From 10f72b4a33f8540389e8eb3ee28f98027b50a7a9 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Sat, 26 Sep 2026 16:52:30 -0400 Subject: [PATCH] docs(review): retire security and cross-family review gates Those reviews are no longer merge gates. A new deploy workflow still needs its job_workflow_ref on the deploy role. --- AGENTS.md | 6 ------ cicd.md | 2 +- code-review.md | 8 -------- terraform-project-layout.md | 2 +- 4 files changed, 2 insertions(+), 16 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 52e477e..d9c9c58 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -22,12 +22,6 @@ State verifiable facts only. Do not cite the handbook to justify changes. Allowed types: `feat` `fix` `docs` `style` `refactor` `perf` `test` `build` `ci` `chore` `revert` `release`. -## Security Gates - -Changes touching payment flows, authentication, secrets, IaC/IAM, or untrusted user input require -a security review. IAM role, policy, or resource-permission changes require cross-family review. -Lambda handler-signature changes alone do not trigger cross-family review. - ## CI and SHA Pins Pin every GitHub Actions ref to a full commit SHA with an inline version comment: diff --git a/cicd.md b/cicd.md index d850204..6c8f12a 100644 --- a/cicd.md +++ b/cicd.md @@ -142,7 +142,7 @@ IAM role `githubdeploy-`, owned by workload Terraform. - `job_workflow_ref`: `Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@*` (and `cd-hcp-spa.yaml`) - `workflow_ref`: the thin caller still `Sea-Haven-Industries//.github/workflows/deploy-api.yaml@refs/heads/main` and `@refs/tags/v*` -Adding a reusable is a cross-family IAM change. Adding an app still adds `workflow_ref` for that caller. Do not pin trust to only `ref:refs/heads/main`. +Adding an app adds `workflow_ref` for that caller. Do not pin trust to only `ref:refs/heads/main`. **Permissions.** Only what the workflows write: diff --git a/code-review.md b/code-review.md index d549ed7..7cc946c 100644 --- a/code-review.md +++ b/code-review.md @@ -50,14 +50,6 @@ When a reviewer identifies a finding that won't be addressed in the current PR, Deferred findings handled informally (retro notes, mental to-do lists, "we'll get to it") fall through the cracks. A ticket in the Jira backlog is the minimum bar for accountability. -## Security Review Gates - -Two separate gates apply to security-sensitive changes: - -**Cross-family review (`cross_review.py`):** Required when the change touches IAM roles, IAM policies, or resource permission boundaries. Run the stateless GPT cross-reviewer via `cross_review.py` in the `security-review` repo. It produces findings-to-verify, not a gospel verdict. After two rounds without convergence, stop and disposition the remainder with Adam. Lambda handler signatures are not a cross-review trigger. - -**Security review:** Required when the change touches sensitive authentication paths, secrets handling, IaC/IAM definitions, payment flows, or surfaces that accept untrusted input. These surfaces warrant a structured security review pass in addition to standard code review. - ## Turnaround - Aim to review within one business day of being requested diff --git a/terraform-project-layout.md b/terraform-project-layout.md index 3b478f6..1adb2dd 100644 --- a/terraform-project-layout.md +++ b/terraform-project-layout.md @@ -43,7 +43,7 @@ Write `//deploy/*` (see [hcp-terraform.md](hcp-terraform.md#deploy-contrac ### `iam_github_deploy.tf` -The `githubdeploy-` role only. Trust and permissions are in [cicd.md](cicd.md#github-deploy-role). Adding a deploy workflow means adding its `job_workflow_ref` here. That is a cross-family IAM change. +The `githubdeploy-` role only. Trust and permissions are in [cicd.md](cicd.md#github-deploy-role). Adding a deploy workflow means adding its `job_workflow_ref` here. Do **not** add `hcp_iam.tf`. `hcptf-` and `hcptf--plan` live in `seahaven-org-baseline`.