wo-po-lookup, po-sync, and workorder-sync read WorkOrders,
WorkOrderComments, purchase-orders and PaymentsDashboard, which are now
SSE-encrypted with alias/seahaven-dynamodb. Tables are imported by name
so grantReadData adds no KMS perms; grant kms:Decrypt explicitly via the
CMK imported from SSM /seahaven/dynamodb/cmk-arn. Replaces the interim
CLI inline policy (Sid Infra95DynamoDbCmkDecrypt) with IaC.
INFRA-95
- Bump Lambda timeout from 5min to 15min (9k+ POs need more time)
- Upload S3 files 25x concurrently instead of sequentially
- Replace clear-then-write with overwrite-in-place + delete stale
to avoid S3 404s during concurrent KB ingestion jobs
Add a new Lambda and CDK construct that scans the purchase-orders
DynamoDB table (owned by po-ingest), converts each PO to markdown,
uploads to S3 under the purchase-orders/ prefix, and triggers a
Bedrock Knowledge Base ingestion job. Runs daily at 02:00 UTC via
EventBridge alongside the existing Notion sync.