Adds three handbook pages covering conventions that were previously
scattered across feedback memories or rederived from scratch each
time:
- bedrock.md captures the cross-region inference profile requirement
for Claude 4.x Bedrock Agents and the alias-version pinning gotcha,
plus the IAM resource pattern and the KB Docker requirement.
- dev-environment.md documents the workstation directory layout,
pyenv/Node conventions, the macOS launchd/TCC sandbox gotcha, and
cleanup cadence.
- lambda-template.md provides a minimal SAM scaffold that follows the
Lambda defaults already in aws-infrastructure.md (Python 3.12,
arm64, explicit 60-day log retention, scoped Secrets Manager
access, module-level secret cache).
Also extends two existing pages:
- sam-project-layout.md gains a Lambda Layers section with the
BuildMethod nesting pattern that caused a ~22-hour production
outage when violated.
- naming-conventions.md adds a Legacy Stacks note acknowledging that
pre-convention PascalCase stacks (SeaHavenDoorUnlockStack,
WorkorderIngestStack) stay as-is rather than risk stack
replacement.
* Update CDK version policy, Node 24 runtime, and GitHub Actions CI/CD
- Pin blessed aws-cdk-lib version (2.253.1) with upgrade procedure
- Update Lambda runtime default from Node 22 to Node 24
- Rewrite CI/CD page to reflect GitHub Actions reusable workflows
(was still referencing CodePipeline/CodeBuild)
* Add pre-push hook for npm ci validation
Catches lock file drift locally before it breaks CI. Includes
install instructions in git-workflow.md.
* Add repo provisioning script
Automates the new-repo checklist: GitHub repo creation, OIDC deploy
role, repo secret, security features, CI/CD workflow stubs, and
pre-push hook installation. Supports both SAM and CDK stack types.
* Add shared VpnEc2Instance CDK construct
Reference construct for the VPN-accessible EC2 pattern used by
file-share and forgejo. Includes VPC/subnet lookup, SG, IAM role,
encrypted EBS, and DLM snapshots. Copy into lib/constructs/.
* Add post-deploy health check template
Template script for project-specific health checks. Copy to
scripts/health-check.sh — CD workflows run it automatically.
Documents the org-wide policy for dependabot.yml files: ecosystem
selection, standard templates for single/multi-ecosystem repos and
SAM projects, auto-assignment, and merge guidance.