mirror of
https://github.com/Sea-Haven-Industries/apm-wo-analysis.git
synced 2026-09-30 21:43:14 +00:00
Complete Phase 1 ingestion. Add a least-privilege IAM user (apm-wo-drop-uploader) to the pipeline stack, scoped to s3:PutObject on the raw/ prefix only — the local launchd uploader authenticates as this user via a dedicated profile, so a laptop credential leak cannot read, list, or touch the analytics data. Replace the scaffold uploader stub with the hardened stampli-pattern script (lockfile, logging, timestamped archive, notifications, settle delay) and align names to the convention (~/apm-wo-drop, ~/.local/bin, com.seahaven.apm-wo-uploader). The plist sets PATH/HOME because launchd runs with a stripped environment and otherwise cannot find aws. The exports bucket already shipped in the Phase 0 scaffold, so the code delta here is the uploader identity and tooling. |
||
|---|---|---|
| .. | ||
| apm-wo-uploader.sh | ||
| com.seahaven.apm-wo-uploader.plist | ||