mirror of
https://github.com/Sea-Haven-Industries/apm-wo-analysis.git
synced 2026-09-30 10:03:15 +00:00
Stand up the Phase 0 CDK scaffold for the daily APM work-order analysis pipeline: two-stack CDK app (pipeline + grafana), classifier and slack-post Lambda packages, dashboards-as-code, the local drop-folder uploader, and a classifier smoke-test placeholder. Wire CI/CD to the org reusable workflows: ci.yaml -> ci-python-sam (ruff + cdk synth) and deploy.yaml -> cd-cdk (OIDC, cdk deploy --all). Pin aws-cdk-lib==2.253.1; Lambdas target Python 3.12 / arm64. Rewrite .gitignore to the org Python-CDK standard so the source-of- truth files (CLAUDE.md, docs/, .claude/agents) are tracked while build artifacts (.venv, cdk.out, caches) stay ignored. Domain logic, stack resources, and dashboards are stubbed and filled in across Phases 1-5 (docs/BUILD.md). cdk synth is green for both stacks; ruff check/format pass.
22 lines
987 B
Python
22 lines
987 B
Python
"""Grafana stack: VPC import, EC2, ALB, SG, Route53, Athena datasource role.
|
|
|
|
Scaffold — resources are added in Phase 5 of docs/BUILD.md. The running box is
|
|
the only non-serverless piece here (self-hosted Grafana OSS on a t4g.small,
|
|
ARM64, VPN-only) and carries an OS/Grafana patching + config-backup obligation.
|
|
Dashboards are provisioned as code from grafana/ — the running instance is never
|
|
the source of truth.
|
|
"""
|
|
|
|
from aws_cdk import Stack
|
|
from constructs import Construct
|
|
|
|
|
|
class GrafanaStack(Stack):
|
|
def __init__(self, scope: Construct, construct_id: str, **kwargs) -> None:
|
|
super().__init__(scope, construct_id, **kwargs)
|
|
|
|
# Phase 5 — EC2 (Amazon Linux 2023, Grafana OSS via user-data),
|
|
# internal ALB (HTTPS, *.seahaven.com ACM cert),
|
|
# SG ingress from VPN/office CIDRs only,
|
|
# Route53 alias grafana.seahaven.com,
|
|
# instance role: Athena + Glue + S3 read (no static keys). TODO
|