mirror of
https://github.com/Sea-Haven-Industries/sh-mcp.git
synced 2026-10-05 23:32:04 +00:00
Sea Haven MCP platform — trust-tiered MCP servers + Cognito/Google auth broker, replacing seahaven-slack-bot and exec-aide (design phase)
- ARM64 markers (enable-qemu both files + platform:LINUX_ARM64) for Docker-bundled tier tasks -> Phase 0b build + exit (per reference_cicd_arm64_qemu). - Node 24 / workflows: sh-agentforce keeps thin ci.yaml/deploy.yaml callers but they call the new cd-sfdx, NOT the AWS CDK templates (corrected the reviewer's framing). - CR-1 decoupling: client/audience matrix injected as config (SSM/CDK env), not hardcoded into the transport-agnostic core; corrected reviewer's 'Secrets Manager' -> SSM (client_ids are non-sensitive). §6 #8d. - Role isolation: new isolated githubdeploy-sh-agentforce (never reuse sh-mcp role), scoped only to read the JWT secret since deploy target is Salesforce not AWS. Reviewer applied AWS/CDK conventions to a Salesforce-deploying repo; folded in with corrections. |
||
|---|---|---|
| docs | ||
| .gitignore | ||
| README.md | ||
sh-mcp
Sea Haven MCP platform. A TypeScript monorepo of trust-tiered MCP servers that expose
Sea Haven's proprietary integrations as tools, plus the Cognito/Google auth broker and the
rebuilt scheduled jobs. This service replaces seahaven-slack-bot and exec-aide, which are
deprecated completely; the conversational surface becomes a configurable Slack task agent.
Status: DESIGN / PLANNING. Not built. No stack deployed. The full design, auth architecture, scope matrix, and build plan live in
docs/design.md. Read it before writing any code.
Shape (planned)
- MCP servers (trust-tiered, remote HTTP, per-server IAM):
sh-mcp-ops— read-mostly, agent-facing (WO/PO/site lookups, KB search, Google Maps, Gmail/Calendar, tasks, reminders).sh-mcp-finance— sensitive, read-only, audited (QBO vendor search, payment lookups).sh-mcp-physical— DEFERRED, admin/out-of-band only (Lenel/Yealink/3CX control).
- Auth — Google Workspace is the single IdP; an Amazon Cognito user pool federated to Google issues scoped, audience-bound JWTs; group → scope mapping via a pre-token Lambda. See design §2.
- Jobs — rebuilt proactive Lambdas (email classify/digest, KB syncs).
- Language — TypeScript everywhere (servers, packages, CDK, jobs).
Open decisions
- Task-agent surface: Agentforce (recommended) vs marketplace Claude app vs custom Bolt assistant (design §12). Drives the model + guardrail story.
- Endpoint exposure specifics (Slack egress ranges / WAF) — design §9 / §11.
Layout (target)
packages/ shared + one package per integration
servers/ sh-mcp-ops, sh-mcp-finance (CDK stacks)
auth/ cognito, pre-token-lambda, group-sync-lambda
jobs/ rebuilt scheduled Lambdas
docs/ design.md (the canonical plan)
See docs/design.md for the authoritative spec.