Files
doczyai-pipelines/archive/devops-pipeline/other-resources/main.tf
T
Katon Minhas afb6d5185d Merged in feature/lesser-table-caching-refactor-hybrid (pull request #847)
Feature/lesser table caching refactor hybrid

* chore: Remove unused duplicate main.py from shared pipeline

* fix: Correct crosswalk paths in aarete_derived.py

* chore: Remove unused documentation files from fieldExtraction

* docs: Add documentation files to documentation folder

* docs: Update README with uv setup, expanded project structure, and branching conventions

* docs: Add uv installation steps with Ubuntu/WSL emphasis

* Enable prompt caching for all remaining LLM calls

- Add _INSTRUCTION() functions for: EXHIBIT_HEADER, EXHIBIT_LINKAGE,
  EXHIBIT_TITLE_MATCH, DATE_FIX, DERIVED_TERM_DATE, CHECK_PROVIDER_NAME_MATCH,
  SPECIAL_CASE_ASSIGNMENT
- Update all invoke_claude() calls in saas and clover pipelines to use
  cache=True with corresponding _INSTRUCTION() functions
- Add new instructions to get_cacheable_instructions() for cache warming
- Update tests for new instruction functions

Functions now using caching:
- prompt_exhibit_level
- prompt_exhibit_lesser (EXHIBIT_LEVEL_LESSER_OF)
- prompt_fee_schedule_breakout
- prompt_grouper_breakout
- prompt_special_case_assignment
- prompt_exhibit_linkage
- prompt_exhibit_header
- prompt_smart_chunked (ONE_TO_ONE templates)
- prompt_date_fix
- prompt_derived_term_date
- prompt_exhibit_title_match
- provider_name_match_check

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Reorder

* feat: Add bcbs_promise client pipeline with OFFSET_TERM extraction

- Add new bcbs_promise client with HSC-based OFFSET_TERM field extraction
- Extract full paragraph text of offset/recoupment provisions from contracts
- Derive OFFSET_INDICATOR (Y/N) from OFFSET_TERM presence
- Fix reorder_columns to preserve extra columns not in COLUMN_ORDER
- Update QC/QA output path to outputs/qc_qa/

* fix: Update dev deps and test assertions for QC/QA output path

- Add pytest/pytest-mock to dev dependencies for mypy type checking
- Update test assertions to expect outputs/qc_qa instead of qa_qc_output

* style: Apply black formatting to prompt_templates.py

* Merge main, move scripts

* Archive some scripts

* update py version

* remove .py version file

* Remove ASCII characters

* Restore testbed code

* restore tracking

* Update testbed metrics

* Enable prompt caching for CODE_LAST_CHECK, FILL_BILL_TYPE, DUAL_LOB_CHECK, and GROUPER_BREAKOUT

- Add CODE_LAST_CHECK_INSTRUCTION() for service specificity classification
- Add FILL_BILL_TYPE_INSTRUCTION() for bill type code determination
- Add DUAL_LOB_CHECK_INSTRUCTION() for Medicare/Medicaid classification
- Update code_funcs.py to use caching for CODE_LAST_CHECK, FILL_BILL_TYPE, GROUPER_BREAKOUT
- Update postprocessing_funcs.py to use caching for DUAL_LOB_CHECK
- Add new instructions to get_cacheable_instructions() for cache warming
- Add unit tests for new instruction functions

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Fix postprocessing_funcs to remove invalid columns

* Merge branch 'main' into feature/lesser-table-caching-refactor-hybrid

* Revert prompt caching changes from aed1b73c

* update formatting

* Update imports


Approved-by: Sha Brown
Approved-by: Praneel Panchigar
2026-01-26 16:52:55 +00:00

365 lines
8.7 KiB
Terraform

terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = "5.39.0"
}
}
backend "s3" {
encrypt = true
}
}
provider "aws" {
default_tags {
tags = {
Terraform = "true"
}
}
}
# s3 bucket - devops
resource "aws_s3_bucket" "devops" {
bucket = local.devops_s3_bucket_name
tags = local.common_tags
}
resource "aws_s3_bucket_policy" "deny_insecure_communication" {
bucket = aws_s3_bucket.devops.id
policy = data.aws_iam_policy_document.deny_insecure_communication.json
}
# s3 bucket - raw-data-ingestion
resource "aws_s3_bucket" "raw_data_ingestion" {
bucket = local.raw_data_ingestion_s3_bucket_name
tags = local.common_tags
}
resource "aws_s3_bucket_policy" "raw_data_ingestion_policy" {
bucket = aws_s3_bucket.raw_data_ingestion.id
policy = data.aws_iam_policy_document.raw_data_ingestion_deny_insecure_communication.json
}
# s3 bucket - mwaa_resources
resource "aws_s3_bucket" "mwaa_resources" {
bucket = local.mwaa_resources_s3_bucket_name
tags = local.common_tags
}
resource "aws_s3_bucket_policy" "mwaa_resources_policy" {
bucket = aws_s3_bucket.mwaa_resources.id
policy = data.aws_iam_policy_document.mwaa_resources_deny_insecure_communication.json
}
# Deny insecure s3 bucket policy
data "aws_iam_policy_document" "deny_insecure_communication" {
statement {
sid = "DenyInsecureCommunications"
principals {
type = "*"
identifiers = ["*"]
}
condition {
test = "Bool"
variable = "aws:SecureTransport"
values = ["false"]
}
effect = "Deny"
actions = ["s3:*"]
resources = [
aws_s3_bucket.devops.arn,
"${aws_s3_bucket.devops.arn}/*",
]
}
}
# Deny insecure s3 bucket policy - raw_data_ingestion
data "aws_iam_policy_document" "raw_data_ingestion_deny_insecure_communication" {
statement {
sid = "DenyInsecureCommunications"
principals {
type = "*"
identifiers = ["*"]
}
condition {
test = "Bool"
variable = "aws:SecureTransport"
values = ["false"]
}
effect = "Deny"
actions = ["s3:*"]
resources = [
aws_s3_bucket.raw_data_ingestion.arn,
"${aws_s3_bucket.raw_data_ingestion.arn}/*",
]
}
}
# Deny insecure s3 bucket policy - mwaa_resources
data "aws_iam_policy_document" "mwaa_resources_deny_insecure_communication" {
statement {
sid = "DenyInsecureCommunications"
principals {
type = "*"
identifiers = ["*"]
}
condition {
test = "Bool"
variable = "aws:SecureTransport"
values = ["false"]
}
effect = "Deny"
actions = ["s3:*"]
resources = [
aws_s3_bucket.mwaa_resources.arn,
"${aws_s3_bucket.mwaa_resources.arn}/*",
]
}
}
# IAM role - snowflake-integration-role
resource "aws_iam_role" "snowflake_integration_role" {
name = local.snowflake_integration_role_name
assume_role_policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = "sts:AssumeRole"
Effect = "Allow"
Sid = ""
Principal = {
AWS = "arn:aws:iam::851725635820:user/3nmi0000-s"
}
Condition = {
StringEquals = {
"sts:ExternalId" = var.storage_integration_external_id
}
}
},
]
})
}
# Construct IAM Policy for snowflake-integration-role
data "aws_iam_policy_document" "snowflake_integration_policy_document" {
statement {
effect = "Allow"
actions = [
"s3:PutObject",
"s3:GetObject",
"s3:GetObjectVersion",
"s3:DeleteObject",
"s3:DeleteObjectVersion"
]
resources = ["${aws_s3_bucket.raw_data_ingestion.arn}*"]
}
statement {
effect = "Allow"
actions = [
"s3:ListBucket",
"s3:GetBucketLocation"
]
resources = ["${aws_s3_bucket.raw_data_ingestion.arn}"]
condition {
test = "StringLike"
variable = "s3:prefix"
values = ["*"]
}
}
}
# IAM Policy for snowflake-integration-role
resource "aws_iam_policy" "snowflake_integration_policy" {
name = local.snowflake_integration_policy_name
description = "Client textract permissions"
policy = data.aws_iam_policy_document.snowflake_integration_policy_document.json
}
# Attach IAM Policy to snowflake-integration-role
resource "aws_iam_role_policy_attachment" "snowflake_integration_policy_attachment" {
role = aws_iam_role.snowflake_integration_role.name
policy_arn = aws_iam_policy.snowflake_integration_policy.arn
}
# IAM role - cross-account-role
resource "aws_iam_role" "cross_account_role" {
count = var.environment != "dev"? 1 : 0
name = local.cross_account_role_name
assume_role_policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = "sts:AssumeRole"
Effect = "Allow"
Sid = ""
Principal = {
AWS = "arn:aws:iam::${var.cross_account_target_account_id}:root"
}
},
]
})
}
# Construct IAM Policy for cross-account-role
data "aws_iam_policy_document" "cross_account_policy_document" {
statement {
effect = "Allow"
actions = [
"s3:PutObject",
"s3:GetObject",
"s3:ListBucket",
"s3:PutObjectAcl",
"s3:GetObjectVersion"
]
resources = [
"${aws_s3_bucket.raw_data_ingestion.arn}",
"${aws_s3_bucket.raw_data_ingestion.arn}/*"
]
}
}
# IAM Policy for cross-account-role
resource "aws_iam_policy" "cross_account_policy" {
count = var.environment != "dev"? 1 : 0
name = local.cross_account_policy_name
description = "This role is used for other AWS account to assume inorder to drop files to our data ingestion bucket. At the time of creation, this is being used by CODE DEV to drop all clients list."
policy = data.aws_iam_policy_document.cross_account_policy_document.json
}
# Attach IAM Policy to cross-account-role
resource "aws_iam_role_policy_attachment" "cross_account_policy_attachment" {
count = var.environment != "dev"? 1 : 0
role = aws_iam_role.cross_account_role[count.index].name
policy_arn = aws_iam_policy.cross_account_policy[count.index].arn
}
# IAM role - mwaa-exec-role
resource "aws_iam_role" "mwaa_exec_role" {
name = local.mwaa_exec_role_role_name
assume_role_policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = "sts:AssumeRole"
Effect = "Allow"
Sid = ""
Principal = {
Service = ["airflow-env.amazonaws.com","airflow.amazonaws.com"]
}
},
]
})
}
# Construct IAM Policy for mwaa-exec-role
data "aws_iam_policy_document" "mwaa_exec_policy_document" {
statement {
effect = "Allow"
actions = ["s3:*"]
resources = [
"${aws_s3_bucket.raw_data_ingestion.arn}/*"
]
}
statement {
effect = "Allow"
actions = ["airflow:CreateCliToken"]
resources = [
"arn:aws:airflow:us-east-2:${var.aws_account_id}:environment/doczy-${var.environment}-infra-mwaa"
]
}
statement {
effect = "Allow"
actions = ["airflow:PublishMetrics"]
resources = [
"arn:aws:airflow:us-east-2:${var.aws_account_id}:environment/doczy-${var.environment}-infra-mwaa"
]
}
statement {
effect = "Deny"
actions = ["s3:ListAllMyBuckets"]
resources = [
"${aws_s3_bucket.mwaa_resources.arn}",
"${aws_s3_bucket.mwaa_resources.arn}/*"
]
}
statement {
effect = "Allow"
actions = [
"s3:GetObject*",
"s3:GetBucket*",
"s3:List*",
"s3:PutObject"
]
resources = [
"${aws_s3_bucket.mwaa_resources.arn}",
"${aws_s3_bucket.mwaa_resources.arn}/*"
]
}
statement {
effect = "Allow"
actions = [
"logs:CreateLogStream",
"logs:CreateLogGroup",
"logs:PutLogEvents",
"logs:GetLogEvents",
"logs:GetLogRecord",
"logs:GetLogGroupFields",
"logs:GetQueryResults"
]
resources = [
"arn:aws:logs:us-east-2:${var.aws_account_id}:log-group:airflow-doczy-${var.environment}-infra-mwaa-*"
]
}
statement {
effect = "Allow"
actions = [
"logs:DescribeLogGroups"
]
resources = ["*"]
}
statement {
effect = "Allow"
actions = [
"cloudwatch:PutMetricData"
]
resources = ["*"]
}
}
# IAM Policy for mwaa-exec-role
resource "aws_iam_policy" "mwaa_exec_policy" {
name = local.mwaa_exec_policy_name
description = ""
policy = data.aws_iam_policy_document.mwaa_exec_policy_document.json
}
# Attach IAM Policy to mwaa-exec-role
resource "aws_iam_role_policy_attachment" "mwaa_exec_policy_attachment" {
role = aws_iam_role.mwaa_exec_role.name
policy_arn = aws_iam_policy.mwaa_exec_policy.arn
}