feat(webhook): ACTIVATE SHOC WO webhook emitter (enabled=True)

The deliberate one-line activation flip (plan Phase 3). Turns on both
DynamoDB stream event-source mappings for workorder-shoc-emitter, which
shipped dark (enabled=False) in PR-2. LATEST start position => the live
feed begins at deploy, no historical flood; SHOC loads history via the
procurement read API first.

DO NOT MERGE until: (1) PR-2 (feat/shoc-wo-webhook) is merged to main;
(2) SHOC's receiver passes the shared HMAC test vectors
(docs/shoc-webhook-test-vectors.json) at the target endpoint; (3) the
cross-account secret read from shoc-backend-dev is confirmed working.
Draft, gated on Luby.
This commit is contained in:
Adam Moussa 2026-07-24 15:36:32 -04:00
parent 61ccc68877
commit dd63812827
No known key found for this signature in database

View file

@ -750,14 +750,12 @@ def _add_shoc_webhook_emitter(stack, work_orders_table, comments_table, alarm_to
shoc_emitter_rejected_queue.grant_send_messages(shoc_emitter)
# ------------------------------------------------------------------
# SHIPS DARK: both event source mappings deploy with enabled=False,
# deliberately. The full stack (Lambda, queues, alarms, secret,
# rotation) deploys and is testable with zero deliveries while SHOC
# has no receiver, so our merge cadence never depends on Luby's.
# Activation is a one-line enabled=True PR gated on the SHOC receiver
# passing the shared HMAC test vectors (plan Phase 3). LATEST start
# position => no historical flood at activation; SHOC loads history
# via the procurement read API instead.
# ACTIVATED (enabled=True) 2026-XX-XX after SHOC's receiver passed the
# shared HMAC test vectors. Shipped DARK originally (enabled=False) so the
# stack could deploy and be tested with zero deliveries while SHOC had no
# receiver; this activation PR is the deliberate one-line flip (plan Phase
# 3). LATEST start position => the feed begins now, no historical flood;
# SHOC loaded history via the procurement read API before this flip.
# Ordering knobs: parallelization_factor=1, bisect_batch_on_error=
# False and retry_attempts=-1 (retry until the 24h record age) are
# REQUIRED for strict per-work-order in-order delivery -- a retryable
@ -775,7 +773,7 @@ def _add_shoc_webhook_emitter(stack, work_orders_table, comments_table, alarm_to
max_record_age=Duration.hours(24),
parallelization_factor=1,
report_batch_item_failures=True,
enabled=False,
enabled=True,
on_failure=lambda_event_sources.SqsDlq(shoc_emitter_failures_queue),
)
)
@ -789,7 +787,7 @@ def _add_shoc_webhook_emitter(stack, work_orders_table, comments_table, alarm_to
max_record_age=Duration.hours(24),
parallelization_factor=1,
report_batch_item_failures=True,
enabled=False,
enabled=True,
on_failure=lambda_event_sources.SqsDlq(shoc_emitter_failures_queue),
)
)