Commit graph

171 commits

Author SHA1 Message Date
Adam Moussa
f7957436bd
fix(iam): drop githubdeploy workflow_ref OIDC condition (PLAT-222) (#215)
Some checks failed
Deploy API / Deploy API to dev (push) Has been cancelled
Deploy API / Deploy API to prod (push) Has been cancelled
* fix(iam): drop githubdeploy workflow_ref OIDC condition

AWS STS does not evaluate GitHub workflow_ref, so that trust condition fail-closes AssumeRoleWithWebIdentity.

* chore(security): retarget githubdeploy Checkov suppression

Dropping the workflow_ref trust condition shifted CKV_AWS_111 from line 49 to 42. Permissions are unchanged.

* style: apply formatter

---------

Co-authored-by: sea-haven-auto-fix[bot] <5037331+sea-haven-auto-fix[bot]@users.noreply.github.com>
2026-09-22 21:30:25 +00:00
Adam Moussa
f632020b20
ci: convert onto org HCP reusables (PLAT-222) (#214)
Some checks are pending
Deploy API / Deploy API to dev (push) Waiting to run
Deploy API / Deploy API to prod (push) Waiting to run
* ci: convert onto org HCP reusables

Switch Fargate CD and CI to the v1.0.13 org workflows, emit ci-complete, and retarget githubdeploy OIDC to the reusable plus the thin caller.

* chore(security): retarget githubdeploy Checkov suppression

The OIDC dual-claim edit shifted CKV_AWS_111 from line 40 to 49. Permissions are unchanged.

* style: apply formatter

* ci: pin org reusables to v1.0.14

Drop collect-only and requirements from the python lint caller now that ci-python-app is lint-only.

* test(ci): probe autofix with a ruff format violation

* style: apply formatter

---------

Co-authored-by: sea-haven-auto-fix[bot] <5037331+sea-haven-auto-fix[bot]@users.noreply.github.com>
2026-09-22 20:01:17 +00:00
Adam Moussa
7574fc471a
chore(ci): remove unused Mergify stub (#213)
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
2026-09-22 18:41:55 +00:00
renovate[bot]
63b31fcdc3
chore(deps): update terraform random to v3.9.1 (#211)
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-22 14:33:14 +00:00
renovate[bot]
449cc10b9f
chore(deps): update dependency boto3 to v1.43.98 (#208)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-22 14:31:22 +00:00
renovate[bot]
78f6d1dbe4
chore(deps): update aws-actions/configure-aws-credentials action to v6.3.0 (#209)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-22 14:31:10 +00:00
renovate[bot]
77780899c2
chore(deps): pin python docker tag to 2f17fc0 (#207)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-22 14:24:50 +00:00
Adam Moussa
d7ad49d00f
feat(api): add OpenAPI Redocly contract and VPC outputs (DEV-289) (#206)
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
* feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289)

Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs
expose the resolved vpc_id and public subnet IDs.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289)

Same extends: recommended ruleset and @redocly/cli 2.52.1 as
internal-portal. Documents current { error: string } JSON errors.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(api): document 4xx and reject invalid form-status weeks (DEV-289)

Health, form-status, and roster document 400. form-status now maps
current and returns 400 for a week that is not current or YYYY-WNN.
Redocly treats 302 as a success response, matching the portal.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* style(test): format VPC contract assertions for ruff (DEV-289)

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289)

Promote operation-4xx-response and the 2xx-or-3xx success rule to error.
Replace unused health and roster 400s with 403, matching portal health.
Form-status keeps its real 400 for invalid week.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(api): split week params and allow live menu nulls (DEV-289)

Menu and form-status take current or YYYY-WNN. Orders take YYYY-WNN or a
calendar date and reject current. Menu payloads may emit null menu_url,
calories, protein, and image_url.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(infra): fail prod apply without the afterhours VPC (DEV-289)

Prod never creates the 10.60 fallback VPC. A terraform_data precondition
fails plan and apply when existing_vpc_id is empty, instead of a check
block that only warns.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:33:48 +00:00
Adam Moussa
fb3a181e0c
feat(api): add flask sentry sdk (#205)
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
Initialize the SDK on gunicorn and the SQS worker with afterhours-style scrubbing. Store the DSN in SSM and inject only the parameter name onto the live task.
2026-09-21 23:48:09 +00:00
Adam Moussa
596e949eef
fix(form): keep Google sign-in across page refresh (#204)
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
2026-09-21 22:50:07 +00:00
Adam Moussa
3efff5e784
fix(infra): share the afterhours VPC in prod (PLAT-215) (#203)
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
* fix(infra): share the afterhours VPC when existing_vpc_id is set

Prod is at the account VPC quota, so the v1.0.0 apply destroyed Lambda/API Gateway then failed on CreateVpc. Skip creating a sixth VPC when the workspace supplies afterhours subnets.

* style(test): format the VPC terraform assertion for ruff
2026-09-21 21:15:47 +00:00
Adam Moussa
697deb94fd
fix(iam): omit checkcomponents from the ECS boundary in non-prod (#202)
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
2026-09-21 16:26:17 -04:00
Adam Moussa
30f88729a6
fix(iam): move hcptf apply grants off the 10KB inline quota (#201) 2026-09-21 20:03:22 +00:00
Adam Moussa
424b1ce1ac
fix(iam): split EC2 grants so the hcptf apply policy fits (#200) 2026-09-21 19:48:09 +00:00
Adam Moussa
f48a82c476
feat(api): serve meals on ECS Fargate instead of Lambda (PLAT-215) (#199)
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
* feat(api): serve meals on ECS Fargate instead of Lambda

Keep the Flask app always-on with in-process jobs so CloudFront no longer fronts a cold-start API Gateway.

* fix(jobs): run delayed close and reminder deliveries

Wall-clock skip windows dropped the only weekly SQS attempt when Scheduler already fired in Eastern time. Dev schedules stay disabled.

* fix(api): return JSON objects and stop logging job payloads

Flask now jsonify-s handler dicts so API responses are not HTML, and the worker logs only event and status.

* fix(ci): restore the reusable workflow so the required check is named ci / ci

Inlining the job reported `ci` instead of the org ruleset's `ci / ci`.

* fix(secrets): drop unused os import so ruff check passes

* style: apply ruff format so ci-python-app lint passes

* fix(infra): give meals its own VPC because prod has none

* chore(security): re-key ALB SG checkov suppression after vpc.tf
2026-09-21 19:34:24 +00:00
renovate[bot]
12df37dab8
chore(deps): update terraform minor and patch (#198)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-21 15:41:31 +00:00
renovate[bot]
67014c954a
chore(deps): update pip minor and patch (#189)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-21 15:41:24 +00:00
renovate[bot]
b4078d3a8b
chore(deps): update dependency prettier to v3.9.8 (#197)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-21 15:40:57 +00:00
Adam Moussa
bbbe359858
fix(iam): ignore default tags on hcptf roles (PLAT-210) (#196)
* fix(iam): ignore default tags on hcptf roles (PLAT-210)

The apply role cannot iam:TagRole on itself. Provider default_tags from
the env split 403'd the prod apply on hcptf-meal-order-manager and -plan.

* fix(iam): ignore tags_all on hcptf roles (PLAT-210)

ignore_changes on tags does not cover provider default_tags. The prod
speculative plan still wanted Environment on tags_all and would TagRole.
2026-09-18 20:53:13 +00:00
Adam Moussa
44c79fdefd
feat(infra): add lightweight meal-order-manager-dev (PLAT-210) (#195)
* feat(infra): add lightweight meal-order-manager-dev (PLAT-210)

Parameterize the HCP root for seahaven-dev with schedules, PITR, alarms, and Paychex gated off so a second env does not clone production cost or side effects.

* fix(infra): drop prod-only authorizer import so dev can create it (PLAT-210)

The PLAT-102 import is already in meal-order-manager-prod state. A shared import block fails in seahaven-dev because the permission does not exist there.

* fix(iam): allow creating the weekly-menu githubdeploy role in seahaven-dev (PLAT-210)

Prod imported that role. A new account needs CreateRole on tf-managed/githubdeploy-meal-order-manager-weekly-menu.
2026-09-18 18:38:45 +00:00
Adam Moussa
12f1eb881f
fix(auth): accept federated portal Cognito tokens for meals admin (DEV-283) (#194)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
* fix(auth): accept federated portal Cognito tokens for meals admin

Google Workspace federation stores email_verified=false, which 403'd the
portal Admin probe while the public menu still loaded.

* fix(iam): grant plan role CloudFront DescribeFunction
2026-09-18 15:31:17 +00:00
Adam Moussa
85f36fcfff
feat(edge): proxy portal meals API paths on orders.seahaven.com (DEV-282) (#193)
Some checks are pending
Build Lambda Layer / build (push) Waiting to run
* feat(edge): proxy portal meals API paths on orders.seahaven.com (DEV-282)

Keep the static form on / while CloudFront forwards submit, form-status, admin, and caller-only order lookup so the portal can use the public meals host without a form redirect.

* fix(style): apply ruff format
2026-09-17 23:52:51 +00:00
renovate[bot]
a81241dc03
chore(deps): update sea-haven-industries/.github action to v1.0.11 (#190)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 16:45:46 +00:00
Adam Moussa
26a92a2f62
feat(auth): accept portal Cognito ID tokens (DEV-238) (#192)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
* feat(auth): accept portal Cognito ID tokens

* fix(auth): distinguish portal verification outages

* docs(auth): document Cognito workspace variables
2026-09-15 22:12:01 +00:00
Adam Moussa
86bb476e27
feat(menu): expose production menu API (#191) 2026-09-15 21:41:10 +00:00
Adam Moussa
ed98ad0ac9
docs(readme): record HCP VCS trigger patterns (PLAT-183) (#188) 2026-09-10 21:00:35 +00:00
Adam Moussa
c1552f0bd3
chore(meals): remove email_report payroll SES path (PLAT-135) (#187)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
* chore(meals): remove email_report payroll SES path (PLAT-135)

Stop Monday SES deduction emails now that Flex checkcomponents owns payroll posting.

* chore(meals): delete email_report handler and SAM resources

Remove the leftover SES Lambda source so it cannot be redeployed from template.yaml.
2026-09-10 19:29:58 +00:00
renovate[bot]
aceb174c4b
chore(deps): update npm minor and patch (#186)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-09 18:44:27 +00:00
renovate[bot]
0aeaff7b0c
chore(deps): update aws-actions/configure-aws-credentials action to v6.2.4 (#185)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-09 18:43:51 +00:00
Adam Moussa
62f61f61d1
feat(meals): send weekly deductions to paychex checkcomponents (PLAT-154) (#184)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
* feat(meals): send weekly deductions to paychex checkcomponents (PLAT-154)

* fix(meals): round checkcomponents amounts half-up

Keep SQS deduction amounts on the same rounding path as submit_order so extra-precision totals cannot diverge by a cent.
2026-09-03 22:04:02 +00:00
Adam Moussa
b043b86fc7
feat(iam): import hcptf roles into app Terraform (PLAT-146) (#183)
* feat(iam): import hcptf roles into app Terraform (PLAT-146)

Move the existing hcptf pair into this repo so app Terraform owns prod IAM after the substrate handoff.

* fix(iam): add apply-role IAM list permissions (PLAT-146)

IamReadOnly omitted ListRoleTags and ListInstanceProfilesForRole needed after detaching the substrate guardrail.
2026-09-02 21:47:12 +00:00
Adam Moussa
8489dc3986
feat(meals): dual-read week keys and meal-to-Flex join (PLAT-134) (#182)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
* feat(meals): dual-read week keys and meal-to-Flex join (PLAT-134)

* style(meals): apply ruff format (PLAT-134)

* docs(meals): clarify week-key dual-read is same-instant (PLAT-134)
2026-09-02 00:01:44 +00:00
renovate[bot]
60aa30bf12
chore(deps): update dependency eslint to v10.9.1 (#180)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-31 22:40:30 +00:00
renovate[bot]
38106bd8bc
chore(deps): update sea-haven-industries/.github action to v1.0.10 (#181)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-31 22:40:14 +00:00
Adam Moussa
72ffb315b1
chore(deps): remove dependabot version updates (#179)
Renovate is the version-update bot on this Interactive repo. GitHub Dependabot alerts stay.
2026-08-25 11:50:59 -04:00
renovate[bot]
c224afcc3e
chore(deps): pin dependencies - abandoned (#167)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
2026-08-24 20:59:58 +00:00
renovate[bot]
a742c4bfa5
chore(deps): update dependency globals to v17.11.0 (#172) 2026-08-24 20:54:55 +00:00
renovate[bot]
4cbc28aba1
chore(deps): update dependency eslint to v10.9.0 (#171) 2026-08-24 20:50:28 +00:00
renovate[bot]
ffef33fbb9
chore(deps): update terraform external to ~> 2.4 (#170) 2026-08-24 20:40:00 +00:00
renovate[bot]
7818afce09
chore(deps): update github actions (#169) 2026-08-24 20:35:23 +00:00
renovate[bot]
432203f04d
chore(deps): update dependency boto3 to v1.43.78 (#168) 2026-08-24 20:32:21 +00:00
Adam Moussa
9407a3e6d7
chore(deps): batch minor and patch updates (#165)
Some checks are pending
Build Lambda Layer / build (push) Waiting to run
2026-08-24 19:47:00 +00:00
dependabot[bot]
ddfb73c9d4
chore(deps): bump boto3 (#155)
Bumps the minor-and-patch group with 1 update in the /functions/email_report directory: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.71 to 1.43.77
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.71...1.43.77)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.76
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-24 15:27:34 -04:00
Adam Moussa
7e6a4f6851
chore(ci): remove pr policy workflow caller (#163) 2026-08-24 15:12:15 -04:00
Adam Moussa
25178cc228
chore(ci): switch auto-merge from seahaven-bot to Mergify (#162) 2026-08-24 13:52:27 -04:00
Adam Moussa
8ef63b51eb
fix(ci): enqueue merge queue as seahaven-bot (PLAT-108) (#160)
* fix(ci): enqueue merge queue as seahaven-bot

* fix(ci): limit seahaven-bot enqueue to PRs targeting main
2026-08-24 15:22:45 +00:00
Adam Moussa
04f49bf4b0
ci: enable squash auto-merge on ready PRs (PLAT-108) (#150)
* ci: enable squash auto-merge on ready PRs

* fix(ci): serialize auto-merge enable and ignore already-enabled
2026-08-21 23:34:27 +00:00
Adam Moussa
9f5ca7773e
ci: add merge_group trigger for required ci / ci (#149) 2026-08-21 17:41:52 -04:00
Adam Moussa
c5c29b2bef
fix(iam): attach per-workload lambda permissions boundary (PLAT-52) (#148)
* fix(iam): attach per-workload lambda permissions boundary (PLAT-52)

* fix(iam): skip boundary delete on weekly-menu role (PLAT-52)
2026-08-20 16:02:46 -04:00
dependabot[bot]
a247f2f45a
chore(deps): bump boto3 (#147)
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
Bumps the minor-and-patch group in /functions/slack_notifier with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.66 to 1.43.71
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.66...1.43.71)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.71
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-17 18:57:10 +00:00