Skip to content

docs: ADR 由来のドキュメント drift を修正(SEC_review 観点5・deployment の secret 一覧)#462

Merged
yusuke0610 merged 4 commits into
mainfrom
claude/adr-product-alignment-qktb1g
Jul 3, 2026
Merged

docs: ADR 由来のドキュメント drift を修正(SEC_review 観点5・deployment の secret 一覧)#462
yusuke0610 merged 4 commits into
mainfrom
claude/adr-product-alignment-qktb1g

Conversation

@yusuke0610

@yusuke0610 yusuke0610 commented Jul 3, 2026

Copy link
Copy Markdown
Owner
  • SEC_review スキルの観点5「LLM プロンプトのサニタイズ」を更新。
    ADR-0008(LLM 廃止)当時の記述のままだったが、ADR-0010 で DevForge Agent
    として LLM を再導入済みのため、現行アーキテクチャ(context_builder /
    静的プロンプト / 構造化出力)に即した確認項目に置き換え
  • docs/deployment.md の常時注入 secret 一覧から anthropic-api-key を削除。
    ADR-0015 で Anthropic / Gemini は Vertex AI(ADC)経由へ移行済みで、
    infra 実装(cloud_run/main.tf)では注入・コンテナとも削除済みだった

Co-Authored-By: Claude Fable 5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_015qpm5pb2utquc7NsTtru5J

Summary by CodeRabbit

  • New Features

    • Added an official ADR index and a new design-principles guide for easier navigation of architecture decisions.
    • Added automated checks to keep ADR files and the index in sync during validation and CI.
  • Documentation

    • Updated contribution, PR, README, and deployment guidance to reflect the new ADR workflow and required secret settings.
  • Bug Fixes

    • Corrected an ADR numbering issue in one document and clarified which API keys are needed for deployment.

claude added 3 commits July 3, 2026 13:43
- SEC_review スキルの観点5「LLM プロンプトのサニタイズ」を更新。
  ADR-0008(LLM 廃止)当時の記述のままだったが、ADR-0010 で DevForge Agent
  として LLM を再導入済みのため、現行アーキテクチャ(context_builder /
  静的プロンプト / 構造化出力)に即した確認項目に置き換え
- docs/deployment.md の常時注入 secret 一覧から anthropic-api-key を削除。
  ADR-0015 で Anthropic / Gemini は Vertex AI(ADC)経由へ移行済みで、
  infra 実装(cloud_run/main.tf)では注入・コンテナとも削除済みだった

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015qpm5pb2utquc7NsTtru5J
ADR が個別の技術判断として独立しており、プロダクト全体の意思決定として
横断参照できない課題への対応(設計リファレンス化の基盤)。

- docs/adr/README.md を新設し、一覧・関係(テーマ・置き換え・関連)の正本とする
  - 現在有効な決定(Accepted)の早見表
  - 全 ADR 一覧(ステータス・テーマ・置き換え/関連)
  - テーマ別の決定系統図(Mermaid)+ 系統の物語(LLM 系の導入→撤去→再導入の
    往復、0005 の根拠入れ替わり等)
- CONTRIBUTING.md の ADR 一覧表を削除し索引へ一本化(0012〜0015・0017 未掲載、
  0006 ステータス古い等の陳腐化が実際に起きていたため、複製を消す)
- 0000-template.md に「関連 ADR」欄(Supersedes / Superseded by / 関連)を追加
- scripts/lint-adr-index.sh を新設(lint-env-keys.sh と同型・bash のみ):
  索引↔ファイルの存在(双方向)・ステータス・見出し番号を突合。
  make lint / test.yml に組込み、PR テンプレートにチェック項目を追加
- 0011 の見出し誤記(# ADR-0009:)を修正
- CLAUDE.md の ADR 節を索引起点の参照フローに更新

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015qpm5pb2utquc7NsTtru5J
ADR 17 本から帰納抽出した 7 つの設計原則を docs/design-principles.md に言語化:

- P1 コスト最適化を第一制約にする
- P2 PII を信頼境界の外に出さない
- P3 正本を定め、規律は機械検証で守る
- P4 責務を層で分離する
- P5 デフォルトは決定論、LLM は対話型に限定する
- P6 可逆性を設計する
- P7 依存は固定し、追従は自動化する

各原則に「内容 / 根拠となった判断(ADR 引用) / 例外・緊張関係」を記述し、
原則 × ADR 対応マトリクス(● 主 / ○ 従)を付与。原則の改訂は ADR 経由という
メタルールを明記した。

- ADR 索引の全 ADR 一覧に「原則」列(中心的な判断軸の ID)を追加
- ADR テンプレートに「設計原則との関係」欄を追加
- README のドキュメント表・CLAUDE.md・CONTRIBUTING.md から参照を追加

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015qpm5pb2utquc7NsTtru5J
@github-actions github-actions Bot added documentation Improvements or additions to documentation ci CI / ワークフロー labels Jul 3, 2026
@coderabbitai

coderabbitai Bot commented Jul 3, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@yusuke0610, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 18 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 73976187-7145-40a5-9e47-6efe0c445bc3

📥 Commits

Reviewing files that changed from the base of the PR and between 684f6be and 05df6a2.

📒 Files selected for processing (1)
  • scripts/lint-adr-index.sh
📝 Walkthrough

Walkthrough

This PR establishes docs/adr/README.md as the authoritative ADR index, adds a scripts/lint-adr-index.sh validation script wired into Makefile and CI, introduces docs/design-principles.md (P1–P7), and updates CLAUDE.md, CONTRIBUTING.md, PR template, ADR template, deployment docs, and the SEC_review skill accordingly.

Changes

ADR Index Governance and Validation

Layer / File(s) Summary
ADR index document
docs/adr/README.md
Adds accepted decisions table, full ADR listing table, and theme-based Mermaid decision-relationship diagrams.
Drift validation script
scripts/lint-adr-index.sh
Validates filename/heading consistency, index membership, link targets, and Accepted status consistency between ADR files and the index.
CI and Makefile wiring
Makefile, .github/workflows/test.yml
Adds lint-adr-index make target wired into lint/.PHONY/help, and a corresponding CI lint step.
Design principles document
docs/design-principles.md
Adds P1–P7 principles with rationale, exceptions, and an ADR-to-principle mapping matrix.
Process and template doc updates
.claude/CLAUDE.md, .github/PULL_REQUEST_TEMPLATE.md, CONTRIBUTING.md, docs/adr/0000-template.md, docs/adr/0011-frontend-textlint-proofread.md, README.md
Updates guidance to reference the ADR index and design-principles doc, enforces index updates on ADR changes, and fixes an ADR heading number.
Deployment and security review doc updates
docs/deployment.md, .claude/skills/SEC_review/SKILL.md
Updates Secret Manager secret list for Stripe/Vertex AI changes and revises the LLM prompt sanitization review checklist.

Estimated code review effort: 2 (Simple) | ~15 minutes

Possibly related PRs

Suggested labels: ci

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately captures the PR’s main goal of fixing ADR-driven documentation drift, including the SEC_review update and deployment secret list change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/adr-product-alignment-qktb1g

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
scripts/lint-adr-index.sh (1)

94-126: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Consider also validating title consistency between the two tables.

Status/Accepted-set drift is checked between "全 ADR 一覧" and "現在有効な決定", but title text isn't cross-checked between the two tables. If a title is updated in one table but not the other, the lint won't catch it.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/lint-adr-index.sh` around lines 94 - 126, The current lint in
lint-adr-index.sh only compares ADR status and the Accepted set, so title text
can drift between the “全 ADR 一覧” and “現在有効な決定” tables without detection. Extend
the existing table cross-check logic near the
accepted_file_nums/index_accepted_nums handling to also extract each ADR title
from both tables and compare them for matching ADR numbers, emitting an error
when the same ADR has different titles. Keep the check aligned with the existing
parsing style and use the same ADR identifiers (for example ADR-$num) so
mismatches are reported consistently.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@scripts/lint-adr-index.sh`:
- Around line 94-126: The current lint in lint-adr-index.sh only compares ADR
status and the Accepted set, so title text can drift between the “全 ADR 一覧” and
“現在有効な決定” tables without detection. Extend the existing table cross-check logic
near the accepted_file_nums/index_accepted_nums handling to also extract each
ADR title from both tables and compare them for matching ADR numbers, emitting
an error when the same ADR has different titles. Keep the check aligned with the
existing parsing style and use the same ADR identifiers (for example ADR-$num)
so mismatches are reported consistently.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: aff473d3-dcc4-4495-bf17-3e2eade34d9a

📥 Commits

Reviewing files that changed from the base of the PR and between 61aca04 and 684f6be.

📒 Files selected for processing (13)
  • .claude/CLAUDE.md
  • .claude/skills/SEC_review/SKILL.md
  • .github/PULL_REQUEST_TEMPLATE.md
  • .github/workflows/test.yml
  • CONTRIBUTING.md
  • Makefile
  • README.md
  • docs/adr/0000-template.md
  • docs/adr/0011-frontend-textlint-proofread.md
  • docs/adr/README.md
  • docs/deployment.md
  • docs/design-principles.md
  • scripts/lint-adr-index.sh

scripts/lint-adr-index.sh はステータス突合はしていたが、「全 ADR 一覧」と
「現在有効な決定」のタイトル列は未検証だった。片方だけリネームして更新し忘れる
drift を検知できるよう、両表に存在する ADR のタイトルが一致するかを追加検証する。

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015qpm5pb2utquc7NsTtru5J
@yusuke0610
yusuke0610 merged commit 6b868f4 into main Jul 3, 2026
20 checks passed
@yusuke0610
yusuke0610 deleted the claude/adr-product-alignment-qktb1g branch July 20, 2026 12:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI / ワークフロー documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants