Files
acdl/.github/workflows
Jon Chery d069654367
acdl-ci / Lint (push) Successful in 10s
acdl-ci / Test (push) Failing after 24s
acdl-ci / Platform check-only (offline) (push) Successful in 24s
Nova Slides Render / render (push) Failing after 24s
feat(P2): env-transition detect-and-destroy — REQ-282..287
- core/env_transition.py: detect_prior_env() + record_applied_env() via DynamoDB nova-contracts table (REQ-282,283)
- scripts/run_platform.sh Step 0b: detect env change, destroy prior env (deletion_protection=false, terraform init -reconfigure + destroy), emit ENV_DESTROYED evidence event, fail closed on destroy failure (REQ-284)
- scripts/run_platform.sh: record applied env after successful apply (REQ-285)
- .github/workflows/deploy.yml: pass NOVA_CONSUMER_REPO to run_platform.sh (REQ-286)
- adapters/terraform/adapter.py: doc comment on env-scoped state key (REQ-287)

No orphan path: if destroy fails, pipeline exits non-zero (no apply runs).

---ci---
project: acdl
phase: 2
milestone: v1.24
status: execute
requirements: [REQ-282,REQ-283,REQ-284,REQ-285,REQ-286,REQ-287]
---/ci---
2026-08-12 14:30:24 +00:00
..

GitHub Workflows — Nova Platform CI/CD Catalog

This directory contains the GitHub Actions workflows for the Nova platform. 3 are generated from workflows-src/<name>; 4 are GitHub-only.

Shared workflows (generated from source)

These 3 are generated from workflows-src/<name>. Run python3 scripts/sync_workflows.py --check to verify no drift.

Workflow Trigger Inputs Required Secrets Purpose
ci.yml pull_request: [main] Lint + test + check-only (runs on every PR)
deploy.yml workflow_call (reusable) + push: [main] contract (string, required), mode (string, default deploy), changeRequestId (string), environment (string) NOVA_AWS_ACCESS_KEY_ID, NOVA_AWS_SECRET_ACCESS_KEY, NOVA_AWS_DEFAULT_REGION, NOVA_KMS_KEY_ID, NOVA_LAMBDA_URL Reusable deploy workflow (invoked by consumer repos via uses: nova/.github/workflows/deploy.yml@v1.19)
modules-lifecycle.yml pull_request: [main] + workflow_dispatch lifecycle_mode (string, default planplan or full) NOVA_AWS_ACCESS_KEY_ID, NOVA_AWS_SECRET_ACCESS_KEY, NOVA_AWS_DEFAULT_REGION, NOVA_AWS_ACCOUNT_ID L1 + L2 module lifecycle pipeline (plan-only default; full apply/modify/destroy on override)

GitHub-only workflows

These 4 have no counterpart (the dev forge lacks the features they require — reusable workflows, matrix needs, release API).

Workflow Trigger Inputs Required Secrets Purpose
platform-test.yml pull_request: [main] Lint + unit + integration + schema-validation (replaces ci.yml for PRs)
primitives-plan.yml pull_request: [main] NOVA_AWS_* Plan-only for all L1 primitives (matrix)
patterns-plan.yml pull_request: [main] NOVA_AWS_* Plan-only for all L2 modules (matrix)
release.yml push: [main] NOVA_RELEASE_TOKEN Semver tag + MAJOR.MINOR/MAJOR floating-tag maintenance + release creation on merge to main

Reusable deploy workflow (deploy.yml)

Consumer repos invoke the deploy workflow via a versioned tag:

jobs:
  deploy:
    uses: nova/.github/workflows/deploy.yml@v1.19
    with:
      contract: .nova/contract.yml
      environment: dev
    secrets: inherit

The workflow checks out the consumer repo + the Nova platform repo, runs scripts/run_platform.sh, and posts deploy outputs as a PR comment + to SSM Parameter Store.