Local CI and the image deploy duplicated the org workflows and still required ci / ci. Pin the callers to those workflows and trust the reusable deploy ref.
* feat(api): collapse Slack, portal, and jobs onto Fargate (PLAT-216)
Move HTTP and scheduled work onto one always-on Flask task so after-hours
loses Lambda cold start without changing the Cognito or roster contracts.
* fix(portal-api): keep CORS headers on unexpected 500s
Portal SPA error handling needs Access-Control-Allow-Origin even when
DynamoDB or other internals fail, otherwise the browser hides the 500.
* fix(api): retarget holidays per account and ship App Home changelog (PLAT-216)
* fix(iam): list ECS tasks and fail closed on non-prod Paychex (PLAT-216)
* fix(portal-api): serve portal JSON with an explicit JSON content type
* fix(cutover): write Slack secrets into empty Terraform shells
DescribeSecret succeeds on HCP-created shells with no version, so skip-if-exists left roster and Slack tokens unset.
* feat(infra): migrate afterhours to HCP Terraform (PLAT-74)
Replace the mgmt SAM stack with a prod-only HCP workspace, in-repo hcptf IAM, stub Lambdas, and zip CD on push to main.
* fix(cutover): retry DDB unprocessed items and skip past at() holidays
Unprocessed BatchWriteItem rows and leftover past at() schedules would drop roster data or abort holiday recreation during prod cutover.