The Elastic Beanstalk nginx proxy kept its 1 MB default body limit, so every
media upload over ~1 MB got an nginx 413 before reaching the API. Ship a
.platform nginx override (120M) in the bundle and assert it in the bundle
contract.
Apply the client-confirmed contract: photos up to 10 MB (JPEG/PNG/HEIC),
videos up to 100 MB (MP4/MOV), at most 10 photos and 3 videos per work order,
with stable generic rejection messages. The request ceiling (110 MB) sits
between the per-kind caps and the proxy so oversize files get the generic
message. The vendor portal accepts the same photo/video types and caps.
* feat(deploy): move dev application CD through Terraform
GitHub creates the immutable Elastic Beanstalk version; HCP Terraform is the only UpdateEnvironment caller via a guarded version_label run.
* fix: add permissions block for dependency-review workflow
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
* fix(terraform): stop pinning the generated dev instance SG
---------
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
* feat(terraform): add safe backend environment adoption
Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer.
* ci(deploy): pause dev and staging deployments
Prevent application releases from racing Terraform adoption while retaining production deployment and validation.
* ci(deploy): require manual environment dispatch
* fix: update `required_version` from `>=1.7.0` to `>=1.9.0`
The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+.
CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding
* chore(deps): add `terraform` to renovate dependency coverage
* ci(deploy): drop unprovisioned prod dispatch path