From 36f49ae2598831393aaaac1abbb2a4fa682a3aa4 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 1 May 2026 19:17:19 -0400 Subject: [PATCH] Add CI/CD pipeline and fix stack name to kebab-case (#3) * Add CI/CD pipeline and fix stack name to kebab-case CodePipeline V2 (po-ingest-pipeline) triggers CodeBuild on push to main, running cdk deploy via buildspec.yml. Stack name changed from PoIngestStack to po-ingest to match naming conventions. * Add RETAIN policy to Secrets Manager secret Prevents the Anthropic API key from being deleted if the stack is ever removed. Matches the RETAIN policy on all other stateful resources (DynamoDB tables, S3 bucket). --- README.md | 9 ++++++++- buildspec.yml | 15 +++++++++++++++ cdk/app.py | 2 +- cdk/stack.py | 1 + 4 files changed, 25 insertions(+), 2 deletions(-) create mode 100644 buildspec.yml diff --git a/README.md b/README.md index 44ba4e3..3e67e7d 100644 --- a/README.md +++ b/README.md @@ -30,7 +30,7 @@ Backfill stats (initial run): 14,825 POs scanned → 9,900 with extractable site ## Architecture -- **IaC:** AWS CDK (Python), stack name `PoIngestStack`, region `us-east-1`. +- **IaC:** AWS CDK (Python), stack name `po-ingest`, region `us-east-1`. - **Lambdas** (all Python 3.12, arm64, 60-day log retention): - `po-email-processor` — S3-triggered, parses PO emails via Claude Haiku. - `po-web-ui` — Function URL, HTML dashboard. @@ -42,6 +42,13 @@ Backfill stats (initial run): 14,825 POs scanned → 9,900 with extractable site - DynamoDB `pending-site-review` — PK `po_number`. POs with no extractable site code and no address match, awaiting manual Payee Central verification. - **Secrets:** Anthropic API key in Secrets Manager at `po-ingest/anthropic-api-key`. - **SES:** adds the `PoEmailRule` to the existing `INBOUND_MAIL` receipt rule set (shared with `workorder-ingest`). +- **CI/CD:** CodePipeline V2 (`po-ingest-pipeline`) → CodeBuild (`po-ingest-build`). Pushes to `main` auto-deploy via `buildspec.yml`. + +## CI/CD + +Merges to `main` trigger the `po-ingest-pipeline` (CodePipeline V2) which runs CodeBuild to `cdk deploy`. The pipeline uses the existing CodeStar connection to the Sea-Haven-Industries GitHub org. + +**Branch protection:** `main` requires a PR (no direct push), no deletion, no force push. ## Setup diff --git a/buildspec.yml b/buildspec.yml new file mode 100644 index 0000000..da69dde --- /dev/null +++ b/buildspec.yml @@ -0,0 +1,15 @@ +version: 0.2 + +phases: + install: + runtime-versions: + python: 3.12 + nodejs: 22 + commands: + - npm install -g aws-cdk + - pip install -r cdk/requirements.txt + - pip install -r lambdas/email_processor/requirements.txt -t lambdas/email_processor/package/ + - cp lambdas/email_processor/handler.py lambdas/email_processor/package/ + build: + commands: + - cd cdk && cdk deploy --require-approval never diff --git a/cdk/app.py b/cdk/app.py index a8ae9ba..1c5f42f 100644 --- a/cdk/app.py +++ b/cdk/app.py @@ -4,7 +4,7 @@ from stack import PoIngestStack app = cdk.App() PoIngestStack(app, "po-ingest", - stack_name="PoIngestStack", + stack_name="po-ingest", env=cdk.Environment(region="us-east-1"), ) app.synth() diff --git a/cdk/stack.py b/cdk/stack.py index cdb0908..21ec4c5 100644 --- a/cdk/stack.py +++ b/cdk/stack.py @@ -53,6 +53,7 @@ class PoIngestStack(Stack): self, "AnthropicApiKey", secret_name="po-ingest/anthropic-api-key", description="Anthropic API key for Coupa PO email parsing", + removal_policy=RemovalPolicy.RETAIN, ) # --- Lambda function ---