payments-dashboard/SETUP.md
Adam Moussa 30a1737345
Some checks failed
Deploy / Deploy to dev (push) Has been cancelled
Deploy / Deploy to prod (push) Has been cancelled
feat(ci): deploy Lambda zips through the org reusable (PLAT-79) (#119)
* feat(ci): deploy Lambda zips through the org reusable (PLAT-79)

* fix(iam): trust only this account's deploy environment (PLAT-79)
2026-09-28 19:41:09 +00:00

3.9 KiB

Payments Dashboard — Setup Guide

Two workspaces, one configuration, selected by HCP variable environment:

Workspace Project Account environment boa_base_url
payments-dashboard-prod seahaven-prod 011934824531 prod https://api.bofa.com
payments-dashboard-dev seahaven-dev 710827005802 dev https://api-sb.bofa.com

Both carry tag app:payments-dashboard. schedules_enabled stays false until cutover.

1. Secrets

Six Secrets Manager names exist in each account. Terraform pins the exact ARNs in terraform/locals.tf. Values stay out of state. Dev shells are not copies of the prod secrets.

Name Used by
payments-dashboard/slack-bot-token slackAppHome
payments-dashboard/slack-signing-secret slackAppHome
payments-dashboard/boa-check-mgmt processPaymentCsv
payments-dashboard/boa-reporting fetchBoaTransactions
payments-dashboard/expense-slack-token expenseProcessor
payments-dashboard/expense-slack-signing-secret expenseReceiver

2. HCP Terraform and GitHub Environments

Prod already applied. A new workspace (dev) uses one bootstrap window:

  1. Tag the workspace app:payments-dashboard. Working directory terraform. VCS on main. Trigger prefix terraform/**. Speculative plans on. Set environment, schedules_enabled=false, and boa_base_url. No project-level variable set.
  2. From seahaven-org-baseline: scripts/create-hcptf-bootstrap-roles.sh --account <dev|prod> --allow-workspace payments-dashboard-<env>
  3. Point that workspace's TFC_AWS_APPLY_ROLE_ARN / TFC_AWS_PLAN_ROLE_ARN at hcptf-bootstrap / hcptf-bootstrap-plan. Set TFC_AWS_PROVIDER_AUTH=true.
  4. One manual apply. This creates the scoped hcptf-* roles, the Lambda boundary, VPC/NAT, and the rest of the stack.
  5. Retarget TFC_AWS_* to hcptf-payments-dashboard / hcptf-payments-dashboard-plan. Re-run the create script with no --allow-workspace.

GitHub Environment dev: no reviewers. DEPLOY_ROLE_ARN is the dev github_deploy_role_arn. Environment prod: reviewers, branch policy main and v*, prod github_deploy_role_arn.

Function zips: push to main deploys dev. A human gh release create vX.Y.Z --target main deploys prod (ship-gate on). workflow_dispatch takes environment and ref. The caller is .github/workflows/deploy.yaml. It calls org reusable cd-hcp-lambda.yaml. Keep schedules_enabled=false until Slack Request URLs and the Stampli uploader point at the prod stack.

HCP outputs to copy: slack_request_url, expense_slack_events_url, csv_bucket_name, static_outbound_ip, github_deploy_role_arn.

3. Bank of America IP whitelist

Submit static_outbound_ip to CashPro before any real Check Management or Reporting call. The NAT EIP is new in seahaven-prod; mgmt 52.86.95.107 stays until cutover.

4. Prod cutover (PLAT-79)

Avoid weekday 9am ET and the 16:00/19:00/22:00 UTC intraday slots.

  1. Merge this repo's PR (SAM CD is gone). First HCP apply is the bootstrap window above with schedules_enabled=false.
  2. Copy DynamoDB PaymentsDashboard mgmt → prod. Verify item counts for payment#, boa_recon#, and boa_balance#. Do not copy seahaven-payments-boa-raw-*.
  3. Prod zip update is a human release, or workflow_dispatch with environment=prod, after the HCP apply. Re-run if the job raced apply.
  4. Instant cut: Slack App Home and Expense bot Request URLs → prod; Stampli uploader bucket → seahaven-payments-csv-011934824531; schedules_enabled=true via a terraform-only merge; disable mgmt EventBridge.
  5. After soak, delete mgmt stack payments-dashboard. Expect VPC ENI drain. Leave mgmt raw bucket as Retain cold archive. Sweep mgmt secrets last. Leave orphan githubdeploy-payments-dashboard.