Wire skyai-finance push: cloud invoices flow into Sky AI's books

After InvoiceIngestWorker writes cost lines and matches resources, it
pushes a normalized invoice payload to skyai-finance-svc's new endpoint
POST /api/v1/integrations/cloud/import-invoice. Idempotent — finance
dedups on (tenant_id, source, external_id), so re-runs return "updated"
not duplicate rows.

ArcadiaCloud.Integrations.SkyaiFinance is the HTTP client. Auth is a
short-lived JWT minted via Guardian (shared secret per memory) with
identity {tenant_id: "platform-admin", roles: ["admin"]} — the role
satisfies finance's RequireWriteRole plug. Identity + base URL are
configurable; SKYAI_FINANCE_URL env var can override the default
http://localhost:4010 for arcadia-dev / prod.

GST line detection: lines whose description contains "gst" or "tax"
get summed into amount_tax_minor; everything else into amount_net_minor;
sum stays gross. Phase 1 enough — proper tax handling lands when
real per-tenant invoices flow.

cloud_invoices gains pushed_to_finance_at + finance_invoice_id so we
don't re-push uselessly (Billing.mark_invoice_pushed/2 records both).
A missing finance config (no :skyai_finance app env) makes the push a
silent skip rather than a worker failure — environments without finance
configured still get a working ingest.

Live verified end-to-end against both services:
- April 2026 DO invoice (33 lines, $86.92) lands in finance as a row
  with gross=$86.92, tax=$7.90, source=digitalocean, tenant=platform-admin
- DigitalOcean vendor auto-created (category=cloud) under platform-admin
- Re-running the worker returns action: "updated" not "created";
  finance still has exactly 1 row for the invoice

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-05-19 22:35:52 +10:00
parent 0079f98bb5
commit 4f2e52af01
6 changed files with 171 additions and 3 deletions

View File

@@ -27,6 +27,19 @@ config :arcadia_cloud, ArcadiaCloudWeb.Endpoint,
config :arcadia_cloud, ArcadiaCloud.Guardian, config :arcadia_cloud, ArcadiaCloud.Guardian,
secret_key: "DuMkIRN3Qcxk8VqOu8nHj5i7a7a7YgBHF4oXqKwDI4A=" secret_key: "DuMkIRN3Qcxk8VqOu8nHj5i7a7a7YgBHF4oXqKwDI4A="
# skyai-finance push — service-to-service identity for cloud invoice push.
# tenant_id="platform-admin" lands invoices in the platform's own books;
# role "admin" satisfies finance's RequireWriteRole plug.
config :arcadia_cloud, :skyai_finance,
base_url: System.get_env("SKYAI_FINANCE_URL") || "http://localhost:4010",
identity_claims: %{
"sub" => "platform-system:platform-admin",
"tenant_id" => "platform-admin",
"tenant_slug" => "platform-admin",
"email" => "platform-system@sky-ai.com",
"roles" => ["admin"]
}
# ## SSL Support # ## SSL Support
# #
# In order to use HTTPS in development, a self-signed # In order to use HTTPS in development, a self-signed

View File

@@ -70,6 +70,17 @@ defmodule ArcadiaCloud.Billing do
|> Repo.update() |> Repo.update()
end end
def mark_invoice_pushed(invoice, finance_invoice_id) do
now = DateTime.utc_now() |> DateTime.truncate(:second)
invoice
|> CloudInvoice.changeset(%{
pushed_to_finance_at: now,
finance_invoice_id: finance_invoice_id
})
|> Repo.update()
end
# ---- cost lines ----------------------------------------------------------- # ---- cost lines -----------------------------------------------------------
@doc """ @doc """

View File

@@ -14,13 +14,16 @@ defmodule ArcadiaCloud.Billing.CloudInvoice do
field :issued_at, :utc_datetime field :issued_at, :utc_datetime
field :csv_fetched_at, :utc_datetime field :csv_fetched_at, :utc_datetime
field :lines_ingested_at, :utc_datetime field :lines_ingested_at, :utc_datetime
field :pushed_to_finance_at, :utc_datetime
field :finance_invoice_id, :string
field :raw, :map field :raw, :map
timestamps(type: :utc_datetime) timestamps(type: :utc_datetime)
end end
@required ~w(provider provider_invoice_id invoice_period)a @required ~w(provider provider_invoice_id invoice_period)a
@optional ~w(amount_cents status issued_at csv_fetched_at lines_ingested_at raw)a @optional ~w(amount_cents status issued_at csv_fetched_at lines_ingested_at
pushed_to_finance_at finance_invoice_id raw)a
def changeset(invoice, attrs) do def changeset(invoice, attrs) do
invoice invoice

View File

@@ -0,0 +1,57 @@
defmodule ArcadiaCloud.Integrations.SkyaiFinance do
@moduledoc """
HTTP client for pushing cloud invoices to skyai-finance-svc.
Auth: mints a short-lived Guardian JWT (shared secret per
project_arcadia_guardian_secret memory) with the platform-admin identity
configured under `:arcadia_cloud, :skyai_finance`. JWT carries role
`admin` because skyai-finance's RequireWriteRole plug accepts `admin`
or `user`, not `platform_admin`.
"""
alias ArcadiaCloud.Guardian
@doc """
Push a single cloud invoice (and ensure-vendor) to skyai-finance.
Idempotent — finance dedups on (tenant_id, source, external_id) and
updates existing rows on re-push.
Returns {:ok, %{vendor_id, invoice_id, action}} | {:error, reason}.
"""
def push_invoice(payload) when is_map(payload) do
with {:ok, base_url} <- fetch(:base_url),
{:ok, identity_claims} <- fetch(:identity_claims),
{:ok, token, _claims} <-
Guardian.encode_and_sign(identity_claims, identity_claims, token_type: :access) do
url = base_url <> "/api/v1/integrations/cloud/import-invoice"
case Req.post(url,
headers: [
{"authorization", "Bearer " <> token},
{"content-type", "application/json"}
],
json: payload,
retry: :transient,
max_retries: 2,
receive_timeout: 15_000
) do
{:ok, %Req.Response{status: status, body: body}} when status in 200..299 ->
{:ok, body}
{:ok, %Req.Response{status: status, body: body}} ->
{:error, {:http, status, body}}
{:error, e} ->
{:error, {:transport, e}}
end
end
end
defp fetch(key) do
case Application.get_env(:arcadia_cloud, :skyai_finance, [])[key] do
nil -> {:error, {:skyai_finance_not_configured, key}}
value -> {:ok, value}
end
end
end

View File

@@ -29,12 +29,84 @@ defmodule ArcadiaCloud.Sync.InvoiceIngestWorker do
{:ok, _} = Billing.replace_cost_lines(invoice, lines) {:ok, _} = Billing.replace_cost_lines(invoice, lines)
matched = Billing.match_cost_lines_to_resources(invoice) matched = Billing.match_cost_lines_to_resources(invoice)
{:ok, _} = Billing.mark_invoice_ingested(invoice) {:ok, invoice} = Billing.mark_invoice_ingested(invoice)
{:ok, %{lines: length(lines), matched: matched}} push_result = push_to_finance(invoice, lines)
{:ok, %{lines: length(lines), matched: matched, finance_push: push_result}}
end end
end end
# ---- push to skyai-finance ------------------------------------------------
defp push_to_finance(%CloudInvoice{} = invoice, lines) do
payload = build_finance_payload(invoice, lines)
case ArcadiaCloud.Integrations.SkyaiFinance.push_invoice(payload) do
{:ok, %{"invoice_id" => fid} = body} ->
Billing.mark_invoice_pushed(invoice, fid)
{:ok, body["action"] || "ok"}
{:error, {:skyai_finance_not_configured, _}} ->
# Push is optional — skipped in environments without finance configured.
:skipped
{:error, reason} ->
# Log and let Oban retry the whole worker; nothing destructive happened.
require Logger
Logger.warning("skyai-finance push failed for invoice #{invoice.id}: #{inspect(reason)}")
{:error, reason}
end
end
defp build_finance_payload(%CloudInvoice{} = invoice, lines) do
gst_minor = total_tax_minor(lines)
gross_minor = invoice.amount_cents || total_amount_minor(lines)
net_minor = max(gross_minor - gst_minor, 0)
%{
"invoice" => %{
"source" => invoice.provider,
"external_id" => invoice.provider_invoice_id,
"date" => Date.to_iso8601(invoice.invoice_period),
"period_start" => Date.to_iso8601(invoice.invoice_period),
"period_end" => Date.to_iso8601(end_of_month(invoice.invoice_period)),
"currency" => "USD",
"amount_gross_minor" => gross_minor,
"amount_tax_minor" => gst_minor,
"amount_net_minor" => net_minor,
"gst_inclusive" => true,
"notes" =>
"Auto-imported from arcadia-cloud. #{length(lines)} line items; #{Enum.count(lines, & &1[:kind])} kind-classified."
},
"vendor" => %{
"name" => "DigitalOcean",
"category" => "cloud",
"default_currency" => "USD"
}
}
end
defp total_amount_minor(lines) do
Enum.reduce(lines, 0, fn l, acc -> acc + (l[:amount_cents] || 0) end)
end
defp total_tax_minor(lines) do
Enum.reduce(lines, 0, fn l, acc ->
desc = (l[:description] || "") |> String.downcase()
if String.contains?(desc, "gst") or String.contains?(desc, "tax") do
acc + (l[:amount_cents] || 0)
else
acc
end
end)
end
defp end_of_month(%Date{} = d) do
d |> Date.end_of_month()
end
# ---- CSV parsing ---------------------------------------------------------- # ---- CSV parsing ----------------------------------------------------------
# DO invoice CSV columns (as of v2 API): # DO invoice CSV columns (as of v2 API):

View File

@@ -0,0 +1,12 @@
defmodule ArcadiaCloud.Repo.Migrations.InvoicePushedToFinance do
use Ecto.Migration
def change do
alter table(:cloud_invoices) do
add :pushed_to_finance_at, :utc_datetime
add :finance_invoice_id, :string
end
create index(:cloud_invoices, [:pushed_to_finance_at])
end
end