feature/portfolio hardening - #8
Merged
Merged
Conversation
rayenmabrouk
commented
Sep 24, 2026
Owner
- Add project README, runbook, troubleshooting and screenshots
- Harden Terraform: tags, variables, SSH opt-in, ECR lifecycle, backups, 5xx alarm
- Add daily SQLite backup/restore to S3; prune old images on deploy
- Harden CI/CD supply chain, add Dockerfile lint, smoke test and secret scan
- Rewrite README for reviewers; update runbook and cost for new resources
- CI smoke test: use a valid dpaste lexer (_text)
- README: document unfixed base-image findings reported by ECR scanning
Original dpaste README moved to docs/upstream-dpaste-README.md. README separates upstream application code from the infrastructure work, lists verified behaviour, trade-offs and AI-assistance disclosure. Screenshots renamed chronologically; admin IP redacted.
…, 5xx alarm - default_tags (Project, Environment, ManagedBy, Repository) on every resource - Environment-specific values exposed as validated root variables (instance type, key pair, instance profile, log retention, image retention, alarm email) - SSH ingress is now opt-in: empty allowed_ssh_cidr closes port 22 (ops use SSM); 0.0.0.0/0 is rejected by validation - ECR lifecycle policy: keep the 10 newest images, expire untagged after 1 day - S3 backup bucket for SQLite (versioned, SSE-S3, TLS-only, public access blocked, 14-day expiry) + SSM parameter with its name - CloudWatch: log metric filter on Caddy access logs + HTTP 5xx alarm (catches a dead dpaste container, which the EC2 status check cannot see); optional SNS email notifications for all alarms - Modules declare required_providers; unused variables removed (tflint clean) - More outputs: instance_id, SSM session command, backup bucket, alarm names - Checkov: 47 passed, 0 failed, 17 skipped with inline justification Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Ho7VHQUmzS2hxeSgwu2zu
- scripts/backup.sh: online SQLite backup (sqlite3 backup API) to the S3 backup bucket, list, and restore with integrity check + pre-restore backup - deploy.sh installs a daily backup timer (non-fatal if backup.sh is missing), reads the region from IMDSv2 instead of hard-coding it, and removes old release images from the instance disk while keeping the rollback target Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Ho7VHQUmzS2hxeSgwu2zu
… scan CI - All third-party actions pinned to full commit SHAs (trivy-action was @master) - permissions: contents: read; concurrency cancels superseded PR runs; timeouts - lint is now blocking (ruff.toml documents the one ignored upstream rule) - docker-build-scan: hadolint (checksum-verified binary) -> build -> container smoke test (health check healthy, non-root uid, GET / and API POST) -> Trivy - new secret-scan job: gitleaks over the full history (.gitleaksignore lists one 2013 upstream Coveralls token) CD - Image is built and scanned before AWS credentials are configured, so the build and the third-party scanner never run with cloud access - Ships backup.sh with deploy.sh (gzip + base64: smaller SSM payload than before) Terraform pipeline: actions pinned, TFLint step added Dockerfile: node:24-slim instead of floating node:lts-slim, PYTHONUNBUFFERED for prompt CloudWatch logs, OCI labels, exec-form HEALTHCHECK, quoted extras Repository hygiene - Dependabot for github-actions, docker, terraform and pip; renovate.json removed (two bots would open duplicate PRs) - Removed upstream leftovers that no longer apply: .travis.yml, .deploystack/, docker.yml.disabled, minimal.docker-compose.yml, original root-running Dockerfile, tox.ini (referenced missing README.rst), issue templates, CONTRIBUTING.md, CODE_OF_CONDUCT.md - .python-version/.node-version match the image (3.10 / 24) - .trivyignore BOM removed; .gitignore covers .env, *.pem, plan files - monitoring stack mounts ~/.aws on Linux/macOS as well as Windows Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Ho7VHQUmzS2hxeSgwu2zu
README restructured: architecture diagram (only resources that exist), inherited vs built, infrastructure with the reason for each component, alarms and what they detect, security controls and the least-privilege IAM a real account would use, CI/CD, exact local/AWS commands, verification table, cost, AWS Academy limitations, project structure, engineering decisions. Clearly separates what was verified in AWS from what was added afterwards. Removes the links to docs/architecture.md and docs/security.md, which did not exist; uses only measured image sizes. Runbook: SSH now optional, backups/restore, alarms and SNS, Session Manager, teardown of the backup bucket, list-nested code blocks fixed (the PowerShell here-string terminator was indented and failed when pasted). New or changed steps are marked [not yet verified]. Cost: third alarm, custom metric, backup bucket, SNS; placeholder row removed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Ho7VHQUmzS2hxeSgwu2zu
"text" is rejected by the API with HTTP 400; verified _text returns 200. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Ho7VHQUmzS2hxeSgwu2zu
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Ho7VHQUmzS2hxeSgwu2zu
rayenmabrouk
added a commit
that referenced
this pull request
Sep 25, 2026
feature/portfolio hardening
rayenmabrouk
added a commit
that referenced
this pull request
Sep 26, 2026
feature/portfolio hardening
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.