tiennm99 3b74aa3abb docs(security): audit reports + IAM least-privilege plan + project policy
Captures the 2026-05-18 security review session output:

- plans/reports/code-reviewer-260518-1019-security-aws-infra.md
- plans/reports/code-reviewer-260518-1019-security-go-app.md
- plans/reports/researcher-260518-1019-security-dependencies.md
- docs/deploy-aws-free-tier-guide.md (adds free-tier hard rule +
  accepted security trade-offs as project standards)

Plan for the two HIGH-severity findings (F1, F2) targeting
github-deploy-miti99bot OIDC role: plans/260518-1019-iam-least-privilege/.
Plan was red-team-reviewed (15 findings applied) and validate-interviewed
(4 decisions recorded). Zero unresolved contradictions. Implementation
not yet started; phase 1 is standalone and lowest risk.

Other audit findings (F3 CORS, F4 root handler, F5-F16) deferred to
future commits; rationale in audit report.
2026-05-18 16:50:38 +07:00
2026-05-15 22:18:27 +07:00
2026-05-15 22:18:27 +07:00
2026-05-15 22:18:27 +07:00
2026-05-15 22:18:27 +07:00

miti99bot

Plug-n-play Telegram bot framework in Go. Runs on AWS Lambda + DynamoDB + EventBridge Scheduler. Strictly free-tier.

Modules

Module What it does
util /help, /info, /stickerid
misc /ping, /mstats, /trongtruonghop disclaimer
wordle Daily Wordle game
loldle League-of-Legends "guess the champion"
lolschedule Pro-match schedule + daily push
twentyq 20-questions game (requires Gemini API key)
trading VN-stocks paper trading

Disable any module by editing MODULES in template.yaml.

Layout

cmd/server/             entrypoint
internal/server/        HTTP routes (/, /webhook, /cron/{name})
internal/telegram/      Telegram webhook + bot wrapper
internal/modules/       Module framework, registry, dispatchers, modules
internal/storage/       KVStore interface; memory + dynamodb providers
internal/ai/            Gemini client (used by twentyq)
template.yaml           AWS SAM IaC (Lambda + Function URL + DynamoDB + Logs + Budget)
docs/deploy-aws-free-tier-guide.md   Full onboarding guide
docs/deploy-aws.md                   Steady-state operations
aws/README.md                        One-time AWS account setup

Run locally

In-memory KV (no AWS required):

TELEGRAM_BOT_TOKEN=\
TELEGRAM_WEBHOOK_SECRET=local \
PORT=8080 \
MODULES= \
go run ./cmd/server

End-to-end smoke test against a Telegram dev bot needs ngrok (local) or a deployed Function URL. The dev bot is created manually; token injected via env vars only.

For DynamoDB integration tests:

make dynamodb-local      # docker run amazon/dynamodb-local on :8001
make test-dynamodb       # runs internal/storage tests against DDB Local

Test

make vet              # go vet
make test             # full unit suite (no emulator)
make test-dynamodb    # storage tests against DynamoDB Local (requires Docker)

Deploy

First-time onboarding: see docs/deploy-aws-free-tier-guide.md.

Steady-state operations: docs/deploy-aws.md.

After the initial setup, every push to main triggers .github/workflows/deploy.yml (GitHub Actions OIDC → SAM deploy). No long-lived AWS keys.

License

Apache-2.0.

S
Description
Plug-n-play Telegram bot framework in Go, self-hosted on Coolify + MongoDB Atlas with cron, games, schedules, and paper trading modules.
Readme Apache-2.0
4.7 MiB
Languages
Go 99.8%
Dockerfile 0.2%