Compare commits

...

2 commits

Author SHA1 Message Date
Adam Moussa
9370abf9ab
Drop three read-idle GSIs (audit M-20) (#35)
Some checks are pending
Deploy / deploy (push) Waiting to run
* Drop read-idle GSIs: by-state and status-index

Audit M-20: 30 days of CloudWatch metrics show 0 reads on both
indexes against 518 (by-state) and ~50k (status-index) WCU of write
amplification. No code path queries either index.

site-code-index follows in the next commit - CloudFormation allows
only one GSI change per table per deploy.

* Drop read-idle site-code-index GSI

Second half of the M-20 cleanup - deployed separately because
CloudFormation allows one GSI change per table per update.
2026-06-03 15:32:23 -04:00
Adam Moussa
a5d2bee748
Fix po-email-processor bundling for arm64 target (#34)
po-email-processor has been down since 2026-05-12: the bundling
command installed wheels for the build host's architecture, so CD
deploys from amd64 runners shipped x86_64 pydantic_core into an
ARM_64 function, crashing every INIT with Runtime.ImportModuleError.

Pin the pip platform to manylinux2014_aarch64 with --only-binary,
matching the pattern wo_stack already uses.

Verified live: deployed from branch, manual invoke OK; 920 emails
from the outage window backfilled via scripts/reprocess logic.
2026-06-03 14:56:02 -04:00
2 changed files with 8 additions and 31 deletions

View file

@ -73,7 +73,9 @@ class PoIngestStack(Stack):
command=[
"bash",
"-c",
"pip install -r requirements.txt -t /asset-output && cp handler.py /asset-output/",
"pip install --platform manylinux2014_aarch64 --only-binary=:all: "
"-r requirements.txt -t /asset-output && "
"cp handler.py /asset-output/",
],
),
),
@ -157,14 +159,8 @@ class PoIngestStack(Stack):
billing_mode=dynamodb.BillingMode.PAY_PER_REQUEST,
removal_policy=RemovalPolicy.RETAIN,
)
verified_sites_table.add_global_secondary_index(
index_name="by-state",
partition_key=dynamodb.Attribute(
name="state",
type=dynamodb.AttributeType.STRING,
),
projection_type=dynamodb.ProjectionType.ALL,
)
# by-state GSI removed 2026-06-03 (audit M-20): 0 reads in 30d against
# 518 WCU of write amplification. Re-add if a state-level query path ships.
# --- Site extractor Lambda (DynamoDB Streams → verified-sites) ---
site_extractor = lambda_.Function(

View file

@ -44,28 +44,9 @@ class WorkorderIngestStack(Stack):
billing_mode=dynamodb.BillingMode.PAY_PER_REQUEST,
removal_policy=RemovalPolicy.RETAIN,
)
work_orders_table.add_global_secondary_index(
index_name="site-code-index",
partition_key=dynamodb.Attribute(
name="site_code",
type=dynamodb.AttributeType.STRING,
),
sort_key=dynamodb.Attribute(
name="updated_at",
type=dynamodb.AttributeType.STRING,
),
)
work_orders_table.add_global_secondary_index(
index_name="status-index",
partition_key=dynamodb.Attribute(
name="wo_status",
type=dynamodb.AttributeType.STRING,
),
sort_key=dynamodb.Attribute(
name="updated_at",
type=dynamodb.AttributeType.STRING,
),
)
# site-code-index and status-index GSIs removed 2026-06-03 (audit M-20):
# 0 reads in 30d against ~50k WCU each of write amplification. Re-add if
# a site-code or status query path ships.
comments_table = dynamodb.Table(
self,