Replace NODEJS_22_X with NODEJS_24_X across all nine Lambda NodejsFunction
definitions in lib/constructs/ (bedrock-agent, slack-handler, notion-sync,
po-sync, workorder-sync). Also add dependabot ignore for @types/node >=26
to prevent premature major bumps while we stay on the nodejs24.x runtime.
Both package.json files already carry @types/node ^24 — no pin change needed.
Refs #72
wo-po-lookup, po-sync, and workorder-sync read WorkOrders,
WorkOrderComments, purchase-orders and PaymentsDashboard, which are now
SSE-encrypted with alias/seahaven-dynamodb. Tables are imported by name
so grantReadData adds no KMS perms; grant kms:Decrypt explicitly via the
CMK imported from SSM /seahaven/dynamodb/cmk-arn. Replaces the interim
CLI inline policy (Sid Infra95DynamoDbCmkDecrypt) with IaC.
INFRA-95
Add a new Lambda and CDK construct that scans the WorkOrders and
WorkOrderComments DynamoDB tables (owned by workorder-ingest),
converts each work order + comment history to markdown, uploads
to S3 under the work-orders/ prefix, and triggers a Bedrock
Knowledge Base ingestion job. Runs daily at 02:00 UTC via
EventBridge alongside the existing Notion sync.