file-share/AGENTS.md
Adam Moussa 2fcf14a437
docs(infra): drop the management rollback hold (PLAT-77)
The old volume, cutover snapshots, and management secrets are deleted, so the docs no longer tell anyone to keep them.
2026-09-29 20:20:12 -04:00

2.1 KiB

AGENTS.md

Instructions for coding agents working in this repository.

Live path

The share runs in seahaven-prod under HCP Terraform workspace file-share-prod. Source is terraform/. Manual apply until the move is sealed. Do not enable auto-apply as part of a docs or cleanup change.

The management-account CDK stack was deleted on 2026-09-29. Do not run cdk deploy. lib/ and bin/ are the retired stack. The CDK deploy workflow has been removed.

The data volume is attached by the workspace variable data_volume_id. Terraform must not create or delete it. The previous management volume was deleted on 2026-09-29.

Infrastructure as Code principles

  • Exact-pin CDK library versions if you touch the retired CDK package. Never use * or ^ ranges.
  • Never commit account IDs, role ARNs, VPC IDs, subnet IDs, or new volume IDs. The live volume id is an HCP variable.
  • Deploy with least-privilege IAM. The instance role has SSM core plus Secrets Manager read on file-share/*.
  • Do not commit cdk.out/.

Instance replacement

user_data_replace_on_change is false. Before any apply that would replace the instance (AMI, user data, instance type):

  1. Read the plan and confirm the instance is being replaced.
  2. Stop and ask for confirmation. Replacement detaches the data volume.
  3. Snapshot the volume first. If a DLM snapshot from the same day exists, use that instead of a second copy.

Security group rules

  • No 0.0.0.0/0 ingress. Ingress is TCP 445, 8080, and 22 from 10.10.0.0/16 and 10.30.0.0/16.
  • Egress 0.0.0.0/0 stays so the instance can install packages and reach the pinned FileBrowser download.
  • SSM Session Manager for instance access. No SSH key and no public port 22. SFTP for user adam is the office path, not an admin login.

Secrets

Stored in AWS Secrets Manager (file-share/smb-password, file-share/filebrowser-password) in seahaven-prod. The instance role reads them at boot. Do not embed secrets in user data or source files. The management-account copies were deleted on 2026-09-29.

Documentation

The Confluence "AWS Architecture Map" (page 1540098) should be updated alongside any architecture change.