mirror of
https://github.com/Sea-Haven-Industries/engineering-handbook.git
synced 2026-09-30 03:23:14 +00:00
docs(review): retire security and cross-family review gates (#50)
Some checks are pending
ci / ci / ci (push) Waiting to run
Some checks are pending
ci / ci / ci (push) Waiting to run
Those reviews are no longer merge gates. A new deploy workflow still needs its job_workflow_ref on the deploy role.
This commit is contained in:
parent
668a9e43bb
commit
b651a74c7e
4 changed files with 2 additions and 16 deletions
|
|
@ -22,12 +22,6 @@ State verifiable facts only. Do not cite the handbook to justify changes.
|
||||||
|
|
||||||
Allowed types: `feat` `fix` `docs` `style` `refactor` `perf` `test` `build` `ci` `chore` `revert` `release`.
|
Allowed types: `feat` `fix` `docs` `style` `refactor` `perf` `test` `build` `ci` `chore` `revert` `release`.
|
||||||
|
|
||||||
## Security Gates
|
|
||||||
|
|
||||||
Changes touching payment flows, authentication, secrets, IaC/IAM, or untrusted user input require
|
|
||||||
a security review. IAM role, policy, or resource-permission changes require cross-family review.
|
|
||||||
Lambda handler-signature changes alone do not trigger cross-family review.
|
|
||||||
|
|
||||||
## CI and SHA Pins
|
## CI and SHA Pins
|
||||||
|
|
||||||
Pin every GitHub Actions ref to a full commit SHA with an inline version comment:
|
Pin every GitHub Actions ref to a full commit SHA with an inline version comment:
|
||||||
|
|
|
||||||
2
cicd.md
2
cicd.md
|
|
@ -142,7 +142,7 @@ IAM role `githubdeploy-<repo>`, owned by workload Terraform.
|
||||||
- `job_workflow_ref`: `Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@*` (and `cd-hcp-spa.yaml`)
|
- `job_workflow_ref`: `Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@*` (and `cd-hcp-spa.yaml`)
|
||||||
- `workflow_ref`: the thin caller still `Sea-Haven-Industries/<repo>/.github/workflows/deploy-api.yaml@refs/heads/main` and `@refs/tags/v*`
|
- `workflow_ref`: the thin caller still `Sea-Haven-Industries/<repo>/.github/workflows/deploy-api.yaml@refs/heads/main` and `@refs/tags/v*`
|
||||||
|
|
||||||
Adding a reusable is a cross-family IAM change. Adding an app still adds `workflow_ref` for that caller. Do not pin trust to only `ref:refs/heads/main`.
|
Adding an app adds `workflow_ref` for that caller. Do not pin trust to only `ref:refs/heads/main`.
|
||||||
|
|
||||||
**Permissions.** Only what the workflows write:
|
**Permissions.** Only what the workflows write:
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -50,14 +50,6 @@ When a reviewer identifies a finding that won't be addressed in the current PR,
|
||||||
|
|
||||||
Deferred findings handled informally (retro notes, mental to-do lists, "we'll get to it") fall through the cracks. A ticket in the Jira backlog is the minimum bar for accountability.
|
Deferred findings handled informally (retro notes, mental to-do lists, "we'll get to it") fall through the cracks. A ticket in the Jira backlog is the minimum bar for accountability.
|
||||||
|
|
||||||
## Security Review Gates
|
|
||||||
|
|
||||||
Two separate gates apply to security-sensitive changes:
|
|
||||||
|
|
||||||
**Cross-family review (`cross_review.py`):** Required when the change touches IAM roles, IAM policies, or resource permission boundaries. Run the stateless GPT cross-reviewer via `cross_review.py` in the `security-review` repo. It produces findings-to-verify, not a gospel verdict. After two rounds without convergence, stop and disposition the remainder with Adam. Lambda handler signatures are not a cross-review trigger.
|
|
||||||
|
|
||||||
**Security review:** Required when the change touches sensitive authentication paths, secrets handling, IaC/IAM definitions, payment flows, or surfaces that accept untrusted input. These surfaces warrant a structured security review pass in addition to standard code review.
|
|
||||||
|
|
||||||
## Turnaround
|
## Turnaround
|
||||||
|
|
||||||
- Aim to review within one business day of being requested
|
- Aim to review within one business day of being requested
|
||||||
|
|
|
||||||
|
|
@ -43,7 +43,7 @@ Write `/<repo>/deploy/*` (see [hcp-terraform.md](hcp-terraform.md#deploy-contrac
|
||||||
|
|
||||||
### `iam_github_deploy.tf`
|
### `iam_github_deploy.tf`
|
||||||
|
|
||||||
The `githubdeploy-<repo>` role only. Trust and permissions are in [cicd.md](cicd.md#github-deploy-role). Adding a deploy workflow means adding its `job_workflow_ref` here. That is a cross-family IAM change.
|
The `githubdeploy-<repo>` role only. Trust and permissions are in [cicd.md](cicd.md#github-deploy-role). Adding a deploy workflow means adding its `job_workflow_ref` here.
|
||||||
|
|
||||||
Do **not** add `hcp_iam.tf`. `hcptf-<repo>` and `hcptf-<repo>-plan` live in `seahaven-org-baseline`.
|
Do **not** add `hcp_iam.tf`. `hcptf-<repo>` and `hcptf-<repo>-plan` live in `seahaven-org-baseline`.
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue