Commit graph

51 commits

Author SHA1 Message Date
dependabot[bot]
e0c2cd8dc0
chore(deps): bump the minor-and-patch group with 2 updates (#34)
Some checks failed
ci / ci / ci (push) Has been cancelled
Bumps the minor-and-patch group with 2 updates: [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github) and [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github).


Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` from 1.0.5 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](9c1ecf9428...7ac3528750)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-11 12:22:53 -04:00
Adam Moussa
93672d5c37
docs(jira): reflect DEV Software Development rename (#33)
Some checks failed
ci / ci / ci (push) Has been cancelled
Update issue-tracking project table after SCRUM/INFRA retirement display
names and SUP sandbox retention.

Refs: PLAT-63
2026-08-05 17:40:17 -04:00
Adam Moussa
a34f9c9e8a
docs(aws): note hcp terraform for stack migrations (#31)
Some checks are pending
ci / ci / ci (push) Waiting to run
Point migrating stacks at the org-baseline checklist; leave SAM/CDK
defaults for greenfield serverless.
2026-08-05 16:09:05 -04:00
Adam Moussa
f16d448822
ci: add org PR policy caller (PLAT-62) (#30)
Some checks are pending
ci / ci / ci (push) Waiting to run
* ci: add org PR policy caller

Refs: PLAT-62

* docs(pr): allow 120-character titles

Refs: PLAT-62
2026-08-04 14:43:44 -04:00
dependabot[bot]
e4edd743f6
build(deps): bump Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml (#29)
Some checks are pending
ci / ci / ci (push) Waiting to run
Bumps the minor-and-patch group with 1 update: [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github).


Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 11:19:35 -04:00
Adam Moussa
896bfc7501
Merge pull request #28: docs: align engineering conventions for Cursor migration (PLAT-62)
Some checks are pending
ci / ci / ci (push) Waiting to run
docs: align engineering conventions for Cursor migration (PLAT-62)
2026-08-03 18:01:08 -04:00
Adam Moussa
ea48737d72
Merge pull request #27 from Sea-Haven-Industries/docs/issue-tracking-standard
Some checks failed
ci / ci / ci (push) Has been cancelled
docs(issue-tracking): add Jira ticket format standard
2026-08-01 20:19:19 -04:00
0c6e09f4e0
docs(issue-tracking): add Jira ticket format standard 2026-07-31 14:16:39 -04:00
Adam Moussa
1fc8370890
Merge pull request #26 from Sea-Haven-Industries/docs/audit-2026-07-28-fixes
Some checks failed
ci / ci / ci (push) Has been cancelled
docs: align deploy policy, workflow pins, and node runtime with current standards
2026-07-28 19:55:34 -04:00
670336506f
docs(lambda): unify the node runtime rule on 24.x
The three pages disagreed: two listed Node 24.x while the workstation
page still allowed 22.x or 24.x, and none said anything about 26.x.
State the rule once under Lambda defaults (24.x standard, 22.x legacy
only until the 2027-04-30 deprecation, never 26.x) and have the other
two pages defer to it.
2026-07-28 19:42:53 -04:00
fc0e9bdc93
docs(cdk-layout): pin example workflow refs, drop hardcoded account
The CI/CD examples referenced the central reusable workflows at @main,
which contradicts the SHA-pin mandate the CI/CD page states and would be
copied into new repos as a mutable ref. Replace both with the
@<full-commit-sha>  # main placeholder and point at the pinning section.

The bin/app.ts example also hardcoded a specific account ID. Make the
env region-only so the account comes from the deploy credentials and the
synthesized template stays account-agnostic.
2026-07-28 19:42:47 -04:00
cfb50ff1fc
docs(git-workflow): make ci-on-merge the sanctioned deploy path
Pipeline deploy on merge to main (or workflow_dispatch where a repo
configures one) is now the only sanctioned path. Local deploy-then-merge
drops to a documented legacy exception that requires a data-loss-prone
stateful change plus advance sign-off, recorded in the PR notes.

Also correct the hook install path for the repo's move under
repositories/seahaven/, and document that core.hooksPath is a single
directory rather than a search path, so a repo-local setting silently
shadows the machine-global security pre-push unless the repo hook is a
shim that re-execs it.
2026-07-28 19:42:33 -04:00
Adam Moussa
3edbb265b5
Merge pull request #25 from Sea-Haven-Industries/ci/pin-reusables-v1.0.2
Some checks are pending
ci / ci / ci (push) Waiting to run
ci(deps): pin org reusable workflows to v1.0.2
2026-07-28 18:11:45 -04:00
Adam Moussa
10d6a40e47 style(ci): normalize workflow block spacing 2026-07-28 18:06:00 -04:00
Adam Moussa
943e179bf0 ci(deps): pin org reusable workflows to v1.0.2 2026-07-28 17:55:42 -04:00
Adam Moussa
f8f04bad41
Merge pull request #24 from Sea-Haven-Industries/docs/cicd-concurrency-convention
Some checks are pending
ci / ci / ci (push) Waiting to run
docs(cicd): document the concurrency convention used by the reusable workflows
2026-07-28 16:45:57 -04:00
a8f1f2be98
docs(cicd): document the concurrency convention used by the reusable workflows
Adds a Concurrency section to cicd.md covering the blocks that already exist in
the central .github repo:

- Deploy reusables set cancel-in-progress: false; CI reusables set it to true.
- The concurrency block sits on the job, not at workflow top level, and uses
  ${{ github.job }} in the key where a reusable has more than one job.
- Concurrency groups are evaluated in the caller's repository, so a group only
  needs to be unique within one repo; the literal workflow-name prefix is what
  keeps two reusables in the same repo apart.
- Deploy keys name the deploy target, so a repo calling one reusable from
  several jobs does not serialise independent deploys. cd-cdk keys on `stacks`
  rather than `stack-name` for that reason, and every key component is an input
  that is required or always defaults.

Quotes the four cd-* group expressions and the ci-typescript-frontend one
verbatim from the workflow files.
2026-07-28 15:59:07 -04:00
Adam Moussa
6786d63291
Merge pull request #23 from Sea-Haven-Industries/docs/fix-cd-sam-usage-example
Some checks are pending
ci / ci / ci (push) Waiting to run
docs(cicd): correct the cd-sam caller example to match the real contract
2026-07-28 12:21:53 -04:00
065a4e9f0e
docs(cicd): correct the cd-sam caller example to match the real contract
The SAM deploy example passed `cfn-role-arn` as a secret and omitted
`deploy-role-arn` entirely. Both are wrong against cd-sam.yaml, which
declares `cfn-role-arn` as a required string INPUT and `deploy-role-arn`
as a required SECRET. A repo scaffolded from the example failed twice:
an unexpected secret, plus a missing required input and secret.

The two ARNs are distinct roles that the old example effectively
conflated into one, so document them side by side: cfn-role-arn is the
CloudFormation execution role the stack deploys as, deploy-role-arn is
the OIDC role the workflow assumes. Also record which inputs have
defaults so callers pass only what they must.

The account ID stays a `<account-id>` placeholder, per the same rule
that removed the hardcoded management-account ARN from the templates.
2026-07-28 12:16:37 -04:00
Adam Moussa
5c362299de
Merge pull request #20 from Sea-Haven-Industries/dependabot/github_actions/minor-and-patch-c43b9b4ac0
Some checks are pending
ci / ci / ci (push) Waiting to run
Bump lycheeverse/lychee-action from 2.8.0 to 2.9.0 in the minor-and-patch group
2026-07-27 17:20:37 -04:00
Adam Moussa
56089d6cc7
Merge pull request #22 from Sea-Haven-Industries/dependabot/github_actions/actions/setup-node-7
Bump actions/setup-node from 6 to 7
2026-07-27 16:41:20 -04:00
dependabot[bot]
1c4d25772f
Bump actions/setup-node from 6 to 7
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-27 20:38:55 +00:00
Adam Moussa
5e955f39c8
Merge pull request #21 from Sea-Haven-Industries/dependabot/github_actions/actions/checkout-7
Bump actions/checkout from 6 to 7
2026-07-27 16:37:03 -04:00
dependabot[bot]
2d873d41bd
Bump actions/checkout from 6 to 7
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-27 19:45:14 +00:00
dependabot[bot]
f86ccf81f2
Bump lycheeverse/lychee-action in the minor-and-patch group
Bumps the minor-and-patch group with 1 update: [lycheeverse/lychee-action](https://github.com/lycheeverse/lychee-action).


Updates `lycheeverse/lychee-action` from 2.8.0 to 2.9.0
- [Release notes](https://github.com/lycheeverse/lychee-action/releases)
- [Commits](8646ba3053...e747777578)

---
updated-dependencies:
- dependency-name: lycheeverse/lychee-action
  dependency-version: 2.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-27 19:45:12 +00:00
Adam Moussa
190b683bb3
Merge pull request #19 from Sea-Haven-Industries/ci/sha-pin-workflow-refs
Some checks are pending
ci / ci / ci (push) Waiting to run
ci: pin reusable-workflow refs to commit SHA
2026-07-27 15:44:35 -04:00
75fb1b0890
ci: pin reusable-workflow refs to commit SHA
Pins the labeler caller to the current .github main tip per the SHA-pin
convention (PR #18). Adds dependabot.yml with the github-actions
ecosystem so the pin is advanced weekly; package-ecosystem coverage is
not needed here (no package manifests in this repo).
2026-07-27 15:40:40 -04:00
Adam Moussa
a75623313b
Merge pull request #18 from Sea-Haven-Industries/docs/sha-pin-reusable-workflows
docs(cicd): pin reusable-workflow refs to commit SHAs instead of @main
2026-07-27 15:30:25 -04:00
5f1818cd6b
docs(cicd): pin reusable-workflow refs to commit SHAs instead of @main
The org standard for reusable-workflow references changes from the mutable
@main branch ref to full commit SHA pins advanced by Dependabot. Adds a
Workflow Ref Pinning section covering the rationale and the two
prerequisites that keep pins current (github-actions ecosystem in
dependabot.yml, org-level Dependabot access to the internal .github repo).
2026-07-27 15:28:31 -04:00
Adam Moussa
0e83835b4a
Merge pull request #17 from Sea-Haven-Industries/docs/conventional-commits
Some checks failed
ci / ci / ci (push) Has been cancelled
2026-07-18 03:01:59 -04:00
855b473479
docs: adopt conventional commit format as the org standard
Make Conventional Commits (type(scope): description) the canonical
commit and PR-title format across Sea Haven, replacing the previous
imperative/capitalized/no-prefix rule.

- commit-messages.md: full rewrite to the type(scope): description
  format with the type table, lowercase/imperative description rules,
  breaking-change (! + BREAKING CHANGE footer) guidance tied to SemVer,
  and updated template and examples.
- git-workflow.md: extend the branch-prefix table with chore/, docs/,
  refactor/, and release/ (alongside the existing feature/bug/hotfix),
  mirroring the commit types.
- pull-requests.md: reconcile the title rule to the Conventional Commit
  format.
- README.md: update the commit-messages one-line summary.

Refs: INFRA-57
2026-07-17 19:30:02 -04:00
Adam Moussa
9c65fcb053
ci: add markdown-lint and link-check CI (INFRA-128) (#16)
Some checks failed
ci / ci / ci (push) Has been cancelled
Add a standalone ci workflow so handbook changes get an automated gate.
The job is named literally "ci / ci" to emit the exact status context the
org main-branch-protection ruleset requires.

- markdownlint-cli2 (.markdownlint-cli2.jsonc): MD013/MD060/MD040 relaxed
  as noisy docs-style rules; fixed 3 MD032 blank-line-around-list issues.
- lychee link check (lychee.toml): internal + external links, tolerates 429.
2026-07-08 16:20:28 -04:00
Adam Moussa
dc736da711
Document repository security and merge-setting baseline (#15)
Codify the org security + merge baseline: auto-merge and auto-delete
head branch (no org default, set per-repo), and the secret-scanning /
CodeQL / code-security surface carried by the 'Sea Haven Standard' org
Code Security Configuration. Note docs-repo CodeQL exception and the
shoc-backend/shoc-frontend-new exclusion.
2026-06-18 12:27:31 -04:00
Adam Moussa
132e4fe51d
Document README badges, repo topics, and PR auto-labeler conventions (INFRA-56/57/70) (#14)
Capture the org conventions rolled out in the INFRA-47 hygiene pass:
- github-standards.md: static-only README badges (dynamic shields break on
  private repos; CI badge is member-only) and a lowercase-hyphenated repo
  topic vocabulary, both part of new-repo provisioning.
- cicd.md: the central inline-config reusable PR labeler — pull_request
  trigger, the three required caller permissions, no per-repo labeler.yml.
2026-06-11 14:25:12 -04:00
Adam Moussa
144240884b
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#13) 2026-06-11 14:14:17 -04:00
Adam Moussa
1c11824196
docs: replace frozen 'blessed version' with automated pin-currency policy (#11)
Exact pins remain (reproducibility) but the pinned version is kept
current by Dependabot version updates gated by CI + dependency review,
not by a number frozen in the handbook. Blanket dependabot ignore
entries are banned; version-specific ignores only, commented and
temporary. Bundled-dep vulnerabilities are a prompt to advance the
pin, never to dismiss the alert.
2026-06-05 12:57:35 -04:00
Adam Moussa
bcb4355c36
docs: move blessed aws-cdk-lib pin to 2.257.0 (#10)
2.253.1 bundles fast-uri 3.1.0 (two high-severity GHSAs, unfixable via
overrides since it ships in the tarball). 2.257.0 bundles patched
fast-uri 3.1.2 and passes npm ci (the 2.254.0 breakage that motivated
the old pin was release-specific).
2026-06-05 12:52:50 -04:00
Adam Moussa
8ebf52b5e6
Merge pull request #9 from Sea-Haven-Industries/feature/jira-linking-convention
Add Jira issue-linking convention + handbook index/standards cleanup
2026-06-02 19:37:46 -04:00
Adam Moussa
e00055b8e2 Drop Dependabot PR assignee from GitHub standards
Pinning every Dependabot PR to a single assignee created noise and a
bottleneck. Remove the assignee requirement and the per-ecosystem
assignees blocks from the example configs.
2026-06-02 19:36:09 -04:00
Adam Moussa
e057e8ab84 Add CDK layout and code review rubric to handbook index
Both pages existed in working drafts but were not linked from the
README table of contents, so they were undiscoverable. Add them to the
index alongside the related SAM layout and code review pages.
2026-06-02 19:36:09 -04:00
Adam Moussa
e749e6f651 Add Jira issue-linking convention
Work is tracked in Jira while code lives in GitHub; the org-level GitHub
for Jira app is already installed but nothing told contributors how to
trigger the link. Document putting the Jira key in the branch name, PR
title, or Refs trailer so branches, commits, and PRs thread into the
issue's development panel. Use a generic PROJ-123 placeholder rather
than naming specific projects, which change over time.
2026-06-02 19:36:03 -04:00
Adam Moussa
7d5d04985a Add deferred findings policy to code review page
Require PR authors to create a GitHub issue for any review
finding deferred past the current PR, and link it in the
review thread before merging. Prevents informal tracking
from dropping items.
2026-05-15 17:13:47 -04:00
Adam Moussa
651dff5dd3
Add Bedrock, dev-env, and Lambda template pages (#7)
Adds three handbook pages covering conventions that were previously
scattered across feedback memories or rederived from scratch each
time:

- bedrock.md captures the cross-region inference profile requirement
  for Claude 4.x Bedrock Agents and the alias-version pinning gotcha,
  plus the IAM resource pattern and the KB Docker requirement.
- dev-environment.md documents the workstation directory layout,
  pyenv/Node conventions, the macOS launchd/TCC sandbox gotcha, and
  cleanup cadence.
- lambda-template.md provides a minimal SAM scaffold that follows the
  Lambda defaults already in aws-infrastructure.md (Python 3.12,
  arm64, explicit 60-day log retention, scoped Secrets Manager
  access, module-level secret cache).

Also extends two existing pages:

- sam-project-layout.md gains a Lambda Layers section with the
  BuildMethod nesting pattern that caused a ~22-hour production
  outage when violated.
- naming-conventions.md adds a Legacy Stacks note acknowledging that
  pre-convention PascalCase stacks (SeaHavenDoorUnlockStack,
  WorkorderIngestStack) stay as-is rather than risk stack
  replacement.
2026-05-14 19:50:37 -04:00
Adam Moussa
4b5d39fb91
Add CDK version policy, update Node 24 and GitHub Actions CI/CD (#6)
* Update CDK version policy, Node 24 runtime, and GitHub Actions CI/CD

- Pin blessed aws-cdk-lib version (2.253.1) with upgrade procedure
- Update Lambda runtime default from Node 22 to Node 24
- Rewrite CI/CD page to reflect GitHub Actions reusable workflows
  (was still referencing CodePipeline/CodeBuild)

* Add pre-push hook for npm ci validation

Catches lock file drift locally before it breaks CI. Includes
install instructions in git-workflow.md.

* Add repo provisioning script

Automates the new-repo checklist: GitHub repo creation, OIDC deploy
role, repo secret, security features, CI/CD workflow stubs, and
pre-push hook installation. Supports both SAM and CDK stack types.

* Add shared VpnEc2Instance CDK construct

Reference construct for the VPN-accessible EC2 pattern used by
file-share and forgejo. Includes VPC/subnet lookup, SG, IAM role,
encrypted EBS, and DLM snapshots. Copy into lib/constructs/.

* Add post-deploy health check template

Template script for project-specific health checks. Copy to
scripts/health-check.sh — CD workflows run it automatically.
2026-05-14 18:39:13 -04:00
Adam Moussa
3bc054c80e
Add CI/CD pipeline requirements page (#5)
Every deployable repo must have a pipeline — no manual
deploys to production.
2026-05-08 13:56:25 -04:00
Adam Moussa
40553157c2
Update PR description template to match team format (#4)
Replace Changes/Test Plan sections with Validation/Tests/Notes
to align with the standardized PR format used across all repos.
2026-05-08 13:56:21 -04:00
Adam Moussa
e3a4cb8a54
Remove wrapper workflow — using required workflow via org ruleset (#3) 2026-05-06 19:59:34 -04:00
Adam Moussa
ab689aafc6
Add Claude Code review workflow (#2) 2026-05-06 18:11:34 -04:00
Adam Moussa
258948747a
Merge pull request #1 from Sea-Haven-Industries/feature/dependabot-standards
Add Dependabot version update configuration standards
2026-05-02 17:31:53 -04:00
Adam Moussa
fc0a77641b Add Dependabot version update configuration standards
Documents the org-wide policy for dependabot.yml files: ecosystem
selection, standard templates for single/multi-ecosystem repos and
SAM projects, auto-assignment, and merge guidance.
2026-05-02 17:29:58 -04:00