Commit graph

5 commits

Author SHA1 Message Date
Adam Moussa
f48a82c476
feat(api): serve meals on ECS Fargate instead of Lambda (PLAT-215) (#199)
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
* feat(api): serve meals on ECS Fargate instead of Lambda

Keep the Flask app always-on with in-process jobs so CloudFront no longer fronts a cold-start API Gateway.

* fix(jobs): run delayed close and reminder deliveries

Wall-clock skip windows dropped the only weekly SQS attempt when Scheduler already fired in Eastern time. Dev schedules stay disabled.

* fix(api): return JSON objects and stop logging job payloads

Flask now jsonify-s handler dicts so API responses are not HTML, and the worker logs only event and status.

* fix(ci): restore the reusable workflow so the required check is named ci / ci

Inlining the job reported `ci` instead of the org ruleset's `ci / ci`.

* fix(secrets): drop unused os import so ruff check passes

* style: apply ruff format so ci-python-app lint passes

* fix(infra): give meals its own VPC because prod has none

* chore(security): re-key ALB SG checkov suppression after vpc.tf
2026-09-21 19:34:24 +00:00
Adam Moussa
bbbe359858
fix(iam): ignore default tags on hcptf roles (PLAT-210) (#196)
* fix(iam): ignore default tags on hcptf roles (PLAT-210)

The apply role cannot iam:TagRole on itself. Provider default_tags from
the env split 403'd the prod apply on hcptf-meal-order-manager and -plan.

* fix(iam): ignore tags_all on hcptf roles (PLAT-210)

ignore_changes on tags does not cover provider default_tags. The prod
speculative plan still wanted Environment on tags_all and would TagRole.
2026-09-18 20:53:13 +00:00
Adam Moussa
44c79fdefd
feat(infra): add lightweight meal-order-manager-dev (PLAT-210) (#195)
* feat(infra): add lightweight meal-order-manager-dev (PLAT-210)

Parameterize the HCP root for seahaven-dev with schedules, PITR, alarms, and Paychex gated off so a second env does not clone production cost or side effects.

* fix(infra): drop prod-only authorizer import so dev can create it (PLAT-210)

The PLAT-102 import is already in meal-order-manager-prod state. A shared import block fails in seahaven-dev because the permission does not exist there.

* fix(iam): allow creating the weekly-menu githubdeploy role in seahaven-dev (PLAT-210)

Prod imported that role. A new account needs CreateRole on tf-managed/githubdeploy-meal-order-manager-weekly-menu.
2026-09-18 18:38:45 +00:00
Adam Moussa
12f1eb881f
fix(auth): accept federated portal Cognito tokens for meals admin (DEV-283) (#194)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
* fix(auth): accept federated portal Cognito tokens for meals admin

Google Workspace federation stores email_verified=false, which 403'd the
portal Admin probe while the public menu still loaded.

* fix(iam): grant plan role CloudFront DescribeFunction
2026-09-18 15:31:17 +00:00
Adam Moussa
b043b86fc7
feat(iam): import hcptf roles into app Terraform (PLAT-146) (#183)
* feat(iam): import hcptf roles into app Terraform (PLAT-146)

Move the existing hcptf pair into this repo so app Terraform owns prod IAM after the substrate handoff.

* fix(iam): add apply-role IAM list permissions (PLAT-146)

IamReadOnly omitted ListRoleTags and ListInstanceProfilesForRole needed after detaching the substrate guardrail.
2026-09-02 21:47:12 +00:00