file-share/AGENTS.md
Adam Moussa bbbdacd01c
docs(infra): drop the management rollback hold (PLAT-77) (#59)
The old volume, cutover snapshots, and management secrets are deleted, so the docs no longer tell anyone to keep them.
2026-09-29 20:22:41 -04:00

40 lines
2.1 KiB
Markdown

# AGENTS.md
Instructions for coding agents working in this repository.
## Live path
The share runs in seahaven-prod under HCP Terraform workspace `file-share-prod`. Source is `terraform/`. Manual apply until the move is sealed. Do not enable auto-apply as part of a docs or cleanup change.
The management-account CDK stack was deleted on 2026-09-29. Do not run `cdk deploy`. `lib/` and `bin/` are the retired stack. The CDK deploy workflow has been removed.
The data volume is attached by the workspace variable `data_volume_id`. Terraform must not create or delete it. The previous management volume was deleted on 2026-09-29.
## Infrastructure as Code principles
- **Exact-pin CDK library versions** if you touch the retired CDK package. Never use `*` or `^` ranges.
- **Never commit** account IDs, role ARNs, VPC IDs, subnet IDs, or new volume IDs. The live volume id is an HCP variable.
- **Deploy with least-privilege IAM.** The instance role has SSM core plus Secrets Manager read on `file-share/*`.
- Do not commit `cdk.out/`.
## Instance replacement
`user_data_replace_on_change` is false. Before any apply that would replace the instance (AMI, user data, instance type):
1. Read the plan and confirm the instance is being replaced.
2. Stop and ask for confirmation. Replacement detaches the data volume.
3. Snapshot the volume first. If a DLM snapshot from the same day exists, use that instead of a second copy.
## Security group rules
- No `0.0.0.0/0` ingress. Ingress is TCP 445, 8080, and 22 from `10.10.0.0/16` and `10.30.0.0/16`.
- Egress `0.0.0.0/0` stays so the instance can install packages and reach the pinned FileBrowser download.
- SSM Session Manager for instance access. No SSH key and no public port 22. SFTP for user `adam` is the office path, not an admin login.
## Secrets
Stored in AWS Secrets Manager (`file-share/smb-password`, `file-share/filebrowser-password`) in seahaven-prod. The instance role reads them at boot. Do not embed secrets in user data or source files. The management-account copies were deleted on 2026-09-29.
## Documentation
The Confluence "AWS Architecture Map" (page 1540098) should be updated alongside any architecture change.