sh-openswe-traces/.github/workflows/ci.yaml
Adam Moussa 0dea585c1a
feat: sh-openswe-traces — LangSmith bulk-export trace archive
Storage-only SAM stack (S3 + KMS CMK + write-only IAM writer + Secrets Manager
holder) as the S3 destination for LangSmith Bulk Export of Open SWE traces, for
long-horizon auditing and prompt improvement (Athena over Parquet).

- template.yaml: versioned SSE-KMS bucket, access-log bucket, TLS-only policy,
  DEEP_ARCHIVE lifecycle; least-privilege LangSmith writer (bucket-wide PutObject,
  ViaService-scoped KMS, no read/delete).
- bootstrap.yaml: dedicated OIDC deploy role + least-privilege CFN exec role so CI
  never touches the shared execution role.
- CI/CD via reusable ci-python-sam / cd-sam workflows.

IAM passed GPT-4.1 cross-review + /sh-security-review (no blocking findings).
2026-07-10 15:45:23 -04:00

10 lines
343 B
YAML

name: CI
on:
pull_request:
branches: [main]
jobs:
ci:
# No Python source in this repo — ruff no-ops on an empty file set and the
# reusable workflow still runs `sam validate --lint` on template.yaml.
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main