afb6d5185d
Feature/lesser table caching refactor hybrid * chore: Remove unused duplicate main.py from shared pipeline * fix: Correct crosswalk paths in aarete_derived.py * chore: Remove unused documentation files from fieldExtraction * docs: Add documentation files to documentation folder * docs: Update README with uv setup, expanded project structure, and branching conventions * docs: Add uv installation steps with Ubuntu/WSL emphasis * Enable prompt caching for all remaining LLM calls - Add _INSTRUCTION() functions for: EXHIBIT_HEADER, EXHIBIT_LINKAGE, EXHIBIT_TITLE_MATCH, DATE_FIX, DERIVED_TERM_DATE, CHECK_PROVIDER_NAME_MATCH, SPECIAL_CASE_ASSIGNMENT - Update all invoke_claude() calls in saas and clover pipelines to use cache=True with corresponding _INSTRUCTION() functions - Add new instructions to get_cacheable_instructions() for cache warming - Update tests for new instruction functions Functions now using caching: - prompt_exhibit_level - prompt_exhibit_lesser (EXHIBIT_LEVEL_LESSER_OF) - prompt_fee_schedule_breakout - prompt_grouper_breakout - prompt_special_case_assignment - prompt_exhibit_linkage - prompt_exhibit_header - prompt_smart_chunked (ONE_TO_ONE templates) - prompt_date_fix - prompt_derived_term_date - prompt_exhibit_title_match - provider_name_match_check 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Reorder * feat: Add bcbs_promise client pipeline with OFFSET_TERM extraction - Add new bcbs_promise client with HSC-based OFFSET_TERM field extraction - Extract full paragraph text of offset/recoupment provisions from contracts - Derive OFFSET_INDICATOR (Y/N) from OFFSET_TERM presence - Fix reorder_columns to preserve extra columns not in COLUMN_ORDER - Update QC/QA output path to outputs/qc_qa/ * fix: Update dev deps and test assertions for QC/QA output path - Add pytest/pytest-mock to dev dependencies for mypy type checking - Update test assertions to expect outputs/qc_qa instead of qa_qc_output * style: Apply black formatting to prompt_templates.py * Merge main, move scripts * Archive some scripts * update py version * remove .py version file * Remove ASCII characters * Restore testbed code * restore tracking * Update testbed metrics * Enable prompt caching for CODE_LAST_CHECK, FILL_BILL_TYPE, DUAL_LOB_CHECK, and GROUPER_BREAKOUT - Add CODE_LAST_CHECK_INSTRUCTION() for service specificity classification - Add FILL_BILL_TYPE_INSTRUCTION() for bill type code determination - Add DUAL_LOB_CHECK_INSTRUCTION() for Medicare/Medicaid classification - Update code_funcs.py to use caching for CODE_LAST_CHECK, FILL_BILL_TYPE, GROUPER_BREAKOUT - Update postprocessing_funcs.py to use caching for DUAL_LOB_CHECK - Add new instructions to get_cacheable_instructions() for cache warming - Add unit tests for new instruction functions 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * Fix postprocessing_funcs to remove invalid columns * Merge branch 'main' into feature/lesser-table-caching-refactor-hybrid * Revert prompt caching changes from aed1b73c * update formatting * Update imports Approved-by: Sha Brown Approved-by: Praneel Panchigar
365 lines
8.7 KiB
Terraform
365 lines
8.7 KiB
Terraform
terraform {
|
|
required_providers {
|
|
aws = {
|
|
source = "hashicorp/aws"
|
|
version = "5.39.0"
|
|
}
|
|
}
|
|
backend "s3" {
|
|
encrypt = true
|
|
}
|
|
}
|
|
|
|
provider "aws" {
|
|
|
|
default_tags {
|
|
tags = {
|
|
Terraform = "true"
|
|
}
|
|
}
|
|
}
|
|
|
|
# s3 bucket - devops
|
|
resource "aws_s3_bucket" "devops" {
|
|
bucket = local.devops_s3_bucket_name
|
|
tags = local.common_tags
|
|
}
|
|
|
|
resource "aws_s3_bucket_policy" "deny_insecure_communication" {
|
|
bucket = aws_s3_bucket.devops.id
|
|
policy = data.aws_iam_policy_document.deny_insecure_communication.json
|
|
}
|
|
|
|
# s3 bucket - raw-data-ingestion
|
|
resource "aws_s3_bucket" "raw_data_ingestion" {
|
|
bucket = local.raw_data_ingestion_s3_bucket_name
|
|
tags = local.common_tags
|
|
}
|
|
|
|
resource "aws_s3_bucket_policy" "raw_data_ingestion_policy" {
|
|
bucket = aws_s3_bucket.raw_data_ingestion.id
|
|
policy = data.aws_iam_policy_document.raw_data_ingestion_deny_insecure_communication.json
|
|
}
|
|
|
|
# s3 bucket - mwaa_resources
|
|
resource "aws_s3_bucket" "mwaa_resources" {
|
|
bucket = local.mwaa_resources_s3_bucket_name
|
|
tags = local.common_tags
|
|
}
|
|
|
|
resource "aws_s3_bucket_policy" "mwaa_resources_policy" {
|
|
bucket = aws_s3_bucket.mwaa_resources.id
|
|
policy = data.aws_iam_policy_document.mwaa_resources_deny_insecure_communication.json
|
|
}
|
|
|
|
# Deny insecure s3 bucket policy
|
|
data "aws_iam_policy_document" "deny_insecure_communication" {
|
|
statement {
|
|
sid = "DenyInsecureCommunications"
|
|
|
|
principals {
|
|
type = "*"
|
|
identifiers = ["*"]
|
|
}
|
|
|
|
condition {
|
|
test = "Bool"
|
|
variable = "aws:SecureTransport"
|
|
values = ["false"]
|
|
}
|
|
|
|
effect = "Deny"
|
|
|
|
actions = ["s3:*"]
|
|
|
|
resources = [
|
|
aws_s3_bucket.devops.arn,
|
|
"${aws_s3_bucket.devops.arn}/*",
|
|
]
|
|
}
|
|
}
|
|
|
|
# Deny insecure s3 bucket policy - raw_data_ingestion
|
|
data "aws_iam_policy_document" "raw_data_ingestion_deny_insecure_communication" {
|
|
statement {
|
|
sid = "DenyInsecureCommunications"
|
|
|
|
principals {
|
|
type = "*"
|
|
identifiers = ["*"]
|
|
}
|
|
|
|
condition {
|
|
test = "Bool"
|
|
variable = "aws:SecureTransport"
|
|
values = ["false"]
|
|
}
|
|
|
|
effect = "Deny"
|
|
|
|
actions = ["s3:*"]
|
|
|
|
resources = [
|
|
aws_s3_bucket.raw_data_ingestion.arn,
|
|
"${aws_s3_bucket.raw_data_ingestion.arn}/*",
|
|
]
|
|
}
|
|
}
|
|
|
|
# Deny insecure s3 bucket policy - mwaa_resources
|
|
data "aws_iam_policy_document" "mwaa_resources_deny_insecure_communication" {
|
|
statement {
|
|
sid = "DenyInsecureCommunications"
|
|
|
|
principals {
|
|
type = "*"
|
|
identifiers = ["*"]
|
|
}
|
|
|
|
condition {
|
|
test = "Bool"
|
|
variable = "aws:SecureTransport"
|
|
values = ["false"]
|
|
}
|
|
|
|
effect = "Deny"
|
|
|
|
actions = ["s3:*"]
|
|
|
|
resources = [
|
|
aws_s3_bucket.mwaa_resources.arn,
|
|
"${aws_s3_bucket.mwaa_resources.arn}/*",
|
|
]
|
|
}
|
|
}
|
|
|
|
# IAM role - snowflake-integration-role
|
|
resource "aws_iam_role" "snowflake_integration_role" {
|
|
name = local.snowflake_integration_role_name
|
|
|
|
assume_role_policy = jsonencode({
|
|
Version = "2012-10-17"
|
|
Statement = [
|
|
{
|
|
Action = "sts:AssumeRole"
|
|
Effect = "Allow"
|
|
Sid = ""
|
|
Principal = {
|
|
AWS = "arn:aws:iam::851725635820:user/3nmi0000-s"
|
|
}
|
|
Condition = {
|
|
StringEquals = {
|
|
"sts:ExternalId" = var.storage_integration_external_id
|
|
}
|
|
}
|
|
},
|
|
]
|
|
})
|
|
}
|
|
|
|
# Construct IAM Policy for snowflake-integration-role
|
|
data "aws_iam_policy_document" "snowflake_integration_policy_document" {
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:PutObject",
|
|
"s3:GetObject",
|
|
"s3:GetObjectVersion",
|
|
"s3:DeleteObject",
|
|
"s3:DeleteObjectVersion"
|
|
]
|
|
resources = ["${aws_s3_bucket.raw_data_ingestion.arn}*"]
|
|
}
|
|
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:ListBucket",
|
|
"s3:GetBucketLocation"
|
|
]
|
|
resources = ["${aws_s3_bucket.raw_data_ingestion.arn}"]
|
|
|
|
condition {
|
|
test = "StringLike"
|
|
variable = "s3:prefix"
|
|
values = ["*"]
|
|
}
|
|
}
|
|
}
|
|
|
|
# IAM Policy for snowflake-integration-role
|
|
resource "aws_iam_policy" "snowflake_integration_policy" {
|
|
name = local.snowflake_integration_policy_name
|
|
description = "Client textract permissions"
|
|
policy = data.aws_iam_policy_document.snowflake_integration_policy_document.json
|
|
}
|
|
|
|
# Attach IAM Policy to snowflake-integration-role
|
|
resource "aws_iam_role_policy_attachment" "snowflake_integration_policy_attachment" {
|
|
role = aws_iam_role.snowflake_integration_role.name
|
|
policy_arn = aws_iam_policy.snowflake_integration_policy.arn
|
|
}
|
|
|
|
|
|
# IAM role - cross-account-role
|
|
resource "aws_iam_role" "cross_account_role" {
|
|
count = var.environment != "dev"? 1 : 0
|
|
name = local.cross_account_role_name
|
|
|
|
assume_role_policy = jsonencode({
|
|
Version = "2012-10-17"
|
|
Statement = [
|
|
{
|
|
Action = "sts:AssumeRole"
|
|
Effect = "Allow"
|
|
Sid = ""
|
|
Principal = {
|
|
AWS = "arn:aws:iam::${var.cross_account_target_account_id}:root"
|
|
}
|
|
},
|
|
]
|
|
})
|
|
}
|
|
|
|
# Construct IAM Policy for cross-account-role
|
|
data "aws_iam_policy_document" "cross_account_policy_document" {
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:PutObject",
|
|
"s3:GetObject",
|
|
"s3:ListBucket",
|
|
"s3:PutObjectAcl",
|
|
"s3:GetObjectVersion"
|
|
]
|
|
resources = [
|
|
"${aws_s3_bucket.raw_data_ingestion.arn}",
|
|
"${aws_s3_bucket.raw_data_ingestion.arn}/*"
|
|
]
|
|
}
|
|
}
|
|
|
|
# IAM Policy for cross-account-role
|
|
resource "aws_iam_policy" "cross_account_policy" {
|
|
count = var.environment != "dev"? 1 : 0
|
|
name = local.cross_account_policy_name
|
|
description = "This role is used for other AWS account to assume inorder to drop files to our data ingestion bucket. At the time of creation, this is being used by CODE DEV to drop all clients list."
|
|
policy = data.aws_iam_policy_document.cross_account_policy_document.json
|
|
}
|
|
|
|
# Attach IAM Policy to cross-account-role
|
|
resource "aws_iam_role_policy_attachment" "cross_account_policy_attachment" {
|
|
count = var.environment != "dev"? 1 : 0
|
|
role = aws_iam_role.cross_account_role[count.index].name
|
|
policy_arn = aws_iam_policy.cross_account_policy[count.index].arn
|
|
}
|
|
|
|
# IAM role - mwaa-exec-role
|
|
resource "aws_iam_role" "mwaa_exec_role" {
|
|
name = local.mwaa_exec_role_role_name
|
|
|
|
assume_role_policy = jsonencode({
|
|
Version = "2012-10-17"
|
|
Statement = [
|
|
{
|
|
Action = "sts:AssumeRole"
|
|
Effect = "Allow"
|
|
Sid = ""
|
|
Principal = {
|
|
Service = ["airflow-env.amazonaws.com","airflow.amazonaws.com"]
|
|
}
|
|
},
|
|
]
|
|
})
|
|
}
|
|
|
|
# Construct IAM Policy for mwaa-exec-role
|
|
data "aws_iam_policy_document" "mwaa_exec_policy_document" {
|
|
statement {
|
|
effect = "Allow"
|
|
actions = ["s3:*"]
|
|
resources = [
|
|
"${aws_s3_bucket.raw_data_ingestion.arn}/*"
|
|
]
|
|
}
|
|
statement {
|
|
effect = "Allow"
|
|
actions = ["airflow:CreateCliToken"]
|
|
resources = [
|
|
"arn:aws:airflow:us-east-2:${var.aws_account_id}:environment/doczy-${var.environment}-infra-mwaa"
|
|
]
|
|
}
|
|
statement {
|
|
effect = "Allow"
|
|
actions = ["airflow:PublishMetrics"]
|
|
resources = [
|
|
"arn:aws:airflow:us-east-2:${var.aws_account_id}:environment/doczy-${var.environment}-infra-mwaa"
|
|
]
|
|
}
|
|
statement {
|
|
effect = "Deny"
|
|
actions = ["s3:ListAllMyBuckets"]
|
|
resources = [
|
|
"${aws_s3_bucket.mwaa_resources.arn}",
|
|
"${aws_s3_bucket.mwaa_resources.arn}/*"
|
|
]
|
|
}
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:GetObject*",
|
|
"s3:GetBucket*",
|
|
"s3:List*",
|
|
"s3:PutObject"
|
|
]
|
|
resources = [
|
|
"${aws_s3_bucket.mwaa_resources.arn}",
|
|
"${aws_s3_bucket.mwaa_resources.arn}/*"
|
|
]
|
|
}
|
|
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"logs:CreateLogStream",
|
|
"logs:CreateLogGroup",
|
|
"logs:PutLogEvents",
|
|
"logs:GetLogEvents",
|
|
"logs:GetLogRecord",
|
|
"logs:GetLogGroupFields",
|
|
"logs:GetQueryResults"
|
|
]
|
|
resources = [
|
|
"arn:aws:logs:us-east-2:${var.aws_account_id}:log-group:airflow-doczy-${var.environment}-infra-mwaa-*"
|
|
]
|
|
}
|
|
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"logs:DescribeLogGroups"
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"cloudwatch:PutMetricData"
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
}
|
|
|
|
# IAM Policy for mwaa-exec-role
|
|
resource "aws_iam_policy" "mwaa_exec_policy" {
|
|
name = local.mwaa_exec_policy_name
|
|
description = ""
|
|
policy = data.aws_iam_policy_document.mwaa_exec_policy_document.json
|
|
}
|
|
|
|
# Attach IAM Policy to mwaa-exec-role
|
|
resource "aws_iam_role_policy_attachment" "mwaa_exec_policy_attachment" {
|
|
role = aws_iam_role.mwaa_exec_role.name
|
|
policy_arn = aws_iam_policy.mwaa_exec_policy.arn
|
|
} |