proposal-system/infra
Adam Moussa a74ac4945f fix: LAM-C1/INF-H1 require IAM auth on Function URL, INF-H3 restrict OpenSearch to VPC
LAM-C1/INF-H1: Change Function URL authType from NONE to AWS_IAM and
grant invokeUrl permission to all four caller Lambdas (suggestions,
pdf-extract, pdf-generate, library-ingest). Lambda HTTP clients will
need SigV4 signing as a follow-up.

INF-H3: Create OpenSearch Serverless VPC endpoint in private subnets
and update network policy from AllowFromPublic to SourceVPCEs, removing
public internet access to the vector search collection.
2026-05-27 18:18:44 -04:00
..
bin Merge main into feature/fix-phase-2, resolve infra conflicts 2026-05-20 19:09:35 -04:00
lib fix: LAM-C1/INF-H1 require IAM auth on Function URL, INF-H3 restrict OpenSearch to VPC 2026-05-27 18:18:44 -04:00
cdk.context.json Initial scaffold: monorepo structure, CDK stacks, CI/CD, domain model 2026-05-16 18:40:46 -04:00
cdk.json Initial scaffold: monorepo structure, CDK stacks, CI/CD, domain model 2026-05-16 18:40:46 -04:00
package-lock.json Bump aws-cdk-lib from 2.253.1 to 2.257.0 in /infra (#58) 2026-05-23 04:34:11 +00:00
package.json Bump aws-cdk-lib from 2.253.1 to 2.257.0 in /infra (#58) 2026-05-23 04:34:11 +00:00
tsconfig.json Initial scaffold: monorepo structure, CDK stacks, CI/CD, domain model 2026-05-16 18:40:46 -04:00