Skip to content

Commit a664a35

Browse files
committed
Add REVIEW.md with automated PR review guidelines
1 parent 5c63e9b commit a664a35

1 file changed

Lines changed: 26 additions & 0 deletions

File tree

REVIEW.md

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
# Review Guidelines - worker (udx-worker base image)
2+
3+
Base container image for the entire UDX worker family (worker-nodejs, worker-php, worker-tooling and their children worker-site, worker-engine, docker-sftp, plus R2A). Ubuntu base, runs as non-root UID/GID 500. A regression here propagates to every downstream image and every tenant workload.
4+
5+
## Critical Areas (extra scrutiny)
6+
7+
- `bin/entrypoint.sh`: the ENTRYPOINT for the whole image family. Trace every change for child-image compatibility (children rely on its env handling, service startup, and exit behavior).
8+
- `lib/*.sh` (`process_manager.sh`, `env_handler.sh`, `secrets.sh`, `worker_config.sh`, `runtime_output.sh`, `cli.sh`): shared runtime library. Function signature or output format changes are breaking changes for children; require a check of downstream usage.
9+
- `src/configs/services.yaml` and `src/configs/worker.yaml`: default service and worker config schema consumed downstream.
10+
- Dockerfile UID/GID 500 creation and the `chown -R` block: everything downstream assumes UID 500 with specific ownership. Changes to user, ownership, or directory permissions are the classic source of child-image breakage (log dirs, port binds, home paths). Flag ANY permissions change and require downstream verification.
11+
- `worker.yml` secrets resolution (`gcp/...`, `aws/...`, `azure/...`, `bitwarden/...` refs): watch for changes that could log resolved secret values or weaken provider auth handling.
12+
13+
## Release Model
14+
15+
- Version comes from GitVersion (`ci/git-version.yml`): merge to `latest` cuts a Minor release automatically when a filtered path changed (`Dockerfile`, `bin/**`, `lib/**`, `src/**`, `etc/**`, `test/**`, `Makefile*`, `ci/**`). There is no changelog; the PR description is the release note - require it to state downstream impact (which child images need rebumps).
16+
- Child images pin this image by version tag; a release is inert for children until each bumps its `FROM` pin. Findings about rollout should reference that pin chain.
17+
18+
## Conventions to Enforce
19+
20+
- Shell passes shellcheck with no new exclusions; Dockerfile passes hadolint; YAML passes yamllint (all run in CI on every push).
21+
- Tool and package versions in the Dockerfile stay pinned; reject newly unpinned installs or removed checksum verification.
22+
- `make test` and `make build` stay the canonical local verification commands.
23+
24+
## Security
25+
26+
- This image handles cloud credentials (GCP_CREDS, AWS_CREDS, AZURE_CREDS, BITWARDEN_CREDS) to resolve secrets. Flag anything that writes credentials to disk outside established paths, echoes them, or broadens their lifetime.

0 commit comments

Comments
 (0)