# Sea Haven Industries Internal software engineering organization for Sea Haven Industries. We build and maintain the serverless infrastructure, internal tools, and integrations that keep operations running. ## Tech Stack - **Cloud:** AWS (us-east-1) — Lambda, API Gateway, DynamoDB, S3, SES, Bedrock, ECS - **IaC:** SAM (serverless stacks), CDK (complex infrastructure) - **Runtimes:** Python 3.12, Node.js 22.x — all Lambda on arm64 - **CI/CD:** GitHub Actions with reusable workflows, OIDC deploy to AWS ## Active Projects ### Operations & Automation | Repo | What it does | |------|-------------| | **afterhours-shift-manager** | Slack bot for managing after-hours on-call shifts with 3CX integration | | **seahaven-door-unlock-api** | Yealink desk phone DSS key unlocks front door via LenelS2 Elements API | | **meal-order-manager** | Automated weekly meal ordering from Redefine Meals — scraper, order form, payroll deductions | ### Finance & Procurement | Repo | What it does | |------|-------------| | **procurement-ingest** | Coupa PO + work order email ingestion pipeline | | **amazon-po-parser** | Coupa PO email parser + Payee Central scraper for Amazon site code resolution | | **payments-dashboard** | Internal payments tracking dashboard | | **stampli-bulk-editor** | Mac GUI app for bulk-editing Stampli invoice pay dates | ### AI & Communication | Repo | What it does | |------|-------------| | **seahaven-slack-bot** | Internal Slack DM assistant powered by AWS Bedrock | | **exec-aide** | Personal AI executive assistant — inbox monitoring, classification, Slack alerts | | **apm-wo-analysis** | Daily APM work order comment classification (S3 + Athena + Lambda + Slack + Grafana) | | **proposal-system** | AI-powered proposal generation and management | | **orchestrator** | LangGraph + Composio multi-model task router (`run.py`) — cross-family review, scanning, connectors | | **open-swe** | Open SWE autonomous coding agent (private fork) — LangGraph Cloud deployment, agent-team successor | | **pr-reviewer** | Local FastAPI + Fireworks dashboard for reviewing org PRs | | **sh-mcp** | Slack AI agents + trust-tiered MCP platform | ### SHOC Dispatch & Ops | Repo | What it does | |------|-------------| | **shoc-backend** | SHOC dispatch/operations platform — .NET 8 backend | | **shoc-frontend-new** | SHOC dispatch/operations platform — React frontend | | **shoc-pr-review-runner** | Sandboxed PR review runner for SHOC — exact-head checkout, clean gates, evidence-backed AI review (read-only) | ### IT & Infrastructure | Repo | What it does | |------|-------------| | **seahaven-org-baseline** | Org-wide AWS security baseline (CDK): mgmt-account CloudTrail/Config/GuardDuty/SecurityHub/WAF/Backup + member-account baselines + org OUs/SCPs (was seahaven-account-baseline) | | **afi-backup-monitor** | Afi.ai backup monitoring — auto-protect users, weekly Slack digest | | **front-integrations** | Front platform integrations — SLA monitoring + Google Workspace user sync | | **forgejo** | Self-hosted Forgejo git server for repo archival and mirroring | | **file-share** | Personal file share — Samba + FileBrowser on EC2 | | **seahaven-site** | Company website — static S3 deployment | | **security-review** | Security review agent — deterministic scanners + agentic review paths (pre-push gate backstop) | | **syslog-server** | UniFi syslog → CloudWatch collector on EC2 (VPN-only) | | **rustdesk-server** | RustDesk Server Pro remote-desktop relay on EC2 (rustdesk.seahaven.com) | | **.github** | Org-level GitHub config — reusable CI/CD workflows, Claude Code review, compliance audits | | **.github-private** | Org profile README (this page) — visible to org members | | **engineering-handbook** | Engineering conventions and best practices | ## Conventions All projects follow the standards in [engineering-handbook](https://github.com/Sea-Haven-Industries/engineering-handbook): - **Naming:** kebab-case everywhere — repos, stacks, Lambda functions, DynamoDB tables, S3 buckets - **Branching:** `main` is protected, all changes via PR, feature branches deleted after merge - **Secrets:** AWS Secrets Manager for all secrets, SSM Parameter Store for non-secret config only - **Lambda defaults:** Python 3.12 or Node 22.x, arm64, 60-day log retention set explicitly - **CI/CD:** Every deployable repo has a pipeline — no manual production deploys