Runs typecheck + lint + boundaries + test (with coverage) + build on every push to main and every PR. Postgres service for tests that need DB. Playwright e2e and Storybook smoke tests gated on validate job passing. Coverage uploaded as artifact (lcov format) for downstream tools (Codecov, etc.) — wiring left to template users. Spec: §6.11