0d2cbdb423
Genericize forge-detection code: gitea→forge/generic_forge, GITEA_ACTOR→FORGE_ACTOR. Drop .gitea byte-identity test assertions (keep GitHub-side + contract conformance). Add test_no_forge_mentions.py guard test (REQ-230). Delete completed migration docs (NOVA_MIGRATION.md, NOVA_AWS_MIGRATION.md). Move NO_HUMANS_THESIS.md to .ciagent/ (internal artifact). Strip ciagent-internal provenance from synced docs (REQ-/D-/P-/CAP- IDs, milestone headers, .ciagent/PROJECT.md citations). Trim README.md (reusable deploy section, local key rotation paragraph). Fix version-tag drift (@v1.13→@v1.19, acdl/→nova/). ---ci--- project: acdl phase: 1 milestone: v1.20 status: execute requirements: [REQ-230, REQ-231, REQ-232] ---/ci---
45 lines
2.5 KiB
Markdown
45 lines
2.5 KiB
Markdown
# GitHub Workflows — Nova Platform CI/CD Catalog
|
|
|
|
This directory contains the GitHub Actions workflows for the Nova
|
|
platform. 3 are generated from `workflows-src/<name>`; 4 are GitHub-only.
|
|
|
|
## Shared workflows (generated from source)
|
|
|
|
These 3 are generated from `workflows-src/<name>`. Run `python3 scripts/sync_workflows.py --check` to verify
|
|
no drift.
|
|
|
|
| Workflow | Trigger | Inputs | Required Secrets | Purpose |
|
|
|----------|---------|--------|------------------|---------|
|
|
| `ci.yml` | `pull_request: [main]` | — | — | Lint + test + check-only (runs on every PR) |
|
|
| `deploy.yml` | `workflow_call` (reusable) + `push: [main]` | `contract` (string, required), `mode` (string, default `deploy`), `changeRequestId` (string), `environment` (string) | `NOVA_AWS_ACCESS_KEY_ID`, `NOVA_AWS_SECRET_ACCESS_KEY`, `NOVA_AWS_DEFAULT_REGION`, `NOVA_KMS_KEY_ID`, `NOVA_LAMBDA_URL` | Reusable deploy workflow (invoked by consumer repos via `uses: nova/.github/workflows/deploy.yml@v1.19`) |
|
|
| `modules-lifecycle.yml` | `pull_request: [main]` + `workflow_dispatch` | `lifecycle_mode` (string, default `plan` — `plan` or `full`) | `NOVA_AWS_ACCESS_KEY_ID`, `NOVA_AWS_SECRET_ACCESS_KEY`, `NOVA_AWS_DEFAULT_REGION`, `NOVA_AWS_ACCOUNT_ID` | L1 + L2 module lifecycle pipeline (plan-only default; full apply/modify/destroy on override) |
|
|
|
|
## GitHub-only workflows
|
|
|
|
These 4 have no counterpart (the dev forge lacks the features
|
|
they require — reusable workflows, matrix `needs`, release API).
|
|
|
|
| Workflow | Trigger | Inputs | Required Secrets | Purpose |
|
|
|----------|---------|--------|------------------|---------|
|
|
| `platform-test.yml` | `pull_request: [main]` | — | — | Lint + unit + integration + schema-validation (replaces `ci.yml` for PRs) |
|
|
| `primitives-plan.yml` | `pull_request: [main]` | — | `NOVA_AWS_*` | Plan-only for all L1 primitives (matrix) |
|
|
| `patterns-plan.yml` | `pull_request: [main]` | — | `NOVA_AWS_*` | Plan-only for all L2 modules (matrix) |
|
|
| `release.yml` | `push: [main]` | — | `NOVA_RELEASE_TOKEN` | Semver tag + MAJOR.MINOR/MAJOR floating-tag maintenance + release creation on merge to main |
|
|
|
|
## Reusable deploy workflow (`deploy.yml`)
|
|
|
|
Consumer repos invoke the deploy workflow via a versioned tag:
|
|
|
|
```yaml
|
|
jobs:
|
|
deploy:
|
|
uses: nova/.github/workflows/deploy.yml@v1.19
|
|
with:
|
|
contract: .nova/contract.yml
|
|
environment: dev
|
|
secrets: inherit
|
|
```
|
|
|
|
The workflow checks out the consumer repo + the Nova platform repo, runs
|
|
`scripts/run_platform.sh`, and posts deploy outputs as a PR comment +
|
|
to SSM Parameter Store. |