mirror of
https://github.com/tiennm99/miti99bot.git
synced 2026-09-13 18:19:15 +00:00
a7729b7db7e488bd2b474dd96b1e87025cd95b64
Replaces the 10x *FullAccess managed policies with a single stack-scoped inline policy (miti99bot-deploy) on the role. Policy boundaries: - All resource ARNs scoped to miti99bot* (covers future miti99bot-dev) - iam:PassRole conditioned on iam:PassedToService = lambda + scheduler - iam:UpdateAssumeRolePolicy excluded (no trust-rewrite escalation) - iam:AttachRolePolicy excluded (SAM uses inline PutRolePolicy) - Wildcards limited to actions with no resource-level support (sts:GetCallerIdentity, s3:ListAllMyBuckets, cloudformation:ListStacks, cloudformation:ValidateTemplate) Rollback: aws/iam-rollback-fullaccess.sh re-attaches all 10 FullAccess policies with retry-on-throttle + final verification. Apply via Phase 4 two-stage cutover (dual-attach trial then detach). Policy is committed but NOT yet attached -- Phase 4 applies it. Plan: plans/260518-1019-iam-least-privilege/phase-03-draft-custom-policy.md Audit: plans/reports/code-reviewer-260518-1019-security-aws-infra.md
miti99bot
Plug-n-play Telegram bot framework in Go. Runs on AWS Lambda + DynamoDB + EventBridge Scheduler. Strictly free-tier.
Modules
| Module | What it does |
|---|---|
util |
/help, /info, /stickerid |
misc |
/ping, /mstats, /trongtruonghop disclaimer |
wordle |
Daily Wordle game |
loldle |
League-of-Legends "guess the champion" |
lolschedule |
Pro-match schedule + daily push |
twentyq |
20-questions game (requires Gemini API key) |
trading |
VN-stocks paper trading |
Disable any module by editing MODULES in template.yaml.
Layout
cmd/server/ entrypoint
internal/server/ HTTP routes (/, /webhook, /cron/{name})
internal/telegram/ Telegram webhook + bot wrapper
internal/modules/ Module framework, registry, dispatchers, modules
internal/storage/ KVStore interface; memory + dynamodb providers
internal/ai/ Gemini client (used by twentyq)
template.yaml AWS SAM IaC (Lambda + Function URL + DynamoDB + Logs + Budget)
docs/deploy-aws-free-tier-guide.md Full onboarding guide
docs/deploy-aws.md Steady-state operations
aws/README.md One-time AWS account setup
Run locally
In-memory KV (no AWS required):
TELEGRAM_BOT_TOKEN=… \
TELEGRAM_WEBHOOK_SECRET=local \
PORT=8080 \
MODULES= \
go run ./cmd/server
End-to-end smoke test against a Telegram dev bot needs ngrok (local) or a deployed Function URL. The dev bot is created manually; token injected via env vars only.
For DynamoDB integration tests:
make dynamodb-local # docker run amazon/dynamodb-local on :8001
make test-dynamodb # runs internal/storage tests against DDB Local
Test
make vet # go vet
make test # full unit suite (no emulator)
make test-dynamodb # storage tests against DynamoDB Local (requires Docker)
Deploy
First-time onboarding: see docs/deploy-aws-free-tier-guide.md.
Steady-state operations: docs/deploy-aws.md.
After the initial setup, every push to main triggers .github/workflows/deploy.yml (GitHub Actions OIDC → SAM deploy). No long-lived AWS keys.
License
Description
Plug-n-play Telegram bot framework in Go, self-hosted on Coolify + MongoDB Atlas with cron, games, schedules, and paper trading modules.
bot-frameworkcoolifycrongeminigoleague-of-legendslong-pollingmongodbmongodb-atlaspaper-tradingself-hostedtelegramtelegram-botwordleworld-cup
Readme
Apache-2.0
4.7 MiB
Languages
Go
99.8%
Dockerfile
0.2%