sh-mcp/docs
Adam Moussa a722d62f02
Some checks failed
deploy / deploy (push) Has been cancelled
docs: add sh-mcp-auth deploy runbook (#5)
First-time deploy procedure for the Phase 2a Cognito auth substrate: the five
one-time prerequisites (CDK bootstrap, the two Google secrets with exact JSON
shapes, the githubdeploy-sh-mcp OIDC role, the managed Google Groups), the
synth → diff → watched manual first deploy → CD hand-off flow, post-deploy
validation (ESSENTIALS + V2 trigger, finance client ceiling, group-sync run,
deny-list hard-revocation smoke test), and rollback/teardown (RETAIN tables;
0a spike teardown deferred until sh-mcp-auth is validated).

Notes that CD (deploy.yaml) is already wired and red on every merge until the
OIDC deploy role exists, and that no Cognito hosted-UI domain ships in 2a
(OAuth code flow deferred to 2b surface wiring).
2026-07-02 15:53:22 -04:00
..
agentforce-plan.md Add Agentforce migration & architecture plan (#1) 2026-06-26 12:47:04 -04:00
build-plan-phase-1.md Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2) 2026-06-26 12:42:17 -04:00
design.md Initial commit: sh-mcp design and plan 2026-06-09 19:25:24 -04:00
runbook-auth-deploy.md docs: add sh-mcp-auth deploy runbook (#5) 2026-07-02 15:53:22 -04:00