Commit graph

17 commits

Author SHA1 Message Date
387bf64b6b
feat(auth): accept portal Cognito ID tokens 2026-09-15 17:49:36 -04:00
Adam Moussa
86bb476e27
feat(menu): expose production menu API (#191) 2026-09-15 21:41:10 +00:00
Adam Moussa
c1552f0bd3
chore(meals): remove email_report payroll SES path (PLAT-135) (#187)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
* chore(meals): remove email_report payroll SES path (PLAT-135)

Stop Monday SES deduction emails now that Flex checkcomponents owns payroll posting.

* chore(meals): delete email_report handler and SAM resources

Remove the leftover SES Lambda source so it cannot be redeployed from template.yaml.
2026-09-10 19:29:58 +00:00
Adam Moussa
62f61f61d1
feat(meals): send weekly deductions to paychex checkcomponents (PLAT-154) (#184)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
* feat(meals): send weekly deductions to paychex checkcomponents (PLAT-154)

* fix(meals): round checkcomponents amounts half-up

Keep SQS deduction amounts on the same rounding path as submit_order so extra-precision totals cannot diverge by a cent.
2026-09-03 22:04:02 +00:00
Adam Moussa
b043b86fc7
feat(iam): import hcptf roles into app Terraform (PLAT-146) (#183)
* feat(iam): import hcptf roles into app Terraform (PLAT-146)

Move the existing hcptf pair into this repo so app Terraform owns prod IAM after the substrate handoff.

* fix(iam): add apply-role IAM list permissions (PLAT-146)

IamReadOnly omitted ListRoleTags and ListInstanceProfilesForRole needed after detaching the substrate guardrail.
2026-09-02 21:47:12 +00:00
renovate[bot]
c224afcc3e
chore(deps): pin dependencies - abandoned (#167)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
2026-08-24 20:59:58 +00:00
renovate[bot]
ffef33fbb9
chore(deps): update terraform external to ~> 2.4 (#170) 2026-08-24 20:40:00 +00:00
Adam Moussa
c5c29b2bef
fix(iam): attach per-workload lambda permissions boundary (PLAT-52) (#148)
* fix(iam): attach per-workload lambda permissions boundary (PLAT-52)

* fix(iam): skip boundary delete on weekly-menu role (PLAT-52)
2026-08-20 16:02:46 -04:00
Adam Moussa
10c86f2de6
fix(apigateway): drop orphaned authorizer invoke role from state (#137)
Apply destroyed the inline policy then failed deleting the role on
iam:ListInstanceProfilesForRole; the role was removed out of band.
2026-08-10 17:48:05 -04:00
Adam Moussa
60abc9fb50
fix(apigateway): grant admin authorizer invoke via resource policy (#136)
Drop the broken AuthorizerCredentialsArn invoke role path that returned
500 without calling the authorizer, and adopt the live Lambda permission.
2026-08-10 17:17:51 -04:00
1519264da1
fix(iam): use literal GitHub OIDC provider ARN for weekly-menu role 2026-08-10 16:12:40 -04:00
3b9b9fb936
feat(iam): add prod weekly-menu GitHub OIDC role 2026-08-10 15:42:12 -04:00
5a00cc33fa
fix(cloudfront): defer custom domain alias until DNS cutover 2026-08-10 13:46:04 -04:00
1f67543f16
fix(ci): satisfy PR policy and authorizer trust constraints
Move weekly-menu step expressions into env blocks, terraform-fmt SES
alignment, and pin API Gateway authorizer invoke role assume conditions.
2026-08-07 19:33:49 -04:00
3906ad1885
fix(infra): assert google-client-id SSM exists at plan time
Wire the google_client_id data source into a check so apply fails closed when the OOB parameter is missing.
2026-08-07 19:28:25 -04:00
1728f6e408
fix(iam): scope SES SendRawEmail to verified identities
Constrain the email-report role to the sender and domain identity ARNs so the policy is not unconstrained write.
2026-08-07 19:21:45 -04:00
40ea4ed898
feat(infra): migrate meal-order-manager to HCP Terraform
Freeze SAM CD and add greenfield Terraform for seahaven-prod so HCP is the sole stack deploy path.
2026-08-07 19:19:51 -04:00