proposal-system/infra/bin/app.ts
Adam Moussa aff38a11ae
Some checks failed
Deploy / Deploy to AWS (push) Has been cancelled
feat(infra): migrate Bedrock KB vector store to Aurora pgvector (#125)
Replaces OpenSearch Serverless with Aurora PostgreSQL Serverless v2 + pgvector as
the Bedrock Knowledge Base vector store (v1 PR3). Bedrock KB requires Aurora SSv2
(RDS Data API), not a plain RDS instance — so the DB engine moves to Aurora.

- foundation: rds.DatabaseInstance (PG15) -> rds.DatabaseCluster Aurora SSv2
  (0.5-4 ACU, enableDataApi). RDS alarms: free-storage -> freeable-memory.
- compute: delete all AOSS (collection, policies, VPC endpoint, index-creator);
  add bedrock_user secret + KB role (scoped rds-data + secret read); repoint
  CfnKnowledgeBase to RDS storage (bedrock_integration.bedrock_kb, vector(1024)).
- lambdas: oss-index-creator -> aurora-pgvector-init (bootstrap schema/table/
  indexes/role via RDS Data API; transient-error retry; password guard).
- ADR 0001 documents the decision.

Eliminates the ~$175-350/mo AOSS OCU floor. NAT kept (egress still needed).
GPT-4.1 cross-review: no BLOCK (FIX applied). tsc clean; foundation synth shows
Aurora cluster with Data API enabled; 23 pytest pass.
2026-06-12 18:44:42 -04:00

47 lines
1.6 KiB
TypeScript

import * as cdk from 'aws-cdk-lib';
import { FoundationStack } from '../lib/foundation-stack';
import { ComputeStack } from '../lib/compute-stack';
import { FrontendStack } from '../lib/frontend-stack';
import { resolveConfig } from '../lib/config';
const app = new cdk.App();
// Multi-env (PR2): `-c env=staging` (default prod). prod keeps the exact construct IDs
// and stack names of the deployed stacks (stackSuffix=''); only staging is suffixed.
const config = resolveConfig(app);
const { env, stackSuffix } = config;
const foundation = new FoundationStack(app, `proposal-system-foundation${stackSuffix}`, {
stackName: `proposal-system-foundation${stackSuffix}`,
env,
config,
description: 'Proposal System - VPC, RDS, S3, SQS, Cognito',
});
const compute = new ComputeStack(app, `proposal-system-compute${stackSuffix}`, {
stackName: `proposal-system-compute${stackSuffix}`,
env,
config,
description: 'Proposal System - API Lambda, Python Lambdas, Bedrock KB',
vpc: foundation.vpc,
lambdaSecurityGroup: foundation.lambdaSecurityGroup,
dbSecret: foundation.dbSecret,
dbCluster: foundation.dbCluster,
uploadsBucket: foundation.uploadsBucket,
generatedBucket: foundation.generatedBucket,
libraryBucket: foundation.libraryBucket,
jobsQueue: foundation.jobsQueue,
userPool: foundation.userPool,
alarmTopic: foundation.alarmTopic,
webClientId: foundation.webClientId,
mobileClientId: foundation.mobileClientId,
});
new FrontendStack(app, `proposal-system-frontend${stackSuffix}`, {
stackName: `proposal-system-frontend${stackSuffix}`,
env,
config,
description: 'Proposal System - CloudFront + S3 web hosting',
});
void compute;