Reviewer flagged two security-relevant items and two operational bugs
on the external-DB + Terraform module merge.
1. Terraform: `enable_execute_command = true` was hardcoded on the app
and embedder services. Production attack surface (anyone with
`ecs:ExecuteCommand` on the service gets a container shell) AND
non-functional today since the task roles have no `ssmmessages:*`
permission. Added a new `enable_execute_command` boolean input
variable defaulting to `false`; when flipped on, the SSM messages
policy is conditionally attached to both task roles so the feature
actually works. README's variable description tells operators to
flip on for incidents, off afterward.
2. Terraform: `secret_arns` output was not marked `sensitive`. The ARNs
themselves aren't secrets, but the embedded secret names print to
`terraform apply` stdout and CI logs. Marked sensitive on both the
module output and the example output. Operators wanting the values
can still `terraform output -json secret_arns`.
3. Terraform: embedder task definition was missing `HOST=0.0.0.0` and
`PORT=8080`. Fargate awsvpc tasks each get their own ENI; default
Node HTTP servers bind 127.0.0.1, which would make every
app→embedder Service Connect call time out. Added both vars to
`embedder_environment`. Also added `NEXT_TELEMETRY_DISABLED=1` to
`app_environment` per the spec's hardening checklist.
4. Compose: docker-compose.external-db.yml uses the `!override` YAML
tag, which requires Docker Compose >= 2.24.0. Silently ignored on
older Compose, causing the `db` dependency to survive the merge and
startup to fail. Documented the minimum version in the override
file's header AND in the main README prerequisites with a deep
link to the External Postgres section.
terraform fmt + validate (module + examples/basic) both clean.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Adds `docker-compose.external-db.yml` so teams can point the stack at a
managed Postgres (RDS, Cloud SQL, etc.) without forking the base compose
file. Disables the bundled `db` service via an unreachable `profiles`
label and replaces `depends_on` / `DATABASE_URL` on `migrator` and `app`
with `!override`-tagged blocks that read `DATABASE_URL` straight from
`.env`. Default `docker compose up -d` flow is unchanged.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>