Skip to content

Add user-bot Lambda code, tests and deploy workflows - #211

Merged
ale210 merged 1 commit into
mainfrom
209-user-bot-lambda
Oct 4, 2026
Merged

ale210 merged 1 commit into
mainfrom
209-user-bot-lambda

Conversation

@ale210

@ale210 ale210 commented Oct 4, 2026

Copy link
Copy Markdown
Member

Part of #209 (PR 2 of 2: the Lambda code and its workflows; the infrastructure went in with #210)

What changes did you make?

  • lambda/user-bot/: TypeScript Lambda. On a successful CreateLoginProfile for a user tagged managed-by = terraform-devops-security with a valid slack_id, it sets a 20-character temporary password (forced reset) and sends it through a MessageSender. Otherwise it changes nothing. The password is never logged.
  • SlackMessageSender (chat.postMessage, checks Slack's ok field rather than the HTTP status) and StubMessageSender (logs only). The deployed handler uses the stub until a Slack app and token exist
  • Vitest unit tests: AWS mocked with aws-sdk-client-mock, Slack by mocking fetch. 36 tests
  • New workflows: user-bot-test.yml (PRs touching lambda/user-bot/**, no AWS credentials) and user-bot-deploy.yml (merge to main or manual run; assumes devops-security-user-bot-deploy and updates only the function's code)
  • terraform-plan.yaml, terraform-apply.yaml and everything under terraform/ are unchanged

Why did you make the changes (we will use this info to test)?

  • So new IAM users can be sent a temporary console password by Slack DM (see Add a user-bot Lambda that DMs new IAM users a temporary console password #209)
  • Test user-bot Lambda should run on this PR and pass
  • After merge, Deploy user-bot Lambda should run green, and aws lambda get-function --function-name user-bot --region us-east-1 should show a CodeSha256 different from the placeholder's (LLba/aL0rfujZfe2GX308Af+BuAl7oqRUuVOV4dV1mo=)

@ale210
ale210 merged commit 5b43117 into main Oct 4, 2026
2 checks passed
@ale210
ale210 deleted the 209-user-bot-lambda branch October 4, 2026 21:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant