Commit graph

89 commits

Author SHA1 Message Date
Adam Moussa
52d26e89c0
Merge pull request #16 from Sea-Haven-Industries/feature/dependabot-auto-assign
Auto-assign Dependabot PRs
2026-05-02 17:28:09 -04:00
Adam Moussa
9bdfceca28 Auto-assign Dependabot PRs to amoussa1229 2026-05-02 17:26:17 -04:00
Adam Moussa
1f243e2ab1
Merge pull request #14 from Sea-Haven-Industries/dependabot/npm_and_yarn/aws-sdk/lib-dynamodb-3.1041.0
build(deps-dev): bump @aws-sdk/lib-dynamodb from 3.1030.0 to 3.1041.0
2026-05-02 17:23:36 -04:00
dependabot[bot]
9115495f3a
build(deps-dev): bump @aws-sdk/lib-dynamodb from 3.1030.0 to 3.1041.0
Bumps [@aws-sdk/lib-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb) from 3.1030.0 to 3.1041.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1041.0/lib/lib-dynamodb)

---
updated-dependencies:
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1041.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-02 21:17:42 +00:00
Adam Moussa
d4c1973004
Merge pull request #10 from Sea-Haven-Industries/feature/add-dependabot-config
Add Dependabot version update configuration
2026-05-02 17:15:44 -04:00
Adam Moussa
d43b7974b4 Add Dependabot version update configuration 2026-05-02 17:14:23 -04:00
Adam Moussa
423c68584f
Merge pull request #9 from Sea-Haven-Industries/feature/alex-rollout
feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions
2026-04-30 18:57:23 -04:00
Adam Moussa
e7b421e4cf fix: flat DM replies, clean up debug logging
DMs now reply flat in conversation instead of threading. Channel
@mentions still thread. Removed verbose debug logging from socket-mode
service, kept minimal operational logs. Added .DS_Store to gitignore.
2026-04-30 18:37:08 -04:00
Adam Moussa
5a9d588ebe fix: add package-lock.json for socket-mode Docker build 2026-04-30 16:44:55 -04:00
Adam Moussa
006dbf7c6b feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions
- Rename bot to Alex with friendly/professional persona (Bedrock Agent instruction rewrite)
- Replace HTTP webhook Lambda with ECS Fargate Socket Mode service (persistent WebSocket)
- Add payment/invoice lookup via PaymentsDashboard table (vendor, invoice, check search)
- Switch from manual SiteAssignments to auto-populated verified-sites table
- Add channel support via app_mention events (threaded replies)
- Add App Home tab with Block Kit capabilities view
- Add unanswered questions logging to seahaven-unanswered-questions DynamoDB table
- Fix pre-existing compliance: add arm64 + 60-day log retention to all Lambdas
- Remove webhook Lambda and seed-sites script (both obsolete)
2026-04-30 16:38:54 -04:00
Adam Moussa
3a3e2dc14f
Merge pull request #8 from Sea-Haven-Industries/dependabot/npm_and_yarn/multi-b112b4ff1d
build(deps): bump fast-xml-parser and @aws-sdk/xml-builder
2026-04-30 12:55:39 -04:00
dependabot[bot]
36e202d7fe
build(deps): bump fast-xml-parser and @aws-sdk/xml-builder
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) and [@aws-sdk/xml-builder](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages-internal/xml-builder). These dependencies needed to be updated together.

Updates `fast-xml-parser` from 5.5.8 to 5.7.2
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.8...v5.7.2)

Updates `@aws-sdk/xml-builder` from 3.972.17 to 3.972.21
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/xml-builder/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/xml-builder)

---
updated-dependencies:
- dependency-name: fast-xml-parser
  dependency-version: 5.7.2
  dependency-type: indirect
- dependency-name: "@aws-sdk/xml-builder"
  dependency-version: 3.972.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-28 18:26:26 +00:00
Adam Moussa
26598e8fff Update README with QBO OAuth flow, VPC, and static IP details 2026-04-13 20:26:06 -04:00
Adam Moussa
d1b91ae661 Read OAuth client credentials from Secrets Manager at runtime
Removes CloudFormation dynamic references for clientId/clientSecret
env vars. Credentials are now fetched from Secrets Manager at runtime
so secret updates don't require a redeploy.
2026-04-13 20:22:21 -04:00
Adam Moussa
9463a07e50 Use Intuit discovery document for OAuth endpoints
Fetch authorization, token, and revocation endpoints from Intuit's
.well-known/openid_configuration at runtime instead of hardcoding.
Cached per Lambda instance for performance.
2026-04-13 19:59:23 -04:00
Adam Moussa
066ff59d22 Place QBO Lambdas in VPC for static outbound IP
Puts qbo-lookup and qbo-oauth Lambdas in seahaven-vpc private subnets
so all outbound traffic routes through NAT Gateway (52.202.83.13).
Required for Intuit app listing IP allowlist.
2026-04-13 19:51:00 -04:00
Adam Moussa
266fe833fd Fix Intuit security compliance issues
- CSRF: store OAuth state in Secure/HttpOnly cookie, validate on callback
- Cache-Control: add no-cache, no-store headers to all responses
- Sensitive info: callback errors now 302 redirect instead of returning HTML
- Logging: remove realmId and sanitize error logs to prevent QBO data leaks
2026-04-13 19:49:29 -04:00
Adam Moussa
acfe8185a9 Add QBO OAuth endpoints for QuickBooks app listing
Adds /qbo/connect, /qbo/callback, /qbo/disconnect, and /qbo/launch
routes to bot.seahaven.com for Intuit app store compliance. Also
updates qbo-lookup to persist rotated refresh tokens automatically.
2026-04-13 19:31:13 -04:00
Adam Moussa
fb026dfd72 Add Amazon site assignments lookup via DynamoDB
- Create SiteAssignments DynamoDB table with state GSI for site code and
  state-based queries
- Add lookup_site function to wo-po-lookup action group lambda
- Add seed script (scripts/seed-sites.ts) to load site CSV into DynamoDB
- Upload site list markdown to KB S3 bucket for semantic search
- Update agent instruction to include site lookup capability
- Update README with site assignment docs and maintenance notes
2026-04-13 19:11:39 -04:00
Adam Moussa
8cb762d055 Fix agent identity: clarify that we ARE Sea Haven, not an external vendor
The bot was suggesting Sea Haven as a vendor to contact because it didn't
understand it belongs to Sea Haven. Updated system prompt to make clear
that Sea Haven is our company and "local vendor" means a subcontractor.
2026-04-13 18:50:35 -04:00
Adam Moussa
8b6e65bd20 Improve Slack formatting for WO/PO lookups
- Add markdown-to-Slack mrkdwn conversion in processor (** → *, ## → bold)
- Restructure lambda output with cleaner sections and date formatting
- Update agent instruction to present data concisely
2026-04-13 18:34:47 -04:00
Adam Moussa
24ebe8bdcc Add WO/PO direct lookup action group for reliable ID-based queries
Vector search couldn't match exact work order/PO numbers, so queries
always came back empty. This adds a dedicated lambda that queries
DynamoDB directly by ID, wired as a Bedrock Agent action group.
2026-04-13 17:59:47 -04:00
Adam Moussa
5943b775eb Update agent alias description to force version bump on deploy 2026-04-13 17:15:11 -04:00
Adam Moussa
510834533b Add work order and purchase order lookups to Bedrock agent instructions
The agent's system prompt and KB description didn't mention WO/PO data,
so it refused queries even though the data was already in the knowledge base.
2026-04-13 17:05:26 -04:00
Adam Moussa
8c71d8267c docs: update README for PO and work order KB syncs
ref #4 — documents the new po-sync and workorder-sync Lambdas,
EventBridge schedules, DynamoDB data sources, and manual trigger
instructions.
2026-04-13 15:42:27 -04:00
Adam Moussa
1dc275dee4
Merge pull request #7 from Sea-Haven-Industries/feature/workorder-kb-sync
feat: work orders → Bedrock KB sync
2026-04-13 15:38:20 -04:00
Adam Moussa
40216430c6 Merge master after PO sync PR merge 2026-04-13 15:38:13 -04:00
Adam Moussa
50d5c3cc81
Merge pull request #6 from Sea-Haven-Industries/feature/po-kb-sync
Tested: 9,279 POs synced, 0 failures, KB ingestion clean
2026-04-13 15:37:29 -04:00
Adam Moussa
641494530b fix: concurrent uploads and overwrite-in-place sync strategy
- Upload S3 files 10x concurrently instead of sequentially
- Replace clear-then-write with overwrite-in-place + delete stale
  to avoid S3 404s during concurrent KB ingestion jobs
2026-04-13 15:36:16 -04:00
Adam Moussa
adbe19aa16 fix: concurrent uploads, overwrite-in-place, 15min timeout
- Bump Lambda timeout from 5min to 15min (9k+ POs need more time)
- Upload S3 files 25x concurrently instead of sequentially
- Replace clear-then-write with overwrite-in-place + delete stale
  to avoid S3 404s during concurrent KB ingestion jobs
2026-04-13 15:36:07 -04:00
Adam Moussa
7240147736 feat: daily work orders DynamoDB → Bedrock KB sync
Add a new Lambda and CDK construct that scans the WorkOrders and
WorkOrderComments DynamoDB tables (owned by workorder-ingest),
converts each work order + comment history to markdown, uploads
to S3 under the work-orders/ prefix, and triggers a Bedrock
Knowledge Base ingestion job. Runs daily at 02:00 UTC via
EventBridge alongside the existing Notion sync.
2026-04-13 14:35:47 -04:00
Adam Moussa
615970eba2 feat: daily purchase-orders DynamoDB → Bedrock KB sync
Add a new Lambda and CDK construct that scans the purchase-orders
DynamoDB table (owned by po-ingest), converts each PO to markdown,
uploads to S3 under the purchase-orders/ prefix, and triggers a
Bedrock Knowledge Base ingestion job. Runs daily at 02:00 UTC via
EventBridge alongside the existing Notion sync.
2026-04-13 14:33:53 -04:00
2dba68c14d Merge feature/notion-kb-sync into master
Daily Notion → Bedrock KB sync: EventBridge cron triggers notion-sync
Lambda which exports Office Operations pages to S3 and kicks off KB
ingestion. Runs at 02:00 UTC. Refs #4
2026-04-13 00:01:44 -04:00
f254776ba6 docs: update README for Notion KB sync
Documents the notion-sync Lambda, daily EventBridge schedule, Notion
secret setup, and updated project structure.

Refs #4
2026-04-13 00:00:39 -04:00
8b18279023 feat: daily Notion → Bedrock KB sync
Adds a scheduled Lambda that pulls all pages from the Office Operations
Notion teamspace, converts them to markdown, uploads to the KB S3 bucket
under a notion/ prefix, and triggers a Bedrock ingestion job. Runs daily
at 02:00 UTC via EventBridge. Notion API key stored in Secrets Manager at
seahaven/notion/api-key (placeholder — fill in post-deploy).
2026-04-12 22:21:39 -04:00
Adam Moussa
505b624242 Add thinking placeholder and improve location parameter handling
- Post '_Sea Haven Assistant is thinking..._' immediately on receipt,
  then update the message with the real response (chat.update)
- Broaden Maps location parameter description so agent passes facility
  names like 'Amazon BFI9' directly to Google Maps rather than asking
  the user to provide a street address
2026-04-12 00:01:33 -04:00
Adam Moussa
635e712966 Switch to Claude Sonnet 4.5 cross-region inference profile
- Update foundation model to us.anthropic.claude-sonnet-4-5-20250929-v1:0
  (cross-region inference profile required for Claude 4.x on Bedrock Agents)
- Broaden agent role IAM policy to cover wildcard-region foundation model ARN
  and inference profile ARN
- Force alias version bump via description change so CloudFormation creates
  agent version 2 with the updated model
- Remove invalid includedType: 'contractor' from Google Maps Places API request
  (caused 400 Bad Request — not a valid place type for searchText endpoint)
2026-04-11 23:52:44 -04:00
Adam Moussa
f01c3f81ce Add README with architecture, deployment, and maintenance docs 2026-04-11 23:17:03 -04:00
Adam Moussa
f7e63e50c9 Initial scaffold: Bedrock-backed Slack DM bot
- CDK stack for Sea Haven Industries internal Slack assistant
- Bedrock Agent (Claude 3.5 Sonnet) with QBO + Google Maps action groups
- VectorKnowledgeBase via @cdklabs/generative-ai-cdk-constructs (AOSS + S3)
- Slack webhook/processor Lambdas with DM-only filtering
- API Gateway HTTP API on bot.seahaven.com
- DynamoDB conversation log with 90-day TTL
- Secrets Manager references for Slack, QBO OAuth, and Google Maps
2026-04-11 23:15:15 -04:00