Commit graph

4 commits

Author SHA1 Message Date
Adam Moussa
5ff8099b7f
ci: require ci-complete for test and Terraform (#121)
Some checks are pending
Deploy / Deploy to dev (push) Waiting to run
Deploy / Deploy to prod (push) Waiting to run
* ci: aggregate test and Terraform as ci-complete

Converted callers emit that check so this repo can leave the ci / ci ruleset.

* ci: add Prettier format and format:check

The autofix prettier preset runs npm run format, and CI fails closed when the tree is unformatted.
2026-10-01 21:39:38 -04:00
Adam Moussa
7c2c806339
refactor(iam): forget in-repo HCP exec roles (#120)
Some checks are pending
Deploy / Deploy to dev (push) Waiting to run
Deploy / Deploy to prod (push) Waiting to run
* refactor(iam): forget in-repo HCP exec roles

Org-baseline owns the apply and plan roles, so this workspace can assume them without a bootstrap window. Prod state forgets the old addresses without destroying the live roles.

* ci(terraform): pin the isolation check to v1.0.21

The pre-release pin cloned the private .github repo with the caller token and the Terraform job failed. v1.0.21 loads the checker from the workflow commit.
2026-10-01 21:29:22 -04:00
Adam Moussa
30a1737345
feat(ci): deploy Lambda zips through the org reusable (PLAT-79) (#119)
Some checks failed
Deploy / Deploy to dev (push) Has been cancelled
Deploy / Deploy to prod (push) Has been cancelled
* feat(ci): deploy Lambda zips through the org reusable (PLAT-79)

* fix(iam): trust only this account's deploy environment (PLAT-79)
2026-09-28 19:41:09 +00:00
Adam Moussa
0e3e95c240
feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79) (#109)
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79)

Replace the mgmt SAM stack with a prod-only HCP workspace using the afterhours stub-plus-zip-CD seam so GitHub Actions owns function code and Terraform owns infrastructure.

* fix(infra): pin secret and CMK ARNs for bootstrap-plan

hcptf-bootstrap-plan cannot ssm:GetParameter or DescribeSecret, so the first plan must not data-source those values.

* fix(infra): add EIP describe and DynamoDB CMK grants for first apply

Scoped apply missed ec2:DescribeAddressesAttribute and kms Encrypt/Decrypt/GenerateDataKey on the table CMK.
2026-09-16 18:29:01 +00:00