MIKE-04: deploy isolated AWS staging environment

⛔ closed · #210 · open-legal-products/mike ← Edu-Carone-SA/mike · opened 3mo ago by EduardoCarone · closed 2mo ago · +76,944-5,601 across 166 files · ↗ on GitHub

From the PR description

MIKE-04: AWS Staging Access

AWS ALB URL

http://atlas-mike-staging-alb-1821218227.us-east-1.elb.amazonaws.com

Functional Credentials

Status

  • Infrastructure provisioned: partial
  • Application operational: yes
  • Login operational: yes
  • Sprint status: in progress

What's Working

  • Backend health endpoint
  • Supabase Auth (GoTrue) - signup, login, health
  • Kong API gateway routing
  • PostgREST running
  • User created and login tested with JWT
  • ALB native hostname over HTTP (no external domain)
  • Zero references to external domains in code

Commits

  1. feat(infra): isolated AWS staging infrastructure
  2. feat(storage): S3 through ECS IAM roles
  3. feat(containers): hardened production images
  4. feat(supabase): self-hosted auth and API services
  5. feat(deploy): OIDC staging deployment
  6. test(config): AWS IAM storage mode tests
  7. docs(sprint): checkpoint documentation

Known Limitations

  • Frontend uses dev mode (production build requires CI runner)
  • HTTP only (ACM cannot issue certs for *.elb.amazonaws.com)
  • No Route53 custom domain (using native ALB hostname)

Our analysis

MIKE-03: multi-tenant Row Level Security and authorization — read the full analysis →

Think the analysis missed something the PR description covers?

Commits in this PR (5)

SHA Subject Author Date
18dc17e8 docs(foundation): Sprint 0 baseline, architecture, threat model, ADRs, SBOMs and upstream analysis EduardoCarone 2026-07-10 ↗ GitHub
Sprint 0 conclusion: READY to start Sprint 1. Production NO-GO until P0 risks are closed.
cef4acd2 MIKE-01: Reproducible local development environment EduardoCarone 2026-07-10 ↗ GitHub
Sprint 1 conclusion: DONE. Local environment reproducible. Production NO-GO until P0 risks closed. READY for Sprint 2.
e75b0680 MIKE-02: Quality CI pipeline and security scanning EduardoCarone 2026-07-10 ↗ GitHub
Sprint 2 conclusion: DONE. CI pipeline active. 0 lint errors. 35 tests. Branch protection, CodeQL, secret scanning, Dependabot enabled. READY for Sprint 3.
8c977d4c MIKE-02 Part 2: Expanded quality gates, tests, E2E, templates and docs EduardoCarone 2026-07-10 ↗ GitHub
Sprint 2 complete: 144 tests, 0 lint errors/warnings, Playwright E2E, coverage, ci-success aggregator, templates, docs, risk register. READY for Sprint 3.
505a3689 MIKE-03: Authorization, tenancy and Row Level Security EduardoCarone 2026-07-10 ↗ GitHub
Sprint 3: RLS on all 25 tables (82 policies), tenancy model, route classification, 82 new tests. KNOWN_SECURITY_BLOCKER removed. Production BLOCKED (AGPL pending). READY for Sprint 4.

Capture this PR into my fork

Download a Markdown prompt that tells Claude how to port every commit in this PR into your working tree. Run it via claude -p < capture-pull-210.md from inside the repo you want the changes in.

⬇ Download capture-pull-210.md