sh-mcp/servers/sh-mcp-ops/cdk/app.ts
Adam Moussa 9bf85aef29 Add runnable sh-mcp-ops and sh-mcp-finance servers
Two thin composition-root servers over the shared transport (design.md §3):
- ops: internal-data, knowledge-base, google-maps, gmail, calendar, tasks,
  reminders. finance: qbo, payments (audited + redacted on egress).
- config from env only (no hardcoded ids/issuer/tables); SH_MCP_ENV selects
  LocalAuthProvider + dev clients (local) vs CognitoAuthProvider + real stubs
  (aws). Finance applies the 15-min finance-token TTL ceiling (design.md §2.5).
- index.ts is the only place .listen() is called; a Lambda handler placeholder
  is exported but not depended on.
- synth-only CDK stubs (no real IAM/Cognito/WAF) so 'cdk synth' has a valid app
  (build-plan §6); READMEs document local run, dev tokens, curl, MCP Inspector.
2026-06-26 12:48:26 -04:00

31 lines
1.1 KiB
TypeScript

/**
* sh-mcp-ops — synth-only CDK app (build-plan §6).
*
* Exists ONLY so the CI `cdk synth` gate has a valid app to synthesize, keeping
* the IaC/ARM64 wiring honest WITHOUT deploying. It defines NO real IAM roles,
* Cognito resources, API Gateway authorizers, or WAF — those carry the mandatory
* human IAM cross-review that cannot run here. The real stack is a later phase.
*
* TODO(phase-2): real stack — gated on Cognito + IAM cross-review (design.md §8).
*/
import { App, Stack, CfnOutput, type StackProps } from 'aws-cdk-lib';
import type { Construct } from 'constructs';
class ShMcpOpsStack extends Stack {
constructor(scope: Construct, id: string, props?: StackProps) {
super(scope, id, props);
// Inert marker output only — no real resources are provisioned here.
new CfnOutput(this, 'PlatformTier', {
value: 'ops',
description: 'sh-mcp-ops trust tier (synth-only placeholder; design.md §3).',
});
}
}
const app = new App();
new ShMcpOpsStack(app, 'sh-mcp-ops', {
description: 'Sea Haven MCP ops-tier server (synth-only stub — no real infra yet).',
});
app.synth();