Commit graph

64 commits

Author SHA1 Message Date
Adam Moussa
27dd15c541
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#30)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-07-06 18:27:14 -04:00
dependabot[bot]
1c2d77141b
Bump aws-cdk-lib in /cdk in the minor-and-patch group across 1 directory (#29)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 1 update in the /cdk directory: [aws-cdk-lib](https://github.com/aws/aws-cdk).


Updates `aws-cdk-lib` from 2.260.0 to 2.261.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.260.0...v2.261.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.261.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-02 15:28:04 -04:00
dependabot[bot]
bcd7d30390
Update slack-sdk requirement in /lambdas/slack_post (#28)
Some checks are pending
Deploy / deploy (push) Waiting to run
Updates the requirements on [slack-sdk](https://github.com/slackapi/python-slack-sdk) to permit the latest version.
- [Release notes](https://github.com/slackapi/python-slack-sdk/releases)
- [Commits](https://github.com/slackapi/python-slack-sdk/compare/v3.33.0...v3.43.0)

---
updated-dependencies:
- dependency-name: slack-sdk
  dependency-version: 3.43.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-02 15:23:37 -04:00
dependabot[bot]
15a9167882
Bump aws-cdk-lib in /cdk in the minor-and-patch group (#27)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group in /cdk with 1 update: [aws-cdk-lib](https://github.com/aws/aws-cdk).


Updates `aws-cdk-lib` from 2.258.1 to 2.260.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.258.1...v2.260.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.260.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:13:34 -04:00
Adam Moussa
44ad13d8cd
Add DLQ messages-present alarm for classifier (INFRA-57) (#26)
Some checks failed
Deploy / deploy (push) Has been cancelled
The classifier DLQ (apm-wo-analysis-classifier-dlq) had no alarm, so a
message landing there after Lambda exhausts async retries — a genuinely
dropped classifier run — surfaced nowhere.

Add a CloudWatch alarm on AWS/SQS ApproximateNumberOfMessagesVisible
(Maximum, threshold >0, 300s period, 1 evaluation period, notBreaching)
that pages the shared site-alerts SNS topic. Mirrors the
workorder-email-processor-dlq-messages alarm in procurement-ingest's
wo_stack and the payments-payroll-batch-dlq-messages alarm convention.
ALARM-only, no OK action, per the CloudWatch-alarm preference.
2026-06-17 15:02:10 -04:00
dependabot[bot]
3456c7a37b
Bump aws-cdk-lib in /cdk in the minor-and-patch group (#25)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps the minor-and-patch group in /cdk with 1 update: [aws-cdk-lib](https://github.com/aws/aws-cdk).


Updates `aws-cdk-lib` from 2.258.0 to 2.258.1
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.258.0...v2.258.1)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.258.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-16 17:26:38 -04:00
Adam Moussa
07cd5ae72a
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#24)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-06-11 14:14:09 -04:00
Adam Moussa
b92c25faf2
docs: CLAUDE.md cdk pin follows handbook Pinning Principle, not a hardcoded version (#22)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-06-05 18:44:12 -04:00
dependabot[bot]
ec363e6adf
Bump aws-cdk-lib in /cdk in the minor-and-patch group (#21)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps the minor-and-patch group in /cdk with 1 update: [aws-cdk-lib](https://github.com/aws/aws-cdk).


Updates `aws-cdk-lib` from 2.257.0 to 2.258.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.257.0...v2.258.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.258.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-05 14:53:10 -04:00
Adam Moussa
6c392a7362
fix(deps): bump aws-cdk-lib pin to 2.257.0 (#20)
Some checks are pending
Deploy / deploy (push) Waiting to run
Org pin moved from 2.253.1 (bundles vulnerable fast-uri 3.1.0, 2 high
GHSAs) to 2.257.0 (bundles patched 3.1.2). Removes the blanket
dependabot ignore per the new handbook pinning policy (exact pins kept
current by Dependabot; blanket ignores banned).
2026-06-05 13:18:47 -04:00
Adam Moussa
47b6a9404f
chore(deps): ignore aws-cdk-lib in Dependabot (org pins ==2.253.1) (#19) 2026-06-05 12:40:47 -04:00
Adam Moussa
e8f375b03b
Add dependency-review caller workflow (#18)
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)
2026-06-05 12:26:32 -04:00
Adam Moussa
ac610d1626 Re-enable CD deploy (remove leftover stack-merge gate)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-05-29 15:25:24 -04:00
Adam Moussa
6535b92e85
Merge pull request #16 from Sea-Haven-Industries/test/suite-hardening
Harden the test suite and wire it into CI
2026-05-29 15:20:54 -04:00
Adam Moussa
094c212323 Set default AWS region in conftest so boto3 clients construct in CI 2026-05-29 15:16:24 -04:00
Adam Moussa
17ce1b918b Install boto3/pandas/awswrangler as test deps so handler tests import in CI 2026-05-29 15:11:19 -04:00
Adam Moussa
0678f3f46f Document CI-run test suite and coverage in README 2026-05-29 15:05:29 -04:00
Adam Moussa
f47757adf0 Add coverage reporting via pytest-cov 2026-05-29 15:02:47 -04:00
Adam Moussa
8e87fe669d Add tests for slack-post handler and slackio 2026-05-29 15:01:25 -04:00
Adam Moussa
76f60abade Add per-bucket and precedence tests for comment intent 2026-05-29 14:59:40 -04:00
Adam Moussa
e555a75d97 Add tests for the Haiku fallback 2026-05-29 14:54:47 -04:00
Adam Moussa
48c030ed13 Add tests for the classifier handler transforms 2026-05-29 14:52:53 -04:00
Adam Moussa
63b6f11bf6 Add tests for the Slack interactions endpoint 2026-05-29 14:33:26 -04:00
Adam Moussa
817e1f6a74 Add synthetic export fixture and run classification quality gate in CI 2026-05-29 14:30:44 -04:00
Adam Moussa
1a126c8179 Enable test execution in CI 2026-05-29 14:30:44 -04:00
Adam Moussa
dcbb0606e6 Add pytest config and conftest for test discovery 2026-05-29 14:30:44 -04:00
Adam Moussa
54ef5400b1
Merge pull request #13 from Sea-Haven-Industries/feature/phase-6-docs
Some checks are pending
Deploy / deploy (push) Waiting to run
Phase 6: docs and re-enable CD on merge
2026-05-29 14:03:59 -04:00
Adam Moussa
6ddcd56f6c
Merge pull request #11 from Sea-Haven-Industries/feature/phase-5-grafana
Phase 5: self-hosted Grafana (EC2, ALB, dashboards-as-code)
2026-05-29 13:58:30 -04:00
Adam Moussa
c41836b319
Merge pull request #10 from Sea-Haven-Industries/feature/phase-4-slack
Phase 4: Slack post + interactions Lambdas (drill-down modals)
2026-05-29 13:55:24 -04:00
Adam Moussa
4cc58f5683
Merge pull request #9 from Sea-Haven-Industries/feature/phase-3-analytics
Some checks are pending
Deploy / deploy (push) Waiting to run
Phase 3: analytics dataset (Glue projection table + Athena)
2026-05-29 13:49:47 -04:00
Adam Moussa
0e96cb59d7
Merge pull request #8 from Sea-Haven-Industries/feature/phase-2-classifier
Phase 2: two-axis classifier Lambda
2026-05-29 13:43:59 -04:00
Adam Moussa
9ee3d84fe0 Enable QEMU for arm64 Lambda bundling in CI/CD 2026-05-29 13:37:01 -04:00
Adam Moussa
0ca738ca8c Enable QEMU for arm64 Lambda bundling in CI/CD 2026-05-29 13:37:00 -04:00
Adam Moussa
c4b9bd4305 Enable QEMU for arm64 Lambda bundling in CI/CD 2026-05-29 13:36:59 -04:00
Adam Moussa
5106853cb9 Enable QEMU for arm64 Lambda bundling in CI/CD 2026-05-29 13:36:58 -04:00
Adam Moussa
d33b82bd92 Enable QEMU for arm64 Lambda bundling in CI/CD 2026-05-29 13:36:56 -04:00
Adam Moussa
9346e29763
Merge pull request #7 from Sea-Haven-Industries/feature/phase-1-ingestion
Phase 1: add drop-folder ingestion and scoped uploader IAM user (Phase 1)
2026-05-29 13:24:07 -04:00
Adam Moussa
f86b4ba1c5
Merge pull request #6 from Sea-Haven-Industries/feature/phase-0-scaffold
Phase 0: scaffold apm-wo-analysis repository
2026-05-29 13:14:37 -04:00
Adam Moussa
1a231131bd Revert "Temporarily disable CD deploy during stack merges"
This reverts commit 611979e44e.
2026-05-29 13:07:02 -04:00
Adam Moussa
fee0fe9a2c Merge phase-0 to carry the CD-disable into phase-6 for an explicit revert 2026-05-29 13:06:57 -04:00
Adam Moussa
dec02170e6 Mark Phase 6 Confluence/Slack docs complete 2026-05-29 12:59:22 -04:00
Adam Moussa
dcda61e728 Add operational runbook (Phase 6)
docs/RUNBOOK.md: incident runbook for a missing daily analysis (detection →
context → triage → resolution-by-cause → post-incident), plus operational
procedures — export upload (direct + drop-folder agent), Grafana OS/app/plugin
patching cadence (clean-replacement preferred), dashboard-JSON redeploy flow +
gotchas, config + grafana.db/EBS backup-restore (DLM snapshot), and a common-
failures quick index. Mirrors to Confluence.
2026-05-29 12:31:14 -04:00
Adam Moussa
60e0b878e3 Refresh README to full operational doc (Phase 6)
Rewrite to the Sea Haven operational template with real resource names from both
stacks: AWS Resources + Lambda Functions tables, Configuration (Secrets/SSM/env/
context), Operations (verify, logs, classifier DLQ, reprocess, Grafana admin),
Documentation, and Notes/Gotchas incl. the deploy-time lessons + a known-debt
list. Corrects stale bits: ALB is internet-facing + office-IP-restricted (not
internal); classifier uses partition projection (no runtime Glue registration);
summary/details JSON live under meta/ not analytics/; grafana uses an instance
role. Adds the resources missing from the old README (classifier DLQ, slack-
interactions Lambda, HTTP API, meta/ + grafana-config/ prefixes, DLM backup,
encrypted volume).
2026-05-29 12:27:05 -04:00
Adam Moussa
611979e44e Temporarily disable CD deploy during stack merges
Gate the deploy job with if:${{ false }} so merging the Phase 0-5 stack into
main does not fire cdk deploy --all on every merge. Both stacks are already
deployed manually and validated in prod. Re-enable at the start of Phase 6 by
reverting this commit.
2026-05-29 11:43:48 -04:00
Adam Moussa
eae4d67e00 Apply cross-review findings (Phase 2/4/5 hardening)
From the cross_reviewer (GPT-4.1) per-PR passes, now that the orchestrator is
back up:

Phase 2 (classifier):
- Process ALL S3 records, not just event["Records"][0] — batched notifications
  no longer silently dropped (the review's only BLOCK).
- Derive the partition dt from the S3 event time, not the Lambda wall-clock —
  stable across retries / the midnight boundary.
- Add an SQS dead-letter queue so a failed run surfaces instead of dropping a
  day's data after Lambda's retries.

Phase 4 (Slack):
- Stage throttling (rate 10 / burst 20) on the public /slack/interactions HTTP
  API. (AWS WAF doesn't attach to apigwv2 HTTP APIs; stage throttling is the
  mechanism.)

Phase 5 (Grafana):
- Explicit encrypted=True on the gp3 root volume.

Tests: synth assertions for the DLQ, stage throttling, and the encrypted volume.
60/60 pass; cdk synth green for both stacks. Deferred NITs (print->logging, sig-
failure source-IP logging, S3 versioning, CIDR-maintenance runbook) -> Phase 6.

NOTE: like the earlier deploy fixes these sit on phase-5 but span phases — the
classifier/DLQ to #8, throttling to #10, encryption to #11 — reconcile at merge.
The encrypted-volume change needs the deferred clean instance replacement to
take effect (can't encrypt a live volume in place).
2026-05-29 11:29:14 -04:00
Adam Moussa
c970635be1 Fix WO table filter: drop custom allValue so :singlequote expands All
The 5 multi-select filter vars had allValue='All'. Grafana does NOT apply the
:singlequote format to a custom allValue, so 'All' was injected bare into
site IN (ALL) -> Athena read ALL as a column ('Column ALL cannot be resolved').
Removing the custom allValue lets :singlequote expand the All selection to the
real quoted value list, so the IN clause is valid SQL.
2026-05-29 11:13:10 -04:00
Adam Moussa
cb01b892bc Fix Grafana panels: rawSQL not rawSql (Athena plugin query key)
All 13 panel/variable queries keyed the SQL as rawSql (lowercase); the
grafana-athena-datasource plugin reads rawSQL (capital SQL). With the wrong key
the plugin saw an empty query, so no Athena query ever fired — variables had no
options and every panel showed a clean 'No data' (no error). This was the root
cause of the empty dashboard; data/datasource/permissions were all fine.
2026-05-29 10:55:02 -04:00
Adam Moussa
d884de8fcc Fix Grafana config-sync: --exact-timestamps for same-size updates
aws s3 sync skips same-size files on download unless --exact-timestamps is set,
so a dashboard edit that doesn't change file size (e.g. refresh 2->1, or a query
tweak) never propagated to the instance. Add --exact-timestamps to all four
sync invocations (boot + 15-min timer).
2026-05-28 19:06:06 -04:00
Adam Moussa
dce53fdc86 Fix Grafana template vars: refresh on dashboard load, not time-range change
All 6 query variables had refresh=2 (on time-range change) with no cached value,
so a plain dashboard load never populated them — $dt resolved to empty and every
panel filtered WHERE dt='' (no data). Set refresh=1 (on dashboard load).
2026-05-28 19:01:24 -04:00
Adam Moussa
3c8b7704f6 Fix Grafana Athena auth: use default credential chain, not ec2_iam_role
Grafana rejected the datasource with 'trying to use non-allowed auth method
ec2_iam_role: Failed to create client' — the plugin's allowed_auth_providers
defaults to default,keys,credentials and excludes ec2_iam_role. Switch authType
to 'default' (AWS SDK default chain), which on EC2 resolves to the instance role
via IMDS (still no static keys) and is allowed out of the box.
2026-05-28 18:59:09 -04:00