mirror of
https://github.com/Sea-Haven-Industries/sh-openswe-traces.git
synced 2026-09-30 12:43:18 +00:00
Storage-only SAM stack (S3 + KMS CMK + write-only IAM writer + Secrets Manager holder) as the S3 destination for LangSmith Bulk Export of Open SWE traces, for long-horizon auditing and prompt improvement (Athena over Parquet). - template.yaml: versioned SSE-KMS bucket, access-log bucket, TLS-only policy, DEEP_ARCHIVE lifecycle; least-privilege LangSmith writer (bucket-wide PutObject, ViaService-scoped KMS, no read/delete). - bootstrap.yaml: dedicated OIDC deploy role + least-privilege CFN exec role so CI never touches the shared execution role. - CI/CD via reusable ci-python-sam / cd-sam workflows. IAM passed GPT-4.1 cross-review + /sh-security-review (no blocking findings).
10 lines
261 B
Text
10 lines
261 B
Text
version = 0.1
|
|
|
|
[default.deploy.parameters]
|
|
stack_name = "sh-openswe-traces"
|
|
region = "us-east-1"
|
|
capabilities = "CAPABILITY_IAM"
|
|
resolve_s3 = true
|
|
confirm_changeset = true
|
|
# Optional: override the export prefix
|
|
# parameter_overrides = "ExportPrefix=langsmith/"
|