Commit graph

14 commits

Author SHA1 Message Date
Adam Moussa
9063d0f438
docs(readme): record HCP VCS trigger patterns (PLAT-183) (#90) 2026-09-10 21:00:45 +00:00
Adam Moussa
c23f990c6f
feat(phones): add T57W door-unlock-with-sp template (#87)
* feat(phones): add T57W door-unlock-with-sp template

* feat: add firmware dir and add latest 3cx supported yealink firmware
2026-09-03 22:56:04 +00:00
Adam Moussa
61f13bddfe
fix(terraform): defer api domain until dns cutover (#83)
API Gateway custom domain names are unique per region across accounts, so prod cannot create doorunlock.seahaven.com while mgmt still holds it.
2026-08-27 23:06:52 +00:00
Adam Moussa
c43bee214c
feat(terraform): add hcp terraform for prod door-unlock-api (PLAT-76) (#81)
* feat(terraform): add hcp terraform for prod door-unlock-api

Move deploy off frozen CDK CD onto an HCP workspace that recreates the HTTP API, five Lambdas, disabled EventBridge rules, and alarms in seahaven-prod without a poller VPC.

* docs(readme): link the door unlock api ops page

* fix(terraform): invoke package build via bash

HCP launches the external data source with bash, so the inner build script should not depend on the git executable bit.
2026-08-27 22:03:12 +00:00
Adam Moussa
bbc113497a
feat(3cx): sync office department blfs via xapi (PLAT-116) (#80)
Some checks failed
Deploy / deploy (push) Has been cancelled
* feat(3cx): sync office department BLFs via XAPI

Keep unlock and lockdown keys in the templates and write colleague plus shared-parking BLFs per extension so phones skip their own line.

* fix(3cx): preserve parking BLF IDs and fail the job on PATCH errors
2026-08-27 14:58:55 -04:00
Adam Moussa
07247d4044
Document the CDK app in the README (#55)
Some checks failed
Deploy / deploy (push) Has been cancelled
The README covered the runtime architecture but never described the
CDK app itself — the infrastructure-as-code component that cdk.json
represents. Add an "Infrastructure (CDK)" section documenting the
project layout, the app entry point, the DoorUnlockStack resources,
cdk.json (the tsx-based app command and context), and synth/diff/deploy
commands. Also list the per-Lambda CloudWatch error alarms the stack
defines under Architecture.
2026-07-10 16:07:24 -04:00
Adam Moussa
3283e62ff2
docs: link Confluence AWS Architecture Map (INFRA-53) (#48)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 17:44:18 -04:00
Adam Moussa
1edf1c8b93 Repo hygiene: PR labeler + README badges (INFRA-56/57) (#35) 2026-06-11 14:13:45 -04:00
Adam Moussa
4265ad90fe Gateway token authorizer + finish CI/CD migration (INFRA-99, INFRA-2) (#32)
* feat: add gateway token authorizer to door-unlock API (INFRA-99)

All three routes (GET /unlock, /lockdown, /lockdown/status) were
AuthorizationType NONE — auth relied solely on each handler checking
the ?token= query param. Add a REQUEST-type HTTP API Lambda authorizer
(door-unlock-api-authorizer) that validates the SAME ?token= value the
Yealink XML Browser keys already send, against the existing
/seahaven/door-unlock/auth-token SSM SecureString, and attach it to all
three routes.

Transparent to the phones: identity source is $request.querystring.token
(exactly what the type-17 XML Browser keys send via GET), simple response
{isAuthorized}, fail-closed, 5-min results cache. Token is cached in
module scope so warm invocations skip SSM.

GET is kept (not switched to POST): the Yealink type-17 XML Browser keys
are GET-only and render the returned Yealink XML — they cannot issue a
POST body or custom headers. POST is therefore deferred to avoid bricking
the door keys.

Handlers retain their own token check as defense-in-depth. Purely
additive change set; no existing Lambda or integration is modified.

* chore: complete CI/CD migration to GitHub Actions (INFRA-2)

GitHub Actions (ci.yaml + deploy.yaml via the Sea Haven reusable
workflows) is the proven deploy path. Remove the now-orphaned
buildspec.yml and update the README CI/CD and architecture sections.

The legacy CodePipeline was already deleted (2026-06-05); the leftover
CodeBuild project seahaven-door-unlock-api-build and its IAM role
seahaven-door-unlock-api-codebuild have now also been decommissioned.
2026-06-08 18:03:30 -04:00
Adam Moussa
ccbc98962b Add lockdown mode and CI/CD pipeline (#3)
* Add lockdown profile toggle endpoints with T58W linekey support

Add a new Lambda handler that toggles Elements lockdown profiles
(Bohemia and Ronkonkoma) via the Elements API, with status
verification before and after each toggle. Returns Yealink XML
to control linekey LEDs (green=inactive, red=locked down).

Also brings both Lambda handlers into compliance with system
standards: Node 22.x runtime, arm64 architecture, 60-day log
retention, and kebab-case function names.

* Add lockdown poller Lambda and fix lockdown handler responses

- Add VPC-connected poller Lambda that monitors lockdown status via
  Elements API every 15 seconds (4 polls per 1-min EventBridge schedule)
- Handle Elements API rate limits (429) with retry-after support
- Fix lockdown handler to use TextScreen XML instead of Execute XML
  (Execute shows globe icon on T58W, TextScreen renders properly)
- Fix Elements API status parsing to be case-insensitive
- Trust toggle action instead of re-checking status (eventual consistency)
- Configure push_xml.server = any in T58W template for Push XML support
- Clear action_url.setup_completed (poller replaces boot-time check)
- Update README with lockdown architecture and known LED limitation

Note: T58W line key LED color does not change to reflect lockdown
status. Execute LED commands are transient on the T58W - the phone's
XML Browser key type immediately overrides them.

* Add buildspec for CodePipeline CI/CD

* Update README with CI/CD pipeline details
2026-05-01 18:52:37 -04:00
Adam Moussa
6f029963e9 Add Yealink T58W door unlock 3CX template
Based on the official 3CX T5x template, stripped to T58W-only with the
door unlock URL hardcoded on line key 2 (type 17/URL). Keys 3+ remain
managed by 3CX BLF as usual.
2026-04-27 13:08:57 -04:00
Adam Moussa
7c626c960e Apply display settings to SP template — both templates now match
Backlight dims to level 1 after 5 min, screensaver and power saving disabled.
2026-04-23 11:00:00 -04:00
Adam Moussa
8eb93536ad Add display settings to door-unlock template and update README
- Backlight dims to level 1 after 5 min, never fully sleeps
- Screensaver and power saving disabled
- README updated with T54W references and SP template manual steps
2026-04-22 20:01:09 -04:00
Adam Moussa
d90f191032 Add README with architecture overview, SSM parameters, and phone setup instructions 2026-04-22 14:37:38 -04:00