Implement reversible PII de-identification round trip (T1–T7)

Build the AWS side of the HNCB demo end to end (region ap-southeast-1):

- T1 /tokenize + T2 /restore: Lambdas behind a public API Gateway (shared-secret
  auth), Presidio detection, random per-request tokens, DynamoDB vault; overlap
  resolution so a ROC ID stays TW_ROC_ID.
- T3: Presidio made private (SG-locked to the tokenize Lambda in-VPC; DynamoDB
  gateway endpoint); only /tokenize + /restore are public.
- T4: RAG Lambda registered as an MCP tool on an AgentCore Gateway (AWS_IAM/SigV4);
  agentcore_setup.sh + a SigV4 MCP invoke test.
- T5: Strands agent deployed to AgentCore Runtime; SigV4 gateway auth, apac
  inference profile, pinned deps.
- T6: advisor UI on S3+CloudFront with a Fusion-less demo orchestrator (/demo)
  chaining tokenize -> runtime -> restore.
- T7: README runbook + trace check; teardown deletes gateway/runtime/memory/ECR.

Verified live: the cloud AgentCore/Bedrock trace shows only tokens, never the
real name. Secrets stay in gitignored local.auto.tfvars.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-01 17:10:58 +10:00
parent 6b2a051be3
commit 78d67a2469
21 changed files with 1439 additions and 107 deletions

View File

@@ -23,3 +23,30 @@ variable "presidio_image_uri" {
type = string
default = "REPLACE_ME_PRESIDIO_IMAGE_URI"
}
# Where the /tokenize Lambda reaches the Presidio detector. After deploy this is
# the Presidio Fargate task's public endpoint (http://<public-ip>:5001). Kept a
# variable so a laptop rehearsal can point at a local/ngrok detector.
variable "presidio_url" {
description = "Base URL of the Presidio detector /analyze service."
type = string
default = "http://localhost:5001"
}
# Shared secret Fusion SaaS presents to the public endpoints (bearer / x-api-key).
# NEVER commit a real value -- pass via TF_VAR_tokenize_api_key or a .tfvars file
# that is gitignored. Empty default leaves the endpoint open (dev only).
variable "tokenize_api_key" {
description = "Shared secret required on /tokenize (and /restore) requests."
type = string
default = ""
sensitive = true
}
# AgentCore Runtime ARN (created out-of-band by `agentcore launch`, see T5). The
# demo orchestrator (T6) invokes it. Empty -> orchestrator skips the agent step.
variable "agent_runtime_arn" {
description = "Bedrock AgentCore Runtime ARN the demo orchestrator invokes."
type = string
default = ""
}