Commit graph

36 commits

Author SHA1 Message Date
Alexandre Brandizzi
1afdbc1dae
Merge pull request #243 from Sea-Haven-Industries/renovate/github-actions
chore(deps): update aws-actions/configure-aws-credentials action to v6.3.0
2026-09-23 03:55:00 +00:00
renovate[bot]
7a6b89ac79
chore(deps): update aws-actions/configure-aws-credentials action to v6.3.0 2026-09-21 07:35:26 +00:00
40a3b135cf
ci: run Playwright smoke with two workers 2026-09-19 20:39:54 +00:00
Cursor Agent
cc7ecb9b5a
fix(ci): classify G13 per queued PR on merge_group
Run live isolation on the merge-queue event so ci-complete actually
gates mixed change sets, without treating the group union as one PR.
2026-09-19 20:20:30 +00:00
af0ae60b80 ci: shard unit tests four ways 2026-09-19 15:41:10 -04:00
8ad7438f26 ci: fan out quality gates from this repository 2026-09-19 15:22:38 -04:00
Adam Moussa
41b26692c3
Merge pull request #238 from Sea-Haven-Industries/chore/pr-template-and-cleanup
chore(repo): add PR template, fix README conventions, drop tracked scratch files
2026-09-18 23:30:58 +00:00
1698d53d38
chore(repo): add PR template, fix README conventions, drop tracked scratch files
The org PR template pre-filled Summary / Validation / Tests / Notes here while
PRs in this repository use Summary / Changes and value / Ticket. A repo template
now overrides the org one, and the review framework gains the description
contract plus a note on the divergence from the org pr-policy workflow, which
is not wired in.

README: the CI badge tracked the retired dev branch; branches come from main,
not dev; the fix/ prefix replaces bug/; staging exists alongside dev; and PRs
now merge through the merge queue.

Cleanup: four PR description drafts under tmp/ were tracked; they are removed
and /tmp/ is ignored.
2026-09-18 19:19:55 -04:00
Adam Moussa
73e3362fcf
Merge pull request #237 from Sea-Haven-Industries/renovate/reconfigure
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Deploy Web / Resolve target (push) Waiting to run
Deploy Web / Deploy SPA to (push) Blocked by required conditions
chore(renovate): widen the schedule, manage workflow actions, surface actionlint
2026-09-18 23:09:28 +00:00
Adam Moussa
e611f193bd
ci: run required checks on merge_group for the merge queue (#236)
governance and Build and test are the required checks on main. A merge queue
only counts checks that ran on the merge_group event, so the workflow now
triggers on it. The governance gate reads the merge group's own base SHA
because github.event.before is empty there.
2026-09-18 19:03:12 -04:00
bebd517290
chore(renovate): widen the schedule, manage workflow actions, surface actionlint
The org window (before 6am on Monday) has produced only one security PR in
this repository since the overlay landed, so the overlay now opens every
weekday morning. The github-actions manager is enabled so the digest-pinned
actions in the workflows follow the org's pinning and grouping rules. A regex
manager tracks the actionlint release installed by the governance job; it is
held for dashboard approval because the SHA256 pin next to it has to be
updated by hand.
2026-09-18 18:50:49 -04:00
c99273d3fc
fix(cd): run deploy scripts from the workflow SHA
An old content ref has no upload/verify scripts. Copy those from
github.workflow_sha so dispatch of a live SHA can finish.
2026-09-18 16:09:58 -04:00
0bf834bb8e
fix(cd): keep .env.production Sentry DSN when the GitHub var is empty
An unset vars.VITE_SENTRY_DSN becomes an empty env value and Vite will
not let .env.production overwrite it, which would ship with Sentry off.
2026-09-18 15:26:55 -04:00
ceecab5438
fix(cd): ignore githubdeploy description and retire leftover pointer CD
SCP denies UpdateRoleDescription on githubdeploy-*, so HCP apply cannot
rewrite the role description. Pointer workflows must not land on main.
2026-09-18 15:04:51 -04:00
Adam Moussa
c96a259365
refactor(cd): ship SPA content from GitHub on main (#220)
Some checks failed
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD

Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.

* ci: run Frontend checks and Terraform CI on PRs to main and dev

Match backend 148 so a PR targeting origin/dev still gets the required
checks. Push remains main only.

* refactor(terraform): keep live/dev and live/staging as HCP roots

Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.

* style: prettier terraform-validate.mjs

* fix(terraform): pin githubdeploy assume-role policy in import checker

Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
2026-09-18 14:30:20 -04:00
Adam Moussa
d88a2e7854
fix(observability): upload source maps under the client Sentry release (SH-342) (#189)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Waiting to run
Dev events bake shoc-frontend@<sha>. Stop tagging artifacts with Terraform
version_label so Sentry can symbolicate them.
2026-09-14 15:21:15 -04:00
Adam Moussa
f23c60ccc2
fix(ci): skip duplicate verify on content CD and ignore origin timeout drift (SH-300) (#183)
* fix(terraform): ignore origin response_completion_timeout in the release plan guard (SH-300)

AWS returns 0 when the timeout is unset. The provider writes null on
origin_path updates, so the first real CD plan failed closed.

* fix(ci): drop duplicate verify from the content CD workflow (SH-300)

Frontend checks already runs verify on PRs and pushes. Removing the
validate job also requires dropping needs: validate so dispatch can run.

* fix(terraform): equate origin timeout 0 and null only (SH-300)

Numeric timeout changes still fail closed. Rename the filter so it is
not read as an after_unknown allowlist.
2026-09-11 19:17:36 +00:00
Adam Moussa
7716b4afc8
fix(ci): confirm release prefix with s3api head-object (SH-300) (#182)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Validate and deploy / Validate production build (push) Waiting to run
Validate and deploy / Deploy shoc-frontend-new-dev through Terraform (push) Blocked by required conditions
grep -q closed the aws s3 ls pipe after a successful upload and failed the deploy.
2026-09-11 18:26:19 +00:00
Adam Moussa
69c24c1c2c
feat(terraform): ship dev content CD through Terraform (SH-300) (#180)
* feat(terraform): ship dev content CD through Terraform (SH-300)

GitHub uploads immutable release prefixes; Terraform owns live publish.
Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set.

* fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)
2026-09-11 13:40:14 -04:00
Adam Moussa
8b5281d357
ci(terraform-isolation): re-evaluate the gate on label changes (#177)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
* ci(terraform-isolation): re-evaluate the gate on label changes

* test(terraform-isolation): lock the ci.yaml label-event contract

* fix(terraform-isolation): do not treat terraform markdown as a mixed change

* fix(ci): do not skip Frontend checks on isolation label events

* ci(terraform-isolation): run label retriggers in a dedicated workflow

* fix: apply eslint formatting

* fix: apply additional missed eslint formatting
2026-09-10 20:45:49 -04:00
8ec91f0dac
ci: run the Terraform isolation gate as a job in the CI workflow 2026-09-10 19:37:27 -04:00
08da408a13
ci(governance): wire Terraform and CDK gates and isolate Terraform PRs
Governance now runs the import-plan checker tests, Terraform fmt and
validate for terraform/live/dev, the isolation gate tests, and the CDK
build, tests, and synth in both modes. A new terraform-isolation
workflow fails PRs that change terraform/** together with application
code; the terraform-isolation-override label is the reviewed exception.
Renovate gains the terraform manager.
2026-09-10 19:15:13 -04:00
87e79072ad
ci(deploy): make dev content deploy workflow_dispatch only
Remove the push-to-dev trigger and the org cd-cdk.yaml caller so CI no
longer runs cdk deploy during the adoption. The workflow assumes the
pinned dev role and runs the simple scripts/deploy-web.sh against a
pinned bucket and distribution, which keeps content deploys working
after CloudFormation relinquishes the stack outputs. Staging is
untouched.
2026-09-10 19:15:12 -04:00
Codex Review Integration
207199559f feat(observability): identify and scrub Sentry transactions 2026-09-03 17:12:49 -03:00
Codex Review Integration
a24002bc24 feat: activate Sentry deployment environments 2026-09-03 15:10:01 -03:00
Alexandre Brandizzi
4df6e76192
ci: add protected staging frontend deployment lane (#151)
* ci: add protected staging deployment lane

* fix: constrain staging publisher permissions

* fix: handle first-push governance baseline

---------

Co-authored-by: Codex Review Integration <codex-review@local.invalid>
2026-08-28 10:59:55 -04:00
Adam Moussa
481fa29f42
ci: pin github actions to immutable shas (#144)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Deploy / deploy (push) Waiting to run
2026-08-26 19:04:46 -03:00
Adam Moussa
3fb629dee3
chore(renovate): add frontend overlay with three-day release age (#142)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Deploy / deploy (push) Waiting to run
* chore(renovate): add Renovate frontend overlay config

* fix: adjust config results for TanStack, packageManager, and package.json
2026-08-26 17:36:34 -03:00
Alexandre Brandizzi
f11e8a5d13
fix(ci): replace ambiguous check names (#141)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Deploy / deploy (push) Waiting to run
* fix(ci): replace ambiguous check names

* fix(ci): clarify visual regression check

* chore(ci): refresh protected checks

* docs(ci): clarify compatibility removal

* fix(ci): add exact-head recovery trigger

* ci: remove legacy check name

---------

Co-authored-by: Codex Review Integration <codex-review@local.invalid>
2026-08-26 13:17:14 -04:00
Arthur Bassi
9d39d5bb14 ci(work-orders): add Playwright visual regression to CI
Run board screenshots in the existing Docker visual job with vendors.
2026-08-20 23:24:14 -03:00
Alexandre Brandizzi
cc0df8f569 fix(vendors): complete shell and visual parity gates 2026-08-10 12:11:38 -03:00
Alexandre Brandizzi
4337cc662b
chore(governance): enforce frontend quality system (#53)
Some checks are pending
CI / ci (push) Waiting to run
CI / governance (push) Waiting to run
Deploy / deploy (push) Waiting to run
* chore(governance): make React/TS conventions mandatory via executable gates

Add AGENTS.md, QUALITY_GATES.md, ARCHITECTURE_AND_CODE_QUALITY.md, and
REVIEW_AND_PR_FRAMEWORK.md as the binding conventions and PR review
contract for humans and all coding/review agents.

Add a single 'npm run verify' command (format + lint + build + test +
governance) and 'npm run governance', which runs a dependency-free godfile
ratchet (whole-repo, baseline in scripts/governance-baseline.json) and a
changed-file maintainability gate (complexity<=20, function<=150, params<=4,
depth<=4) via ESLint. Legacy is handled by ratchets, not relaxation: 5
godfiles over 500 lines are grandfathered debt; maintainability thresholds
apply to changed TS/TSX (72 legacy violations across ~51 files otherwise).

Add a repo-owned 'governance' CI job that runs 'npm run verify' so every
gate is guaranteed from this repository, independent of the org reusable
workflow.

* fix(governance): make frontend ratchets fail closed
2026-07-24 16:47:34 -03:00
Alexandre Brandizzi
166df904ac
feat(infra): AWS S3 + CloudFront CD pipeline on dev.seahaven.com (#21)
Some checks failed
CI / ci (push) Has been cancelled
Deploy / deploy (push) Has been cancelled
Self-contained CDK app (S3 + CloudFront + OIDC deploy role) deployed via the org reusable cd-cdk.yaml. Frontend served on dev.seahaven.com with the *.seahaven.com cert and a Route 53 apex alias; the SPA calls the dev backend directly at https://api.dev.seahaven.com/api.
2026-07-07 06:14:06 -03:00
4464e76228 Convert CI to org reusable workflow caller
Some checks failed
CI / ci (push) Has been cancelled
Replace the inline 5-job ci.yml with a thin caller of the org reusable
workflow ci-typescript-frontend.yaml. The standards gate, changed-line
guard, format/lint/build, unit tests, and Playwright browser smoke now
live centrally in Sea-Haven-Industries/.github and are maintained once.

Renames ci.yml -> ci.yaml (kebab-case .yaml convention) and triggers on
pull_request and push to main and dev, so this branch keeps CI coverage.

The reusable workflow runs as a single `ci` job, so this caller emits the
`ci / ci` status context. Branch-protection rulesets for main and dev must
have their required checks switched from the old job names (Metadata and
standards, Code quality, Build, Unit tests, Browser smoke) to `ci / ci`.
2026-06-24 16:46:47 -04:00
Adam Moussa
0af9d871ab
Add CODEOWNERS requiring internal-dev review (#20)
Assign all files to the internal-dev team so every pull request needs an
approving review from an internal-dev member, giving internal engineering
oversight of changes. The org main-branch-protection ruleset enforces this
via required code-owner review; the internal-dev team has write access, so
it is an eligible code owner.
2026-06-22 16:46:19 -04:00
Arthur Bassi
a0cf7b9ef0
Feat/vite typescript migration (#16)
* chore: add eslint, prettier, husky and commitlint tooling

* ci: add GitHub Actions workflow for lint and build

* build: migrate from CRA to Vite with TypeScript config

* docs: add architecture plan and design system documentation

* fix: scope ESLint to new components and hooks directories

* feat: add HTTP client, query cache and shared utilities

* feat: add theme system and global application styles

* feat: add shared UI, layout and domain badge components

* feat: add auth domain, provider and login page

* feat: add app shell, file-based routing and bootstrap

* feat: add protected layout and dashboard module

* feat: add accounts CRUD module

* feat: add assets CRUD module

* feat: add contacts CRUD module

* feat: add employees CRUD module

* feat: add locations CRUD module

* feat: add calendar events module

* feat: add follow-ups CRUD module

* feat: add PM schedules CRUD module

* feat: add work orders module with dispatch modals

* feat: add vendors CRUD and portal token panel

* feat: add vendor purchase orders module

* feat: add uplifts queue module

* feat: add settings for dropdowns and task templates

* feat: add vendor portal routes and signature capture

* test: add Vitest setup and Playwright login e2e spec

* chore: remove legacy CRA pages, Redux store and JS hooks

* chore: update gitignore and env example for Vite

* docs: translate pt-BR docs and Cursor rules to English

* fix(ci): fix login e2e session mock and prettier formatting

* fix(build): use mjs router script for Node 20 CI compatibility

* chore: remove migration scripts and unused generouted router

* fix(auth): restore JWT and align CRUD with backend routes

* fix(api): add no-content helpers and align paths with backend

* fix(accounts): align detail and mutation payloads with backend

* fix(contacts): resolve detail via GetContacts and map address DTOs

* fix(work-orders): align routes, delete body, and create payload

* fix(vendors): delete vendors via REST route

* fix(pm-schedules): handle empty save and delete responses

* fix(employees): add fallbacks for detail and dropdown calls

* chore(calendar): disable routes until backend exists

* chore(env): switch tracked env vars to Vite prefixes

* fix(api): align frontend contracts with backend review findings

Correct Work Order getById query param, asset site options via Location API,
Employee JobTitleId payload, and remove stale API paths.

* fix(employees,pm-schedules): align forms with backend API contracts

Align PM Schedule form and save payload with PMSchedule_DTO fields.
Bind employee Job Title select to jobTitleId for create/update payloads.
Add regression tests for both flows.

* fix(pm-schedules): gate edit/delete for Dev API contract

Production Dev API exposes only GetList and Save.

Hide unsupported edit/delete UI and block the edit route.

Add regression tests for disabled actions.

* docs(env): document VITE_API_URL must include /api suffix

* refactor(api): extract shared API prefix URL resolution

* feat(build): fail build on misconfigured absolute VITE_API_URL

* test(api): cover API URL contract and prefix resolution

* feat(auth): disable login submit until email and password are valid

* test(auth): align login tests with disabled submit behavior

* Feat/ab/menu-and-header (#17)

* chore(deps): add lucide-react for layout icon migration

* feat(auth): add getPrimaryUserRole helper for header display

* style(theme): add sidebar active tokens and nav group typography

* refactor(menu): migrate nav icons to lucide and trim menu groups

* feat(layout): redesign sidebar, topbar, and admin shell viewport

* chore(menu): hide Reports and Documents from sidebar

---------

Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>

* ci: add frontend PR quality baseline (#18)

* chore(deps): add lucide-react for layout icon migration

* feat(auth): add getPrimaryUserRole helper for header display

* style(theme): add sidebar active tokens and nav group typography

* refactor(menu): migrate nav icons to lucide and trim menu groups

* feat(layout): redesign sidebar, topbar, and admin shell viewport

* chore(menu): hide Reports and Documents from sidebar

* ci: add PR quality baseline checks

* ci: avoid self-matching standards guard

* ci: split frontend quality gates

---------

Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>

---------

Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-06-18 14:41:17 -03:00