Commit graph

27 commits

Author SHA1 Message Date
dependabot[bot]
2d873d41bd
Bump actions/checkout from 6 to 7
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-27 19:45:14 +00:00
Adam Moussa
190b683bb3
Merge pull request #19 from Sea-Haven-Industries/ci/sha-pin-workflow-refs
Some checks are pending
ci / ci / ci (push) Waiting to run
ci: pin reusable-workflow refs to commit SHA
2026-07-27 15:44:35 -04:00
75fb1b0890
ci: pin reusable-workflow refs to commit SHA
Pins the labeler caller to the current .github main tip per the SHA-pin
convention (PR #18). Adds dependabot.yml with the github-actions
ecosystem so the pin is advanced weekly; package-ecosystem coverage is
not needed here (no package manifests in this repo).
2026-07-27 15:40:40 -04:00
Adam Moussa
a75623313b
Merge pull request #18 from Sea-Haven-Industries/docs/sha-pin-reusable-workflows
docs(cicd): pin reusable-workflow refs to commit SHAs instead of @main
2026-07-27 15:30:25 -04:00
5f1818cd6b
docs(cicd): pin reusable-workflow refs to commit SHAs instead of @main
The org standard for reusable-workflow references changes from the mutable
@main branch ref to full commit SHA pins advanced by Dependabot. Adds a
Workflow Ref Pinning section covering the rationale and the two
prerequisites that keep pins current (github-actions ecosystem in
dependabot.yml, org-level Dependabot access to the internal .github repo).
2026-07-27 15:28:31 -04:00
Adam Moussa
0e83835b4a
Merge pull request #17 from Sea-Haven-Industries/docs/conventional-commits
Some checks failed
ci / ci / ci (push) Has been cancelled
2026-07-18 03:01:59 -04:00
855b473479
docs: adopt conventional commit format as the org standard
Make Conventional Commits (type(scope): description) the canonical
commit and PR-title format across Sea Haven, replacing the previous
imperative/capitalized/no-prefix rule.

- commit-messages.md: full rewrite to the type(scope): description
  format with the type table, lowercase/imperative description rules,
  breaking-change (! + BREAKING CHANGE footer) guidance tied to SemVer,
  and updated template and examples.
- git-workflow.md: extend the branch-prefix table with chore/, docs/,
  refactor/, and release/ (alongside the existing feature/bug/hotfix),
  mirroring the commit types.
- pull-requests.md: reconcile the title rule to the Conventional Commit
  format.
- README.md: update the commit-messages one-line summary.

Refs: INFRA-57
2026-07-17 19:30:02 -04:00
Adam Moussa
9c65fcb053
ci: add markdown-lint and link-check CI (INFRA-128) (#16)
Some checks failed
ci / ci / ci (push) Has been cancelled
Add a standalone ci workflow so handbook changes get an automated gate.
The job is named literally "ci / ci" to emit the exact status context the
org main-branch-protection ruleset requires.

- markdownlint-cli2 (.markdownlint-cli2.jsonc): MD013/MD060/MD040 relaxed
  as noisy docs-style rules; fixed 3 MD032 blank-line-around-list issues.
- lychee link check (lychee.toml): internal + external links, tolerates 429.
2026-07-08 16:20:28 -04:00
Adam Moussa
dc736da711
Document repository security and merge-setting baseline (#15)
Codify the org security + merge baseline: auto-merge and auto-delete
head branch (no org default, set per-repo), and the secret-scanning /
CodeQL / code-security surface carried by the 'Sea Haven Standard' org
Code Security Configuration. Note docs-repo CodeQL exception and the
shoc-backend/shoc-frontend-new exclusion.
2026-06-18 12:27:31 -04:00
Adam Moussa
132e4fe51d
Document README badges, repo topics, and PR auto-labeler conventions (INFRA-56/57/70) (#14)
Capture the org conventions rolled out in the INFRA-47 hygiene pass:
- github-standards.md: static-only README badges (dynamic shields break on
  private repos; CI badge is member-only) and a lowercase-hyphenated repo
  topic vocabulary, both part of new-repo provisioning.
- cicd.md: the central inline-config reusable PR labeler — pull_request
  trigger, the three required caller permissions, no per-repo labeler.yml.
2026-06-11 14:25:12 -04:00
Adam Moussa
144240884b
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#13) 2026-06-11 14:14:17 -04:00
Adam Moussa
1c11824196
docs: replace frozen 'blessed version' with automated pin-currency policy (#11)
Exact pins remain (reproducibility) but the pinned version is kept
current by Dependabot version updates gated by CI + dependency review,
not by a number frozen in the handbook. Blanket dependabot ignore
entries are banned; version-specific ignores only, commented and
temporary. Bundled-dep vulnerabilities are a prompt to advance the
pin, never to dismiss the alert.
2026-06-05 12:57:35 -04:00
Adam Moussa
bcb4355c36
docs: move blessed aws-cdk-lib pin to 2.257.0 (#10)
2.253.1 bundles fast-uri 3.1.0 (two high-severity GHSAs, unfixable via
overrides since it ships in the tarball). 2.257.0 bundles patched
fast-uri 3.1.2 and passes npm ci (the 2.254.0 breakage that motivated
the old pin was release-specific).
2026-06-05 12:52:50 -04:00
Adam Moussa
8ebf52b5e6
Merge pull request #9 from Sea-Haven-Industries/feature/jira-linking-convention
Add Jira issue-linking convention + handbook index/standards cleanup
2026-06-02 19:37:46 -04:00
Adam Moussa
e00055b8e2 Drop Dependabot PR assignee from GitHub standards
Pinning every Dependabot PR to a single assignee created noise and a
bottleneck. Remove the assignee requirement and the per-ecosystem
assignees blocks from the example configs.
2026-06-02 19:36:09 -04:00
Adam Moussa
e057e8ab84 Add CDK layout and code review rubric to handbook index
Both pages existed in working drafts but were not linked from the
README table of contents, so they were undiscoverable. Add them to the
index alongside the related SAM layout and code review pages.
2026-06-02 19:36:09 -04:00
Adam Moussa
e749e6f651 Add Jira issue-linking convention
Work is tracked in Jira while code lives in GitHub; the org-level GitHub
for Jira app is already installed but nothing told contributors how to
trigger the link. Document putting the Jira key in the branch name, PR
title, or Refs trailer so branches, commits, and PRs thread into the
issue's development panel. Use a generic PROJ-123 placeholder rather
than naming specific projects, which change over time.
2026-06-02 19:36:03 -04:00
Adam Moussa
7d5d04985a Add deferred findings policy to code review page
Require PR authors to create a GitHub issue for any review
finding deferred past the current PR, and link it in the
review thread before merging. Prevents informal tracking
from dropping items.
2026-05-15 17:13:47 -04:00
Adam Moussa
651dff5dd3
Add Bedrock, dev-env, and Lambda template pages (#7)
Adds three handbook pages covering conventions that were previously
scattered across feedback memories or rederived from scratch each
time:

- bedrock.md captures the cross-region inference profile requirement
  for Claude 4.x Bedrock Agents and the alias-version pinning gotcha,
  plus the IAM resource pattern and the KB Docker requirement.
- dev-environment.md documents the workstation directory layout,
  pyenv/Node conventions, the macOS launchd/TCC sandbox gotcha, and
  cleanup cadence.
- lambda-template.md provides a minimal SAM scaffold that follows the
  Lambda defaults already in aws-infrastructure.md (Python 3.12,
  arm64, explicit 60-day log retention, scoped Secrets Manager
  access, module-level secret cache).

Also extends two existing pages:

- sam-project-layout.md gains a Lambda Layers section with the
  BuildMethod nesting pattern that caused a ~22-hour production
  outage when violated.
- naming-conventions.md adds a Legacy Stacks note acknowledging that
  pre-convention PascalCase stacks (SeaHavenDoorUnlockStack,
  WorkorderIngestStack) stay as-is rather than risk stack
  replacement.
2026-05-14 19:50:37 -04:00
Adam Moussa
4b5d39fb91
Add CDK version policy, update Node 24 and GitHub Actions CI/CD (#6)
* Update CDK version policy, Node 24 runtime, and GitHub Actions CI/CD

- Pin blessed aws-cdk-lib version (2.253.1) with upgrade procedure
- Update Lambda runtime default from Node 22 to Node 24
- Rewrite CI/CD page to reflect GitHub Actions reusable workflows
  (was still referencing CodePipeline/CodeBuild)

* Add pre-push hook for npm ci validation

Catches lock file drift locally before it breaks CI. Includes
install instructions in git-workflow.md.

* Add repo provisioning script

Automates the new-repo checklist: GitHub repo creation, OIDC deploy
role, repo secret, security features, CI/CD workflow stubs, and
pre-push hook installation. Supports both SAM and CDK stack types.

* Add shared VpnEc2Instance CDK construct

Reference construct for the VPN-accessible EC2 pattern used by
file-share and forgejo. Includes VPC/subnet lookup, SG, IAM role,
encrypted EBS, and DLM snapshots. Copy into lib/constructs/.

* Add post-deploy health check template

Template script for project-specific health checks. Copy to
scripts/health-check.sh — CD workflows run it automatically.
2026-05-14 18:39:13 -04:00
Adam Moussa
3bc054c80e
Add CI/CD pipeline requirements page (#5)
Every deployable repo must have a pipeline — no manual
deploys to production.
2026-05-08 13:56:25 -04:00
Adam Moussa
40553157c2
Update PR description template to match team format (#4)
Replace Changes/Test Plan sections with Validation/Tests/Notes
to align with the standardized PR format used across all repos.
2026-05-08 13:56:21 -04:00
Adam Moussa
e3a4cb8a54
Remove wrapper workflow — using required workflow via org ruleset (#3) 2026-05-06 19:59:34 -04:00
Adam Moussa
ab689aafc6
Add Claude Code review workflow (#2) 2026-05-06 18:11:34 -04:00
Adam Moussa
258948747a
Merge pull request #1 from Sea-Haven-Industries/feature/dependabot-standards
Add Dependabot version update configuration standards
2026-05-02 17:31:53 -04:00
Adam Moussa
fc0a77641b Add Dependabot version update configuration standards
Documents the org-wide policy for dependabot.yml files: ecosystem
selection, standard templates for single/multi-ecosystem repos and
SAM projects, auto-assignment, and merge guidance.
2026-05-02 17:29:58 -04:00
Adam Moussa
0333e7f8f5 Add engineering handbook
Conventions covering naming, git workflow, commit messages, pull
requests, code review, GitHub standards, AWS infrastructure, SAM
project layout, and secrets management. Commit messages section
adapted from RomuloOliveira/commit-messages-guide (CC-BY-4.0).
2026-05-02 16:42:44 -04:00