The three pages disagreed: two listed Node 24.x while the workstation
page still allowed 22.x or 24.x, and none said anything about 26.x.
State the rule once under Lambda defaults (24.x standard, 22.x legacy
only until the 2027-04-30 deprecation, never 26.x) and have the other
two pages defer to it.
Add a standalone ci workflow so handbook changes get an automated gate.
The job is named literally "ci / ci" to emit the exact status context the
org main-branch-protection ruleset requires.
- markdownlint-cli2 (.markdownlint-cli2.jsonc): MD013/MD060/MD040 relaxed
as noisy docs-style rules; fixed 3 MD032 blank-line-around-list issues.
- lychee link check (lychee.toml): internal + external links, tolerates 429.
Exact pins remain (reproducibility) but the pinned version is kept
current by Dependabot version updates gated by CI + dependency review,
not by a number frozen in the handbook. Blanket dependabot ignore
entries are banned; version-specific ignores only, commented and
temporary. Bundled-dep vulnerabilities are a prompt to advance the
pin, never to dismiss the alert.
2.253.1 bundles fast-uri 3.1.0 (two high-severity GHSAs, unfixable via
overrides since it ships in the tarball). 2.257.0 bundles patched
fast-uri 3.1.2 and passes npm ci (the 2.254.0 breakage that motivated
the old pin was release-specific).
* Update CDK version policy, Node 24 runtime, and GitHub Actions CI/CD
- Pin blessed aws-cdk-lib version (2.253.1) with upgrade procedure
- Update Lambda runtime default from Node 22 to Node 24
- Rewrite CI/CD page to reflect GitHub Actions reusable workflows
(was still referencing CodePipeline/CodeBuild)
* Add pre-push hook for npm ci validation
Catches lock file drift locally before it breaks CI. Includes
install instructions in git-workflow.md.
* Add repo provisioning script
Automates the new-repo checklist: GitHub repo creation, OIDC deploy
role, repo secret, security features, CI/CD workflow stubs, and
pre-push hook installation. Supports both SAM and CDK stack types.
* Add shared VpnEc2Instance CDK construct
Reference construct for the VPN-accessible EC2 pattern used by
file-share and forgejo. Includes VPC/subnet lookup, SG, IAM role,
encrypted EBS, and DLM snapshots. Copy into lib/constructs/.
* Add post-deploy health check template
Template script for project-specific health checks. Copy to
scripts/health-check.sh — CD workflows run it automatically.