9bac2685cb
workflows-src/rotate-aws-key.yml — daily cron (0 0 * * *) + workflow_dispatch, wraps scripts/rotate_spike_key.sh (uses NOVA_AWS_* static-key auth to IAM- rotate the nova-spike-runner key; uploads the new key to the consumer's Actions secret store; idempotent — deactivates the old key only after the new propagates, verified by a post-PUT GET). Synced to .github + .gitea. v0.2 scope: the mechanism exists (SPEC §5.9 — exists-not-ran); the v0.2 deploy uses the currently-active key. Documented in ARCHITECTURE.md §12.9. The synced workflow file is forge-agnostic (REQ-230): forge base URL / owner / consumer repo come from repository secrets (NOVA_FORGE_*, NOVA_CONSUMER_REPO), not literals. rotate_spike_key.sh reads NOVA_FORGE_* with NOVA_GITEA_* backward-compat fallback. sync_workflows.py PAIRS extended to include rotate-aws-key.yml (was hardcoded to 3 pairs). ---ci--- project: acdl phase: 3 milestone: v1.26 status: execute wave: W7 ---
GitHub Workflows — Nova Platform CI/CD Catalog
This directory contains the GitHub Actions workflows for the Nova
platform. 3 are generated from workflows-src/<name>; 4 are GitHub-only.
Shared workflows (generated from source)
These 3 are generated from workflows-src/<name>. Run python3 scripts/sync_workflows.py --check to verify
no drift.
| Workflow | Trigger | Inputs | Required Secrets | Purpose |
|---|---|---|---|---|
ci.yml |
pull_request: [main] |
— | — | Lint + test + check-only (runs on every PR) |
deploy.yml |
workflow_call (reusable) + push: [main] |
contract (string, required), mode (string, default deploy), changeRequestId (string), environment (string) |
NOVA_AWS_ACCESS_KEY_ID, NOVA_AWS_SECRET_ACCESS_KEY, NOVA_AWS_DEFAULT_REGION, NOVA_KMS_KEY_ID, NOVA_LAMBDA_URL |
Reusable deploy workflow (invoked by consumer repos via uses: nova/.github/workflows/deploy.yml@v1.19) |
modules-lifecycle.yml |
pull_request: [main] + workflow_dispatch |
lifecycle_mode (string, default plan — plan or full) |
NOVA_AWS_ACCESS_KEY_ID, NOVA_AWS_SECRET_ACCESS_KEY, NOVA_AWS_DEFAULT_REGION, NOVA_AWS_ACCOUNT_ID |
L1 + L2 module lifecycle pipeline (plan-only default; full apply/modify/destroy on override) |
GitHub-only workflows
These 4 have no counterpart (the dev forge lacks the features
they require — reusable workflows, matrix needs, release API).
| Workflow | Trigger | Inputs | Required Secrets | Purpose |
|---|---|---|---|---|
platform-test.yml |
pull_request: [main] |
— | — | Lint + unit + integration + schema-validation (replaces ci.yml for PRs) |
primitives-plan.yml |
pull_request: [main] |
— | NOVA_AWS_* |
Plan-only for all L1 primitives (matrix) |
patterns-plan.yml |
pull_request: [main] |
— | NOVA_AWS_* |
Plan-only for all L2 modules (matrix) |
release.yml |
push: [main] |
— | NOVA_RELEASE_TOKEN |
Semver tag + MAJOR.MINOR/MAJOR floating-tag maintenance + release creation on merge to main |
Reusable deploy workflow (deploy.yml)
Consumer repos invoke the deploy workflow via a versioned tag:
jobs:
deploy:
uses: nova/.github/workflows/deploy.yml@v1.19
with:
contract: .nova/contract.yml
environment: dev
secrets: inherit
The workflow checks out the consumer repo + the Nova platform repo, runs
scripts/run_platform.sh, and posts deploy outputs as a PR comment +
to SSM Parameter Store.