Commit graph

5 commits

Author SHA1 Message Date
3e9a1c60bf
feat(api): serve meals on ECS Fargate instead of Lambda
Keep the Flask app always-on with in-process jobs so CloudFront no longer fronts a cold-start API Gateway.
2026-09-21 14:37:48 -04:00
Adam Moussa
bbbe359858
fix(iam): ignore default tags on hcptf roles (PLAT-210) (#196)
* fix(iam): ignore default tags on hcptf roles (PLAT-210)

The apply role cannot iam:TagRole on itself. Provider default_tags from
the env split 403'd the prod apply on hcptf-meal-order-manager and -plan.

* fix(iam): ignore tags_all on hcptf roles (PLAT-210)

ignore_changes on tags does not cover provider default_tags. The prod
speculative plan still wanted Environment on tags_all and would TagRole.
2026-09-18 20:53:13 +00:00
Adam Moussa
44c79fdefd
feat(infra): add lightweight meal-order-manager-dev (PLAT-210) (#195)
* feat(infra): add lightweight meal-order-manager-dev (PLAT-210)

Parameterize the HCP root for seahaven-dev with schedules, PITR, alarms, and Paychex gated off so a second env does not clone production cost or side effects.

* fix(infra): drop prod-only authorizer import so dev can create it (PLAT-210)

The PLAT-102 import is already in meal-order-manager-prod state. A shared import block fails in seahaven-dev because the permission does not exist there.

* fix(iam): allow creating the weekly-menu githubdeploy role in seahaven-dev (PLAT-210)

Prod imported that role. A new account needs CreateRole on tf-managed/githubdeploy-meal-order-manager-weekly-menu.
2026-09-18 18:38:45 +00:00
Adam Moussa
12f1eb881f
fix(auth): accept federated portal Cognito tokens for meals admin (DEV-283) (#194)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
* fix(auth): accept federated portal Cognito tokens for meals admin

Google Workspace federation stores email_verified=false, which 403'd the
portal Admin probe while the public menu still loaded.

* fix(iam): grant plan role CloudFront DescribeFunction
2026-09-18 15:31:17 +00:00
Adam Moussa
b043b86fc7
feat(iam): import hcptf roles into app Terraform (PLAT-146) (#183)
* feat(iam): import hcptf roles into app Terraform (PLAT-146)

Move the existing hcptf pair into this repo so app Terraform owns prod IAM after the substrate handoff.

* fix(iam): add apply-role IAM list permissions (PLAT-146)

IamReadOnly omitted ListRoleTags and ListInstanceProfilesForRole needed after detaching the substrate guardrail.
2026-09-02 21:47:12 +00:00