This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
exec-aide/pipeline.yaml
Adam Moussa 5abb51807f
Add DM fixes, digest stats, tasks/reminders, calendar, and CI/CD pipeline (#15)
* Fix flat replies in DMs

DM replies were threaded under Adam's message instead of appearing flat.
Root cause: listener fell back to event["ts"] as thread_ts for new DMs,
causing say() to post as a threaded reply. Removed the fallback so DMs
always use flat messages with placeholder update.

Closes #4

* Add synchronous digest trigger for inline stats

Changed trigger_daily_digest from async (fire-and-forget) to synchronous
invocation so Lauren can report summary stats inline while the full Block
Kit digest arrives as a separate DM.

Closes #1

* Add tasks and reminders

- DynamoDB task CRUD with TASK#{ulid} prefix
- 5 new tools: create_task, list_tasks, complete_task, delete_task, create_reminder
- New exec-aide-reminder Lambda triggered by EventBridge Scheduler one-shots
- CDK: reminder Lambda, scheduler IAM role, conversation Lambda permissions
- Updated system prompt with task/reminder capabilities

Closes #3

* Add Google Calendar integration

- New src/shared/calendar.py: OAuth service builder, list_events,
  create_event, check_availability (reuses gmail-oauth secret)
- 3 new tools: get_calendar_events, create_calendar_event, check_availability
- Extended OAuth scopes to include calendar in gmail.py and token script
- Updated system prompt with calendar capabilities

Requires re-running scripts/get_gmail_token.py to grant the calendar scope
and updating the exec-aide/gmail-oauth secret with the new refresh token.

Closes #2

* Add CodeBuild CI/CD pipeline

CodePipeline triggers on pushes to main, CodeBuild runs cdk deploy via buildspec.

* Update README for tasks, reminders, calendar, and CI/CD pipeline
2026-05-05 10:45:14 -04:00

172 lines
5.4 KiB
YAML

AWSTemplateFormatVersion: "2010-09-09"
Description: CI/CD pipeline — CodePipeline + CodeBuild for CDK deployments
Parameters:
GitHubOwner:
Type: String
Default: Sea-Haven-Industries
GitHubRepo:
Type: String
Default: exec-aide
GitHubBranch:
Type: String
Default: main
ConnectionArn:
Type: String
Description: CodeConnections ARN for GitHub
Default: arn:aws:codeconnections:us-east-1:328440206208:connection/52bc9d0e-1088-43bc-9394-2c513ed10bc6
Resources:
ArtifactBucket:
Type: AWS::S3::Bucket
Properties:
BucketName: exec-aide-pipeline-artifacts
LifecycleConfiguration:
Rules:
- Id: expire-artifacts
Status: Enabled
ExpirationInDays: 30
Tags:
- Key: Purpose
Value: pipeline-artifacts
- Key: ManagedBy
Value: !Ref AWS::StackName
CodeBuildRole:
Type: AWS::IAM::Role
Properties:
RoleName: exec-aide-codebuild
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Service: codebuild.amazonaws.com
Action: sts:AssumeRole
Policies:
- PolicyName: codebuild-permissions
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- logs:CreateLogGroup
- logs:CreateLogStream
- logs:PutLogEvents
Resource: !Sub "arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/codebuild/exec-aide-build*"
- Effect: Allow
Action:
- s3:GetObject
- s3:PutObject
- s3:GetBucketLocation
Resource:
- !GetAtt ArtifactBucket.Arn
- !Sub "${ArtifactBucket.Arn}/*"
- Effect: Allow
Action: sts:AssumeRole
Resource:
- !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-deploy-role-${AWS::AccountId}-${AWS::Region}"
- !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-file-publishing-role-${AWS::AccountId}-${AWS::Region}"
- !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-lookup-role-${AWS::AccountId}-${AWS::Region}"
- !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-cfn-exec-role-${AWS::AccountId}-${AWS::Region}"
CodeBuildProject:
Type: AWS::CodeBuild::Project
Properties:
Name: exec-aide-build
Description: Build and deploy exec-aide CDK stack
ServiceRole: !GetAtt CodeBuildRole.Arn
Artifacts:
Type: CODEPIPELINE
Environment:
Type: ARM_CONTAINER
ComputeType: BUILD_GENERAL1_SMALL
Image: aws/codebuild/amazonlinux-aarch64-standard:3.0
EnvironmentVariables: []
PrivilegedMode: false
Source:
Type: CODEPIPELINE
BuildSpec: buildspec.yml
TimeoutInMinutes: 10
PipelineRole:
Type: AWS::IAM::Role
Properties:
RoleName: exec-aide-pipeline
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Service: codepipeline.amazonaws.com
Action: sts:AssumeRole
Policies:
- PolicyName: pipeline-permissions
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- codeconnections:UseConnection
Resource: !Ref ConnectionArn
- Effect: Allow
Action:
- s3:GetObject
- s3:PutObject
- s3:GetBucketLocation
Resource:
- !GetAtt ArtifactBucket.Arn
- !Sub "${ArtifactBucket.Arn}/*"
- Effect: Allow
Action:
- codebuild:StartBuild
- codebuild:BatchGetBuilds
Resource: !GetAtt CodeBuildProject.Arn
Pipeline:
Type: AWS::CodePipeline::Pipeline
Properties:
Name: exec-aide-pipeline
RoleArn: !GetAtt PipelineRole.Arn
ArtifactStore:
Type: S3
Location: !Ref ArtifactBucket
Stages:
- Name: Source
Actions:
- Name: GitHub
ActionTypeId:
Category: Source
Owner: AWS
Provider: CodeStarSourceConnection
Version: "1"
Configuration:
ConnectionArn: !Ref ConnectionArn
FullRepositoryId: !Sub "${GitHubOwner}/${GitHubRepo}"
BranchName: !Ref GitHubBranch
DetectChanges: true
OutputArtifacts:
- Name: SourceOutput
- Name: Build
Actions:
- Name: CDKDeploy
ActionTypeId:
Category: Build
Owner: AWS
Provider: CodeBuild
Version: "1"
Configuration:
ProjectName: !Ref CodeBuildProject
InputArtifacts:
- Name: SourceOutput
OutputArtifacts:
- Name: BuildOutput
Outputs:
PipelineName:
Value: !Ref Pipeline
PipelineUrl:
Value: !Sub "https://${AWS::Region}.console.aws.amazon.com/codesuite/codepipeline/pipelines/${Pipeline}/view"
ArtifactBucketName:
Value: !Ref ArtifactBucket