# AWS deployment

## Target

- Region: `eu-west-2`
- Public host: `https://api.threasury.org/`
- Runtime: existing Threasury Apache/PHP host, isolated application directory and database identity
- Free Tier credential profile: Standard Systems Manager `SecureString` parameters, encrypted with the AWS-managed `alias/aws/ssm` key
- Runtime identity: IAM Roles Anywhere with an external CA and one-hour temporary sessions; no long-lived AWS access key
- Logs/metrics: structured audit, access, error, webhook-lag, retry, dead-letter, latency and quota telemetry

## Release controls

1. Run unit, failure, architecture and contract suites.
2. Package without `.env`, reports, backups or local databases.
3. Upload to a timestamped release directory.
4. Create bootstrap, JWT, schema-signing and audit-signing material as Standard SecureString parameters; never print it.
5. Grant the runtime only the `/threasury/gateway/*` parameter prefix.
6. Configure a dedicated `api.threasury.org` virtual host at the URL root, TLS/HSTS, request-size limits and headers; retain the old `/gateway` path only as a compatibility redirect after cut-over.
7. Run Apache configuration validation and origin health checks.
8. Back up the database, run locked idempotent migrations and complete an isolated pre-switch health check.
9. Switch the current symlink atomically, run public health and Control Tower checks, and automatically roll back on failure.
10. Certify each live adapter/capability independently before enablement.

`deploy/deploy_gateway_to_aws.sh` implements the guarded host release. It does not reveal credentials. The activated Free Tier profile uses IAM Roles Anywhere and Standard Parameter Store only; it does not provision the billable Aurora, MSK, Private CA, NAT Gateway or Secrets Manager resources in the institutional CloudFormation target.

The paid institutional profile remains available as an explicit future opt-in by setting `GATEWAY_CREDENTIAL_BACKEND=aws-secrets-manager` and deploying the separately approved multi-AZ stack. See `FREE_TIER_ACTIVATION.md` for the current live handover.
