Organisation level GitHub configuration for WebbPulse: the reusable workflows every repository calls, a composite action, and the public organisation profile.
This repository is public and holds nothing estate specific. No AWS account ids, role
ARNs, bucket names, registry hostnames, domain names, distribution ids or HCP workspace
names live here. Every one of those values arrives from the calling repository as an
input or a secret.
.github/workflows/contains the sharedworkflow_callworkflows, plusci.yml, which lints this repository's own workflow files with actionlint. Each reusable workflow is documented in.github/workflows/README.md.actions/contains composite actions:actions/affected-domains, which works out which backend domains a diff affects so CI shards and deploys run only for the domains whose code changed; andactions/base-image-cache, which resolves and caches a Dockerfile's base image so a build matrix pulls it once.profile/README.mdis the organisation profile rendered on the WebbPulse GitHub organisation page.
One line each, pointing at the section that documents the inputs, secrets and behaviour.
python-ci.ymlruns uv based lint, type check, security and a pytest matrix that fans out one job per domain.typescript-ci.ymlruns Node install, lint, format check, typecheck, unit tests, build, and an optional Playwright job.container-image.ymlbuilds one domain image with buildx, pushes it to ECR through OIDC, and returns the digest pinned image URI.lambda-image-deploy.ymlpoints one or many Lambda functions at an image URI concurrently, waiting for each function to settle either side of the update.lambda-domains-deploy.ymlis the whole backend deploy for a repository that ships one image per domain onto one Lambda function per domain, composing the three workflows above.spa-deploy.ymlbuilds a frontend, syncs it to S3 in three ordered passes so the site is never briefly broken, and invalidates CloudFront.e2e.ymlverifies a deployed environment through the real edge and publishes a check run on the deployed commit.codeartifact-publish-python.ymlbuilds a Python package with uv and publishes it to CodeArtifact, skipping a version that is already published.codeartifact-publish-npm.ymldoes the same for an npm package, reading the name and version frompackage.json.terraform-speculative-plan.ymlrunsterraform fmt -check,initandvalidateon a pull request touchingterraform/**, and nothing else.
Callers pin a tag or a commit SHA of this repository, never @main, because a reusable
workflow referenced by a branch changes underneath every caller the moment this
repository is pushed to. Releases are cut as immutable vMAJOR.MINOR.PATCH tags and the
major tag is then moved onto that commit, so a caller pinned to the moving v3 picks up
backward compatible fixes without editing anything, and a breaking change to any input,
secret or output means a new major tag instead. A repository that wants this to be an
explicit, reviewed event pins the 40 character SHA with the tag in a trailing comment,
exactly as this repository pins every third party action.
Full detail is in Releasing and what callers pin to and Pinning and updates.