* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD
Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.
* ci: run Frontend checks and Terraform CI on PRs to main and dev
Match backend 148 so a PR targeting origin/dev still gets the required
checks. Push remains main only.
* refactor(terraform): keep live/dev and live/staging as HCP roots
Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.
* style: prettier terraform-validate.mjs
* fix(terraform): pin githubdeploy assume-role policy in import checker
Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
* feat(terraform): ship dev content CD through Terraform (SH-300)
GitHub uploads immutable release prefixes; Terraform owns live publish.
Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set.
* fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)
* ci(terraform-isolation): re-evaluate the gate on label changes
* test(terraform-isolation): lock the ci.yaml label-event contract
* fix(terraform-isolation): do not treat terraform markdown as a mixed change
* fix(ci): do not skip Frontend checks on isolation label events
* ci(terraform-isolation): run label retriggers in a dedicated workflow
* fix: apply eslint formatting
* fix: apply additional missed eslint formatting
Two-phase runbook, ownership boundary, workspace invariants, rollback
per phase, and operational rules in terraform/README.md; CDK adoption
mode and the retired cd-cdk path in infra/cdk/README.md; gate matrix and
deployment section updates.
* chore(governance): make React/TS conventions mandatory via executable gates
Add AGENTS.md, QUALITY_GATES.md, ARCHITECTURE_AND_CODE_QUALITY.md, and
REVIEW_AND_PR_FRAMEWORK.md as the binding conventions and PR review
contract for humans and all coding/review agents.
Add a single 'npm run verify' command (format + lint + build + test +
governance) and 'npm run governance', which runs a dependency-free godfile
ratchet (whole-repo, baseline in scripts/governance-baseline.json) and a
changed-file maintainability gate (complexity<=20, function<=150, params<=4,
depth<=4) via ESLint. Legacy is handled by ratchets, not relaxation: 5
godfiles over 500 lines are grandfathered debt; maintainability thresholds
apply to changed TS/TSX (72 legacy violations across ~51 files otherwise).
Add a repo-owned 'governance' CI job that runs 'npm run verify' so every
gate is guaranteed from this repository, independent of the org reusable
workflow.
* fix(governance): make frontend ratchets fail closed