apm-wo-analysis/scripts/com.seahaven.apm-wo-uploader.plist
Adam Moussa 7befc8f0d7 Add drop-folder ingestion and scoped uploader IAM user
Complete Phase 1 ingestion. Add a least-privilege IAM user
(apm-wo-drop-uploader) to the pipeline stack, scoped to s3:PutObject
on the raw/ prefix only — the local launchd uploader authenticates as
this user via a dedicated profile, so a laptop credential leak cannot
read, list, or touch the analytics data.

Replace the scaffold uploader stub with the hardened stampli-pattern
script (lockfile, logging, timestamped archive, notifications, settle
delay) and align names to the convention (~/apm-wo-drop, ~/.local/bin,
com.seahaven.apm-wo-uploader). The plist sets PATH/HOME because launchd
runs with a stripped environment and otherwise cannot find aws.

The exports bucket already shipped in the Phase 0 scaffold, so the code
delta here is the uploader identity and tooling.
2026-05-28 16:32:56 -04:00

44 lines
1.6 KiB
Text

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<!--
launchd agent for the apm-wo-analysis drop-folder uploader.
Install (the runnable copy MUST live outside ~/Documents — macOS TCC sandbox):
install -d "$HOME/.local/bin" "$HOME/apm-wo-drop"
cp scripts/apm-wo-uploader.sh "$HOME/.local/bin/apm-wo-uploader.sh"
chmod +x "$HOME/.local/bin/apm-wo-uploader.sh"
cp scripts/com.seahaven.apm-wo-uploader.plist "$HOME/Library/LaunchAgents/"
launchctl load "$HOME/Library/LaunchAgents/com.seahaven.apm-wo-uploader.plist"
Verify it is healthy (LastExitStatus 0, not 32256 = TCC-blocked):
launchctl list | grep apm-wo-uploader
Paths are absolute for the deploying account (adammoussa). Re-copy the script
to ~/.local/bin after any edit to the repo source.
-->
<plist version="1.0">
<dict>
<key>Label</key>
<string>com.seahaven.apm-wo-uploader</string>
<key>ProgramArguments</key>
<array>
<string>/bin/bash</string>
<string>/Users/adammoussa/.local/bin/apm-wo-uploader.sh</string>
</array>
<key>WatchPaths</key>
<array>
<string>/Users/adammoussa/apm-wo-drop</string>
</array>
<key>EnvironmentVariables</key>
<dict>
<key>PATH</key>
<string>/usr/local/bin:/opt/homebrew/bin:/usr/bin:/bin:/usr/sbin:/sbin</string>
<key>HOME</key>
<string>/Users/adammoussa</string>
</dict>
<key>StandardOutPath</key>
<string>/tmp/apm-wo-uploader.out.log</string>
<key>StandardErrorPath</key>
<string>/tmp/apm-wo-uploader.err.log</string>
</dict>
</plist>