Commit graph

16 commits

Author SHA1 Message Date
amoussa1229
3704fa0292 chore: upgrade Lambda runtime from nodejs22.x to nodejs24.x
Replace NODEJS_22_X with NODEJS_24_X across all nine Lambda NodejsFunction
definitions in lib/constructs/ (bedrock-agent, slack-handler, notion-sync,
po-sync, workorder-sync). Also add dependabot ignore for @types/node >=26
to prevent premature major bumps while we stay on the nodejs24.x runtime.

Both package.json files already carry @types/node ^24 — no pin change needed.

Refs #72
2026-07-04 05:26:03 +00:00
Adam Moussa
46f568f6ea
feat(slack-bot): codify kms:Decrypt grants for CMK'd DynamoDB readers (INFRA-95 / M-3) (#51)
wo-po-lookup, po-sync, and workorder-sync read WorkOrders,
WorkOrderComments, purchase-orders and PaymentsDashboard, which are now
SSE-encrypted with alias/seahaven-dynamodb. Tables are imported by name
so grantReadData adds no KMS perms; grant kms:Decrypt explicitly via the
CMK imported from SSM /seahaven/dynamodb/cmk-arn. Replaces the interim
CLI inline policy (Sid Infra95DynamoDbCmkDecrypt) with IaC.

INFRA-95
2026-06-09 12:33:06 -04:00
Adam Moussa
307a5ed661
fix: grant bedrock:GetGuardrail to agent execution role (#39)
The Bedrock Agents service fetches the guardrail config via GetGuardrail
before applying it. The role only had ApplyGuardrail, so every agent
invocation logged an AccessDenied and tripped the CIS 4.1
UnauthorizedAPICalls alarm.

Scoped to the same guardrail ARNs already granted for ApplyGuardrail.
Cross-reviewed (IAM change): APPROVE, no findings.
2026-06-04 16:50:19 -04:00
Adam Moussa
a3457be911
Add guardrail to seahaven-alex agent (#38)
Audit finding M-19: the employee-facing assistant had no guardrail
despite access to QBO, payments, WO/PO, and HR/SA8000 data.

Adds prompt-attack (HIGH input), content filters, and masking of
credential/financial identifiers (SSN, cards, bank numbers, keys).
Names/emails/phones deliberately unmasked - vendor contact lookup is
the bot's core function. MISCONDUCT output at MEDIUM so SA8000
misconduct-reporting questions are not suppressed.

Cross-reviewed (1 BLOCK fixed: ApplyGuardrail now covers version-
suffixed ARNs; explicit guardrail->version->agent dependencies added).
Alias description bump forces a new agent version (v10) so the live
alias snapshots the guardrail config.
2026-06-03 15:16:06 -04:00
Adam Moussa
006dbf7c6b feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions
- Rename bot to Alex with friendly/professional persona (Bedrock Agent instruction rewrite)
- Replace HTTP webhook Lambda with ECS Fargate Socket Mode service (persistent WebSocket)
- Add payment/invoice lookup via PaymentsDashboard table (vendor, invoice, check search)
- Switch from manual SiteAssignments to auto-populated verified-sites table
- Add channel support via app_mention events (threaded replies)
- Add App Home tab with Block Kit capabilities view
- Add unanswered questions logging to seahaven-unanswered-questions DynamoDB table
- Fix pre-existing compliance: add arm64 + 60-day log retention to all Lambdas
- Remove webhook Lambda and seed-sites script (both obsolete)
2026-04-30 16:38:54 -04:00
Adam Moussa
066ff59d22 Place QBO Lambdas in VPC for static outbound IP
Puts qbo-lookup and qbo-oauth Lambdas in seahaven-vpc private subnets
so all outbound traffic routes through NAT Gateway (52.202.83.13).
Required for Intuit app listing IP allowlist.
2026-04-13 19:51:00 -04:00
Adam Moussa
acfe8185a9 Add QBO OAuth endpoints for QuickBooks app listing
Adds /qbo/connect, /qbo/callback, /qbo/disconnect, and /qbo/launch
routes to bot.seahaven.com for Intuit app store compliance. Also
updates qbo-lookup to persist rotated refresh tokens automatically.
2026-04-13 19:31:13 -04:00
Adam Moussa
fb026dfd72 Add Amazon site assignments lookup via DynamoDB
- Create SiteAssignments DynamoDB table with state GSI for site code and
  state-based queries
- Add lookup_site function to wo-po-lookup action group lambda
- Add seed script (scripts/seed-sites.ts) to load site CSV into DynamoDB
- Upload site list markdown to KB S3 bucket for semantic search
- Update agent instruction to include site lookup capability
- Update README with site assignment docs and maintenance notes
2026-04-13 19:11:39 -04:00
Adam Moussa
8cb762d055 Fix agent identity: clarify that we ARE Sea Haven, not an external vendor
The bot was suggesting Sea Haven as a vendor to contact because it didn't
understand it belongs to Sea Haven. Updated system prompt to make clear
that Sea Haven is our company and "local vendor" means a subcontractor.
2026-04-13 18:50:35 -04:00
Adam Moussa
8b6e65bd20 Improve Slack formatting for WO/PO lookups
- Add markdown-to-Slack mrkdwn conversion in processor (** → *, ## → bold)
- Restructure lambda output with cleaner sections and date formatting
- Update agent instruction to present data concisely
2026-04-13 18:34:47 -04:00
Adam Moussa
24ebe8bdcc Add WO/PO direct lookup action group for reliable ID-based queries
Vector search couldn't match exact work order/PO numbers, so queries
always came back empty. This adds a dedicated lambda that queries
DynamoDB directly by ID, wired as a Bedrock Agent action group.
2026-04-13 17:59:47 -04:00
Adam Moussa
5943b775eb Update agent alias description to force version bump on deploy 2026-04-13 17:15:11 -04:00
Adam Moussa
510834533b Add work order and purchase order lookups to Bedrock agent instructions
The agent's system prompt and KB description didn't mention WO/PO data,
so it refused queries even though the data was already in the knowledge base.
2026-04-13 17:05:26 -04:00
Adam Moussa
505b624242 Add thinking placeholder and improve location parameter handling
- Post '_Sea Haven Assistant is thinking..._' immediately on receipt,
  then update the message with the real response (chat.update)
- Broaden Maps location parameter description so agent passes facility
  names like 'Amazon BFI9' directly to Google Maps rather than asking
  the user to provide a street address
2026-04-12 00:01:33 -04:00
Adam Moussa
635e712966 Switch to Claude Sonnet 4.5 cross-region inference profile
- Update foundation model to us.anthropic.claude-sonnet-4-5-20250929-v1:0
  (cross-region inference profile required for Claude 4.x on Bedrock Agents)
- Broaden agent role IAM policy to cover wildcard-region foundation model ARN
  and inference profile ARN
- Force alias version bump via description change so CloudFormation creates
  agent version 2 with the updated model
- Remove invalid includedType: 'contractor' from Google Maps Places API request
  (caused 400 Bad Request — not a valid place type for searchText endpoint)
2026-04-11 23:52:44 -04:00
Adam Moussa
f7e63e50c9 Initial scaffold: Bedrock-backed Slack DM bot
- CDK stack for Sea Haven Industries internal Slack assistant
- Bedrock Agent (Claude 3.5 Sonnet) with QBO + Google Maps action groups
- VectorKnowledgeBase via @cdklabs/generative-ai-cdk-constructs (AOSS + S3)
- Slack webhook/processor Lambdas with DM-only filtering
- API Gateway HTTP API on bot.seahaven.com
- DynamoDB conversation log with 90-day TTL
- Secrets Manager references for Slack, QBO OAuth, and Google Maps
2026-04-11 23:15:15 -04:00