diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 70c1e7d..b62fbf9 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1101,8 +1101,24 @@ Resources: # CDK deploy roles (4 repos) # --------------------------------------------------------------------------- + # DECOMMISSIONED — being removed from this stack in two steps. + # + # seahaven-slack-bot was retired (superseded by sh-mcp) and this role was + # deleted directly in IAM on 2026-07-23, leaving the stack holding a resource + # that no longer exists. That ghost broke EVERY subsequent stack update: the + # Outputs section resolved !GetAtt SeahavenSlackBotDeployRole.Arn as a live + # IAM read, which 404s. A change-set does not reveal this, because the + # resource itself is unchanged and Outputs are not previewed. + # + # Step 1 (this change): drop the Output so updates stop resolving the ghost, + # and record Retain so that step 2 cannot issue DeleteRole against a role + # that is not there. + # Step 2 (follow-up): delete the resource block itself. With Retain recorded, + # CloudFormation simply stops managing it — no IAM call is made. SeahavenSlackBotDeployRole: Type: AWS::IAM::Role + DeletionPolicy: Retain + UpdateReplacePolicy: Retain Properties: RoleName: githubdeploy-seahaven-slack-bot AssumeRolePolicyDocument: @@ -1283,8 +1299,10 @@ Outputs: Value: !GetAtt AfiBackupMonitorDeployRole.Arn PaymentsDashboardDeployRoleArn: Value: !GetAtt PaymentsDashboardDeployRole.Arn - SeahavenSlackBotDeployRoleArn: - Value: !GetAtt SeahavenSlackBotDeployRole.Arn + # SeahavenSlackBotDeployRoleArn removed 2026-07-27: the role was deleted + # out-of-band on 2026-07-23, so this !GetAtt failed as a live IAM read and + # broke every stack update. Nothing imported it (the Output had no + # ExportName, and no stack imports any export from this stack). ExecAideDeployRoleArn: Value: !GetAtt ExecAideDeployRole.Arn SeahavenDoorUnlockApiDeployRoleArn: