mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 10:23:14 +00:00
* fix: isolate dev CDK deploys on their own bootstrap qualifier (B-1) Dev synthesizes against the oswedev qualifier and the dev infra deploy role is scoped to cdk-oswedev-* — it can no longer assume the default hnb659fds bootstrap roles whose admin cfn-exec-role deploys prod, closing the cross-env escalation (OSWE-IAC-01). Prod stays on the default qualifier. * test: assert per-env bootstrap qualifier isolation + document (B-1)
43 lines
1.4 KiB
JavaScript
43 lines
1.4 KiB
JavaScript
#!/usr/bin/env node
|
|
import "source-map-support/register";
|
|
import * as cdk from "aws-cdk-lib";
|
|
import { ACCOUNT, REGION, bootstrapQualifier } from "../lib/config";
|
|
import { OpenSweIamStack } from "../lib/open-swe-iam-stack";
|
|
import { OpenSweStack } from "../lib/open-swe-stack";
|
|
import { KebabNamingAspect } from "../lib/aspects/kebab-naming-aspect";
|
|
|
|
const app = new cdk.App();
|
|
const env = { account: ACCOUNT, region: REGION };
|
|
|
|
// Account-level shared OIDC deploy roles (singletons). Deployed FIRST.
|
|
new OpenSweIamStack(app, "OpenSweIamStack", {
|
|
stackName: "open-swe-iam",
|
|
env,
|
|
});
|
|
|
|
// The two env stacks — explicit kebab-case stackName (never let CDK default to
|
|
// PascalCase), env-parameterised so resources are `open-swe-<env>-*`.
|
|
//
|
|
// B-1 / OSWE-IAC-01: dev synthesizes against its OWN bootstrap qualifier
|
|
// (`oswedev`), so it deploys via the cdk-oswedev-* roles the dev infra role is
|
|
// scoped to — and NOT the default hnb659fds bootstrap roles that deploy prod.
|
|
// Prod stays on the default qualifier (no synthesizer override).
|
|
new OpenSweStack(app, "OpenSweDevStack", {
|
|
stackName: "open-swe-dev",
|
|
env,
|
|
envName: "dev",
|
|
synthesizer: new cdk.DefaultStackSynthesizer({
|
|
qualifier: bootstrapQualifier("dev"),
|
|
}),
|
|
});
|
|
|
|
new OpenSweStack(app, "OpenSweProdStack", {
|
|
stackName: "open-swe-prod",
|
|
env,
|
|
envName: "prod",
|
|
});
|
|
|
|
// Fail synth on any non-kebab-case explicit resource/stack name.
|
|
cdk.Aspects.of(app).add(new KebabNamingAspect());
|
|
|
|
app.synth();
|