open-swe/deploy/seahaven
Adam Moussa 5e30bc6be2
Point dev agent at seahaven-open-swe-dev org + un-pin the owner guard (#27)
Dev now runs against the dedicated seahaven-open-swe-dev org (repo openswe-dev-sandbox),
isolated from the real Sea Haven org. Two changes:

- config-store.ts: iacManagedSsm repo targeting is now per-env — dev =
  seahaven-open-swe-dev/openswe-dev-sandbox, prod stays Sea-Haven-Industries/open-swe-pilot.
  ALLOWED_GITHUB_ORGS tracks the env owner. Adds a dev-only SEED_USER_MAPPINGS param so the
  triggering GitHub login (amoussa1229) resolves and @openswe comments aren't skipped.

- fetch-config.sh: replace the unconditional hard-pin to Sea-Haven-Industries with an owner
  GUARD that HONORS the configured owner (OPENSWE_REPO_OWNER override, else the SSM value) but
  forces a per-env safe org when the normalized owner is blank or the upstream langchain-ai.
  Normalization (lowercase, strip whitespace, first path segment, drop dots) catches
  langchain-ai/<repo>, langchain-ai., and case variants without over-blocking legit orgs
  (e.g. langchain-ai-fork). Fallback org is per-env so dev can't fall back into the real org.

Reviews: GPT-4.1 cross-review APPROVE (round 1 found a path/dot bypass -> hardened, round 2 clean);
/sh-security-review authz one LOW (env-invariant fallback) -> fixed. Positive org allowlist still
enforced by the app via ALLOWED_GITHUB_ORGS.
2026-06-27 19:29:03 -04:00
..
aegra ci: promote dev → prod via fast-forward (not force-push from main) (#2) 2026-06-26 11:20:10 -04:00
nginx feat(deploy): add Sea Haven self-hosted deployment capture 2026-06-25 17:28:34 -04:00
systemd feat(deploy): add Sea Haven self-hosted deployment capture 2026-06-25 17:28:34 -04:00
DEPLOYMENT.md feat(deploy): AWS-sourced fetch-config + seed_store + rotation docs (PR#7) (#8) 2026-06-26 15:06:41 -04:00
fetch-config.sh Point dev agent at seahaven-open-swe-dev org + un-pin the owner guard (#27) 2026-06-27 19:29:03 -04:00
put-config.sh feat: Secrets Manager + SSM config store for open-swe (T11) (#10) 2026-06-26 16:07:23 -04:00
ROTATION.md feat(deploy): AWS-sourced fetch-config + seed_store + rotation docs (PR#7) (#8) 2026-06-26 15:06:41 -04:00
seed_store.sh fix: don't crash-loop the box when no user mapping is configured (#25) 2026-06-26 20:06:53 -04:00