open-swe/infra/lib/constructs
Adam Moussa faae9a685b
Some checks are pending
Build & publish app artifacts / Publish + deploy (dev) (push) Waiting to run
Build & publish app artifacts / Publish + deploy (prod) (push) Waiting to run
Infra CD / Infra CI (pre-deploy) (push) Waiting to run
Infra CD / Deploy open-swe-dev (push) Blocked by required conditions
Infra CD / Deploy open-swe-prod (push) Blocked by required conditions
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
Scope secrets fetch to --secret-id-list; drop ListSecrets grant (#48)
Switch fetch-config.sh from a name-prefix batch-get-secret-value
--filters scan to an explicit --secret-id-list (the 28 SECRET_VARS,
chunked at the 20/call cap). An id-list batch authorizes per-secret
ARN, so the instance role's BatchGetSecretValue moves from Resource:*
to the open-swe-<env>/* prefix and the account-wide ListSecrets grant
is dropped entirely. The box can no longer enumerate secret names
account-wide; cross-env value isolation is unchanged (GetSecretValue
was already prefix-scoped). Resolves OSWE-IAC-SECRETS-LIST-01.

Also capture each chunk response into a variable and consume the
producer via command substitution so a failed AWS call aborts under
set -e instead of being swallowed by process substitution and
misreported as a missing required var.

Refs: OSWE-IAC-SECRETS-LIST-01
2026-06-28 20:45:17 -04:00
..
ami-cache.ts feat: stand up dev properly — assets bucket + artifact CD + baked AMI + on-box uv sync (T7+T19+T14) (#18) 2026-06-26 18:49:09 -04:00
app-service.ts fix(deploy): use %%...%% for CDK user-data tokens (don't collide with @@ sed) (#21) 2026-06-26 19:06:37 -04:00
assets-bucket.ts feat: stand up dev properly — assets bucket + artifact CD + baked AMI + on-box uv sync (T7+T19+T14) (#18) 2026-06-26 18:49:09 -04:00
config-store.ts Point dev agent at seahaven-open-swe-dev org + un-pin the owner guard (#27) 2026-06-27 19:29:03 -04:00
github-deploy-roles.ts ci: gate dev→prod promotion on green checks + add rollback safety net (#28) 2026-06-27 20:21:59 -04:00
instance-role.ts Scope secrets fetch to --secret-id-list; drop ListSecrets grant (#48) 2026-06-28 20:45:17 -04:00