# Payments Dashboard — Setup Guide Two workspaces, one configuration, selected by HCP variable `environment`: | Workspace | Project | Account | `environment` | `boa_base_url` | |-----------|---------|---------|---------------|----------------| | `payments-dashboard-prod` | `seahaven-prod` | `011934824531` | `prod` | `https://api.bofa.com` | | `payments-dashboard-dev` | `seahaven-dev` | `710827005802` | `dev` | `https://api-sb.bofa.com` | Both carry tag `app:payments-dashboard`. `schedules_enabled` stays false until cutover. ## 1. Secrets Six Secrets Manager names exist in each account. Terraform pins the exact ARNs in `terraform/locals.tf`. Values stay out of state. Dev shells are not copies of the prod secrets. | Name | Used by | |------|---------| | `payments-dashboard/slack-bot-token` | slackAppHome | | `payments-dashboard/slack-signing-secret` | slackAppHome | | `payments-dashboard/boa-check-mgmt` | processPaymentCsv | | `payments-dashboard/boa-reporting` | fetchBoaTransactions | | `payments-dashboard/expense-slack-token` | expenseProcessor | | `payments-dashboard/expense-slack-signing-secret` | expenseReceiver | ## 2. HCP Terraform and GitHub Environments `hcptf-payments-dashboard`, `hcptf-payments-dashboard-plan`, and `payments-dashboard-lambda-boundary` live in org-baseline stack `seahaven-hcptf`, one pair per account. This repo does not create them. Prod state already has the old copies. `terraform/removed.tf` forgets those addresses and does not destroy them. 1. Tag the workspace `app:payments-dashboard`. Working directory `terraform`. VCS on `main`. Trigger prefix `terraform/**`. Speculative plans on. Set `environment`, `schedules_enabled=false`, and `boa_base_url`. No project-level variable set. 2. Point `TFC_AWS_APPLY_ROLE_ARN` / `TFC_AWS_PLAN_ROLE_ARN` at `hcptf-payments-dashboard` / `hcptf-payments-dashboard-plan` in that account. Set `TFC_AWS_PROVIDER_AUTH=true`. 3. Apply only after `seahaven-hcptf` has created those roles and `arn:aws:iam:::policy/tf-managed/payments-dashboard-lambda-boundary`. Prod roles already exist. A dev apply waits until the same names exist in `710827005802`. GitHub Environment `dev`: no reviewers. `DEPLOY_ROLE_ARN` is the dev `github_deploy_role_arn`. Environment `prod`: reviewers, branch policy `main` and `v*`, prod `github_deploy_role_arn`. Function zips: push to `main` deploys dev. A human `gh release create vX.Y.Z --target main` deploys prod (`ship-gate` on). `workflow_dispatch` takes `environment` and `ref`. The caller is `.github/workflows/deploy.yaml`. It calls org reusable `cd-hcp-lambda.yaml`. Keep `schedules_enabled=false` until Slack Request URLs and the Stampli uploader point at the prod stack. HCP outputs to copy: `slack_request_url`, `expense_slack_events_url`, `csv_bucket_name`, `static_outbound_ip`, `github_deploy_role_arn`. ## 3. Bank of America IP whitelist Submit `static_outbound_ip` to CashPro before any real Check Management or Reporting call. The NAT EIP is new in seahaven-prod; mgmt `52.86.95.107` stays until cutover. ## 4. Prod cutover (PLAT-79) Avoid weekday 9am ET and the 16:00/19:00/22:00 UTC intraday slots. 1. Prod infrastructure is already applied. Exec roles stay `hcptf-payments-dashboard` and `hcptf-payments-dashboard-plan`, owned by org-baseline stack `seahaven-hcptf`. `schedules_enabled` stays false until cutover. 2. Copy DynamoDB `PaymentsDashboard` mgmt → prod. Verify item counts for `payment#`, `boa_recon#`, and `boa_balance#`. Do not copy `seahaven-payments-boa-raw-*`. 3. Prod zip update is a human release, or `workflow_dispatch` with `environment=prod`, after the HCP apply. Re-run if the job raced apply. 4. Instant cut: Slack App Home and Expense bot Request URLs → prod; Stampli uploader bucket → `seahaven-payments-csv-011934824531`; `schedules_enabled=true` via a terraform-only merge; disable mgmt EventBridge. 5. After soak, delete mgmt stack `payments-dashboard`. Expect VPC ENI drain. Leave mgmt raw bucket as Retain cold archive. Sweep mgmt secrets last. Leave orphan `githubdeploy-payments-dashboard`.