From 2fcf14a437da5fc8d8c245af8b95433334f7e1e8 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 29 Sep 2026 20:20:12 -0400 Subject: [PATCH] docs(infra): drop the management rollback hold (PLAT-77) The old volume, cutover snapshots, and management secrets are deleted, so the docs no longer tell anyone to keep them. --- AGENTS.md | 4 ++-- README.md | 11 +---------- 2 files changed, 3 insertions(+), 12 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 6f8ea5c..f691e66 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -8,7 +8,7 @@ The share runs in seahaven-prod under HCP Terraform workspace `file-share-prod`. The management-account CDK stack was deleted on 2026-09-29. Do not run `cdk deploy`. `lib/` and `bin/` are the retired stack. The CDK deploy workflow has been removed. -The data volume is attached by the workspace variable `data_volume_id`. Terraform must not create or delete it. The previous management volume is retained until 2026-10-06 and is not the live disk. +The data volume is attached by the workspace variable `data_volume_id`. Terraform must not create or delete it. The previous management volume was deleted on 2026-09-29. ## Infrastructure as Code principles @@ -33,7 +33,7 @@ The data volume is attached by the workspace variable `data_volume_id`. Terrafor ## Secrets -Stored in AWS Secrets Manager (`file-share/smb-password`, `file-share/filebrowser-password`). The instance role reads them at boot. Do not embed secrets in user data or source files. Do not delete the management-account copies before 2026-10-06. +Stored in AWS Secrets Manager (`file-share/smb-password`, `file-share/filebrowser-password`) in seahaven-prod. The instance role reads them at boot. Do not embed secrets in user data or source files. The management-account copies were deleted on 2026-09-29. ## Documentation diff --git a/README.md b/README.md index 857aca9..e1b270c 100644 --- a/README.md +++ b/README.md @@ -34,16 +34,7 @@ The instance role reads these secrets in seahaven-prod at boot. Do not put the v | `file-share/smb-password` | Samba user password | | `file-share/filebrowser-password` | FileBrowser admin password | -Copies of the same secret names still exist in the management account until 2026-10-06. - -## Rollback hold - -The management CloudFormation stack is deleted. These stay until 2026-10-06, then they can be deleted: - -- Data volume `vol-04d951cccacc435b5` (detached) -- Snapshot `snap-090186cf7e7b49b1c` - -The management deploy role `githubdeploy-file-share` is left in place. The CDK deploy workflow is gone so a dispatch cannot recreate the stack. +The management-account copies of those secrets were deleted on 2026-09-29, along with the old data volume and its cutover snapshots. The management deploy role `githubdeploy-file-share` is left in place. The CDK deploy workflow is gone so a dispatch cannot recreate the stack. ## Expanding storage