import * as cdk from 'aws-cdk-lib'; import { FoundationStack } from '../lib/foundation-stack'; import { ComputeStack } from '../lib/compute-stack'; import { FrontendStack } from '../lib/frontend-stack'; import { resolveConfig } from '../lib/config'; const app = new cdk.App(); // Multi-env (PR2): `-c env=staging` (default prod). prod targets seahaven-prod // (011934824531) with no stack-name suffix; staging is suffixed and currently hard-disabled // (see resolveConfig — mgmt account is frozen). const config = resolveConfig(app); const { env, stackSuffix } = config; // Pipeline-only deploy signal (WARN, not block). Prod deploys must go through the cd-cdk // pipeline (GitHub Actions sets CI/GITHUB_ACTIONS). A local synth/deploy to prod is a // drift risk + "no manual prod deploys" violation. True enforcement is an org-baseline SCP // (tracked follow-up); this is the cheap in-repo backstop. if (config.envName === 'prod' && !process.env.CI && !process.env.GITHUB_ACTIONS) { // eslint-disable-next-line no-console console.warn( '\n⚠️ Running the PROD CDK app outside CI. Prod deploys must go through the cd-cdk ' + 'pipeline (deploy.yaml, workflow_dispatch). Do NOT `cdk deploy` to prod locally.\n', ); } const foundation = new FoundationStack(app, `proposal-system-foundation${stackSuffix}`, { stackName: `proposal-system-foundation${stackSuffix}`, env, config, description: 'Proposal System - VPC, RDS, S3, SQS, Cognito', }); const compute = new ComputeStack(app, `proposal-system-compute${stackSuffix}`, { stackName: `proposal-system-compute${stackSuffix}`, env, config, description: 'Proposal System - API Lambda, Python Lambdas, Bedrock KB', vpc: foundation.vpc, lambdaSecurityGroup: foundation.lambdaSecurityGroup, dbSecret: foundation.dbSecret, dbCluster: foundation.dbCluster, uploadsBucket: foundation.uploadsBucket, generatedBucket: foundation.generatedBucket, libraryBucket: foundation.libraryBucket, jobsQueue: foundation.jobsQueue, userPool: foundation.userPool, alarmTopic: foundation.alarmTopic, webClientId: foundation.webClientId, mobileClientId: foundation.mobileClientId, }); new FrontendStack(app, `proposal-system-frontend${stackSuffix}`, { stackName: `proposal-system-frontend${stackSuffix}`, env, config, description: 'Proposal System - CloudFront + S3 web hosting', }); void compute;