diff --git a/aws-infrastructure.md b/aws-infrastructure.md index bd6253d..b28019e 100644 --- a/aws-infrastructure.md +++ b/aws-infrastructure.md @@ -4,7 +4,8 @@ - **SAM** is the default for new serverless stacks (Lambda + API Gateway + DynamoDB) - **CDK** only for complex infrastructure (ECS, VPCs, multi-service compositions) -- Every deployed resource should be managed by CloudFormation +- **Migrating stacks** from mgmt into seahaven-prod / seahaven-dev use **HCP Terraform** (migrate-and-convert; do not convert in place in mgmt). The authoritative per-stack steps live in the `seahaven-org-baseline` README migration checklist (plan/apply role patterns, boundary widen, artifact packaging, cutover). Reference implementation: `afi-backup-monitor` (PLAT-56). +- Every deployed resource should be managed by IaC (CloudFormation via SAM/CDK, or HCP Terraform state for migrated stacks) - No manually-created Lambdas, roles, or other resources outside of IaC ## Lambda Defaults