sh-mcp/servers/sh-mcp-finance/cdk/app.ts
Adam Moussa 9bf85aef29 Add runnable sh-mcp-ops and sh-mcp-finance servers
Two thin composition-root servers over the shared transport (design.md §3):
- ops: internal-data, knowledge-base, google-maps, gmail, calendar, tasks,
  reminders. finance: qbo, payments (audited + redacted on egress).
- config from env only (no hardcoded ids/issuer/tables); SH_MCP_ENV selects
  LocalAuthProvider + dev clients (local) vs CognitoAuthProvider + real stubs
  (aws). Finance applies the 15-min finance-token TTL ceiling (design.md §2.5).
- index.ts is the only place .listen() is called; a Lambda handler placeholder
  is exported but not depended on.
- synth-only CDK stubs (no real IAM/Cognito/WAF) so 'cdk synth' has a valid app
  (build-plan §6); READMEs document local run, dev tokens, curl, MCP Inspector.
2026-06-26 12:48:26 -04:00

30 lines
1 KiB
TypeScript

/**
* sh-mcp-finance — synth-only CDK app (build-plan §6).
*
* Exists ONLY so the CI `cdk synth` gate has a valid app to synthesize. Defines
* NO real IAM/Cognito/API-Gateway/WAF resources (those need the mandatory human
* IAM cross-review). The real stack — including the finance least-privilege role
* and audit wiring (design.md §2.5) — is a later phase.
*
* TODO(phase-2): real stack — gated on Cognito + IAM cross-review (design.md §8).
*/
import { App, Stack, CfnOutput, type StackProps } from 'aws-cdk-lib';
import type { Construct } from 'constructs';
class ShMcpFinanceStack extends Stack {
constructor(scope: Construct, id: string, props?: StackProps) {
super(scope, id, props);
new CfnOutput(this, 'PlatformTier', {
value: 'finance',
description: 'sh-mcp-finance trust tier (synth-only placeholder; design.md §3).',
});
}
}
const app = new App();
new ShMcpFinanceStack(app, 'sh-mcp-finance', {
description: 'Sea Haven MCP finance-tier server (synth-only stub — no real infra yet).',
});
app.synth();