Sitelet https://github.com/WebbPulse/.github
Skip to content

Latest commit

 

History

57 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

WebbPulse/.github

Organisation level GitHub configuration for WebbPulse: the reusable workflows every repository calls, a composite action, and the public organisation profile.

This repository is public and holds nothing estate specific. No AWS account ids, role ARNs, bucket names, registry hostnames, domain names, distribution ids or HCP workspace names live here. Every one of those values arrives from the calling repository as an input or a secret.

What is here

  • .github/workflows/ contains the shared workflow_call workflows, plus ci.yml, which lints this repository's own workflow files with actionlint. Each reusable workflow is documented in .github/workflows/README.md.
  • actions/ contains composite actions: actions/affected-domains, which works out which backend domains a diff affects so CI shards and deploys run only for the domains whose code changed; and actions/base-image-cache, which resolves and caches a Dockerfile's base image so a build matrix pulls it once.
  • profile/README.md is the organisation profile rendered on the WebbPulse GitHub organisation page.

Reusable workflows

One line each, pointing at the section that documents the inputs, secrets and behaviour.

  • python-ci.yml runs uv based lint, type check, security and a pytest matrix that fans out one job per domain.
  • typescript-ci.yml runs Node install, lint, format check, typecheck, unit tests, build, and an optional Playwright job.
  • container-image.yml builds one domain image with buildx, pushes it to ECR through OIDC, and returns the digest pinned image URI.
  • lambda-image-deploy.yml points one or many Lambda functions at an image URI concurrently, waiting for each function to settle either side of the update.
  • lambda-domains-deploy.yml is the whole backend deploy for a repository that ships one image per domain onto one Lambda function per domain, composing the three workflows above.
  • spa-deploy.yml builds a frontend, syncs it to S3 in three ordered passes so the site is never briefly broken, and invalidates CloudFront.
  • e2e.yml verifies a deployed environment through the real edge and publishes a check run on the deployed commit.
  • codeartifact-publish-python.yml builds a Python package with uv and publishes it to CodeArtifact, skipping a version that is already published.
  • codeartifact-publish-npm.yml does the same for an npm package, reading the name and version from package.json.
  • terraform-speculative-plan.yml runs terraform fmt -check, init and validate on a pull request touching terraform/**, and nothing else.

Pinning

Callers pin a tag or a commit SHA of this repository, never @main, because a reusable workflow referenced by a branch changes underneath every caller the moment this repository is pushed to. Releases are cut as immutable vMAJOR.MINOR.PATCH tags and the major tag is then moved onto that commit, so a caller pinned to the moving v3 picks up backward compatible fixes without editing anything, and a breaking change to any input, secret or output means a new major tag instead. A repository that wants this to be an explicit, reviewed event pins the 40 character SHA with the tag in a trailing comment, exactly as this repository pins every third party action.

Full detail is in Releasing and what callers pin to and Pinning and updates.

About

Organization profile for WebbPulse. profile/README.md is what github.com/WebbPulse renders above the repository list.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages