/** * sh-mcp-ops — synth-only CDK app (build-plan §6). * * Exists ONLY so the CI `cdk synth` gate has a valid app to synthesize, keeping * the IaC/ARM64 wiring honest WITHOUT deploying. It defines NO real IAM roles, * Cognito resources, API Gateway authorizers, or WAF — those carry the mandatory * human IAM cross-review that cannot run here. The real stack is a later phase. * * TODO(phase-2): real stack — gated on Cognito + IAM cross-review (design.md §8). */ import { App, Stack, CfnOutput, type StackProps } from 'aws-cdk-lib'; import type { Construct } from 'constructs'; class ShMcpOpsStack extends Stack { constructor(scope: Construct, id: string, props?: StackProps) { super(scope, id, props); // Inert marker output only — no real resources are provisioned here. new CfnOutput(this, 'PlatformTier', { value: 'ops', description: 'sh-mcp-ops trust tier (synth-only placeholder; design.md §3).', }); } } const app = new App(); new ShMcpOpsStack(app, 'sh-mcp-ops', { description: 'Sea Haven MCP ops-tier server (synth-only stub — no real infra yet).', }); app.synth();