procurement-ingest/cdk
Adam Moussa cf8ca2eeb6
feat(api): custom domain procurement-api.seahaven.com (stacked on PR-2) (#140)
* feat(api): custom domain procurement-api.seahaven.com for the read API

Stacked on feat/shoc-wo-webhook. Gives the SHOC-facing read API a stable,
brandable endpoint instead of the opaque execute-api URL.

- procurement_api_stack.py: REGIONAL API Gateway DomainName (TLS 1.2) +
  empty base-path mapping to the prod stage, so callers hit
  https://procurement-api.seahaven.com/work-orders (no /prod segment). The
  ACM cert ARN is read from SSM (/procurement-api/custom-domain/certificate-arn)
  via value_for_string_parameter, because the seahaven.com zone is in the
  mgmt account (cross-account DNS) and the cert is issued out of band. Outputs
  expose the regional alias target + hosted-zone id for the mgmt A-record.
- scripts/setup_procurement_api_domain.sh: idempotent two-step runbook
  (cert: request + mgmt-zone validation + wait + SSM; alias: post-deploy
  A-record from stack outputs). Verifies both account identities.
- handler._base_url: omit the /{stage} segment for a custom-domain request
  (the base-path mapping serves the stage at the root) so the docs never
  advertise a broken server URL; execute-api hosts keep /{stage}.
- openapi.json: custom domain added as servers[0] (recommended), execute-api
  kept as the direct fallback + the per-request injection target.

No IAM/auth/policy change (same API id + resource policy), so the SigV4
surface and the mandatory cross-family gates are unaffected. 751 pytest,
ruff, cdk synth, redocly lint all green.

* fix(api): use .endswith('.amazonaws.com') instead of substring check for execute-api detection

The prior '.execute-api.' in domain substring check is fragile and
triggers CodeQL incomplete-sanitization warnings. All API Gateway default
domains end with .amazonaws.com, so a suffix check is more precise and
also silences the false-positive alert.

Refs: https://github.com/Sea-Haven-Industries/procurement-ingest/security/code-scanning/6
2026-07-24 18:41:10 -04:00
..
app.py feat(api): procurement-api read stack + OpenAPI docs (SHOC reconciliation path) (#127) 2026-07-23 19:32:20 -04:00
cdk.json Initial commit: PO email ingestion pipeline 2026-04-07 12:12:30 -04:00
common.py fix(cdk): explicit Lambda LogGroups replace log_retention (INFRA-114) (#126) 2026-07-23 17:21:07 -04:00
po_stack.py fix(cdk): explicit Lambda LogGroups replace log_retention (INFRA-114) (#126) 2026-07-23 17:21:07 -04:00
procurement_api_stack.py feat(api): custom domain procurement-api.seahaven.com (stacked on PR-2) (#140) 2026-07-24 18:41:10 -04:00
requirements.txt chore(deps): bump boto3 to 1.43.51 (po/web_ui, po/site_extractor, wo/web_ui) and constructs to 10.7.1 (cdk) (#121) 2026-07-20 17:22:15 -04:00
wo_stack.py feat(webhook): SHOC WO webhook emitter - dark-ship streams + HMAC secret/rotation (PR-2) (#137) 2026-07-24 22:12:20 +00:00