-engineer.md index d6ee9f2..a5bfa7e 100644 --- a/.claude/agents/classifier-engineer.md +++ b/.claude/agents/classifier-engineer.md @@ -23,5 +23,5 @@ Resolution policy: comment intent wins when confident; fall back to structured s ## Guardrails - Do not invent buckets without checking the canonical taxonomy in `CLAUDE.md`; if a new bucket is warranted, propose it with the supporting comment samples and counts. -- Changes to the Lambda handler signature or its IAM require the mandatory `cross_reviewer` pass (see project `CLAUDE.md`). Flag when your change crosses that line. +- Changes to the Lambda handler signature or its IAM require the mandatory `cross_reviewer` pass (see project `CLAUDE.md`; orchestrator since archived — use `cross_review.py` in `security-review`). Flag when your change crosses that line. - Never silently drop rows. Blank-comment rows are excluded from the classified total by design; say so when reporting counts. diff --git a/CLAUDE.md b/CLAUDE.md index 4c2d971..a79e52d 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -91,7 +91,7 @@ The export reaches S3 by **direct upload or a local drop-folder**, never SES/ema - **kebab-case** everything (repo, stack, bucket, Lambda, role). Buckets `apm-wo-analysis-*-328440206208`. - **Secrets → Secrets Manager** (`apm-wo-analysis/anthropic-api-key`); operational config → SSM. -- **Mandatory cross-review** (`cross_reviewer`, GPT-4.1) on any IAM/policy change or Lambda handler-signature change before merge. Flag as outstanding if the orchestrator is unavailable. +- **Mandatory cross-review** (`cross_reviewer`, GPT-4.1) on any IAM/policy change or Lambda handler-signature change before merge — run via `python3 ~/Documents/repositories/seahaven/security-review/cross_review.py ""` (orchestrator archived 2026-07-14; cross_reviewer now lives in the `security-review` repo). Flag as outstanding if `cross_review.py` is unavailable. - Smoke-test the classifier against a **real export** before declaring any classification change done (see the pre-action-smoke-test preference). - README + the Confluence "AWS Architecture Map" (page 1540098) updated **in the same work** as any architecture change. Update the `apm-wo-comment-analysis` project memory on status/resource changes. @@ -104,7 +104,7 @@ Repo-specific subagents live in `.claude/agents/`: - **slack-blockkit-designer** — owns the daily post / alert / modal Block Kit. - **grafana-author** — owns the dashboards-as-code JSON and Athena SQL. -Most build work (CDK, Lambda code, git, deploys) stays native. Delegate the IAM/handler review to `cross_reviewer`; use the `sh-*` skills at provisioning, review, and documentation boundaries. +Most build work (CDK, Lambda code, git, deploys) stays native. Delegate the IAM/handler review to `cross_reviewer` (orchestrator since archived; use `cross_review.py` in `security-review`); use the `sh-*` skills at provisioning, review, and documentation boundaries. --- diff --git a/docs/BUILD.md b/docs/BUILD.md index 1cb9a77..a7e1767 100644 --- a/docs/BUILD.md +++ b/docs/BUILD.md @@ -2,7 +2,7 @@ End-to-end build instructions. Read `../CLAUDE.md` first for the domain model and locked decisions. Account `328440206208`, region `us-east-1`, all names kebab-case. -> Convention gates that apply throughout: OIDC deploy role created **before** any CD; secrets in Secrets Manager; `cross_reviewer` on IAM/handler diffs; `ruff` clean + `cdk synth` green before push; README + Confluence + memory updated as part of the work, not after. +> Convention gates that apply throughout: OIDC deploy role created **before** any CD; secrets in Secrets Manager; `cross_reviewer` on IAM/handler diffs (orchestrator since archived; use `cross_review.py` in `security-review`); `ruff` clean + `cdk synth` green before push; README + Confluence + memory updated as part of the work, not after. ## Target repo layout @@ -114,9 +114,9 @@ aws s3 cp ./Sheet1-1.xlsx s3://apm-wo-analysis-exports-328440206208/raw/ **2.3 Runtime:** Python 3.12, ARM64, 512 MB, 120 s. Layer: `awswrangler` (AWS SDK for pandas) ARM64 managed layer. IAM: read `raw/`, write `analytics/`, read the Anthropic secret, Glue `CreatePartition`/`BatchCreatePartition`. -**2.4 Cross-review (MANDATORY):** the handler signature + IAM policy diff go through `cross_reviewer` before merge: +**2.4 Cross-review (MANDATORY):** the handler signature + IAM policy diff go through `cross_reviewer` before merge (orchestrator archived; `cross_reviewer` now lives in `security-review`): ```bash -python3 ~/Documents/repositories/orchestrator/run.py "Review this diff for breaking changes: " +python3 ~/Documents/repositories/seahaven/security-review/cross_review.py "Review this diff for breaking changes: " ``` **Validate (smoke test):** `pytest tests/test_classify.py` runs `classify()` over the sample export and asserts "Other" ≤ ~10% and that known fixtures land in the right buckets. Use the `classifier-engineer` agent for tuning.