- Enable MFA for root and avoid day-to-day root usage.
- Select a single primary region for MVP.
- Bootstrap CDK:
npx cdk bootstrap aws://<account-id>/<region>- Configure GitHub OIDC:
- Create
token.actions.githubusercontent.comIAM OIDC provider. - Create deploy roles for
devandprod. - Restrict trust to repository and branch/environment claims.
- Create
- Set GitHub environments:
devandprodAWS_REGIONvariableAWS_DEPLOY_ROLE_ARNsecret
# synth
npm run cdk:synth
# deploy dev
npx cdk deploy TrustedLearningContextServiceStack-dev --context stage=dev --require-approval never
# deploy prod
npx cdk deploy TrustedLearningContextServiceStack-prod --context stage=prod --require-approval never- The platform stack provisions Cognito resources for API auth:
- user pool
- user pool domain
- app clients for OAuth2 client credentials flow
- Stack outputs include issuer URL, token endpoint, and app client IDs.
- Retrieve app client secrets with
aws cognito-idp describe-user-pool-clientfor the created user pool/client IDs. - Use token endpoint
/oauth2/tokento mint bearer tokens and call API routes.
Use these steps when you want to tear down an entire stage (for example dev) in AWS.
- Destroy the CDK stack:
npx cdk destroy TrustedLearningContextServiceStack-dev --context stage=dev --force- Delete retained data resources created by the stack. By default, some resources are retained to protect data (DynamoDB tables and S3 bucket), so remove them manually:
# Empty and remove the stage bucket (replace with your actual bucket name)
aws s3 rm s3://<raw-payload-bucket-name> --recursive
aws s3 rb s3://<raw-payload-bucket-name>
# Delete stage DynamoDB tables
aws dynamodb delete-table --table-name TrustedLearningContextCredentialTable-dev
aws dynamodb delete-table --table-name TrustedLearningContextEventTable-dev
aws dynamodb delete-table --table-name TrustedLearningContextSubmissionTable-dev- (Optional) remove CI/CD/OIDC infrastructure for that repo if you no longer deploy from GitHub Actions:
# If you deployed the CICD stack via CDK
npx cdk destroy TrustedLearningContextServiceCicdStack-dev --context stage=dev --force
# Optional manual cleanup if needed
aws iam delete-role --role-name GitHubDeployRoleDev- Verify cleanup:
- CloudFormation stack is deleted.
- No
*-devDynamoDB tables remain. trusted-learning-context-service-queue-devandtrusted-learning-context-service-dlq-devare gone.- The stage API endpoint no longer responds.
- Monitor DLQ message count alarm.
- Monitor Persist Lambda errors.
- Monitor API 5xx alarm.
- Monitor DynamoDB throttling alarm.
- Review dashboard
trusted-learning-context-service-<stage>.
- Transport ID:
submissionId(ULID-derived). - Persistence IDs: deterministic hash-derived IDs.
- Duplicate content produces same
credentialId/eventId. - Persistence writes use conditional expressions to avoid accidental overwrite.