proposal-system/README.md

212 lines
10 KiB
Markdown
Raw Normal View History

Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
# Proposal System
![.NET](https://img.shields.io/badge/.NET-512BD4?logo=dotnet&logoColor=white)
![TypeScript](https://img.shields.io/badge/TypeScript-3178C6?logo=typescript&logoColor=white)
![Python](https://img.shields.io/badge/Python-3776AB?logo=python&logoColor=white)
![AWS CDK](https://img.shields.io/badge/AWS-CDK-FF9900?logo=amazonaws&logoColor=white)
![CI](https://github.com/Sea-Haven-Industries/proposal-system/actions/workflows/ci.yaml/badge.svg)
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
Internal proposal management platform for Sea Haven Industries. Dispatchers submit proposal requests, AI generates draft line items from historical data via Bedrock RAG, admins review and approve in a pricing workspace, and the system produces branded PDFs for delivery.
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
## Architecture Overview
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
Monorepo with five primary services:
- **.NET 8 API** -- Clean Architecture REST API hosted on Lambda behind API Gateway (JWT-authorized) with Function URL (AWS_IAM) for internal access
- **React 19 Web** -- MUI v9 admin/dispatcher workspace served via CloudFront + S3
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
- **React Native Mobile** -- iOS-first field app for dispatchers (offline-capable)
- **Python Lambdas** -- PDF extraction, PDF generation, library ingestion, AI suggestions, Aurora pgvector bootstrap
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
- **CDK Infrastructure** -- Three TypeScript stacks managing all AWS resources
## Repository Structure
```
proposal-system/
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
├── api/ .NET 8 Web API (Lambda-hosted, EF Core + PostgreSQL)
├── web/ React 19 + MUI v9 + Vite frontend
├── mobile/ React Native 0.86 iOS app
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
├── lambdas/ Python 3.12 processing functions (arm64)
├── infra/ CDK TypeScript (3 stacks)
├── shared/ TypeScript API contracts (shared between web + mobile)
├── scripts/ Post-deploy and utility scripts
├── .github/ CI/CD workflows
└── docker-compose.yml
```
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
## Tech Stack
| Component | Technologies |
|---|---|
| API | .NET 8, ASP.NET Core, EF Core + Npgsql, FluentValidation, Cognito JWT, Amazon.Lambda.AspNetCoreServer |
| Web | React 19, TypeScript, MUI v9, Vite, Redux Toolkit, TanStack Query, axios |
| Mobile | React Native CLI 0.86, React 19, React Native Paper, React Navigation, react-native-app-auth (PKCE), amazon-cognito-identity-js (SRP), Keychain, offline draft queue |
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
| Lambdas | Python 3.12, arm64, pdfplumber, reportlab, httpx, boto3 |
| Infrastructure | CDK TypeScript (aws-cdk-lib pinned exact, kept current by Dependabot) |
| AI/RAG | Bedrock Knowledge Base (Titan Embeddings v2), Aurora PostgreSQL + pgvector vector store (see ADR 0001), Claude Sonnet via Bedrock cross-region inference |
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
| Auth | Cognito User Pool + Google OAuth IdP (groups: dispatchers, admins, sysadmins) |
## AWS Resources
All resources are in **us-east-1** (account 328440206208).
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
| CDK Stack | Key Resources |
|---|---|
| `proposal-system-foundation` | Aurora PostgreSQL 15 Serverless v2 (RDS Data API, pgvector), S3 buckets, SQS queue + DLQ, Cognito user pool, Secrets Manager |
| `proposal-system-compute` | API Gateway HTTP API (JWT authorizer + access logging), .NET 8 API Lambda + Function URL (AWS_IAM), Python Lambdas (pdf-extract, pdf-generate, library-ingest, suggestions, aurora-pgvector-init bootstrap), Bedrock KB (Aurora pgvector store) |
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
| `proposal-system-frontend` | CloudFront distribution (S3 OAC) |
| Resource Type | Names |
|---|---|
| S3 Buckets | `proposal-system-uploads`, `proposal-system-generated`, `proposal-system-library`, `seahaven-ios-certificates` |
| SQS | `proposal-system-jobs` (720s visibility, SQS-managed encryption, reportBatchItemFailures) + `proposal-system-jobs-dlq` (SQS-managed encryption, message body filtering by jobType) |
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
| Secrets | `proposal-system/db-credentials`, `proposal-system/internal-api-key` |
## Local Development
### Prerequisites
- .NET 8 SDK
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
- Node.js 24+
- Python 3.12
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
- PostgreSQL 16 (via docker-compose or native)
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
### Database
```bash
docker compose up -d # starts PostgreSQL on port 5432
# database: proposalsystem, password: localdev
```
### API
```bash
cd api
dotnet restore
dotnet run --project src/ProposalSystem.Api
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
# runs on http://localhost:5000
```
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
In development mode (`DevMode=true` in appsettings.Development.json):
- JWT auth uses a local symmetric HMAC key (no Cognito required)
- S3 service returns fake presigned URLs
- SQS publisher logs messages without sending
### Web Frontend
```bash
cd web
npm install
npm run dev
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
# runs on http://localhost:5173, proxies /api to localhost:5000
```
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
When `VITE_COGNITO_CLIENT_ID` is not set, the login screen shows role-selector buttons for local development.
### Infrastructure
```bash
cd infra
npm install
npx cdk synth
```
## CI/CD
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
### CI (on pull request to main)
Seven parallel jobs calling org reusable workflows:
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
| Job | Workflow | What it checks |
|---|---|---|
| .NET Build & Test | `ci-dotnet.yaml` | Restore, build, test the API solution (123 xUnit tests) |
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
| Web Frontend Check | `ci-typescript-cdk.yaml` | TypeScript typecheck for web |
| Web Tests | inline job | vitest suite (26 tests — auth, interceptors, components) |
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
| Mobile Typecheck | `ci-typescript-cdk.yaml` | TypeScript typecheck for mobile |
| Python Lint | `ci-python-sam.yaml` | ruff check + format on lambdas/ |
| Python Tests | inline job | pytest suite (37 tests — pdf-generate, suggestions, library-ingest, internal API signing) |
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
| CDK Synth | `ci-typescript-cdk.yaml` | Synthesize CDK stacks (includes .NET publish) |
### Deploy (manual)
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
Auto-deploy on push to main is currently disabled (PR #167) — both deploy workflows run via `workflow_dispatch` from the Actions tab. `deploy.yaml` calls the `cd-cdk.yaml` reusable workflow:
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
1. Publishes .NET 8 API and Python Lambdas
2. Runs `cdk deploy --all`
3. Executes `scripts/post-deploy.sh` (builds web, syncs to S3, invalidates CloudFront)
Deploy uses OIDC role `githubdeploy-proposal-system`. Concurrency group prevents parallel deploys.
### Mobile Deploy
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
Workflow: `deploy-mobile.yaml` -- builds and uploads to TestFlight via `cd-mobile-ios.yaml` reusable workflow on `macos-26`.
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
Trigger: **manual only** (`workflow_dispatch`) while the app is pre-V1, to save macOS runner cost.
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
## Mobile iOS
The iOS app uses **Fastlane** with **match** for code signing. Certificates and profiles are stored in the `seahaven-ios-certificates` S3 bucket (versioning enabled, public access blocked).
Build and upload to TestFlight is handled by the `cd-mobile-ios.yaml` reusable workflow. Required secrets:
| Secret | Purpose |
|---|---|
| `AWS_DEPLOY_ROLE_ARN` | OIDC role for match S3 access |
| `MATCH_PASSWORD` | Decryption passphrase for signing assets |
| `ASC_KEY_ID` | App Store Connect API key ID |
| `ASC_ISSUER_ID` | App Store Connect issuer |
| `ASC_KEY_CONTENT` | App Store Connect API key (base64) |
## Authentication & Authorization
Two-layer auth architecture with defense-in-depth:
| Path | Authorizer | Authentication |
|---|---|---|
| External clients → API Gateway `/{proxy+}` | Cognito JWT authorizer (web + mobile client IDs) | .NET JWT middleware (ValidateAudience=true) |
| `/api/health` | None (public) | None |
| `/api/auth/callback`, `/api/auth/dev-login` | None (unauthenticated) | None (pre-auth endpoints) |
| Internal Lambdas → Function URL | AWS_IAM (grantInvokeUrl) | Internal API key (`X-Internal-Api-Key` header, value from Secrets Manager) |
**Role-based access:** Cognito groups (`dispatchers`, `admins`, `sysadmins`) map to API roles via `cognito:groups` claim. Dispatchers can only see their own proposals (ownership enforced in service layer). VendorProposals and GeneratedPdfs endpoints restricted to admins/sysadmins.
**Internal API key:** Python Lambdas call the .NET API via a Lambda Function URL with AWS_IAM auth (bypasses API Gateway JWT check). The `InternalApiKeyMiddleware` validates the `X-Internal-Api-Key` header and assigns the `admins` role to the synthetic identity. Lambdas cache the API key from Secrets Manager with a 5-minute TTL.
## Data Flow
1. Dispatcher submits proposal request (web or mobile)
2. API creates proposal record (with advisory-locked number generation), publishes SQS message
3. If vendor PDF attached: `pdf-extract` Lambda parses and structures data
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
4. Suggestions Lambda queries Bedrock KB for similar proposals, generates line items via Claude
5. Admin reviews/edits line items in pricing workspace
6. On approval: `pdf-generate` Lambda creates branded PDF
Add iOS CD pipeline and refactor workflows to org reusable callers (#24) * Add iOS native project for React Native mobile app Xcode project with bundle ID com.seahavenind.proposals, CocoaPods configuration, and app scaffolding. * Add Fastlane configuration for iOS builds and TestFlight distribution Configures match with S3 storage (seahaven-ios-certificates bucket) for code signing and a beta lane for automated TestFlight uploads. * Add mobile CI job and iOS CD workflow (disabled) CI: adds mobile typecheck job on PRs. CD: deploy-mobile.yaml builds and uploads to TestFlight via Fastlane on a macOS runner with OIDC auth for match S3 access. Currently workflow_dispatch only — activate for V1 release. * Refactor workflows to thin wrappers calling org reusable workflows CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam from the org repo. Deploy calls cd-cdk with post-deploy script for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios. Adds deploy concurrency groups to both deploy workflows. * Add mobile Dependabot entries and remove assignees Add npm and bundler ecosystems for mobile/. Remove assignees from all entries — convention no longer in use. * Add comprehensive README for the proposal-system monorepo * Fix mobile TypeScript errors and add package-lock.json Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef type error, fix navigation type cast, add @types/react-native-vector-icons, and generate package-lock.json for CI. * Add .npmrc for mobile to resolve peer dependency conflicts react-native-screens@4.x requires react-native >= 0.82 but the project uses 0.79. legacy-peer-deps allows installation until the next React Native upgrade.
2026-05-18 15:30:30 -04:00
7. On send: `library-ingest` Lambda adds approved proposal to KB for future matching
Failed SQS messages are reported via `batchItemFailures` and retried up to 3 times before moving to the DLQ.
## Testing
186 tests across three stacks, all run in CI on every PR:
| Suite | Framework | Count | Coverage |
|---|---|---|---|
| .NET API | xUnit | 123 | State machine transitions, authorization attributes, middleware, validators, ProposalNumberGenerator, LineItemService state guards |
| Web | vitest | 26 | ProtectedRoute, RoleGuard, API client interceptor (401 logout, token attachment) |
| Python Lambdas | pytest | 37 | pdf-generate, suggestions, library-ingest handler contracts, internal API signing |
```bash
cd api && dotnet test # .NET tests
cd web && npm test # vitest
cd lambdas && python -m pytest # pytest
```
## Security
Hardening applied across all layers (see AUDIT-REPORT.md for full details):
- **Auth:** Cognito JWT validation with audience check, startup fails if auth not configured, DevMode gated to `IsDevelopment()`
- **API:** FluentValidation on all DTOs, generic error responses (no stack traces or config leaks), structured audit logging with before/after diffs
- **Function URL:** AWS_IAM auth + internal API key (two-layer defense)
- **Infrastructure:** S3 `enforceSSL` + `BLOCK_ALL`, SQS managed encryption, Aurora in private subnets, Cognito optional TOTP MFA, API Gateway access logging
- **Lambdas:** Prompt injection sanitization, PDF size limits, numeric validation on AI suggestions, S3 key sanitization, idempotent SQS processing
- **CI/CD:** OIDC (no long-lived credentials), org reusable workflows (`@main`), `--require-approval broadening` on local deploys
- **Web:** sessionStorage for tokens (not localStorage), error boundaries, role guards on all admin routes, 401 interceptor clears auth state