open-swe/deploy/seahaven
Adam Moussa aef6b26912
feat: Secrets Manager + SSM config store for open-swe (T11) (#10)
Create the per-env config surface the EC2 box reads at boot via
fetch-config.sh / seed_store.sh:

- ConfigStore construct (infra/lib/constructs/config-store.ts):
  - 28 value-LESS Secrets Manager shells  open-swe-<env>/<VAR>
    (RemovalPolicy.RETAIN, no SecretString/generateSecretString — real
    values are set out-of-band by put-config.sh, never in IaC/state).
  - 8 IaC-managed SSM params  /open-swe-<env>/<VAR>  with real,
    stable/derivable values (SANDBOX_TYPE, DEFAULT_REPO_OWNER/NAME,
    ALLOWED_GITHUB_ORGS, DASHBOARD_*_URL/ORIGINS, LLM_MODEL_ID).
  - OUT_OF_BAND_SSM documents the ~30 params CDK intentionally does NOT
    own (operationally-variable / env-specific-unknown).
- Wire ConfigStore into OpenSwe<Env>Stack.
- KebabNamingAspect: exempt Secrets Manager + SSM names, which carry the
  literal UPPER_SNAKE env-var segment (open-swe-dev/DASHBOARD_JWT_SECRET).
- deploy/seahaven/put-config.sh: out-of-band populator (placeholders only,
  OPENSWE_PUT_<VAR> env indirection; no real values committed).

Synth-only; not deployed. Instance-role read grants on open-swe-<env>/*
already exist from T6 — no IAM/trust changes here.
2026-06-26 16:07:23 -04:00
..
aegra ci: promote dev → prod via fast-forward (not force-push from main) (#2) 2026-06-26 11:20:10 -04:00
nginx feat(deploy): add Sea Haven self-hosted deployment capture 2026-06-25 17:28:34 -04:00
systemd feat(deploy): add Sea Haven self-hosted deployment capture 2026-06-25 17:28:34 -04:00
DEPLOYMENT.md feat(deploy): AWS-sourced fetch-config + seed_store + rotation docs (PR#7) (#8) 2026-06-26 15:06:41 -04:00
fetch-config.sh feat(deploy): AWS-sourced fetch-config + seed_store + rotation docs (PR#7) (#8) 2026-06-26 15:06:41 -04:00
put-config.sh feat: Secrets Manager + SSM config store for open-swe (T11) (#10) 2026-06-26 16:07:23 -04:00
ROTATION.md feat(deploy): AWS-sourced fetch-config + seed_store + rotation docs (PR#7) (#8) 2026-06-26 15:06:41 -04:00
seed_store.sh feat(deploy): AWS-sourced fetch-config + seed_store + rotation docs (PR#7) (#8) 2026-06-26 15:06:41 -04:00