* Add CI workflow and apply ruff formatting
* Disable cdk synth — email_processor uses pre-built package dir
The email_processor Lambda bundles deps into a gitignored package/
directory. cdk synth fails in CI without a build step to recreate it.
Disabling until packaging is standardized.
* Use CDK BundlingOptions for email_processor Lambda packaging
Replaces the pre-built gitignored package/ directory with CDK's
built-in bundling. Deps are now installed inside a Docker container
during cdk synth, so the build works identically locally and in CI.
Re-enables run-cdk-synth in the CI workflow.
* Add CI/CD pipeline and fix stack name to kebab-case
CodePipeline V2 (po-ingest-pipeline) triggers CodeBuild on push
to main, running cdk deploy via buildspec.yml. Stack name changed
from PoIngestStack to po-ingest to match naming conventions.
* Add RETAIN policy to Secrets Manager secret
Prevents the Anthropic API key from being deleted if the stack
is ever removed. Matches the RETAIN policy on all other stateful
resources (DynamoDB tables, S3 bucket).
Pin existing CloudFormation stack name via stack_name property so
the live stack is not affected. Construct ID now follows the org
kebab-case standard.
CDK stack with SES receipt rule, S3 bucket, email processor Lambda
(Claude-powered extraction), web UI Lambda with Function URL, and
DynamoDB for storage. Includes reprocessing script for missed emails.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>