Adds an access log group (/aws/apigateway/seahaven-slack-webhook, 90-day
retention) with JSON access-log format and DefaultRouteSettings throttling
(rate 2 rps, burst 5) on the seahaven-slack-webhook HTTP API default stage,
applied via CfnStage property overrides. Matches the pattern landed on
seahaven-door-unlock-api.
Refs INFRA-29 (AWS audit M-18)
Removes CloudFormation dynamic references for clientId/clientSecret
env vars. Credentials are now fetched from Secrets Manager at runtime
so secret updates don't require a redeploy.
Puts qbo-lookup and qbo-oauth Lambdas in seahaven-vpc private subnets
so all outbound traffic routes through NAT Gateway (52.202.83.13).
Required for Intuit app listing IP allowlist.
Adds /qbo/connect, /qbo/callback, /qbo/disconnect, and /qbo/launch
routes to bot.seahaven.com for Intuit app store compliance. Also
updates qbo-lookup to persist rotated refresh tokens automatically.
- CDK stack for Sea Haven Industries internal Slack assistant
- Bedrock Agent (Claude 3.5 Sonnet) with QBO + Google Maps action groups
- VectorKnowledgeBase via @cdklabs/generative-ai-cdk-constructs (AOSS + S3)
- Slack webhook/processor Lambdas with DM-only filtering
- API Gateway HTTP API on bot.seahaven.com
- DynamoDB conversation log with 90-day TTL
- Secrets Manager references for Slack, QBO OAuth, and Google Maps