* feat(iam): import hcptf roles into app Terraform (PLAT-146)
Move the existing prod plan/apply pair into this repo. First apply uses the bootstrap window because DenySelfMutation blocks self-detach of seahaven-hcptf-iam-management.
* fix(iam): let the plan role refresh imported hcptf roles (PLAT-146)
The scoped plan-refresh sidecar only covered tf-managed/afi-*. After import, plans need GetRole on the hcptf pair in this workspace.
* style(iam): terraform fmt hcp_iam.tf (PLAT-146)
CI terraform fmt -check failed on alignment in the apply-services document.
* fix(iam): tighten plan-refresh and scoped boundary pin (PLAT-146)
Plan-refresh copied lambda:* from apply, so a plan session could mutate afi functions. Drop the unsuffixed org-wide Lambda boundary so scoped apply cannot retarget exec roles onto that ceiling.
* fix(iam): replace deprecated managed_policy_arns (PLAT-146)
Keep exclusive attachment control so the apply role stays empty and the plan role keeps ViewOnlyAccess.
* ci(iam): retrigger HCP commit status (PLAT-146)