Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 31 additions & 0 deletions REVIEW.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# Review Guidelines - github-rabbit-action

Public GitHub Marketplace composite action (`udx/github-rabbit-action`) that resolves environment/lifecycle, runs safety checks, then `docker run`s the R2A image (`usabilitydynamics/rabbit-automation-action`). `action.yml` is effectively the entire product. Callers consume the movable `v1` compatibility tag; immutable `v1.x.y` tags are released from `production` per `docs/releasing.md`. Treat every `action.yml` change as production-facing for all consumers.

## Critical Areas (extra scrutiny)

- Safety checks step in `action.yml`: blocks manual (`workflow_dispatch`) apply to production and blocks `destroy` for the production lifecycle; delete events also abort on environment-resolution mismatch. Any change that weakens, reorders, or adds bypasses to these checks is a production-destruction risk and needs explicit justification plus test evidence.
- Lifecycle resolution: `bin/resolve-lifecycle.sh`, `bin/lib/lifecycle.sh`, `bin/lib/environment.sh`, `src/configs/lifecycle-policy.yaml`. Production lifecycle must remain gated on protected branches; reject changes that let unprotected branches resolve to production.
- Config merge: `bin/merge-configs.sh`, `bin/lib/merge.sh` (covered by `tests/run-merge-tests.sh`). Merge semantics changes require matching test updates.
- State backend inputs (`state_backend`, `state_backend_config`, `state_prefix_key`, `multi_repo`): wrong defaults or renames silently repoint or collide OpenTofu state across tenants. Renaming or changing the default of ANY input is a breaking change for marketplace consumers.
- Credential handling: AWS creds are forwarded into the container via `-e` env vars; GCP creds are mounted read-only at `/tmp/gcp-credentials.json` from `GOOGLE_APPLICATION_CREDENTIALS`. Watch for changes that widen this surface (writable mounts, workspace copies, echoing env, credentials reaching artifacts or logs).
- Image resolution: `r2a_version` defaults to `latest` (unpinned production dependency). Flag changes that make pinning harder; support movement toward pinned versions or digests.

## Release and Compatibility Contract (AGENTS.md + docs/releasing.md)

- Keep public action changes backward compatible within `v1`. Breaking input, output, safety, or lifecycle-contract changes require a new major tag.
- Input/output names, defaults, and `branding:` in `action.yml` are public API; behavior changes must update README usage examples in the same PR, and user-facing changes need a `CHANGELOG.md` entry.
- Releases are immutable `v1.x.y` tags from `production`, published via the Marketplace UI, with `v1` moved only after caller canary validation. PRs must not publish or move tags.
- `.rabbit/repo.yaml` is generated by `rabbit.ci`; changes to workflows, branch protection, environments, or Actions configuration must include the regenerated file in the same PR. Implementation or docs changes do not need a refresh.

## Conventions to Enforce

- `make test` (action-contract validation) must pass; CI also runs actionlint. New or modified `run:` steps use `shell: bash` with `set -euo pipefail`.
- Pass GitHub expressions to steps via `env:` rather than inlining `${{ }}` inside script bodies (script injection risk on inputs and branch names).
- Composite steps keep the numbered banner-comment structure; new steps get a number and description.
- Pinned tooling stays pinned with checksums (e.g. the yq install verifies a sha256); reject unpinned downloads.

## Security

- This is a public repo and a supply-chain node for every tenant. Scrutinize any new external download, curl-pipe-to-shell, or unpinned tool install.
- No secrets, tokens, project IDs, or tenant names in examples or defaults.