Sea Haven AP — internal AP automation (ap.seahaven.com)
Find a file
2026-09-26 17:04:06 -04:00
.github Merge remote-tracking branch 'origin/main' into feature/seahaven-dev-spa-api-cd 2026-09-26 17:04:06 -04:00
e2e feat(web): add minimal Filter slide-over for invoice processing (AP-46) (#19) 2026-09-25 22:35:10 +00:00
packages feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
placeholder style(cd): format placeholder HTML for Prettier 2026-09-22 14:05:54 -04:00
public/fixtures feat(frontend): add invoice detail 3-pane shell (AP-6) (#9) 2026-08-10 22:22:22 +00:00
scripts fix(cd): name the missing deploy prerequisites 2026-09-26 16:49:44 -04:00
src feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
terraform fix(cd): block the Google IdP until real credentials are set 2026-09-26 16:39:28 -04:00
.dockerignore feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
.env.example feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
.gitignore feat(shared): add payment ladder and CSV domain package (AP-13) (#11) 2026-08-10 19:28:02 -04:00
.npmrc feat(api): stand up Hono Drizzle foundation with auth and Redocly (AP-14) (#12) 2026-08-11 00:10:49 +00:00
.prettierignore feat(api): stand up Hono Drizzle foundation with auth and Redocly (AP-14) (#12) 2026-08-11 00:10:49 +00:00
.prettierrc feat(frontend): scaffold vite spa and ci (AP-4) 2026-08-10 16:42:19 -04:00
.redocly.lint-ignore.yaml feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
docker-compose.yml chore(deps): update postgres docker tag to v18 (#51) 2026-08-25 18:19:19 +00:00
Dockerfile feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
eslint.config.js feat(api): stand up Hono Drizzle foundation with auth and Redocly (AP-14) (#12) 2026-08-11 00:10:49 +00:00
index.html feat(frontend): scaffold vite spa and ci (AP-4) 2026-08-10 16:42:19 -04:00
package-lock.json feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
package.json ci(workflows): call org frontend CI on the merge queue (#67) 2026-09-26 21:00:55 +00:00
playwright.config.ts feat(web): fix shell chrome, logo home, and live nav badges (#14) 2026-08-14 12:28:35 -04:00
README.md fix(cd): name the missing deploy prerequisites 2026-09-26 16:49:44 -04:00
redocly.yaml feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64) 2026-09-25 22:43:44 +00:00
tsconfig.json feat(frontend): scaffold vite spa and ci (AP-4) 2026-08-10 16:42:19 -04:00
tsconfig.node.json feat(frontend): scaffold vite spa and ci (AP-4) 2026-08-10 16:42:19 -04:00
vite.config.ts feat(api): stand up Hono Drizzle foundation with auth and Redocly (AP-14) (#12) 2026-08-11 00:10:49 +00:00
vitest.config.ts feat(frontend): scaffold vite spa and ci (AP-4) 2026-08-10 16:42:19 -04:00

Sea Haven AP

Internal accounts payable automation for Sea Haven Industries. Local API is http://127.0.0.1:8787. Hosted origin on seahaven-dev is the CloudFront default domain after HCP apply; GitHub Environment dev deploys the placeholder and API image.

Workspace layout

npm workspaces:

  • @seahaven-ap/web — Vite/React SPA (repo root)
  • @seahaven-ap/shared — payment ladder, invoice helpers, pay-date parsers, CSV constants (packages/shared)
  • @seahaven-ap/api — Hono API, Drizzle schema, auth/RBAC (packages/api)

Local development

Frontend (mocks)

npm ci
cp .env.example .env   # optional; defaults already use mocks
npm run dev

App serves at http://localhost:3000. VITE_USE_MOCKS=true is the default data path until AP-15 wires live API calls.

API + data plane (AP-14)

docker compose up -d
cp .env.example .env
npm run db:migrate
npm run db:seed
npm run dev:api

API listens on http://127.0.0.1:8787. Vite proxies /api to that port.

Smoke:

curl -s http://127.0.0.1:8787/api/health
curl -s http://127.0.0.1:8787/api/me

DEV_AUTH_BYPASS=true is local-only and only allowed when NODE_ENV is development or test (rejected for production, staging, preview, and any other value). Cookie session names are ap_* locally and __Host-ap_* outside local.

API roles (source of truth): admin, ap_processor, approver, viewer. Frontend mocks still use ap_operator until AP-15 remaps them.

OpenAPI / Redocly

Linting uses the same redocly.yaml ruleset as procurement-ingest.

npm run lint:api
npm run docs:preview   # builds HTML via redocly build-docs and opens it

Hosted seahaven-dev

HCP Terraform workspace seahaven-ap-dev (project seahaven-dev) uses working directory terraform and a terraform/** VCS trigger on main. GitHub Environment dev holds DEPLOY_ROLE_ARN for githubdeploy-seahaven-ap.

The first apply creates secret seahaven-ap/google-oidc with client_id and client_secret set to replace-me. Replace both values in Secrets Manager, then re-run the HCP apply. A terraform/** change on main starts that apply. The Google IdP is not registered while the placeholder is still current.

The merge that adds these workflows can start Deploy Web and Deploy API before that apply has written /seahaven-ap/deploy/* and before GitHub Environment dev has DEPLOY_ROLE_ARN. Those runs fail on purpose until both exist. Re-run them after the apply.

  • .github/workflows/deploy-web.yaml syncs placeholder/ to the web bucket. It does not run vite build.
  • .github/workflows/deploy-api.yaml builds the API image with GIT_SHA, registers the task definition from /seahaven-ap/deploy/task-environment, migrates, and checks GET /api/health.

Terraform environment is dev only. Prod hostname and GitHub Environment prod are AP-12.

Verify

npm run verify
npm run test:e2e
python3 scripts/test-terraform-dev-only.py
bash scripts/test-verify-api-health.sh