open-swe/infra/lib/constructs
Adam Moussa 623ff66fe4
chore(secrets): drop OPENAI/GOOGLE/GROQ key shells (revoked, providers removed)
Those three providers were dropped in the Bedrock/Fireworks migration and their keys
revoked; the live Secrets Manager objects (open-swe-{dev,prod}/{OPENAI,GOOGLE,GROQ}_API_KEY)
were deleted (7-day recovery). Remove them from the IaC so a future cdk deploy does not
recreate the shells, and from fetch-config's mirror array so boot stops requesting them:
- config-store.ts SECRET_VARS + descriptions (28 -> 25 shells)
- fetch-config.sh SECRET_VARS array (kept in lockstep)
- put-config.sh: drop the put_secret lines; ANTHROPIC_API_KEY re-labelled optional
  (eval judge only — Bedrock builder/reviewer auth via the host IAM role).

REQUIRED_PROVIDER_KEYS is not set in SSM, so it uses the FIREWORKS_API_KEY default.
2026-06-29 15:52:42 -04:00
..
ami-cache.ts feat: stand up dev properly — assets bucket + artifact CD + baked AMI + on-box uv sync (T7+T19+T14) (#18) 2026-06-26 18:49:09 -04:00
app-service.ts fix: env-scope the EC2 launch template name (unblocks prod deploy) (#51) 2026-06-29 00:51:16 -04:00
assets-bucket.ts feat: stand up dev properly — assets bucket + artifact CD + baked AMI + on-box uv sync (T7+T19+T14) (#18) 2026-06-26 18:49:09 -04:00
config-store.ts chore(secrets): drop OPENAI/GOOGLE/GROQ key shells (revoked, providers removed) 2026-06-29 15:52:42 -04:00
github-deploy-roles.ts fix: isolate dev CDK deploys on their own bootstrap qualifier (B-1/OSWE-IAC-01) (#55) 2026-06-29 12:39:23 -04:00
instance-role.ts deploy(bedrock): grant instance-role Bedrock invoke + repoint LLM_MODEL_ID / eval model ids 2026-06-29 15:45:01 -04:00