afb6d5185d
Feature/lesser table caching refactor hybrid * chore: Remove unused duplicate main.py from shared pipeline * fix: Correct crosswalk paths in aarete_derived.py * chore: Remove unused documentation files from fieldExtraction * docs: Add documentation files to documentation folder * docs: Update README with uv setup, expanded project structure, and branching conventions * docs: Add uv installation steps with Ubuntu/WSL emphasis * Enable prompt caching for all remaining LLM calls - Add _INSTRUCTION() functions for: EXHIBIT_HEADER, EXHIBIT_LINKAGE, EXHIBIT_TITLE_MATCH, DATE_FIX, DERIVED_TERM_DATE, CHECK_PROVIDER_NAME_MATCH, SPECIAL_CASE_ASSIGNMENT - Update all invoke_claude() calls in saas and clover pipelines to use cache=True with corresponding _INSTRUCTION() functions - Add new instructions to get_cacheable_instructions() for cache warming - Update tests for new instruction functions Functions now using caching: - prompt_exhibit_level - prompt_exhibit_lesser (EXHIBIT_LEVEL_LESSER_OF) - prompt_fee_schedule_breakout - prompt_grouper_breakout - prompt_special_case_assignment - prompt_exhibit_linkage - prompt_exhibit_header - prompt_smart_chunked (ONE_TO_ONE templates) - prompt_date_fix - prompt_derived_term_date - prompt_exhibit_title_match - provider_name_match_check 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Reorder * feat: Add bcbs_promise client pipeline with OFFSET_TERM extraction - Add new bcbs_promise client with HSC-based OFFSET_TERM field extraction - Extract full paragraph text of offset/recoupment provisions from contracts - Derive OFFSET_INDICATOR (Y/N) from OFFSET_TERM presence - Fix reorder_columns to preserve extra columns not in COLUMN_ORDER - Update QC/QA output path to outputs/qc_qa/ * fix: Update dev deps and test assertions for QC/QA output path - Add pytest/pytest-mock to dev dependencies for mypy type checking - Update test assertions to expect outputs/qc_qa instead of qa_qc_output * style: Apply black formatting to prompt_templates.py * Merge main, move scripts * Archive some scripts * update py version * remove .py version file * Remove ASCII characters * Restore testbed code * restore tracking * Update testbed metrics * Enable prompt caching for CODE_LAST_CHECK, FILL_BILL_TYPE, DUAL_LOB_CHECK, and GROUPER_BREAKOUT - Add CODE_LAST_CHECK_INSTRUCTION() for service specificity classification - Add FILL_BILL_TYPE_INSTRUCTION() for bill type code determination - Add DUAL_LOB_CHECK_INSTRUCTION() for Medicare/Medicaid classification - Update code_funcs.py to use caching for CODE_LAST_CHECK, FILL_BILL_TYPE, GROUPER_BREAKOUT - Update postprocessing_funcs.py to use caching for DUAL_LOB_CHECK - Add new instructions to get_cacheable_instructions() for cache warming - Add unit tests for new instruction functions 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Fix postprocessing_funcs to remove invalid columns * Merge branch 'main' into feature/lesser-table-caching-refactor-hybrid * Revert prompt caching changes from aed1b73c * update formatting * Update imports Approved-by: Sha Brown Approved-by: Praneel Panchigar
137 lines
3.9 KiB
Terraform
137 lines
3.9 KiB
Terraform
resource "aws_iam_role" "ec2_role" {
|
|
name = local.ec2_role_name
|
|
|
|
assume_role_policy = jsonencode({
|
|
Version = "2012-10-17"
|
|
Statement = [
|
|
{
|
|
Action = "sts:AssumeRole"
|
|
Effect = "Allow"
|
|
Sid = ""
|
|
Principal = {
|
|
Service = "ec2.amazonaws.com"
|
|
}
|
|
}
|
|
]
|
|
})
|
|
}
|
|
|
|
# Attached all policies created here to the ec2 role
|
|
|
|
|
|
|
|
# Combine all policy documents into a single document
|
|
data "aws_iam_policy_document" "combined_policy_document" {
|
|
statement {
|
|
sid = "S3Permissions"
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:ListBucket",
|
|
"s3:ListAllMyBuckets",
|
|
"s3:GetObject",
|
|
"s3:PutObject",
|
|
"s3:GetObjectTagging",
|
|
"s3:PutObjectTagging"
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "SecretsManagerOperations"
|
|
effect = "Allow"
|
|
actions = [
|
|
"secretsmanager:GetResourcePolicy",
|
|
"secretsmanager:GetSecretValue",
|
|
"secretsmanager:DescribeSecret",
|
|
"secretsmanager:PutSecretValue",
|
|
"secretsmanager:ListSecretVersionIds",
|
|
"secretsmanager:GetRandomPassword",
|
|
"secretsmanager:ListSecrets",
|
|
"secretsmanager:BatchGetSecretValue"
|
|
]
|
|
# Need to restrict this to ARN of the secrets later
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "SSMUpdateInstanceInformation"
|
|
effect = "Allow"
|
|
actions = ["ssm:UpdateInstanceInformation"]
|
|
# Refernce the instance by its instance id
|
|
resources = ["${aws_instance.streamlit_server.arn}"]
|
|
}
|
|
statement {
|
|
sid = "BedrockPermissions"
|
|
effect = "Allow"
|
|
actions = [
|
|
"bedrock:InvokeAgent",
|
|
"bedrock:InvokeModel",
|
|
"bedrock:InvokeModelWithResponseStream",
|
|
"bedrock:ListFoundationModels"
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "APIGatewayInvokeFullAccess"
|
|
effect = "Allow"
|
|
actions = ["execute-api:Invoke",
|
|
"execute-api:ManageConnections"]
|
|
resources = ["arn:aws:execute-api:*:*:*"]
|
|
}
|
|
statement {
|
|
sid = "AmazonSSMManagedInstanceCore"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ssm:DescribeAssociation",
|
|
"ssm:GetDeployablePatchSnapshotForInstance",
|
|
"ssm:GetDocument",
|
|
"ssm:DescribeDocument",
|
|
"ssm:GetManifest",
|
|
"ssm:GetParameter",
|
|
"ssm:GetParameters",
|
|
"ssm:ListAssociations",
|
|
"ssm:ListInstanceAssociations",
|
|
"ssm:PutInventory",
|
|
"ssm:PutComplianceItems",
|
|
"ssm:PutConfigurePackageResult",
|
|
"ssm:UpdateAssociationStatus",
|
|
"ssm:UpdateInstanceAssociationStatus",
|
|
"ssm:UpdateInstanceInformation",
|
|
"ssmmessages:CreateControlChannel",
|
|
"ssmmessages:CreateDataChannel",
|
|
"ssmmessages:OpenControlChannel",
|
|
"ssmmessages:OpenDataChannel",
|
|
"ec2messages:AcknowledgeMessage",
|
|
"ec2messages:DeleteMessage",
|
|
"ec2messages:FailMessage",
|
|
"ec2messages:GetEndpoint",
|
|
"ec2messages:GetMessages",
|
|
"ec2messages:SendReply"
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
# statement for cli policy
|
|
statement {
|
|
effect = "Allow"
|
|
actions = ["airflow:CreateCliToken"]
|
|
resources = ["*"]
|
|
}
|
|
}
|
|
|
|
# Attached the combined document to the ec2 role
|
|
resource "aws_iam_policy" "combined_policy" {
|
|
name = "${local.ec2_role_name}-combined-policy"
|
|
description = "Combined policy for Bedrock, Secrets Manager, SSM, and S3"
|
|
policy = data.aws_iam_policy_document.combined_policy_document.json
|
|
}
|
|
|
|
resource "aws_iam_role_policy_attachment" "combined_policy_attachment" {
|
|
role = aws_iam_role.ec2_role.name
|
|
policy_arn = aws_iam_policy.combined_policy.arn
|
|
}
|
|
|
|
output "ec2_role_name" {
|
|
value = local.ec2_role_name
|
|
}
|