Commit graph

13 commits

Author SHA1 Message Date
Adam Moussa
e611f193bd
ci: run required checks on merge_group for the merge queue (#236)
governance and Build and test are the required checks on main. A merge queue
only counts checks that ran on the merge_group event, so the workflow now
triggers on it. The governance gate reads the merge group's own base SHA
because github.event.before is empty there.
2026-09-18 19:03:12 -04:00
Adam Moussa
c96a259365
refactor(cd): ship SPA content from GitHub on main (#220)
Some checks failed
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD

Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.

* ci: run Frontend checks and Terraform CI on PRs to main and dev

Match backend 148 so a PR targeting origin/dev still gets the required
checks. Push remains main only.

* refactor(terraform): keep live/dev and live/staging as HCP roots

Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.

* style: prettier terraform-validate.mjs

* fix(terraform): pin githubdeploy assume-role policy in import checker

Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
2026-09-18 14:30:20 -04:00
Adam Moussa
69c24c1c2c
feat(terraform): ship dev content CD through Terraform (SH-300) (#180)
* feat(terraform): ship dev content CD through Terraform (SH-300)

GitHub uploads immutable release prefixes; Terraform owns live publish.
Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set.

* fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)
2026-09-11 13:40:14 -04:00
Adam Moussa
8b5281d357
ci(terraform-isolation): re-evaluate the gate on label changes (#177)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
* ci(terraform-isolation): re-evaluate the gate on label changes

* test(terraform-isolation): lock the ci.yaml label-event contract

* fix(terraform-isolation): do not treat terraform markdown as a mixed change

* fix(ci): do not skip Frontend checks on isolation label events

* ci(terraform-isolation): run label retriggers in a dedicated workflow

* fix: apply eslint formatting

* fix: apply additional missed eslint formatting
2026-09-10 20:45:49 -04:00
8ec91f0dac
ci: run the Terraform isolation gate as a job in the CI workflow 2026-09-10 19:37:27 -04:00
08da408a13
ci(governance): wire Terraform and CDK gates and isolate Terraform PRs
Governance now runs the import-plan checker tests, Terraform fmt and
validate for terraform/live/dev, the isolation gate tests, and the CDK
build, tests, and synth in both modes. A new terraform-isolation
workflow fails PRs that change terraform/** together with application
code; the terraform-isolation-override label is the reviewed exception.
Renovate gains the terraform manager.
2026-09-10 19:15:13 -04:00
Alexandre Brandizzi
4df6e76192
ci: add protected staging frontend deployment lane (#151)
* ci: add protected staging deployment lane

* fix: constrain staging publisher permissions

* fix: handle first-push governance baseline

---------

Co-authored-by: Codex Review Integration <codex-review@local.invalid>
2026-08-28 10:59:55 -04:00
Adam Moussa
481fa29f42
ci: pin github actions to immutable shas (#144)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Deploy / deploy (push) Waiting to run
2026-08-26 19:04:46 -03:00
Alexandre Brandizzi
f11e8a5d13
fix(ci): replace ambiguous check names (#141)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Deploy / deploy (push) Waiting to run
* fix(ci): replace ambiguous check names

* fix(ci): clarify visual regression check

* chore(ci): refresh protected checks

* docs(ci): clarify compatibility removal

* fix(ci): add exact-head recovery trigger

* ci: remove legacy check name

---------

Co-authored-by: Codex Review Integration <codex-review@local.invalid>
2026-08-26 13:17:14 -04:00
Arthur Bassi
9d39d5bb14 ci(work-orders): add Playwright visual regression to CI
Run board screenshots in the existing Docker visual job with vendors.
2026-08-20 23:24:14 -03:00
Alexandre Brandizzi
cc0df8f569 fix(vendors): complete shell and visual parity gates 2026-08-10 12:11:38 -03:00
Alexandre Brandizzi
4337cc662b
chore(governance): enforce frontend quality system (#53)
Some checks are pending
CI / ci (push) Waiting to run
CI / governance (push) Waiting to run
Deploy / deploy (push) Waiting to run
* chore(governance): make React/TS conventions mandatory via executable gates

Add AGENTS.md, QUALITY_GATES.md, ARCHITECTURE_AND_CODE_QUALITY.md, and
REVIEW_AND_PR_FRAMEWORK.md as the binding conventions and PR review
contract for humans and all coding/review agents.

Add a single 'npm run verify' command (format + lint + build + test +
governance) and 'npm run governance', which runs a dependency-free godfile
ratchet (whole-repo, baseline in scripts/governance-baseline.json) and a
changed-file maintainability gate (complexity<=20, function<=150, params<=4,
depth<=4) via ESLint. Legacy is handled by ratchets, not relaxation: 5
godfiles over 500 lines are grandfathered debt; maintainability thresholds
apply to changed TS/TSX (72 legacy violations across ~51 files otherwise).

Add a repo-owned 'governance' CI job that runs 'npm run verify' so every
gate is guaranteed from this repository, independent of the org reusable
workflow.

* fix(governance): make frontend ratchets fail closed
2026-07-24 16:47:34 -03:00
4464e76228 Convert CI to org reusable workflow caller
Some checks failed
CI / ci (push) Has been cancelled
Replace the inline 5-job ci.yml with a thin caller of the org reusable
workflow ci-typescript-frontend.yaml. The standards gate, changed-line
guard, format/lint/build, unit tests, and Playwright browser smoke now
live centrally in Sea-Haven-Industries/.github and are maintained once.

Renames ci.yml -> ci.yaml (kebab-case .yaml convention) and triggers on
pull_request and push to main and dev, so this branch keeps CI coverage.

The reusable workflow runs as a single `ci` job, so this caller emits the
`ci / ci` status context. Branch-protection rulesets for main and dev must
have their required checks switched from the old job names (Metadata and
standards, Code quality, Build, Unit tests, Browser smoke) to `ci / ci`.
2026-06-24 16:46:47 -04:00