diff --git a/README.md b/README.md index e214539..7b38817 100644 --- a/README.md +++ b/README.md @@ -17,7 +17,7 @@ Engineering conventions and best practices for Sea Haven Industries. - [Code Review](code-review.md) -- what to look for, giving feedback, turnaround expectations - [Code Review Rubric](code-review-rubric.md) -- BLOCK/FIX/NIT/QUESTION finding categories and output format - [GitHub Standards](github-standards.md) -- branch defaults, repo hygiene, Dependabot -- [AWS Infrastructure](aws-infrastructure.md) -- SAM vs CDK, Lambda defaults, CloudFormation +- [AWS Infrastructure](aws-infrastructure.md) -- SAM vs CDK, HCP VCS file triggers, Lambda defaults, CloudFormation - [SAM Project Layout](sam-project-layout.md) -- standard directory structure for serverless projects - [CDK Project Layout](cdk-project-layout.md) -- standard directory structure for CDK projects - [Lambda Starter Template](lambda-template.md) -- minimal SAM scaffold for a new Python Lambda diff --git a/aws-infrastructure.md b/aws-infrastructure.md index b28019e..6621f70 100644 --- a/aws-infrastructure.md +++ b/aws-infrastructure.md @@ -8,6 +8,16 @@ - Every deployed resource should be managed by IaC (CloudFormation via SAM/CDK, or HCP Terraform state for migrated stacks) - No manually-created Lambdas, roles, or other resources outside of IaC +## HCP Terraform VCS file triggers + +New prod/dev HCP workspaces follow the first-apply runbook in `seahaven-org-baseline`. When the workspace is created, set VCS file triggers before the first merge to the tracked branch. + +- Keep `file-triggers-enabled`. Do not turn file triggers off so that docs-only commits skip prod applies. +- `trigger-prefixes` are added to the working directory. `trigger-patterns` replace the working-directory filter and must include a glob for that directory. +- If the plan reads files outside the working directory (Lambda source, layers, `requirements.txt`, build scripts that copy `src/`, `functions/`, `lambda/`, or `lambdas/`), list those paths in `trigger-prefixes` or `trigger-patterns`. An empty pair with `working-directory=terraform` queues runs only for `terraform/` changes, so a source-only merge is ingested and then silently skipped. +- Record the live prefixes or patterns in the app README next to the workspace name. +- `python3 scripts/check_hcp_workspace_triggers.py` in `seahaven-org-baseline` lists file-triggered workspaces in `seahaven-mgmt`, `seahaven-prod`, and `seahaven-dev` and flags an empty prefix/pattern pair when the repo working directory references those source trees. + ## Lambda Defaults These apply to every Lambda in every project. Verify, don't assume.