Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Read AGENTS.md first.
70 changes: 70 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
# .github/workflows/ci.yml — Stoicera baseline (ai/ENGINEERING.md §7).
# Steps run for the stack that is present (package.json → pnpm, pyproject.toml → uv).
# The final job "ci" is the required status check of the organisation ruleset.
name: CI
on:
pull_request:
push:
branches: [main]

concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true

jobs:
test:
runs-on: ubuntu-latest
env:
CI: true
steps:
- uses: actions/checkout@v5
- id: stack
run: |
[ -f package.json ] && echo node=true >> "$GITHUB_OUTPUT" || true
[ -f pyproject.toml ] && echo python=true >> "$GITHUB_OUTPUT" || true
[ -f Dockerfile ] && echo docker=true >> "$GITHUB_OUTPUT" || true

# Node / TypeScript
- if: steps.stack.outputs.node == 'true'
uses: pnpm/action-setup@v6
- if: steps.stack.outputs.node == 'true'
uses: actions/setup-node@v6
with: { node-version: 22, cache: pnpm }
- if: steps.stack.outputs.node == 'true'
run: |
pnpm install --frozen-lockfile
pnpm lint
pnpm typecheck
pnpm test -- --coverage
pnpm build
pnpm audit --audit-level=high

# Python
- if: steps.stack.outputs.python == 'true'
uses: astral-sh/setup-uv@v7
- if: steps.stack.outputs.python == 'true'
run: |
uv sync --frozen
uv run ruff check .
uv run ruff format --check .
uv run pytest --cov
uv run pip-audit || uvx pip-audit

# Container
- if: steps.stack.outputs.docker == 'true'
run: docker build -t app:${{ github.sha }} .
- if: steps.stack.outputs.docker == 'true'
uses: aquasecurity/trivy-action@0.35.0
with:
image-ref: app:${{ github.sha }}
severity: HIGH,CRITICAL
exit-code: "1"
ignore-unfixed: true

ci:
# Aggregate gate: the organisation ruleset requires this check by name.
runs-on: ubuntu-latest
needs: [test]
if: always()
steps:
- run: test "${{ needs.test.result }}" = "success"
38 changes: 38 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
# migration-lab — Agent Context


## Company (Stoicera Software Group)

Two founders (Sebastian Kern, Raphael Lugmayr), Upper Austria. Brands: Stoicera (B2B web/AI/EU cloud, modern stack) and Lugmayr-Kern (.NET/Java contract work, B2C). Goal until 7.7.2027: 10,000 € monthly result, half recurring — every task names the goal it serves; results first, ship the 80 % version, measure, iterate. Founders orchestrate; agents build, test, deploy, operate. Truth before effect: no invented facts, no superlatives, name assumptions. Simple over complete. Decide and report in three lines (done, open, blocked). Customer contact answered substantively within 4 hours. Never: customer data or secrets in repo/prompts; dark patterns; religious or warrior vocabulary in anything public; Hostinger/Vercel/Railway. German (AT) for customers, code in English, commits in German.

## What migration-lab is

See `docs/00_ssot.md`. One sentence here: public, reproducible Java legacy modernisation with measured results, for Austrian SMEs and universities.
Non-goals: <three bullets>.
Active PRD: `docs/prd/NN_*.md` — read before building.

## How we work here

- Work = GitHub issue. Questions as issue comments, not chat.
- Fresh git worktree per task from `origin/main` (never build on main), PR against `main` with `Closes #NN` and the template Intent · Gherkin · Evidence · Debt taken · Open. Small PRs. CI green before PR. Full loop: `ai/prompts/factory-feature.md`.
- Build: `<cmd>` · Test: `<cmd>` · Lint/Typecheck: `<cmd>` · Migrate: `<cmd>`
- Deploy: push to `main` → GitHub Actions → Coolify (`<app name>`) → smoke test → Sentry check. PostHog receives events from `main` (big products). Rollback: `<cmd>`.
- Preview per PR at `<pattern>`.
- Before you request review: check the result against the intent, fix deviations yourself. Copilot review runs automatically on every PR; a second model reviews security.
- Decisions with reach → `docs/decisions/` (ADR, one page). Cycle memo → `docs/cycles/`.
- After any production change: append one line to `ops/runlog.md` (date · agent · what · rollback).

## Conventions

- Stack: <Next.js 15, TypeScript strict, Prisma, PostgreSQL 17, Tailwind, shadcn/ui>.
- Money in cents (integer), time zone Europe/Vienna, tenant id on every table.
- No new dependency without one sentence of justification in the PR. No speculative abstractions.
- Tests: unit for logic, integration for API, one E2E per critical path. Synthetic data only.
- Accessibility and Lighthouse ≥ 90 on public pages are merge gates.

## Never

- Personal or customer data in repo, fixtures, logs or prompts.
- Secrets in files; use 1Password (`op run`) or Coolify secrets.
- Destructive operations (drop, force-push, rm -rf on servers) without a fresh backup and a run-log line.
- Silent scope changes: if the PRD is wrong, say so in the issue, then build.
2 changes: 2 additions & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,5 @@
@AGENTS.md

# CLAUDE.md — migration-lab

You are working on **migration-lab**: a public, reproducible legacy modernization (Java 8 / Spring Boot 1.5 / AngularJS → Java 25 / Spring Boot 4 / Angular 22) with a Selenium safety net, measured AI-assisted test generation, and a German migration playbook. This is a portfolio piece of the Stoicera Software Group aimed at Austrian SMEs and universities (JKU) — it must demonstrate how a senior team de-risks migrations. Honesty and reproducibility are the product.
Expand Down
Loading