mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 16:13:15 +00:00
PR#1 of the AWS migration. CDK TypeScript app under /infra: stacks open-swe-iam (four per-env GitHub-OIDC deploy roles) + open-swe-dev/-prod (per-env EC2 instance role + AMI cache). aws-cdk-lib pinned exact 2.260.0; kebab naming Aspect + 15 tests. IAM is synth-only (NOT deployed). Cleared the Phase-1 security gates: - T4 GPT-4.1 IAM cross-review (StringEquals trust; cdk-hnb659fds-* wildcard kept as org convention; AWS-RunShellScript timeboxed to T19). - T5 /sh-security-review: deploy roles split PER-ENV with env-scoped OIDC trust (dev=branch ref+tag dev, prod=environment:prod+tag prod) so a dev token cannot reach prod; re-verified block:false.
21 lines
443 B
JSON
21 lines
443 B
JSON
{
|
|
"app": "npx ts-node --prefer-ts-exts bin/app.ts",
|
|
"watch": {
|
|
"include": ["**"],
|
|
"exclude": [
|
|
"README.md",
|
|
"cdk*.json",
|
|
"**/*.d.ts",
|
|
"**/*.js",
|
|
"tsconfig.json",
|
|
"package*.json",
|
|
"node_modules",
|
|
"cdk.out"
|
|
]
|
|
},
|
|
"context": {
|
|
"@aws-cdk/aws-lambda:recognizeLayerVersion": true,
|
|
"@aws-cdk/core:checkSecretUsage": true,
|
|
"@aws-cdk/core:target-partitions": ["aws"]
|
|
}
|
|
}
|