# Payments Dashboard — Setup Guide Prod only. Workspace `payments-dashboard-prod` in project `seahaven-prod` (account `011934824531`). No seahaven-dev workspace. ## 1. Secrets Six Secrets Manager names already exist in seahaven-prod (copied from mgmt with trailing newlines stripped). Terraform reads them by name; values stay out of state. | Name | Used by | |------|---------| | `payments-dashboard/slack-bot-token` | slackAppHome | | `payments-dashboard/slack-signing-secret` | slackAppHome | | `payments-dashboard/boa-check-mgmt` | processPaymentCsv | | `payments-dashboard/boa-reporting` | fetchBoaTransactions | | `payments-dashboard/expense-slack-token` | expenseProcessor | | `payments-dashboard/expense-slack-signing-secret` | expenseReceiver | ## 2. HCP Terraform and GitHub Environment First apply uses the hcptf-bootstrap window (exact `StringEquals` trust, never `StringLike`): 1. Create the HCP workspace. Auto-apply off. No project-level variable set. Working directory `terraform`. File trigger prefix `terraform/**` only. Speculative plans on. VCS on `main`. 2. From `seahaven-org-baseline`: `scripts/create-hcptf-bootstrap-roles.sh --account prod --allow-workspace payments-dashboard-prod` 3. Point workspace `TFC_AWS_APPLY_ROLE_ARN` / `TFC_AWS_PLAN_ROLE_ARN` at `hcptf-bootstrap` / `hcptf-bootstrap-plan`. Set `TFC_AWS_PROVIDER_AUTH=true`. 4. One manual apply with `schedules_enabled=false`. This creates the scoped `hcptf-*` roles, the Lambda boundary, VPC/NAT, and the rest of the stack. 5. Retarget `TFC_AWS_*` to `hcptf-payments-dashboard` / `hcptf-payments-dashboard-plan`. Re-run the create script with no `--allow-workspace`. 6. Second manual apply as the scoped role. Then seal auto-apply on after live-path proof. GitHub Environment `prod`: reviewers, branch policy `main` only, Environment variable `DEPLOY_ROLE_ARN` = Terraform output `github_deploy_role_arn`. Function zips: Actions → Deploy on push to `main`, or `workflow_dispatch`. Keep `schedules_enabled=false` until Slack Request URLs and the Stampli uploader point at this stack. HCP outputs to copy: `slack_request_url`, `expense_slack_events_url`, `csv_bucket_name`, `static_outbound_ip`, `github_deploy_role_arn`. ## 3. Bank of America IP whitelist Submit `static_outbound_ip` to CashPro before any real Check Management or Reporting call. The NAT EIP is new in seahaven-prod; mgmt `52.86.95.107` stays until cutover. ## 4. Prod cutover (PLAT-79) Avoid weekday 9am ET and the 16:00/19:00/22:00 UTC intraday slots. 1. Merge this repo's PR (SAM CD is gone). First HCP apply is the bootstrap window above with `schedules_enabled=false`. 2. Copy DynamoDB `PaymentsDashboard` mgmt → prod. Verify item counts for `payment#`, `boa_recon#`, and `boa_balance#`. Do not copy `seahaven-payments-boa-raw-*`. 3. GHA `workflow_dispatch` (or the merge deploy; re-run if it raced apply) to overwrite stubs. 4. Instant cut: Slack App Home and Expense bot Request URLs → prod; Stampli uploader bucket → `seahaven-payments-csv-011934824531`; `schedules_enabled=true` via a terraform-only merge; disable mgmt EventBridge. 5. After soak, delete mgmt stack `payments-dashboard`. Expect VPC ENI drain. Leave mgmt raw bucket as Retain cold archive. Sweep mgmt secrets last. Leave orphan `githubdeploy-payments-dashboard`.