* feat(api): serve meals on ECS Fargate instead of Lambda
Keep the Flask app always-on with in-process jobs so CloudFront no longer fronts a cold-start API Gateway.
* fix(jobs): run delayed close and reminder deliveries
Wall-clock skip windows dropped the only weekly SQS attempt when Scheduler already fired in Eastern time. Dev schedules stay disabled.
* fix(api): return JSON objects and stop logging job payloads
Flask now jsonify-s handler dicts so API responses are not HTML, and the worker logs only event and status.
* fix(ci): restore the reusable workflow so the required check is named ci / ci
Inlining the job reported `ci` instead of the org ruleset's `ci / ci`.
* fix(secrets): drop unused os import so ruff check passes
* style: apply ruff format so ci-python-app lint passes
* fix(infra): give meals its own VPC because prod has none
* chore(security): re-key ALB SG checkov suppression after vpc.tf
* fix(iam): ignore default tags on hcptf roles (PLAT-210)
The apply role cannot iam:TagRole on itself. Provider default_tags from
the env split 403'd the prod apply on hcptf-meal-order-manager and -plan.
* fix(iam): ignore tags_all on hcptf roles (PLAT-210)
ignore_changes on tags does not cover provider default_tags. The prod
speculative plan still wanted Environment on tags_all and would TagRole.
* feat(infra): add lightweight meal-order-manager-dev (PLAT-210)
Parameterize the HCP root for seahaven-dev with schedules, PITR, alarms, and Paychex gated off so a second env does not clone production cost or side effects.
* fix(infra): drop prod-only authorizer import so dev can create it (PLAT-210)
The PLAT-102 import is already in meal-order-manager-prod state. A shared import block fails in seahaven-dev because the permission does not exist there.
* fix(iam): allow creating the weekly-menu githubdeploy role in seahaven-dev (PLAT-210)
Prod imported that role. A new account needs CreateRole on tf-managed/githubdeploy-meal-order-manager-weekly-menu.
* fix(auth): accept federated portal Cognito tokens for meals admin
Google Workspace federation stores email_verified=false, which 403'd the
portal Admin probe while the public menu still loaded.
* fix(iam): grant plan role CloudFront DescribeFunction
* feat(edge): proxy portal meals API paths on orders.seahaven.com (DEV-282)
Keep the static form on / while CloudFront forwards submit, form-status, admin, and caller-only order lookup so the portal can use the public meals host without a form redirect.
* fix(style): apply ruff format
* chore(meals): remove email_report payroll SES path (PLAT-135)
Stop Monday SES deduction emails now that Flex checkcomponents owns payroll posting.
* chore(meals): delete email_report handler and SAM resources
Remove the leftover SES Lambda source so it cannot be redeployed from template.yaml.
* feat(meals): send weekly deductions to paychex checkcomponents (PLAT-154)
* fix(meals): round checkcomponents amounts half-up
Keep SQS deduction amounts on the same rounding path as submit_order so extra-precision totals cannot diverge by a cent.
* feat(iam): import hcptf roles into app Terraform (PLAT-146)
Move the existing hcptf pair into this repo so app Terraform owns prod IAM after the substrate handoff.
* fix(iam): add apply-role IAM list permissions (PLAT-146)
IamReadOnly omitted ListRoleTags and ListInstanceProfilesForRole needed after detaching the substrate guardrail.