Document CORS, cron idempotency, and SSM config in template

Add comments explaining CORS dev server strategy, dual EST/EDT cron
idempotency, and manual SSM parameter creation for Google Client ID.
This commit is contained in:
Adam Moussa 2026-05-13 12:59:12 -04:00
parent 763da24134
commit 09593b1d91

View file

@ -202,6 +202,8 @@ Resources:
Type: AWS::Serverless::HttpApi
Properties:
StageName: $default
# CORS only allows the production domain. For local development, use the
# Flask dev server (app.py) which proxies API requests and doesn't enforce CORS.
CorsConfiguration:
AllowOrigins:
- !If
@ -283,6 +285,8 @@ Resources:
Environment:
Variables:
AGGREGATE_FUNCTION_ARN: !GetAtt AggregateOrdersFunction.Arn
# Both EST and EDT schedules fire every week year-round. The handler is
# idempotent, so the "wrong timezone" firing is a harmless no-op.
Events:
CloseEST:
Type: Schedule
@ -468,6 +472,11 @@ Resources:
Value: CHANGE_ME
Description: Slack channel ID for meal order notifications
# GoogleClientIdParam (/meal-order-manager/google-client-id) is managed
# manually via AWS CLI since it varies per environment. Create it with:
# aws ssm put-parameter --name /meal-order-manager/google-client-id \
# --type String --value "<YOUR_GOOGLE_CLIENT_ID>"
Outputs:
ApiUrl:
Description: API Gateway endpoint URL