Commit graph

13 commits

Author SHA1 Message Date
Adam Moussa
dbaf99df49 Fix review findings: IAM, routing guards, past-date check, roster safety
- Ring scheduler: use DynamoDBCrudPolicy (resolve_shift needs Query)
- Button pickup: update 3CX for active shift type, not just night
- Pick/drop/swap commands: only update 3CX when shift type is active
- Swap command: add missing past-date guard
- add_roster_entry: reject if extension already exists
- Apply ruff formatting
2026-05-12 16:32:46 -04:00
Adam Moussa
954ac018ce Switch from RingGroup API to Queue API at extension 801
The 3CX routing was changed from ring group 800 to queue 801 in a
previous PR on ring-scheduler-3cx. Updates all callers and the SAM
template parameter default accordingly.
2026-05-12 16:23:24 -04:00
Adam Moussa
b137334c5b Merge ring-scheduler-3cx as 4th Lambda function
- Add afterhours-ring-scheduler Lambda with 4 EventBridge rules
  (daily 8am EST/EDT + weekend 5pm EST/EDT) for 3CX ring group
  routing updates
- Extract shared ring_scheduler.py module for direct ring group
  updates from both the scheduled Lambda and the Slack bot
- Replace cross-Lambda invoke with direct update_ring_group() call
  in the Slack bot — eliminates lambda:InvokeFunction dependency
- Use RingGroup API (correct) instead of Queue API (was wrong in
  the original ring-scheduler repo)
- Eliminate YAML config fallback — DynamoDB is the sole schedule
  source
- Add RingGroupNumber CloudFormation parameter
2026-05-12 15:44:12 -04:00
Adam Moussa
7979e2a4e7 Migrate secrets from SSM Parameter Store to Secrets Manager
- Slack bot token and signing secret now read from Secrets Manager
- 3CX credentials (domain, client-id, client-secret) moved to
  Secrets Manager under afterhours-shift-manager/3cx-* prefix
- Channel ID is now a non-secret CloudFormation parameter (ShiftChannel)
- Add shared secrets.py helper for Secrets Manager reads
- Remove SSM and KMS IAM policies, add secretsmanager:GetSecretValue
2026-05-12 15:41:44 -04:00
Adam Moussa
0fed60248a Restructure src/ to per-function layout with shared Layer
Move from flat src/ to per-function directories:
- src/slack-bot/ — Slack Bolt Lambda handler
- src/weekly-post/ — Monday schedule + pay post
- src/roster-sync/ — Daily 3CX roster sync
- src/shared/ — Lambda Layer with schedule, blocks, three_cx_client

Each function has its own requirements.txt and CodeUri. Shared
modules are deployed as a SAM Layer (afterhours-shared) importable
as `from shared.X import Y`.
2026-05-12 15:39:28 -04:00
Adam Moussa
3de9243f6b Add arm64, log retention, and compliance fixes
- Set arm64 architecture globally for all Lambda functions
- Add explicit CloudWatch log groups with 60-day retention
- Add missing WeeklyPostFunctionArn to stack outputs
- Add Dependabot assignees for both ecosystems
- Add samconfig.toml.example for onboarding
2026-05-12 15:36:22 -04:00
Adam Moussa
7b2275a430
Post shift change notifications to the schedule channel (#21) (#22)
Slash command handlers (drop, pick, swap) were posting notifications to
command["channel_id"] — wherever the command was run. If someone ran
/oncall drop from a DM, the notification went there instead of the
schedule channel. Pickup buttons didn't have this problem because
body["channel"]["id"] is always the channel where the button lives.

Added SHIFT_CHANNEL_PARAM to the SlackBotFunction env vars, read it on
cold start, and route all slash command shift-change notifications to
the configured schedule channel.

Closes #21
2026-05-01 14:15:56 -04:00
Adam Moussa
14f9723a87
Change pay report recipient to payroll@seahaven.com (#16)
Update PAYROLL_RECIPIENTS env var from adam@seahaven.com to
payroll@seahaven.com so weekly Bonus Pay Summary emails go
directly to the payroll team. Fixes #12
2026-04-08 13:24:45 -04:00
Adam Moussa
9e2eab6953 DM pay reports to admin, rename email to Bonus Pay Summary
- Pay summary sent as DM to designated user instead of channel
- Email shows only per-person totals, no shift breakdown
- Renamed email subject/header to "Bonus Pay Summary"
2026-04-07 19:07:44 -04:00
Adam Moussa
a570a96311 Broaden SES permission to all verified identities 2026-04-07 19:01:12 -04:00
Adam Moussa
9deb8bf251 Email weekly pay summary to payroll via SES on Mondays
Sends an HTML pay summary email to configured payroll recipients
alongside the existing Slack post. Uses SES with noreply@seahaven.com
as sender. Recipients configured via PAYROLL_RECIPIENTS env var
(set to adam@seahaven.com for testing, switch to payroll@seahaven.com
for production).

Closes #3
2026-04-07 18:54:19 -04:00
Adam Moussa
ac3bd455e7 Add 3CX roster sync Lambda with daily EventBridge trigger
Syncs DynamoDB roster from a configured 3CX group daily at 6am ET
(before the 7am schedule post). Includes ThreeCXClient for XAPI
authentication and group member queries. Preserves existing
slack_user_id links and guards against accidental roster wipes.

Closes #4
2026-04-07 18:43:19 -04:00
Adam Moussa
4d0cdb5cfb Initial commit: after-hours shift manager Slack bot
Slack Bolt app on Lambda for managing on-call shifts. Employees can
pick up, drop, and swap shifts via /oncall commands. Changes update
3CX ring group 800 routing in real time for same-day shifts.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-03 18:32:32 -04:00