Commit graph

24 commits

Author SHA1 Message Date
Adam Moussa
1199252673
Merge branch 'main' into chore/staging-adoption-complete 2026-09-18 16:45:04 -04:00
ae852f15ea
fix(cd): skip source-map upload when sentry-cli is absent
August SPA trees have no @sentry/cli. Skipping that step lets a
workflow_dispatch of the live staging SHA finish the S3 sync.
2026-09-18 16:27:25 -04:00
7b37529006
chore(terraform): complete staging SPA adoption
Pin staging adoption_complete to true so tags and the bucket policy
match the already-adopted dev root.
2026-09-18 16:14:10 -04:00
Adam Moussa
c96a259365
refactor(cd): ship SPA content from GitHub on main (#220)
Some checks failed
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD

Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.

* ci: run Frontend checks and Terraform CI on PRs to main and dev

Match backend 148 so a PR targeting origin/dev still gets the required
checks. Push remains main only.

* refactor(terraform): keep live/dev and live/staging as HCP roots

Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.

* style: prettier terraform-validate.mjs

* fix(terraform): pin githubdeploy assume-role policy in import checker

Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
2026-09-18 14:30:20 -04:00
Adam Moussa
d88a2e7854
fix(observability): upload source maps under the client Sentry release (SH-342) (#189)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Waiting to run
Dev events bake shoc-frontend@<sha>. Stop tagging artifacts with Terraform
version_label so Sentry can symbolicate them.
2026-09-14 15:21:15 -04:00
Adam Moussa
29aecff2bb
fix(ci): hash the served index.html byte stream in CloudFront verify (SH-300) (#186)
Some checks failed
Frontend checks / Build and test (push) Has been cancelled
Frontend checks / governance (push) Has been cancelled
Frontend checks / Visual regression (push) Has been cancelled
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
Capturing the curl body in "$(...)" strips the trailing newline, so the
served sha256 never matched dist/index.html and every release and rollback
verify polled to the budget and failed. Hash the response stream directly
and give the test fixture a trailing newline so the suite covers it.
2026-09-11 18:10:51 -03:00
Adam Moussa
c30e8aa74b
fix(ci): assert the baked API URL in served JS assets (SH-300) (#184)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Waiting to run
Vite puts VITE_API_URL in hashed JS, not index.html. Scan every
referenced /assets file and reject staging or localhost there too.
2026-09-11 19:38:07 +00:00
Adam Moussa
f23c60ccc2
fix(ci): skip duplicate verify on content CD and ignore origin timeout drift (SH-300) (#183)
* fix(terraform): ignore origin response_completion_timeout in the release plan guard (SH-300)

AWS returns 0 when the timeout is unset. The provider writes null on
origin_path updates, so the first real CD plan failed closed.

* fix(ci): drop duplicate verify from the content CD workflow (SH-300)

Frontend checks already runs verify on PRs and pushes. Removing the
validate job also requires dropping needs: validate so dispatch can run.

* fix(terraform): equate origin timeout 0 and null only (SH-300)

Numeric timeout changes still fail closed. Rename the filter so it is
not read as an after_unknown allowlist.
2026-09-11 19:17:36 +00:00
Adam Moussa
7716b4afc8
fix(ci): confirm release prefix with s3api head-object (SH-300) (#182)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Validate and deploy / Validate production build (push) Waiting to run
Validate and deploy / Deploy shoc-frontend-new-dev through Terraform (push) Blocked by required conditions
grep -q closed the aws s3 ls pipe after a successful upload and failed the deploy.
2026-09-11 18:26:19 +00:00
Adam Moussa
69c24c1c2c
feat(terraform): ship dev content CD through Terraform (SH-300) (#180)
* feat(terraform): ship dev content CD through Terraform (SH-300)

GitHub uploads immutable release prefixes; Terraform owns live publish.
Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set.

* fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)
2026-09-11 13:40:14 -04:00
f532aa6059
feat(terraform): complete dev environment adoption (SH-300) 2026-09-11 11:22:28 -04:00
Adam Moussa
8b5281d357
ci(terraform-isolation): re-evaluate the gate on label changes (#177)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
* ci(terraform-isolation): re-evaluate the gate on label changes

* test(terraform-isolation): lock the ci.yaml label-event contract

* fix(terraform-isolation): do not treat terraform markdown as a mixed change

* fix(ci): do not skip Frontend checks on isolation label events

* ci(terraform-isolation): run label retriggers in a dedicated workflow

* fix: apply eslint formatting

* fix: apply additional missed eslint formatting
2026-09-10 20:45:49 -04:00
08da408a13
ci(governance): wire Terraform and CDK gates and isolate Terraform PRs
Governance now runs the import-plan checker tests, Terraform fmt and
validate for terraform/live/dev, the isolation gate tests, and the CDK
build, tests, and synth in both modes. A new terraform-isolation
workflow fails PRs that change terraform/** together with application
code; the terraform-isolation-override label is the reviewed exception.
Renovate gains the terraform manager.
2026-09-10 19:15:13 -04:00
87e79072ad
ci(deploy): make dev content deploy workflow_dispatch only
Remove the push-to-dev trigger and the org cd-cdk.yaml caller so CI no
longer runs cdk deploy during the adoption. The workflow assumes the
pinned dev role and runs the simple scripts/deploy-web.sh against a
pinned bucket and distribution, which keeps content deploys working
after CloudFormation relinquishes the stack outputs. Staging is
untouched.
2026-09-10 19:15:12 -04:00
78398482cf
feat(terraform): add dev root and import guard for HCP adoption
Port the reviewed dev root and environment-owned/inventory modules from
111eb556 with the 13 pinned dev identifiers. adoption_complete is pinned
to false in code; the root has no variables so a workspace variable
cannot change what applies. The tf-poc root, staging root, and tf-poc
map entries are dropped; staging constants stay only for the checker's
cross-environment negative tests.
2026-09-10 19:15:09 -04:00
Codex Review Integration
207199559f feat(observability): identify and scrub Sentry transactions 2026-09-03 17:12:49 -03:00
Alexandre Brandizzi
4df6e76192
ci: add protected staging frontend deployment lane (#151)
* ci: add protected staging deployment lane

* fix: constrain staging publisher permissions

* fix: handle first-push governance baseline

---------

Co-authored-by: Codex Review Integration <codex-review@local.invalid>
2026-08-28 10:59:55 -04:00
arthur.bassi
251edd9c61 fix(work-orders): drop vendor collateral from slide-over PR
Restore vendors and page-header to origin/dev so this PR stays the WO
slide-over/media slice only. Remove stale godfile baseline entries now
under the 500-line cap.
2026-08-11 13:54:31 -03:00
Alexandre Brandizzi
ca7829036f
feat(vendors): add company roster workflows (SH-198) (#64)
Some checks failed
CI / ci (push) Has been cancelled
CI / governance (push) Has been cancelled
Deploy / deploy (push) Has been cancelled
* feat(vendors): support company roster workflows

* fix(vendors): address roster review feedback

* test(vendors): preserve draft on roster load failure

* fix(vendors): preserve current roster selection
2026-08-04 09:53:48 -03:00
Arthur Bassi
6e99dc0af2 refactor(work-orders): pass board-api governance maintainability gate
Split oversized API/mapper/UI modules and extract focused helpers so the
exact head satisfies godfile and complexity ratchets without relaxing thresholds.
2026-07-28 09:56:27 -03:00
Alexandre Brandizzi
09ed3693f6 refactor: enforce dispatch detail quality gates 2026-07-24 18:51:50 -03:00
Alexandre Brandizzi
45909e7aa6
Complete vendor operations roadmap frontend (#52)
* feat(vendors): complete operations roadmap frontend

* test(vendors): cover work order assignment flow

* fix(vendors): address review feedback

* fix(vendors): prevent stale preference saves

* fix(vendors): require truthful appointment bounds
2026-07-24 18:10:45 -03:00
Alexandre Brandizzi
4337cc662b
chore(governance): enforce frontend quality system (#53)
Some checks are pending
CI / ci (push) Waiting to run
CI / governance (push) Waiting to run
Deploy / deploy (push) Waiting to run
* chore(governance): make React/TS conventions mandatory via executable gates

Add AGENTS.md, QUALITY_GATES.md, ARCHITECTURE_AND_CODE_QUALITY.md, and
REVIEW_AND_PR_FRAMEWORK.md as the binding conventions and PR review
contract for humans and all coding/review agents.

Add a single 'npm run verify' command (format + lint + build + test +
governance) and 'npm run governance', which runs a dependency-free godfile
ratchet (whole-repo, baseline in scripts/governance-baseline.json) and a
changed-file maintainability gate (complexity<=20, function<=150, params<=4,
depth<=4) via ESLint. Legacy is handled by ratchets, not relaxation: 5
godfiles over 500 lines are grandfathered debt; maintainability thresholds
apply to changed TS/TSX (72 legacy violations across ~51 files otherwise).

Add a repo-owned 'governance' CI job that runs 'npm run verify' so every
gate is guaranteed from this repository, independent of the org reusable
workflow.

* fix(governance): make frontend ratchets fail closed
2026-07-24 16:47:34 -03:00
Alexandre Brandizzi
166df904ac
feat(infra): AWS S3 + CloudFront CD pipeline on dev.seahaven.com (#21)
Some checks failed
CI / ci (push) Has been cancelled
Deploy / deploy (push) Has been cancelled
Self-contained CDK app (S3 + CloudFront + OIDC deploy role) deployed via the org reusable cd-cdk.yaml. Frontend served on dev.seahaven.com with the *.seahaven.com cert and a Route 53 apex alias; the SPA calls the dev backend directly at https://api.dev.seahaven.com/api.
2026-07-07 06:14:06 -03:00