* feat(ci): deploy Lambda zips through the org reusable (PLAT-79) * fix(iam): trust only this account's deploy environment (PLAT-79)
3.9 KiB
Payments Dashboard — Setup Guide
Two workspaces, one configuration, selected by HCP variable environment:
| Workspace | Project | Account | environment |
boa_base_url |
|---|---|---|---|---|
payments-dashboard-prod |
seahaven-prod |
011934824531 |
prod |
https://api.bofa.com |
payments-dashboard-dev |
seahaven-dev |
710827005802 |
dev |
https://api-sb.bofa.com |
Both carry tag app:payments-dashboard. schedules_enabled stays false until cutover.
1. Secrets
Six Secrets Manager names exist in each account. Terraform pins the exact
ARNs in terraform/locals.tf. Values stay out of state. Dev shells are not
copies of the prod secrets.
| Name | Used by |
|---|---|
payments-dashboard/slack-bot-token |
slackAppHome |
payments-dashboard/slack-signing-secret |
slackAppHome |
payments-dashboard/boa-check-mgmt |
processPaymentCsv |
payments-dashboard/boa-reporting |
fetchBoaTransactions |
payments-dashboard/expense-slack-token |
expenseProcessor |
payments-dashboard/expense-slack-signing-secret |
expenseReceiver |
2. HCP Terraform and GitHub Environments
Prod already applied. A new workspace (dev) uses one bootstrap window:
- Tag the workspace
app:payments-dashboard. Working directoryterraform. VCS onmain. Trigger prefixterraform/**. Speculative plans on. Setenvironment,schedules_enabled=false, andboa_base_url. No project-level variable set. - From
seahaven-org-baseline:scripts/create-hcptf-bootstrap-roles.sh --account <dev|prod> --allow-workspace payments-dashboard-<env> - Point that workspace's
TFC_AWS_APPLY_ROLE_ARN/TFC_AWS_PLAN_ROLE_ARNathcptf-bootstrap/hcptf-bootstrap-plan. SetTFC_AWS_PROVIDER_AUTH=true. - One manual apply. This creates the scoped
hcptf-*roles, the Lambda boundary, VPC/NAT, and the rest of the stack. - Retarget
TFC_AWS_*tohcptf-payments-dashboard/hcptf-payments-dashboard-plan. Re-run the create script with no--allow-workspace.
GitHub Environment dev: no reviewers. DEPLOY_ROLE_ARN is the dev
github_deploy_role_arn. Environment prod: reviewers, branch policy main
and v*, prod github_deploy_role_arn.
Function zips: push to main deploys dev. A human
gh release create vX.Y.Z --target main deploys prod (ship-gate on).
workflow_dispatch takes environment and ref. The caller is
.github/workflows/deploy.yaml. It calls org reusable cd-hcp-lambda.yaml.
Keep schedules_enabled=false until Slack Request URLs and the Stampli
uploader point at the prod stack.
HCP outputs to copy: slack_request_url, expense_slack_events_url,
csv_bucket_name, static_outbound_ip, github_deploy_role_arn.
3. Bank of America IP whitelist
Submit static_outbound_ip to CashPro before any real Check Management or
Reporting call. The NAT EIP is new in seahaven-prod; mgmt 52.86.95.107 stays
until cutover.
4. Prod cutover (PLAT-79)
Avoid weekday 9am ET and the 16:00/19:00/22:00 UTC intraday slots.
- Merge this repo's PR (SAM CD is gone). First HCP apply is the bootstrap
window above with
schedules_enabled=false. - Copy DynamoDB
PaymentsDashboardmgmt → prod. Verify item counts forpayment#,boa_recon#, andboa_balance#. Do not copyseahaven-payments-boa-raw-*. - Prod zip update is a human release, or
workflow_dispatchwithenvironment=prod, after the HCP apply. Re-run if the job raced apply. - Instant cut: Slack App Home and Expense bot Request URLs → prod;
Stampli uploader bucket →
seahaven-payments-csv-011934824531;schedules_enabled=truevia a terraform-only merge; disable mgmt EventBridge. - After soak, delete mgmt stack
payments-dashboard. Expect VPC ENI drain. Leave mgmt raw bucket as Retain cold archive. Sweep mgmt secrets last. Leave orphangithubdeploy-payments-dashboard.