Commit graph

28 commits

Author SHA1 Message Date
5fc749bc0e
refactor(cdk): encrypt migrated log groups with seahaven-logs CMK (INFRA-114) 2026-07-06 18:09:19 -04:00
62a3a7f0be
refactor(cdk): replace deprecated logRetention with explicit LogGroup (INFRA-114) 2026-07-06 17:59:27 -04:00
dependabot[bot]
70a438b3c3
Bump aws-cdk-lib in /cdk in the minor-and-patch group (#72)
Bumps the minor-and-patch group in /cdk with 1 update: [aws-cdk-lib](https://github.com/aws/aws-cdk).


Updates `aws-cdk-lib` from 2.259.0 to 2.260.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.259.0...v2.260.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.260.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 15:55:17 -04:00
Adam Moussa
35dc32390c
Add DLQ messages-present alarm for workorder-email-processor (#68)
Some checks failed
Deploy / deploy (push) Has been cancelled
The existing workorder-email-processor-errors alarm fires on any errored
async invocation, but a message only reaches the DLQ after Lambda exhausts
its async retries and gives up — a genuinely dropped work-order email that
the errors alarm alone does not distinguish.

Add an ALARM-only CloudWatch alarm (workorder-email-processor-dlq-messages)
on the EmailProcessorDlq ApproximateNumberOfMessagesVisible metric
(Statistic MAXIMUM, period 5m, evaluationPeriods 1, threshold > 0,
treatMissingData NOT_BREACHING). Routes to the same shared site-alerts SNS
topic via SnsAction, mirroring the errors-alarm construct style.

Refs INFRA-41 / audit H-8.
2026-06-17 17:31:16 -04:00
Adam Moussa
0615aa5b77
Add CloudWatch alarm for po-email-processor DLQ messages (#69)
Page when any message lands in the EmailProcessorDlq, which means a PO
email was permanently dropped after po-email-processor exhausted its
async Lambda retries. Without this, the errors alarm catches the failing
invocations but nothing surfaces the resulting dead-lettered email.

AWS/SQS ApproximateNumberOfMessagesVisible, Maximum over a single 5-min
period > 0, notBreaching on missing data. Reuses the shared site-alerts
SNS topic, ALARM-only, matching the existing po-email-processor-errors
alarm. The metric helper derives the QueueName dimension from the queue
construct (Fn::GetAtt QueueName), so the alarm tracks the CDK-generated
queue name without hardcoding it.
2026-06-17 17:28:42 -04:00
Adam Moussa
86f2ebb42d
Codify S3 Block Public Access on ingest buckets (#71)
Add block_public_access=BlockPublicAccess.BLOCK_ALL to the po-ingest and
workorder-ingest EmailBucket constructs. The buckets are already private
at runtime via account-level and AWS-default BPA, so this is a no-op for
behavior; it closes the codification gap that left CKV_AWS_53-56 firing
on the synthesized templates and blocking the security pre-push gate
(and the DLQ-alarm PRs that ride on it).
2026-06-17 17:23:06 -04:00
Adam Moussa
0fdf407e1d
Add CloudWatch alarm coverage for po-ingest and workorder-ingest (#70)
Some checks are pending
Deploy / deploy (push) Waiting to run
* Add CloudWatch alarm coverage for po-ingest and workorder-ingest

Expands alarm coverage across both CDK stacks. All alarms are ALARM-only
(no OK action) to the shared site-alerts SNS topic, with TreatMissingData
NOT_BREACHING. The site-alerts topic is now imported once near the top of
each stack so every alarm reuses one Topic instance.

po-ingest (cdk/po_stack.py):
- Errors: po-ingest-site-extractor
- Throttles: po-email-processor, po-ingest-site-extractor, po-web-ui
- Duration (p99, >=45000ms, eval3/dp2): po-email-processor (orphan adoption),
  po-ingest-site-extractor, po-web-ui
- DynamoDB throttle + system-error: purchase-orders, verified-sites,
  pending-site-review

workorder-ingest (cdk/wo_stack.py):
- Throttles: workorder-email-processor
- Duration (p95, >=45000ms, eval3/dp2): workorder-email-processor (orphan adoption)
- DynamoDB throttle + system-error: WorkOrders, WorkOrderComments

DynamoDB ThrottledRequests/SystemErrors emit only at the TableName+Operation
dimension set, so each table alarm is a Sum math expression across operations
via the non-deprecated metric_*_for_operations helpers (metric_throttled_requests
is deprecated/invalid in aws-cdk-lib 2.259.0).

Refs INFRA-41 / audit H-8.

* Drop NEEDS ADAM SIGN-OFF wording from alarm comments

Duration alarm thresholds are owner-approved; remove the sign-off flag
from po_stack.py and wo_stack.py comments. Threshold values, eval config,
and orphan-delete notes are unchanged.
2026-06-17 14:46:03 -04:00
dependabot[bot]
0f699595b5
Bump aws-cdk-lib in /cdk in the minor-and-patch group across 1 directory (#65)
Bumps the minor-and-patch group with 1 update in the /cdk directory: [aws-cdk-lib](https://github.com/aws/aws-cdk).


Updates `aws-cdk-lib` from 2.258.1 to 2.259.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.258.1...v2.259.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.259.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-16 20:57:49 +00:00
dependabot[bot]
98a9ae1979
Bump aws-cdk-lib in /cdk in the minor-and-patch group (#58)
Bumps the minor-and-patch group in /cdk with 1 update: [aws-cdk-lib](https://github.com/aws/aws-cdk).


Updates `aws-cdk-lib` from 2.258.0 to 2.258.1
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.258.0...v2.258.1)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.258.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-12 15:08:34 -04:00
Adam Moussa
47fa35688d
fix(po): grant KMS on seahaven-dynamodb CMK to purchase-orders consumers (INFRA-104) (#56)
Some checks are pending
Deploy / deploy (push) Waiting to run
The purchase-orders table was migrated to SSE-KMS (alias/seahaven-dynamodb,
INFRA-95/M-3) out-of-band, but po_stack never declared the key, so
grant_read_write_data did not propagate kms perms. po-email-processor failed
~99.6% of invocations with kms:Decrypt AccessDeniedException, a data-loss
outage on the PO ingestion write path.

- po_stack: declare encryption_key on purchase-orders (reconciles SSE drift;
  no-op against the already-encrypted live table) so the existing grants add
  kms:Decrypt/GenerateDataKey/DescribeKey to EmailProcessor, WebUI, SiteExtractor.
- wo_stack: pre-emptive grant_encrypt_decrypt on the WO processor role ahead of
  the WorkOrders CMK migration (INFRA-6); tables left unencrypted, no table change.

GPT-4.1 cross-review: no blockers.
2026-06-10 19:31:55 -04:00
Adam Moussa
109c565cbf
Reconcile IaC with out-of-band DLQ + Function URL changes (INFRA-74, INFRA-41) (#50)
Some checks are pending
Deploy / deploy (push) Waiting to run
Make CDK the source of truth for two sets of changes applied out-of-band
via CLI to the po-ingest and WorkorderIngestStack stacks.

INFRA-74 (audit C-5): remove the public FunctionUrlAuthType.NONE Function
URL construct (and its auto-generated Principal:* invoke permission +
output) from both po-web-ui and workorder-web-ui. The URLs were already
deleted live via CLI; CFN's delete is idempotent.

INFRA-41 (audit H-8): add a CDK-managed SQS dead-letter queue
(dead_letter_queue=, 14d retention, SSL-enforced, CDK-generated name) and
an ALARM-only Errors alarm (Sum, threshold>0, site-alerts topic) for both
po-email-processor and workorder-email-processor, mirroring the
apm-wo-analysis-classifier DLQ and payments-payroll-batch alarm patterns.

Interim CLI resources (per-fn -dlq queues, -errors alarms, dlq-send inline
policies, OnFailure event-invoke-configs) removed post-deploy.
2026-06-08 16:02:29 -04:00
dependabot[bot]
64ff6f09ca
Bump aws-cdk-lib in /cdk in the minor-and-patch group (#48)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps the minor-and-patch group in /cdk with 1 update: [aws-cdk-lib](https://github.com/aws/aws-cdk).


Updates `aws-cdk-lib` from 2.257.0 to 2.258.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.257.0...v2.258.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.258.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-05 14:49:27 -04:00
Adam Moussa
7732069a73
fix(deps): pin aws-cdk-lib to ==2.257.0 (#43)
Some checks are pending
Deploy / deploy (push) Waiting to run
* fix(deps): re-pin aws-cdk-lib to ==2.253.1

* fix(deps): pin aws-cdk-lib to 2.257.0 (exact)
2026-06-05 13:22:45 -04:00
dependabot[bot]
ad17cac484
Update aws-cdk-lib requirement from >=2.255.0 to >=2.257.0 in /cdk (#36)
Updates the requirements on [aws-cdk-lib](https://github.com/aws/aws-cdk) to permit the latest version.
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.255.0...v2.257.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.257.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-03 22:48:09 +00:00
Adam Moussa
9370abf9ab
Drop three read-idle GSIs (audit M-20) (#35)
Some checks are pending
Deploy / deploy (push) Waiting to run
* Drop read-idle GSIs: by-state and status-index

Audit M-20: 30 days of CloudWatch metrics show 0 reads on both
indexes against 518 (by-state) and ~50k (status-index) WCU of write
amplification. No code path queries either index.

site-code-index follows in the next commit - CloudFormation allows
only one GSI change per table per deploy.

* Drop read-idle site-code-index GSI

Second half of the M-20 cleanup - deployed separately because
CloudFormation allows one GSI change per table per update.
2026-06-03 15:32:23 -04:00
Adam Moussa
a5d2bee748
Fix po-email-processor bundling for arm64 target (#34)
po-email-processor has been down since 2026-05-12: the bundling
command installed wheels for the build host's architecture, so CD
deploys from amd64 runners shipped x86_64 pydantic_core into an
ARM_64 function, crashing every INIT with Runtime.ImportModuleError.

Pin the pip platform to manylinux2014_aarch64 with --only-binary,
matching the pattern wo_stack already uses.

Verified live: deployed from branch, manual invoke OK; 920 emails
from the outage window backfilled via scripts/reprocess logic.
2026-06-03 14:56:02 -04:00
dependabot[bot]
d233488875
Update aws-cdk-lib requirement from >=2.253.1 to >=2.255.0 in /cdk (#28)
Updates the requirements on [aws-cdk-lib](https://github.com/aws/aws-cdk) to permit the latest version.
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.253.1...v2.255.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.255.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-19 19:20:42 +00:00
Adam Moussa
5112c1345b
Merge workorder-ingest into unified procurement repo (#22)
* Merge workorder-ingest pipeline into unified repo

Move PO lambdas under lambdas/po/, add WO pipeline under lambdas/wo/.
Two independent CloudFormation stacks in one CDK app. Fix WO stack
compliance: ARM64 architecture, 60-day log retention, aarch64 bundling,
RETAIN on Anthropic secret. Remove stale CodePipeline buildspec.

* Fix test_local.py import path and remove dead shared/models.py

test_local.py referenced the old lambdas/email_processor path. Updated
to lambdas/wo/email_processor. Removed shared/ directory entirely as
nothing imports from it.

* Escape HTML in both web UI dashboards to prevent XSS

Both Function URLs are public (auth_type=NONE) and render
email-derived content via f-strings. Attacker-crafted emails
could inject scripts. Added html.escape() on all interpolated
values in both PO and WO dashboards.

* Add pagination to WO web UI scan

get_work_orders() only fetched the first 1MB page from DynamoDB.
Loop on LastEvaluatedKey to match the PO web UI pattern.

* Fix esc(None) TypeError and javascript: scheme in PO web UI

Coerce supplier name through `or ""` before escaping to handle
nested None from DynamoDB. Add scheme allowlist on view_order_url
to block javascript:/data: hrefs from LLM-extracted URLs.

* Fix WO render_badge None guard, updated_at slice, and backfill path

Add null guard to WO render_badge matching the PO version. Use
`or ""` before slicing updated_at to handle explicit None values.
Fix backfill_sites.py sys.path to use new lambdas/po/site_extractor.

* Harden WO web UI and fix JS-context XSS in both dashboards

- Use json.dumps for onclick URLs to prevent JS string breakout
- Add .lower() to WO render_badge color lookup matching PO pattern
- Add pagination to get_comments query
- Cap get_work_orders to 500 results matching PO pattern

* Apply ruff formatting to web UI handlers
2026-05-12 15:21:06 -04:00
dependabot[bot]
429611030e
Update aws-cdk-lib requirement from >=2.252.0 to >=2.253.1 in /cdk (#16)
Updates the requirements on [aws-cdk-lib](https://github.com/aws/aws-cdk) to permit the latest version.
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/v2.253.1/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.252.0...v2.253.1)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.253.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 22:27:13 +00:00
Adam Moussa
abdf2aa035
Add CI workflow (#18)
* Add CI workflow and apply ruff formatting

* Disable cdk synth — email_processor uses pre-built package dir

The email_processor Lambda bundles deps into a gitignored package/
directory. cdk synth fails in CI without a build step to recreate it.
Disabling until packaging is standardized.

* Use CDK BundlingOptions for email_processor Lambda packaging

Replaces the pre-built gitignored package/ directory with CDK's
built-in bundling. Deps are now installed inside a Docker container
during cdk synth, so the build works identically locally and in CI.
Re-enables run-cdk-synth in the CI workflow.
2026-05-08 16:01:21 -04:00
dependabot[bot]
a7ca58d9d9
Update aws-cdk-lib requirement from >=2.150.0 to >=2.252.0 in /cdk
Updates the requirements on [aws-cdk-lib](https://github.com/aws/aws-cdk) to permit the latest version.
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.150.0...v2.252.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.252.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-02 21:24:26 +00:00
dependabot[bot]
1832ce2853
Update constructs requirement from >=10.0.0 to >=10.6.0 in /cdk
Updates the requirements on [constructs](https://github.com/aws/constructs) to permit the latest version.
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.0.0...v10.6.0)

---
updated-dependencies:
- dependency-name: constructs
  dependency-version: 10.6.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-02 21:17:20 +00:00
Adam Moussa
e66062c934 Align PO schema with enriched records and improve extraction prompt
Replaces extraction prompt with domain-specific rules: trade
classification taxonomy (23 categories), site_code skip list,
zip padding, revision email type, and structured extraction for
fiscal_year, trade, and coupa_category.

Handler changes:
- New "revision" email type overwrites existing PO via put_item
- enrich_parsed() adds top-level state, ship_to_raw, data_source
- pad_zip() zero-pads short zip codes (e.g., "7001" → "07001")
- Removed invoice_total/invoice_count (Payee Central only)

Web UI: added revision badge, new detail fields (site code, state,
trade, fiscal year, coupa category, data source), line item table
now shows Qty/Unit/Price columns, list view shows Site and Trade.

CDK: fixed StreamViewType to match deployed table (NEW_IMAGE).
README: documented PO record schema and revision flow.
2026-05-01 19:53:26 -04:00
Adam Moussa
36f49ae259
Add CI/CD pipeline and fix stack name to kebab-case (#3)
* Add CI/CD pipeline and fix stack name to kebab-case

CodePipeline V2 (po-ingest-pipeline) triggers CodeBuild on push
to main, running cdk deploy via buildspec.yml. Stack name changed
from PoIngestStack to po-ingest to match naming conventions.

* Add RETAIN policy to Secrets Manager secret

Prevents the Anthropic API key from being deleted if the stack
is ever removed. Matches the RETAIN policy on all other stateful
resources (DynamoDB tables, S3 bucket).
2026-05-01 19:17:19 -04:00
Adam Moussa
f5d1eaeb5b Add address reverse-lookup fallback and pending-site-review table
When no site code is found via Claude extraction or regex cascade,
the Lambda now checks the PO address against a cold-start cache of
verified-sites (normalized street + zip match). If still no match,
the PO is written to a new pending-site-review table for manual
verification against Payee Central.
2026-04-30 15:01:09 -04:00
Adam Moussa
ec416079f5 Add verified-sites pipeline via DynamoDB Streams
Enable DynamoDB Streams on purchase-orders table and add a site-extractor
Lambda that extracts Amazon facility codes and addresses from PO ship-to
data, upserting them into a new verified-sites table. Includes a backfill
script for existing POs and upgrades existing Lambdas to arm64 + 60-day
log retention.
2026-04-30 14:26:53 -04:00
Adam Moussa
3514e74e40 Fix stack naming to follow kebab-case convention
Pin existing CloudFormation stack name via stack_name property so
the live stack is not affected. Construct ID now follows the org
kebab-case standard.
2026-04-28 14:43:48 -04:00
Adam Moussa
fc690dd958 Initial commit: PO email ingestion pipeline
CDK stack with SES receipt rule, S3 bucket, email processor Lambda
(Claude-powered extraction), web UI Lambda with Function URL, and
DynamoDB for storage. Includes reprocessing script for missed emails.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-07 12:12:30 -04:00