Commit graph

9 commits

Author SHA1 Message Date
ea173a0966 Enable Container Insights + RunningTaskCount alarm (NEEDS ADAM SIGN-OFF)
Enable Container Insights on the seahaven-socket-mode ECS cluster and add the
seahaven-socket-mode-running-tasks alarm (fires when running tasks < 1 against
desiredCount=1). RunningTaskCount is only published with Container Insights
enabled, which adds CloudWatch metric + log-ingestion cost.

This is isolated in its own commit so it can be dropped if the cost/config
change is declined — revert this commit (cluster containerInsightsV2 +
enableRunningTaskAlarm flag) and the rest of the alarm coverage is unaffected.
2026-06-17 13:57:48 -04:00
c28d5b1170 Add CloudWatch alarm coverage via MonitoringConstruct
Add a MonitoringConstruct (lib/constructs/monitoring.ts) wiring CloudWatch
alarms to the shared site-alerts SNS topic for the seahaven-slack-bot stack.
Every alarm uses an SNS alarm action only (no OK action) and treats missing
data as NOT_BREACHING; alarm names are repo-namespaced kebab-case.

Coverage:
- Lambda (9 fns): Errors, Throttles, Duration (p99, eval3/dp2, ~80% of timeout)
- DynamoDB (seahaven-conversations, seahaven-unanswered-questions):
  ThrottledRequests + SystemErrors via the per-operations metric-math helpers
  (the bare TableName-only helpers are deprecated/invalid); operations scoped
  to 6 CRUD ops to stay under the 10-metric alarm-math cap
- API Gateway v2 (seahaven-slack-webhook): 5xx, 4xx, Latency (ApiId dimension)
- ECS Fargate (seahaven-socket-mode): CPU + Memory utilization (AWS/ECS)

Expose qbo-oauth Lambda and the ECS cluster/service as public readonly handles
without changing logical IDs. RunningTaskCount alarm is gated off pending
Container Insights sign-off (separate commit).
2026-06-17 13:57:07 -04:00
Adam Moussa
006dbf7c6b feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions
- Rename bot to Alex with friendly/professional persona (Bedrock Agent instruction rewrite)
- Replace HTTP webhook Lambda with ECS Fargate Socket Mode service (persistent WebSocket)
- Add payment/invoice lookup via PaymentsDashboard table (vendor, invoice, check search)
- Switch from manual SiteAssignments to auto-populated verified-sites table
- Add channel support via app_mention events (threaded replies)
- Add App Home tab with Block Kit capabilities view
- Add unanswered questions logging to seahaven-unanswered-questions DynamoDB table
- Fix pre-existing compliance: add arm64 + 60-day log retention to all Lambdas
- Remove webhook Lambda and seed-sites script (both obsolete)
2026-04-30 16:38:54 -04:00
Adam Moussa
066ff59d22 Place QBO Lambdas in VPC for static outbound IP
Puts qbo-lookup and qbo-oauth Lambdas in seahaven-vpc private subnets
so all outbound traffic routes through NAT Gateway (52.202.83.13).
Required for Intuit app listing IP allowlist.
2026-04-13 19:51:00 -04:00
Adam Moussa
40216430c6 Merge master after PO sync PR merge 2026-04-13 15:38:13 -04:00
Adam Moussa
7240147736 feat: daily work orders DynamoDB → Bedrock KB sync
Add a new Lambda and CDK construct that scans the WorkOrders and
WorkOrderComments DynamoDB tables (owned by workorder-ingest),
converts each work order + comment history to markdown, uploads
to S3 under the work-orders/ prefix, and triggers a Bedrock
Knowledge Base ingestion job. Runs daily at 02:00 UTC via
EventBridge alongside the existing Notion sync.
2026-04-13 14:35:47 -04:00
Adam Moussa
615970eba2 feat: daily purchase-orders DynamoDB → Bedrock KB sync
Add a new Lambda and CDK construct that scans the purchase-orders
DynamoDB table (owned by po-ingest), converts each PO to markdown,
uploads to S3 under the purchase-orders/ prefix, and triggers a
Bedrock Knowledge Base ingestion job. Runs daily at 02:00 UTC via
EventBridge alongside the existing Notion sync.
2026-04-13 14:33:53 -04:00
8b18279023 feat: daily Notion → Bedrock KB sync
Adds a scheduled Lambda that pulls all pages from the Office Operations
Notion teamspace, converts them to markdown, uploads to the KB S3 bucket
under a notion/ prefix, and triggers a Bedrock ingestion job. Runs daily
at 02:00 UTC via EventBridge. Notion API key stored in Secrets Manager at
seahaven/notion/api-key (placeholder — fill in post-deploy).
2026-04-12 22:21:39 -04:00
Adam Moussa
f7e63e50c9 Initial scaffold: Bedrock-backed Slack DM bot
- CDK stack for Sea Haven Industries internal Slack assistant
- Bedrock Agent (Claude 3.5 Sonnet) with QBO + Google Maps action groups
- VectorKnowledgeBase via @cdklabs/generative-ai-cdk-constructs (AOSS + S3)
- Slack webhook/processor Lambdas with DM-only filtering
- API Gateway HTTP API on bot.seahaven.com
- DynamoDB conversation log with 90-day TTL
- Secrets Manager references for Slack, QBO OAuth, and Google Maps
2026-04-11 23:15:15 -04:00