diff --git a/REVIEW.md b/REVIEW.md new file mode 100644 index 0000000..76a31d1 --- /dev/null +++ b/REVIEW.md @@ -0,0 +1,31 @@ +# Review Guidelines - github-rabbit-action + +Public GitHub Marketplace composite action (`udx/github-rabbit-action`) that resolves environment/lifecycle, runs safety checks, then `docker run`s the R2A image (`usabilitydynamics/rabbit-automation-action`). `action.yml` is effectively the entire product. Callers consume the movable `v1` compatibility tag; immutable `v1.x.y` tags are released from `production` per `docs/releasing.md`. Treat every `action.yml` change as production-facing for all consumers. + +## Critical Areas (extra scrutiny) + +- Safety checks step in `action.yml`: blocks manual (`workflow_dispatch`) apply to production and blocks `destroy` for the production lifecycle; delete events also abort on environment-resolution mismatch. Any change that weakens, reorders, or adds bypasses to these checks is a production-destruction risk and needs explicit justification plus test evidence. +- Lifecycle resolution: `bin/resolve-lifecycle.sh`, `bin/lib/lifecycle.sh`, `bin/lib/environment.sh`, `src/configs/lifecycle-policy.yaml`. Production lifecycle must remain gated on protected branches; reject changes that let unprotected branches resolve to production. +- Config merge: `bin/merge-configs.sh`, `bin/lib/merge.sh` (covered by `tests/run-merge-tests.sh`). Merge semantics changes require matching test updates. +- State backend inputs (`state_backend`, `state_backend_config`, `state_prefix_key`, `multi_repo`): wrong defaults or renames silently repoint or collide OpenTofu state across tenants. Renaming or changing the default of ANY input is a breaking change for marketplace consumers. +- Credential handling: AWS creds are forwarded into the container via `-e` env vars; GCP creds are mounted read-only at `/tmp/gcp-credentials.json` from `GOOGLE_APPLICATION_CREDENTIALS`. Watch for changes that widen this surface (writable mounts, workspace copies, echoing env, credentials reaching artifacts or logs). +- Image resolution: `r2a_version` defaults to `latest` (unpinned production dependency). Flag changes that make pinning harder; support movement toward pinned versions or digests. + +## Release and Compatibility Contract (AGENTS.md + docs/releasing.md) + +- Keep public action changes backward compatible within `v1`. Breaking input, output, safety, or lifecycle-contract changes require a new major tag. +- Input/output names, defaults, and `branding:` in `action.yml` are public API; behavior changes must update README usage examples in the same PR, and user-facing changes need a `CHANGELOG.md` entry. +- Releases are immutable `v1.x.y` tags from `production`, published via the Marketplace UI, with `v1` moved only after caller canary validation. PRs must not publish or move tags. +- `.rabbit/repo.yaml` is generated by `rabbit.ci`; changes to workflows, branch protection, environments, or Actions configuration must include the regenerated file in the same PR. Implementation or docs changes do not need a refresh. + +## Conventions to Enforce + +- `make test` (action-contract validation) must pass; CI also runs actionlint. New or modified `run:` steps use `shell: bash` with `set -euo pipefail`. +- Pass GitHub expressions to steps via `env:` rather than inlining `${{ }}` inside script bodies (script injection risk on inputs and branch names). +- Composite steps keep the numbered banner-comment structure; new steps get a number and description. +- Pinned tooling stays pinned with checksums (e.g. the yq install verifies a sha256); reject unpinned downloads. + +## Security + +- This is a public repo and a supply-chain node for every tenant. Scrutinize any new external download, curl-pipe-to-shell, or unpinned tool install. +- No secrets, tokens, project IDs, or tenant names in examples or defaults.