Adds a Concurrency section to cicd.md covering the blocks that already exist in
the central .github repo:
- Deploy reusables set cancel-in-progress: false; CI reusables set it to true.
- The concurrency block sits on the job, not at workflow top level, and uses
${{ github.job }} in the key where a reusable has more than one job.
- Concurrency groups are evaluated in the caller's repository, so a group only
needs to be unique within one repo; the literal workflow-name prefix is what
keeps two reusables in the same repo apart.
- Deploy keys name the deploy target, so a repo calling one reusable from
several jobs does not serialise independent deploys. cd-cdk keys on `stacks`
rather than `stack-name` for that reason, and every key component is an input
that is required or always defaults.
Quotes the four cd-* group expressions and the ci-typescript-frontend one
verbatim from the workflow files.
The SAM deploy example passed `cfn-role-arn` as a secret and omitted
`deploy-role-arn` entirely. Both are wrong against cd-sam.yaml, which
declares `cfn-role-arn` as a required string INPUT and `deploy-role-arn`
as a required SECRET. A repo scaffolded from the example failed twice:
an unexpected secret, plus a missing required input and secret.
The two ARNs are distinct roles that the old example effectively
conflated into one, so document them side by side: cfn-role-arn is the
CloudFormation execution role the stack deploys as, deploy-role-arn is
the OIDC role the workflow assumes. Also record which inputs have
defaults so callers pass only what they must.
The account ID stays a `<account-id>` placeholder, per the same rule
that removed the hardcoded management-account ARN from the templates.
The org standard for reusable-workflow references changes from the mutable
@main branch ref to full commit SHA pins advanced by Dependabot. Adds a
Workflow Ref Pinning section covering the rationale and the two
prerequisites that keep pins current (github-actions ecosystem in
dependabot.yml, org-level Dependabot access to the internal .github repo).
Capture the org conventions rolled out in the INFRA-47 hygiene pass:
- github-standards.md: static-only README badges (dynamic shields break on
private repos; CI badge is member-only) and a lowercase-hyphenated repo
topic vocabulary, both part of new-repo provisioning.
- cicd.md: the central inline-config reusable PR labeler — pull_request
trigger, the three required caller permissions, no per-repo labeler.yml.
* Update CDK version policy, Node 24 runtime, and GitHub Actions CI/CD
- Pin blessed aws-cdk-lib version (2.253.1) with upgrade procedure
- Update Lambda runtime default from Node 22 to Node 24
- Rewrite CI/CD page to reflect GitHub Actions reusable workflows
(was still referencing CodePipeline/CodeBuild)
* Add pre-push hook for npm ci validation
Catches lock file drift locally before it breaks CI. Includes
install instructions in git-workflow.md.
* Add repo provisioning script
Automates the new-repo checklist: GitHub repo creation, OIDC deploy
role, repo secret, security features, CI/CD workflow stubs, and
pre-push hook installation. Supports both SAM and CDK stack types.
* Add shared VpnEc2Instance CDK construct
Reference construct for the VPN-accessible EC2 pattern used by
file-share and forgejo. Includes VPC/subnet lookup, SG, IAM role,
encrypted EBS, and DLM snapshots. Copy into lib/constructs/.
* Add post-deploy health check template
Template script for project-specific health checks. Copy to
scripts/health-check.sh — CD workflows run it automatically.