* Add CI workflow and apply ruff formatting
* Disable cdk synth — email_processor uses pre-built package dir
The email_processor Lambda bundles deps into a gitignored package/
directory. cdk synth fails in CI without a build step to recreate it.
Disabling until packaging is standardized.
* Use CDK BundlingOptions for email_processor Lambda packaging
Replaces the pre-built gitignored package/ directory with CDK's
built-in bundling. Deps are now installed inside a Docker container
during cdk synth, so the build works identically locally and in CI.
Re-enables run-cdk-synth in the CI workflow.
When no site code is found via Claude extraction or regex cascade,
the Lambda now checks the PO address against a cold-start cache of
verified-sites (normalized street + zip match). If still no match,
the PO is written to a new pending-site-review table for manual
verification against Payee Central.
The Claude extraction prompt now explicitly asks for site_code (the
Amazon facility code) and structured ship_to address fields (street,
city, state, zip). The site-extractor Lambda prefers these direct
fields when available, falling back to regex for older PO records.
Enable DynamoDB Streams on purchase-orders table and add a site-extractor
Lambda that extracts Amazon facility codes and addresses from PO ship-to
data, upserting them into a new verified-sites table. Includes a backfill
script for existing POs and upgrades existing Lambdas to arm64 + 60-day
log retention.