Commit graph

8 commits

Author SHA1 Message Date
Adam Moussa
affa1a64f8
docs(cd): separate terraform infra from github app deploys (#46)
Some checks failed
ci / ci / ci (push) Has been cancelled
Make HCP Terraform plus GitHub Actions content CD the default for new
workloads, and keep SAM/CDK documented as the remaining path.
2026-09-15 22:05:33 +00:00
Adam Moussa
896bfc7501
Merge pull request #28: docs: align engineering conventions for Cursor migration (PLAT-62)
Some checks are pending
ci / ci / ci (push) Waiting to run
docs: align engineering conventions for Cursor migration (PLAT-62)
2026-08-03 18:01:08 -04:00
a8f1f2be98
docs(cicd): document the concurrency convention used by the reusable workflows
Adds a Concurrency section to cicd.md covering the blocks that already exist in
the central .github repo:

- Deploy reusables set cancel-in-progress: false; CI reusables set it to true.
- The concurrency block sits on the job, not at workflow top level, and uses
  ${{ github.job }} in the key where a reusable has more than one job.
- Concurrency groups are evaluated in the caller's repository, so a group only
  needs to be unique within one repo; the literal workflow-name prefix is what
  keeps two reusables in the same repo apart.
- Deploy keys name the deploy target, so a repo calling one reusable from
  several jobs does not serialise independent deploys. cd-cdk keys on `stacks`
  rather than `stack-name` for that reason, and every key component is an input
  that is required or always defaults.

Quotes the four cd-* group expressions and the ci-typescript-frontend one
verbatim from the workflow files.
2026-07-28 15:59:07 -04:00
065a4e9f0e
docs(cicd): correct the cd-sam caller example to match the real contract
The SAM deploy example passed `cfn-role-arn` as a secret and omitted
`deploy-role-arn` entirely. Both are wrong against cd-sam.yaml, which
declares `cfn-role-arn` as a required string INPUT and `deploy-role-arn`
as a required SECRET. A repo scaffolded from the example failed twice:
an unexpected secret, plus a missing required input and secret.

The two ARNs are distinct roles that the old example effectively
conflated into one, so document them side by side: cfn-role-arn is the
CloudFormation execution role the stack deploys as, deploy-role-arn is
the OIDC role the workflow assumes. Also record which inputs have
defaults so callers pass only what they must.

The account ID stays a `<account-id>` placeholder, per the same rule
that removed the hardcoded management-account ARN from the templates.
2026-07-28 12:16:37 -04:00
5f1818cd6b
docs(cicd): pin reusable-workflow refs to commit SHAs instead of @main
The org standard for reusable-workflow references changes from the mutable
@main branch ref to full commit SHA pins advanced by Dependabot. Adds a
Workflow Ref Pinning section covering the rationale and the two
prerequisites that keep pins current (github-actions ecosystem in
dependabot.yml, org-level Dependabot access to the internal .github repo).
2026-07-27 15:28:31 -04:00
Adam Moussa
132e4fe51d
Document README badges, repo topics, and PR auto-labeler conventions (INFRA-56/57/70) (#14)
Capture the org conventions rolled out in the INFRA-47 hygiene pass:
- github-standards.md: static-only README badges (dynamic shields break on
  private repos; CI badge is member-only) and a lowercase-hyphenated repo
  topic vocabulary, both part of new-repo provisioning.
- cicd.md: the central inline-config reusable PR labeler — pull_request
  trigger, the three required caller permissions, no per-repo labeler.yml.
2026-06-11 14:25:12 -04:00
Adam Moussa
4b5d39fb91
Add CDK version policy, update Node 24 and GitHub Actions CI/CD (#6)
* Update CDK version policy, Node 24 runtime, and GitHub Actions CI/CD

- Pin blessed aws-cdk-lib version (2.253.1) with upgrade procedure
- Update Lambda runtime default from Node 22 to Node 24
- Rewrite CI/CD page to reflect GitHub Actions reusable workflows
  (was still referencing CodePipeline/CodeBuild)

* Add pre-push hook for npm ci validation

Catches lock file drift locally before it breaks CI. Includes
install instructions in git-workflow.md.

* Add repo provisioning script

Automates the new-repo checklist: GitHub repo creation, OIDC deploy
role, repo secret, security features, CI/CD workflow stubs, and
pre-push hook installation. Supports both SAM and CDK stack types.

* Add shared VpnEc2Instance CDK construct

Reference construct for the VPN-accessible EC2 pattern used by
file-share and forgejo. Includes VPC/subnet lookup, SG, IAM role,
encrypted EBS, and DLM snapshots. Copy into lib/constructs/.

* Add post-deploy health check template

Template script for project-specific health checks. Copy to
scripts/health-check.sh — CD workflows run it automatically.
2026-05-14 18:39:13 -04:00
Adam Moussa
3bc054c80e
Add CI/CD pipeline requirements page (#5)
Every deployable repo must have a pipeline — no manual
deploys to production.
2026-05-08 13:56:25 -04:00