Commit graph

26 commits

Author SHA1 Message Date
396b1c690b
fix(cd): honor reusable workflow inputs when resolving deploy target 2026-09-18 11:33:34 -04:00
8f4fa36647
refactor(cd): ship Elastic Beanstalk versions from GitHub on main
Keep application and Terraform changes in separate PRs so a merge cannot race an HCP apply against an app deploy.
2026-09-17 15:54:31 -04:00
Alexandre Brandizzi
4ae6d02d55 feat(deploy): rebuild protected staging lane 2026-09-16 15:52:02 -03:00
Alexandre Brandizzi
9a49a5c40a fix(deploy): apply the health-convergence fix to the dev Terraform rollback
The dev Terraform rollback verify was the one gate the previous commit
missed, and it is the copy that actually ran on 34293894914. It still
decided on the first Ready poll: previous version correctly restored,
health not yet converged, reported as a failed rollback.

Split the version and health conditions the same way the other three
gates now do — a Ready poll on the wrong version fails immediately and
names the version that came up, while the correct version with unsettled
health keeps polling inside the unchanged 80 x 15s budget. Timeout now
reports the last observed status, version and health.
2026-09-10 10:55:45 -03:00
Alexandre Brandizzi
d1e3fb03ce fix(deploy): let EB health converge before failing the version gate
Elastic Beanstalk reports Ready as soon as a rollout finishes, before
enhanced health has converged. Both verification gates decided on the first
Ready poll, so a release whose version had activated correctly was failed on
a health value that had not settled yet — and then rolled back.

The failure message compounded it: run 34293894914 printed 'Environment
became Ready without activating expected version a0fdd199...' when the
active version was exactly a0fdd199... The discriminator was health, not
version, which sends whoever reads the log after the wrong problem.

Separate the two conditions, keep polling while the correct version is
active but health has not settled, and report the last observed state on
timeout. An environment that stays unhealthy for the full window still
fails; this does not widen what counts as a good deploy.
2026-09-08 21:31:55 -03:00
Adam Moussa
1bdbc12292
fix(deploy): treat applied HCP runs as success (#108)
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
* fix(deploy): treat applied HCP runs as success

* fix(deploy): wait on rollback apply result

* fix(deploy): compare G3 formatting against the PR merge base

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(deploy): fence rollback create-run on unlock success

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 13:26:11 -04:00
Adam Moussa
69ba573315
chore(terraform): remove tf-poc rehearsal (SH-300) (#95)
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
* chore(terraform): remove tf-poc rehearsal

* chore(terraform): drop tf-poc from live module and CI

* chore: clean remaining tf-poc reference from `shared_certificate_arn`
2026-09-03 10:40:32 -04:00
Adam Moussa
77c3016c9d
feat(deploy): move dev application CD through Terraform (#102)
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
* feat(deploy): move dev application CD through Terraform

GitHub creates the immutable Elastic Beanstalk version; HCP Terraform is the only UpdateEnvironment caller via a guarded version_label run.

* fix: add permissions block for dependency-review workflow

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* fix(terraform): stop pinning the generated dev instance SG

---------

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-09-03 14:12:06 +00:00
Adam Moussa
24f08d3cb1
feat(terraform): adopt live deployment roles safely (#94)
* feat(terraform): add safe backend environment adoption

Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer.

* ci(deploy): pause dev and staging deployments

Prevent application releases from racing Terraform adoption while retaining production deployment and validation.

* ci(deploy): require manual environment dispatch

* fix: update `required_version` from `>=1.7.0` to `>=1.9.0`

The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+.

CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding

* chore(deps): add `terraform` to renovate dependency coverage

* ci(deploy): drop unprovisioned prod dispatch path
2026-08-31 11:51:18 -04:00
Adam Moussa
e90e51d271
chore(renovate): add frontend overlay with three-day release age (#90)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
* chore(renovate): add Renovate frontend overlay config

* chore: remove dependabot.yml config

* fix: add `github-actions` to `enabledManagers`

With the removal of this repositories `dependabot.yml`, a lack of `github-actions` within the config would leave a coverage gap on `actions/checkout`, `actions/setup-dotnet`, `actions/setup-node`, etc.

* fix(renovate): annotate pinned actions

---------

Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-08-26 18:58:31 -03:00
dependabot[bot]
c0f6f78661
chore(deps): bump aws-actions/aws-elasticbeanstalk-deploy
Bumps [aws-actions/aws-elasticbeanstalk-deploy](https://github.com/aws-actions/aws-elasticbeanstalk-deploy) from 1.0.6 to 1.0.8.
- [Release notes](https://github.com/aws-actions/aws-elasticbeanstalk-deploy/releases)
- [Changelog](https://github.com/aws-actions/aws-elasticbeanstalk-deploy/blob/main/CHANGELOG.md)
- [Commits](cfad3e5e44...7883cdd454)

---
updated-dependencies:
- dependency-name: aws-actions/aws-elasticbeanstalk-deploy
  dependency-version: 1.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-11 02:44:28 +00:00
dependabot[bot]
66e1a662c3
chore(deps): bump actions/checkout from 4 to 7 (#51)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](https://github.com/actions/checkout/compare/v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-08-04 09:56:24 -03:00
dependabot[bot]
c7e7ffa313
chore(deps): bump actions/setup-dotnet from 4 to 6 (#50)
Bumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 4 to 6.
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](https://github.com/actions/setup-dotnet/compare/v4...v6)

---
updated-dependencies:
- dependency-name: actions/setup-dotnet
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-08-04 09:49:05 -03:00
dependabot[bot]
b2366acdfa
chore(deps): bump actions/setup-node from 6.5.0 to 7.0.0 (#49)
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.5.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](249970729c...8207627860)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 09:40:55 -03:00
Alexandre Brandizzi
47c3fff4ba
fix(cdk): allow Beanstalk VPC discovery (#44)
Some checks failed
Validate and deploy dev / Validate deployable source bundle (push) Has been cancelled
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Has been cancelled
* fix(cdk): allow Beanstalk VPC discovery

* chore(ci): clarify backend check name

* fix(eb): allow temporary object cleanup

* fix(cdk): allow managed environment stack update

* fix(cdk): allow Beanstalk template read

* fix(cdk): apply supported Beanstalk S3 policy

* fix(cdk): allow load balancer discovery and cancel

* fix(cdk): allow Beanstalk resource discovery
2026-07-30 11:40:06 -04:00
Adam Moussa
83ed6a1790
fix(eb): configure work-order webhook HMAC secret source (#41)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
2026-07-30 11:44:43 -03:00
Alexandre Brandizzi
658bae77d3
fix(cdk): grant observed Elastic Beanstalk deploy reads (#38)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
* fix(cdk): grant observed EB deploy reads

* fix(cdk): model EB deployment capability

* fix(cdk): scope EB platform ACL read

* fix(deploy): verify exact EB release

* docs(deploy): record unresolved EB ACL gate
2026-07-28 15:04:48 -03:00
Alexandre Brandizzi
da29dcf983 fix: make deploy artifacts immutable 2026-07-28 10:38:38 -03:00
Alexandre Brandizzi
73b525a685 ci: document CDK advisory exception 2026-07-27 19:29:37 -03:00
Alexandre Brandizzi
9057668459 ci: automate dev backend deployment 2026-07-27 19:26:07 -03:00
Alexandre Brandizzi
833fb816ee
chore(governance): enforce backend architecture and quality gates (#31)
* docs(governance): add canonical governance docs, unified quality-gate script, and CI parity

- ARCHITECTURE_AND_CODE_QUALITY.md: canonical layering, EF allowlist,
  transaction/commit convention, cancellation, migrations, error disclosure,
  Big-O/perf, ADR exceptions (supersedes BACKEND_ARCHITECTURE.md)
- QUALITY_GATES.md: gate inventory + pass/fail/skip semantics; local==CI
- REVIEW_AND_PR_FRAMEWORK.md: exact-head review, board-backed regression
  inventory, security/perf evidence, ADR exceptions, no godfile theater
- AGENTS.md: repo-specific delta + precedence pointers
- scripts/governance-check.sh: unified G1 restore + G2 ArchitectureTests +
  G3 changed-file format (portable bash)
- .github/workflows/architecture-quality.yml: call the same local script
- ArchitectureTests.cs: add business-service interface-dependency invariant

* fix(governance): make backend gate complete

* fix(ci): enforce governance on every pull request
2026-07-24 17:41:10 -03:00
Alexandre Brandizzi
7d245eb717
refactor: enforce backend boundaries and optimize dispatch (#30)
* refactor(api): enforce service and data-service boundaries

* refactor(api): complete feature service boundaries

* refactor(identity): enforce service and data boundaries

* refactor(vendors): enforce service and data boundaries

* refactor(workorders): enforce service and data boundaries

* refactor(backend): enforce architecture and optimize dispatch

* style(backend): format changed architecture files

* fix(architecture): address backend review follow-ups

* fix(backend): sanitize exception disclosure in changed API endpoints

Replace raw exception-message disclosure (ex.Message) returned to API
callers with a stable sanitized public message plus correlated structured
internal logging, across the endpoints changed in this PR.

- Add SanitizedErrors helper: logs the original exception at Error with a
  generated correlation id and returns a stable public message referencing
  it so support can trace without exposing internals.
- Inject ILogger<T> into the 14 changed controllers and route every
  ex.Message/dbex.Message disclosure through the helper, preserving status
  codes, response shapes, and business data (e.g. OpenWorkOrders).
- Leave FluentValidation (vex.Errors) and existing fixed-message catches
  untouched; out-of-scope controllers (Account/Contact/Employee/Asset/
  PMSchedule) are unchanged.
- Add focused tests proving internal exception text is not returned and
  that Error logging carrying the original exception is invoked.

* fix(architecture): abstract job run state access

* style: format board update service

* test: use collection assertion idiom
2026-07-24 17:35:34 -03:00
dd1ffba06d Add CODEOWNERS requiring internal-dev review 2026-06-22 18:23:54 -04:00
d4d94a2e89 Add CI workflow calling org ci-dotnet reusable 2026-06-22 18:23:54 -04:00
Adam Moussa
f53a276f1d
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#5)
Add the callable PR labeler workflow. README badges skipped: no root
README.md exists in this repo (only BACKEND_ARCHITECTURE.md). Dependabot
unchanged.

Part of INFRA-47 (INFRA-56, INFRA-57).
2026-06-11 14:14:27 -04:00
Adam Moussa
3a61885c71
Add dependency-review caller workflow (#3)
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)
2026-06-05 12:27:11 -04:00