Replace NODEJS_22_X with NODEJS_24_X across all nine Lambda NodejsFunction
definitions in lib/constructs/ (bedrock-agent, slack-handler, notion-sync,
po-sync, workorder-sync). Also add dependabot ignore for @types/node >=26
to prevent premature major bumps while we stay on the nodejs24.x runtime.
Both package.json files already carry @types/node ^24 — no pin change needed.
Refs #72
wo-po-lookup, po-sync, and workorder-sync read WorkOrders,
WorkOrderComments, purchase-orders and PaymentsDashboard, which are now
SSE-encrypted with alias/seahaven-dynamodb. Tables are imported by name
so grantReadData adds no KMS perms; grant kms:Decrypt explicitly via the
CMK imported from SSM /seahaven/dynamodb/cmk-arn. Replaces the interim
CLI inline policy (Sid Infra95DynamoDbCmkDecrypt) with IaC.
INFRA-95
The Bedrock Agents service fetches the guardrail config via GetGuardrail
before applying it. The role only had ApplyGuardrail, so every agent
invocation logged an AccessDenied and tripped the CIS 4.1
UnauthorizedAPICalls alarm.
Scoped to the same guardrail ARNs already granted for ApplyGuardrail.
Cross-reviewed (IAM change): APPROVE, no findings.
Audit finding M-19: the employee-facing assistant had no guardrail
despite access to QBO, payments, WO/PO, and HR/SA8000 data.
Adds prompt-attack (HIGH input), content filters, and masking of
credential/financial identifiers (SSN, cards, bank numbers, keys).
Names/emails/phones deliberately unmasked - vendor contact lookup is
the bot's core function. MISCONDUCT output at MEDIUM so SA8000
misconduct-reporting questions are not suppressed.
Cross-reviewed (1 BLOCK fixed: ApplyGuardrail now covers version-
suffixed ARNs; explicit guardrail->version->agent dependencies added).
Alias description bump forces a new agent version (v10) so the live
alias snapshots the guardrail config.
Puts qbo-lookup and qbo-oauth Lambdas in seahaven-vpc private subnets
so all outbound traffic routes through NAT Gateway (52.202.83.13).
Required for Intuit app listing IP allowlist.
Adds /qbo/connect, /qbo/callback, /qbo/disconnect, and /qbo/launch
routes to bot.seahaven.com for Intuit app store compliance. Also
updates qbo-lookup to persist rotated refresh tokens automatically.
- Create SiteAssignments DynamoDB table with state GSI for site code and
state-based queries
- Add lookup_site function to wo-po-lookup action group lambda
- Add seed script (scripts/seed-sites.ts) to load site CSV into DynamoDB
- Upload site list markdown to KB S3 bucket for semantic search
- Update agent instruction to include site lookup capability
- Update README with site assignment docs and maintenance notes
The bot was suggesting Sea Haven as a vendor to contact because it didn't
understand it belongs to Sea Haven. Updated system prompt to make clear
that Sea Haven is our company and "local vendor" means a subcontractor.
Vector search couldn't match exact work order/PO numbers, so queries
always came back empty. This adds a dedicated lambda that queries
DynamoDB directly by ID, wired as a Bedrock Agent action group.
- Post '_Sea Haven Assistant is thinking..._' immediately on receipt,
then update the message with the real response (chat.update)
- Broaden Maps location parameter description so agent passes facility
names like 'Amazon BFI9' directly to Google Maps rather than asking
the user to provide a street address
- Update foundation model to us.anthropic.claude-sonnet-4-5-20250929-v1:0
(cross-region inference profile required for Claude 4.x on Bedrock Agents)
- Broaden agent role IAM policy to cover wildcard-region foundation model ARN
and inference profile ARN
- Force alias version bump via description change so CloudFormation creates
agent version 2 with the updated model
- Remove invalid includedType: 'contractor' from Google Maps Places API request
(caused 400 Bad Request — not a valid place type for searchText endpoint)
- CDK stack for Sea Haven Industries internal Slack assistant
- Bedrock Agent (Claude 3.5 Sonnet) with QBO + Google Maps action groups
- VectorKnowledgeBase via @cdklabs/generative-ai-cdk-constructs (AOSS + S3)
- Slack webhook/processor Lambdas with DM-only filtering
- API Gateway HTTP API on bot.seahaven.com
- DynamoDB conversation log with 90-day TTL
- Secrets Manager references for Slack, QBO OAuth, and Google Maps