From 886418ca782e789dded5da4d7c83b6f28e0abf92 Mon Sep 17 00:00:00 2001 From: Andy Potanin Date: Wed, 19 Aug 2026 16:55:43 -0400 Subject: [PATCH 1/2] Add REVIEW.md with automated PR review guidelines --- REVIEW.md | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 REVIEW.md diff --git a/REVIEW.md b/REVIEW.md new file mode 100644 index 0000000..5c0bd63 --- /dev/null +++ b/REVIEW.md @@ -0,0 +1,29 @@ +# Review Guidelines - github-rabbit-action + +Public GitHub Marketplace composite action (`udx/github-rabbit-action`) that resolves environment/lifecycle, runs safety checks, then `docker run`s the R2A image (`usabilitydynamics/rabbit-automation-action`). `action.yml` is effectively the entire product; treat every change to it as production-facing for all consumers, who float on the `@v5` major tag. + +## Critical Areas (extra scrutiny) + +- Safety checks in `action.yml` (manual-apply-to-production block and destroy-on-production block): any change that weakens, reorders, or adds bypasses to these checks is a production-destruction risk. Require explicit justification and a test/demo evidence link. +- Lifecycle resolution: `bin/merge-configs.sh`, `bin/lib/*.sh`, `src/configs/lifecycle-policy.yaml`. Production lifecycle must remain gated on protected branches; reject changes that let unprotected branches resolve to production. +- State backend inputs (`state_backend`, `state_backend_config`, `state_prefix_key`, `multi_repo`): wrong defaults or renames silently repoint or collide OpenTofu state across tenants. Renaming or changing the default of ANY input is a breaking change for marketplace consumers. +- Credential handling: AWS creds forwarded from env; GCP creds are copied into the workspace as `gcp-credentials.json`. Watch for changes that widen the credential surface (new copies, echoing env, credentials reaching uploaded artifacts or logs). +- Image resolution: `r2a_version` defaults to `latest`. Flag any change that makes pinning harder; prefer changes that move toward pinned digests. + +## Marketplace Contract + +- Input/output names, defaults, and `branding:` in `action.yml` are public API. Breaking changes require a new major tag and README migration notes in the same PR. +- README is the consumer contract: behavior changes must update README usage examples in the same PR. +- Consumers reference `@v5` (floating major). Any merged change lands on consumers immediately once the tag moves; review as if deploying to production. + +## Conventions to Enforce + +- Every `run:` step uses `shell: bash` with `set -euo pipefail`. +- Pass GitHub expressions to steps via `env:` rather than inlining `${{ }}` inside script bodies (script injection risk on inputs and branch names). +- Composite steps keep the numbered banner-comment structure; new steps get a number and description. +- No workflows exist in this repo; there is no CI safety net. Review IS the test gate here, so be more thorough than usual: trace input flow end to end for every changed input. + +## Security + +- This is a public repo and a supply-chain node for every tenant. Scrutinize any new external download, curl-pipe-to-shell, or unpinned tool install. +- No secrets, tokens, project IDs, or tenant names in examples or defaults. From 6fe0027475d3e38b55c1af7c96a04343cc8e53c7 Mon Sep 17 00:00:00 2001 From: Andy Potanin Date: Wed, 19 Aug 2026 17:09:37 -0400 Subject: [PATCH 2/2] Address Copilot and Devin review feedback on REVIEW.md --- REVIEW.md | 24 +++++++++++++----------- 1 file changed, 13 insertions(+), 11 deletions(-) diff --git a/REVIEW.md b/REVIEW.md index 5c0bd63..76a31d1 100644 --- a/REVIEW.md +++ b/REVIEW.md @@ -1,27 +1,29 @@ # Review Guidelines - github-rabbit-action -Public GitHub Marketplace composite action (`udx/github-rabbit-action`) that resolves environment/lifecycle, runs safety checks, then `docker run`s the R2A image (`usabilitydynamics/rabbit-automation-action`). `action.yml` is effectively the entire product; treat every change to it as production-facing for all consumers, who float on the `@v5` major tag. +Public GitHub Marketplace composite action (`udx/github-rabbit-action`) that resolves environment/lifecycle, runs safety checks, then `docker run`s the R2A image (`usabilitydynamics/rabbit-automation-action`). `action.yml` is effectively the entire product. Callers consume the movable `v1` compatibility tag; immutable `v1.x.y` tags are released from `production` per `docs/releasing.md`. Treat every `action.yml` change as production-facing for all consumers. ## Critical Areas (extra scrutiny) -- Safety checks in `action.yml` (manual-apply-to-production block and destroy-on-production block): any change that weakens, reorders, or adds bypasses to these checks is a production-destruction risk. Require explicit justification and a test/demo evidence link. -- Lifecycle resolution: `bin/merge-configs.sh`, `bin/lib/*.sh`, `src/configs/lifecycle-policy.yaml`. Production lifecycle must remain gated on protected branches; reject changes that let unprotected branches resolve to production. +- Safety checks step in `action.yml`: blocks manual (`workflow_dispatch`) apply to production and blocks `destroy` for the production lifecycle; delete events also abort on environment-resolution mismatch. Any change that weakens, reorders, or adds bypasses to these checks is a production-destruction risk and needs explicit justification plus test evidence. +- Lifecycle resolution: `bin/resolve-lifecycle.sh`, `bin/lib/lifecycle.sh`, `bin/lib/environment.sh`, `src/configs/lifecycle-policy.yaml`. Production lifecycle must remain gated on protected branches; reject changes that let unprotected branches resolve to production. +- Config merge: `bin/merge-configs.sh`, `bin/lib/merge.sh` (covered by `tests/run-merge-tests.sh`). Merge semantics changes require matching test updates. - State backend inputs (`state_backend`, `state_backend_config`, `state_prefix_key`, `multi_repo`): wrong defaults or renames silently repoint or collide OpenTofu state across tenants. Renaming or changing the default of ANY input is a breaking change for marketplace consumers. -- Credential handling: AWS creds forwarded from env; GCP creds are copied into the workspace as `gcp-credentials.json`. Watch for changes that widen the credential surface (new copies, echoing env, credentials reaching uploaded artifacts or logs). -- Image resolution: `r2a_version` defaults to `latest`. Flag any change that makes pinning harder; prefer changes that move toward pinned digests. +- Credential handling: AWS creds are forwarded into the container via `-e` env vars; GCP creds are mounted read-only at `/tmp/gcp-credentials.json` from `GOOGLE_APPLICATION_CREDENTIALS`. Watch for changes that widen this surface (writable mounts, workspace copies, echoing env, credentials reaching artifacts or logs). +- Image resolution: `r2a_version` defaults to `latest` (unpinned production dependency). Flag changes that make pinning harder; support movement toward pinned versions or digests. -## Marketplace Contract +## Release and Compatibility Contract (AGENTS.md + docs/releasing.md) -- Input/output names, defaults, and `branding:` in `action.yml` are public API. Breaking changes require a new major tag and README migration notes in the same PR. -- README is the consumer contract: behavior changes must update README usage examples in the same PR. -- Consumers reference `@v5` (floating major). Any merged change lands on consumers immediately once the tag moves; review as if deploying to production. +- Keep public action changes backward compatible within `v1`. Breaking input, output, safety, or lifecycle-contract changes require a new major tag. +- Input/output names, defaults, and `branding:` in `action.yml` are public API; behavior changes must update README usage examples in the same PR, and user-facing changes need a `CHANGELOG.md` entry. +- Releases are immutable `v1.x.y` tags from `production`, published via the Marketplace UI, with `v1` moved only after caller canary validation. PRs must not publish or move tags. +- `.rabbit/repo.yaml` is generated by `rabbit.ci`; changes to workflows, branch protection, environments, or Actions configuration must include the regenerated file in the same PR. Implementation or docs changes do not need a refresh. ## Conventions to Enforce -- Every `run:` step uses `shell: bash` with `set -euo pipefail`. +- `make test` (action-contract validation) must pass; CI also runs actionlint. New or modified `run:` steps use `shell: bash` with `set -euo pipefail`. - Pass GitHub expressions to steps via `env:` rather than inlining `${{ }}` inside script bodies (script injection risk on inputs and branch names). - Composite steps keep the numbered banner-comment structure; new steps get a number and description. -- No workflows exist in this repo; there is no CI safety net. Review IS the test gate here, so be more thorough than usual: trace input flow end to end for every changed input. +- Pinned tooling stays pinned with checksums (e.g. the yq install verifies a sha256); reject unpinned downloads. ## Security