docs(infra): drop the management rollback hold (PLAT-77) (#59)

The old volume, cutover snapshots, and management secrets are deleted, so the docs no longer tell anyone to keep them.
This commit is contained in:
Adam Moussa 2026-09-29 20:22:41 -04:00 • committed by GitHub
parent 3a07b2e968
commit bbbdacd01c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 3 additions and 12 deletions

View file

@ -8,7 +8,7 @@ The share runs in seahaven-prod under HCP Terraform workspace `file-share-prod`.
The management-account CDK stack was deleted on 2026-09-29. Do not run `cdk deploy`. `lib/` and `bin/` are the retired stack. The CDK deploy workflow has been removed. The management-account CDK stack was deleted on 2026-09-29. Do not run `cdk deploy`. `lib/` and `bin/` are the retired stack. The CDK deploy workflow has been removed.
The data volume is attached by the workspace variable `data_volume_id`. Terraform must not create or delete it. The previous management volume is retained until 2026-10-06 and is not the live disk. The data volume is attached by the workspace variable `data_volume_id`. Terraform must not create or delete it. The previous management volume was deleted on 2026-09-29.
## Infrastructure as Code principles ## Infrastructure as Code principles
@ -33,7 +33,7 @@ The data volume is attached by the workspace variable `data_volume_id`. Terrafor
## Secrets ## Secrets
Stored in AWS Secrets Manager (`file-share/smb-password`, `file-share/filebrowser-password`). The instance role reads them at boot. Do not embed secrets in user data or source files. Do not delete the management-account copies before 2026-10-06. Stored in AWS Secrets Manager (`file-share/smb-password`, `file-share/filebrowser-password`) in seahaven-prod. The instance role reads them at boot. Do not embed secrets in user data or source files. The management-account copies were deleted on 2026-09-29.
## Documentation ## Documentation

View file

@ -34,16 +34,7 @@ The instance role reads these secrets in seahaven-prod at boot. Do not put the v
| `file-share/smb-password` | Samba user password | | `file-share/smb-password` | Samba user password |
| `file-share/filebrowser-password` | FileBrowser admin password | | `file-share/filebrowser-password` | FileBrowser admin password |
Copies of the same secret names still exist in the management account until 2026-10-06. The management-account copies of those secrets were deleted on 2026-09-29, along with the old data volume and its cutover snapshots. The management deploy role `githubdeploy-file-share` is left in place. The CDK deploy workflow is gone so a dispatch cannot recreate the stack.
## Rollback hold
The management CloudFormation stack is deleted. These stay until 2026-10-06, then they can be deleted:
- Data volume `vol-04d951cccacc435b5` (detached)
- Snapshot `snap-090186cf7e7b49b1c`
The management deploy role `githubdeploy-file-share` is left in place. The CDK deploy workflow is gone so a dispatch cannot recreate the stack.
## Expanding storage ## Expanding storage