Commit graph

6 commits

Author SHA1 Message Date
1188a4c1cb
ci: consolidate required checks behind ci-complete 2026-09-19 20:47:59 +00:00
24e4f2b7f7
fix(governance): diff G3 and G13 from the merge base, not the base tip
The gate computed changed files with a two-dot diff against the PR base tip,
so everything main gained after the branch point counted as this change. A
branch behind main that touched C# failed G13 whenever main had merged
Terraform in between, which is how #152 failed after #154, #156 and #158
landed. The merge queue no longer requires branches to be current, so the
false positive would have hit every stale PR. Both diffs now start at the
merge base. Push and merge-group runs are unchanged because their base is an
ancestor of the head.
2026-09-18 19:12:21 -04:00
8f4fa36647
refactor(cd): ship Elastic Beanstalk versions from GitHub on main
Keep application and Terraform changes in separate PRs so a merge cannot race an HCP apply against an app deploy.
2026-09-17 15:54:31 -04:00
Adam Moussa
77c3016c9d
feat(deploy): move dev application CD through Terraform (#102)
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
* feat(deploy): move dev application CD through Terraform

GitHub creates the immutable Elastic Beanstalk version; HCP Terraform is the only UpdateEnvironment caller via a guarded version_label run.

* fix: add permissions block for dependency-review workflow

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* fix(terraform): stop pinning the generated dev instance SG

---------

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-09-03 14:12:06 +00:00
Adam Moussa
24f08d3cb1
feat(terraform): adopt live deployment roles safely (#94)
* feat(terraform): add safe backend environment adoption

Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer.

* ci(deploy): pause dev and staging deployments

Prevent application releases from racing Terraform adoption while retaining production deployment and validation.

* ci(deploy): require manual environment dispatch

* fix: update `required_version` from `>=1.7.0` to `>=1.9.0`

The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+.

CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding

* chore(deps): add `terraform` to renovate dependency coverage

* ci(deploy): drop unprovisioned prod dispatch path
2026-08-31 11:51:18 -04:00
Alexandre Brandizzi
833fb816ee
chore(governance): enforce backend architecture and quality gates (#31)
* docs(governance): add canonical governance docs, unified quality-gate script, and CI parity

- ARCHITECTURE_AND_CODE_QUALITY.md: canonical layering, EF allowlist,
  transaction/commit convention, cancellation, migrations, error disclosure,
  Big-O/perf, ADR exceptions (supersedes BACKEND_ARCHITECTURE.md)
- QUALITY_GATES.md: gate inventory + pass/fail/skip semantics; local==CI
- REVIEW_AND_PR_FRAMEWORK.md: exact-head review, board-backed regression
  inventory, security/perf evidence, ADR exceptions, no godfile theater
- AGENTS.md: repo-specific delta + precedence pointers
- scripts/governance-check.sh: unified G1 restore + G2 ArchitectureTests +
  G3 changed-file format (portable bash)
- .github/workflows/architecture-quality.yml: call the same local script
- ArchitectureTests.cs: add business-service interface-dependency invariant

* fix(governance): make backend gate complete

* fix(ci): enforce governance on every pull request
2026-07-24 17:41:10 -03:00