- @app/storage med MockStorage + AwsStorage delas mellan API och worker
- Workerns readUrl() ger presignerad S3-URL i aws-läge (fixar mock-s3 404)
- sync-env-from-ssm.py hämtar /cibello/prod/* och skriver .env; first-deploy.sh kör det i prod
- /readyz returnerar 503 om app.aamos.healthCheck() misslyckas
- docs/SECRETS.md med rotations- och SSM-regler
- Convert C:\Users\Public\cibello-verified-final-result.json to
packages/database/src/seed/data/verified-recipes.ts (committed, hermetic).
- Replace/extend the 23 placeholder SEED_RECIPES via re-export.
- Upsert on slug with onConflictDoUpdate of ALL recipe fields.
- Hard-reject recipes with unmapped canonical ingredients (0 rejected this batch).
- Derive allergens and compute nutrition per portion from ingredients at seed time.
- Run food-safety lint; auto-patch 8 legacy raw-protein recipes with safe-cooking phrase.
- Resolve 4 suspected title duplicates via variantOfSlug.
- Guard brand name: creatorDisplayName uses BRAND.name, never JSON placeholder.
- Preserve verificationStatus (editorial/verified) and source-registry FKs.
- Extend allergen-invariant test to cover full 246-recipe catalog.
- Stabilise API tests by disabling file parallelism (flakiness from shared DB state).
Refs: seed pipeline, brand-guard, safety canary