mirror of
https://github.com/Sea-Haven-Industries/engineering-handbook.git
synced 2026-09-30 03:23:14 +00:00
docs(review): retire security and cross-family review gates (#50)
Some checks are pending
ci / ci / ci (push) Waiting to run
Some checks are pending
ci / ci / ci (push) Waiting to run
Those reviews are no longer merge gates. A new deploy workflow still needs its job_workflow_ref on the deploy role.
This commit is contained in:
parent
668a9e43bb
commit
b651a74c7e
4 changed files with 2 additions and 16 deletions
|
|
@ -22,12 +22,6 @@ State verifiable facts only. Do not cite the handbook to justify changes.
|
|||
|
||||
Allowed types: `feat` `fix` `docs` `style` `refactor` `perf` `test` `build` `ci` `chore` `revert` `release`.
|
||||
|
||||
## Security Gates
|
||||
|
||||
Changes touching payment flows, authentication, secrets, IaC/IAM, or untrusted user input require
|
||||
a security review. IAM role, policy, or resource-permission changes require cross-family review.
|
||||
Lambda handler-signature changes alone do not trigger cross-family review.
|
||||
|
||||
## CI and SHA Pins
|
||||
|
||||
Pin every GitHub Actions ref to a full commit SHA with an inline version comment:
|
||||
|
|
|
|||
2
cicd.md
2
cicd.md
|
|
@ -142,7 +142,7 @@ IAM role `githubdeploy-<repo>`, owned by workload Terraform.
|
|||
- `job_workflow_ref`: `Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@*` (and `cd-hcp-spa.yaml`)
|
||||
- `workflow_ref`: the thin caller still `Sea-Haven-Industries/<repo>/.github/workflows/deploy-api.yaml@refs/heads/main` and `@refs/tags/v*`
|
||||
|
||||
Adding a reusable is a cross-family IAM change. Adding an app still adds `workflow_ref` for that caller. Do not pin trust to only `ref:refs/heads/main`.
|
||||
Adding an app adds `workflow_ref` for that caller. Do not pin trust to only `ref:refs/heads/main`.
|
||||
|
||||
**Permissions.** Only what the workflows write:
|
||||
|
||||
|
|
|
|||
|
|
@ -50,14 +50,6 @@ When a reviewer identifies a finding that won't be addressed in the current PR,
|
|||
|
||||
Deferred findings handled informally (retro notes, mental to-do lists, "we'll get to it") fall through the cracks. A ticket in the Jira backlog is the minimum bar for accountability.
|
||||
|
||||
## Security Review Gates
|
||||
|
||||
Two separate gates apply to security-sensitive changes:
|
||||
|
||||
**Cross-family review (`cross_review.py`):** Required when the change touches IAM roles, IAM policies, or resource permission boundaries. Run the stateless GPT cross-reviewer via `cross_review.py` in the `security-review` repo. It produces findings-to-verify, not a gospel verdict. After two rounds without convergence, stop and disposition the remainder with Adam. Lambda handler signatures are not a cross-review trigger.
|
||||
|
||||
**Security review:** Required when the change touches sensitive authentication paths, secrets handling, IaC/IAM definitions, payment flows, or surfaces that accept untrusted input. These surfaces warrant a structured security review pass in addition to standard code review.
|
||||
|
||||
## Turnaround
|
||||
|
||||
- Aim to review within one business day of being requested
|
||||
|
|
|
|||
|
|
@ -43,7 +43,7 @@ Write `/<repo>/deploy/*` (see [hcp-terraform.md](hcp-terraform.md#deploy-contrac
|
|||
|
||||
### `iam_github_deploy.tf`
|
||||
|
||||
The `githubdeploy-<repo>` role only. Trust and permissions are in [cicd.md](cicd.md#github-deploy-role). Adding a deploy workflow means adding its `job_workflow_ref` here. That is a cross-family IAM change.
|
||||
The `githubdeploy-<repo>` role only. Trust and permissions are in [cicd.md](cicd.md#github-deploy-role). Adding a deploy workflow means adding its `job_workflow_ref` here.
|
||||
|
||||
Do **not** add `hcp_iam.tf`. `hcptf-<repo>` and `hcptf-<repo>-plan` live in `seahaven-org-baseline`.
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue