Commit graph

13 commits

Author SHA1 Message Date
Adam Moussa
d0659ebf6f
ci: add org PR policy caller (PLAT-62) (#69)
* ci: add org PR policy caller

Refs: PLAT-62

* ci: update callable-pr-policy to v1.0.6

* chore: retrigger PR checks
2026-08-07 10:54:07 -04:00
dependabot[bot]
fdee41dc82
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml
Bumps [Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml](https://github.com/sea-haven-industries/.github) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-30 05:49:42 +00:00
dependabot[bot]
184a289f9c
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml
Bumps [Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml](https://github.com/sea-haven-industries/.github) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-30 05:44:02 +00:00
dependabot[bot]
6066807ad2
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-30 05:38:41 +00:00
dependabot[bot]
7fb9cb7818
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-30 02:13:25 +00:00
Adam Moussa
ed5985672b ci: declare workflow permissions and normalize block spacing 2026-07-28 18:07:48 -04:00
Adam Moussa
09443bf179 ci(deps): pin org reusable workflows to v1.0.2 2026-07-28 17:58:00 -04:00
Adam Moussa
848682cc94
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#42)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-07-06 18:27:25 -04:00
Adam Moussa
e32401e554
Repo hygiene: PR labeler + README badges + dependabot (INFRA-56/57/66) (#29)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-06-11 14:13:26 -04:00
Adam Moussa
6754ceaa42
Add dependency-review caller workflow (#20)
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)
2026-06-05 12:26:38 -04:00
Adam Moussa
d2b718a126
Fix compliance audit violations from issue #6 (#7)
Pin aws-cdk-lib to blessed 2.253.1, add dependabot.yml, export
backup verification Lambda ARN, pin node-version: 24 in workflows,
add __pycache__ to .gitignore.
2026-05-18 16:35:23 -04:00
Adam Moussa
cfda99927b
Add 3-2-1 backup strategy (#2)
* Add 3-2-1 backup strategy with cross-region replication and GCS offsite

Implements a fully compliant 3-2-1 backup architecture:
- Copy 1 (live): Harden existing EBS snapshots to 30-day retention
- Copy 2 (near-site): S3 cross-region replication to us-west-2 with
  Object Lock (governance 90d) and versioning
- Copy 3 (offsite): GCS bucket in dedicated seahaven-backups GCP project
  with 2-year irreversible retention lock

Also adds a verification Lambda that checks all 3 locations daily and
runs monthly restore tests with SQLite integrity checks.

* Enable QEMU in CI for arm64 Lambda Docker builds

* Commit cdk.context.json for CI synth without AWS credentials

Vpc.fromLookup requires cached context to synthesize without
AWS credentials. Required for CI which runs cdk synth without
an OIDC role.

* Fix GCP project ID to sea-haven-backups

* Address code review findings for backup verification

Fix 4 critical issues:
- Add filter/priority/deleteMarkerReplication to S3 CRR rule (deploy would fail without)
- Add stack dependency so replica deploys before main stack
- Fix DB file extension matching (.sqlite3/.sql instead of .db)
- Replace nonexistent `forgejo restore` command with actual restore steps in README

Fix 4 moderate issues:
- Add timeout=10 to Slack webhook urlopen call
- Add filter='data' to tarfile.extract for PEP 706 compliance
- Add explicit ValueError for unknown handler mode
- Use date-scoped S3/GCS prefix instead of unbounded listing

* Fix backup strategy bug findings

* Handle SQL text dumps separately from binary SQLite in restore test

Forgejo dump produces gitea-db.sql as a text SQL dump (XORM export),
not a binary SQLite file. Opening it directly with sqlite3.connect()
throws DatabaseError. Now imports the SQL dump into a temp DB first.

* Fix GCS backup check: align staleness cutoff and add size validation

GCS check used a 72h cutoff but only listed 2 days of prefixes (~48h),
making the staleness check unreachable. Also added 1MB minimum file
size validation to match the S3 check.

* Rename SECRET_ARN env vars to SECRET_NAME to match actual values

* Fix EBS snapshot state check, drop unused GCS write grant and dead lifecycle rule

* Fix restore runbook, DLM snapshot tagging, README cleanup, and gsutil prompt

* Fix restore runbook: trailing-dot cp idiom and Glacier restore step

* Rename GCS service account to match read-only permissions

* Add 4 GiB ephemeral storage to verification Lambda

Monthly restore-test downloads and extracts the full dump tarball
in /tmp. As the dump grows with LFS data, the default 512 MB will
eventually cause ENOSPC failures.

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-05-14 18:08:06 -04:00
Adam Moussa
a500d69716 Add Forgejo CDK stack
EC2 (t4g.small, arm64) in private subnet with VPN-only access,
DLM nightly snapshots, and Route53 DNS at forgejo.seahaven.com.
2026-05-11 17:52:37 -04:00