payments-dashboard/SETUP.md
Adam Moussa 30a1737345
Some checks failed
Deploy / Deploy to dev (push) Has been cancelled
Deploy / Deploy to prod (push) Has been cancelled
feat(ci): deploy Lambda zips through the org reusable (PLAT-79) (#119)
* feat(ci): deploy Lambda zips through the org reusable (PLAT-79)

* fix(iam): trust only this account's deploy environment (PLAT-79)
2026-09-28 19:41:09 +00:00

82 lines
3.9 KiB
Markdown

# Payments Dashboard — Setup Guide
Two workspaces, one configuration, selected by HCP variable `environment`:
| Workspace | Project | Account | `environment` | `boa_base_url` |
|-----------|---------|---------|---------------|----------------|
| `payments-dashboard-prod` | `seahaven-prod` | `011934824531` | `prod` | `https://api.bofa.com` |
| `payments-dashboard-dev` | `seahaven-dev` | `710827005802` | `dev` | `https://api-sb.bofa.com` |
Both carry tag `app:payments-dashboard`. `schedules_enabled` stays false until cutover.
## 1. Secrets
Six Secrets Manager names exist in each account. Terraform pins the exact
ARNs in `terraform/locals.tf`. Values stay out of state. Dev shells are not
copies of the prod secrets.
| Name | Used by |
|------|---------|
| `payments-dashboard/slack-bot-token` | slackAppHome |
| `payments-dashboard/slack-signing-secret` | slackAppHome |
| `payments-dashboard/boa-check-mgmt` | processPaymentCsv |
| `payments-dashboard/boa-reporting` | fetchBoaTransactions |
| `payments-dashboard/expense-slack-token` | expenseProcessor |
| `payments-dashboard/expense-slack-signing-secret` | expenseReceiver |
## 2. HCP Terraform and GitHub Environments
Prod already applied. A new workspace (dev) uses one bootstrap window:
1. Tag the workspace `app:payments-dashboard`. Working directory `terraform`.
VCS on `main`. Trigger prefix `terraform/**`. Speculative plans on.
Set `environment`, `schedules_enabled=false`, and `boa_base_url`.
No project-level variable set.
2. From `seahaven-org-baseline`:
`scripts/create-hcptf-bootstrap-roles.sh --account <dev|prod> --allow-workspace payments-dashboard-<env>`
3. Point that workspace's `TFC_AWS_APPLY_ROLE_ARN` / `TFC_AWS_PLAN_ROLE_ARN` at
`hcptf-bootstrap` / `hcptf-bootstrap-plan`. Set `TFC_AWS_PROVIDER_AUTH=true`.
4. One manual apply. This creates the scoped `hcptf-*` roles, the Lambda
boundary, VPC/NAT, and the rest of the stack.
5. Retarget `TFC_AWS_*` to `hcptf-payments-dashboard` /
`hcptf-payments-dashboard-plan`. Re-run the create script with no
`--allow-workspace`.
GitHub Environment `dev`: no reviewers. `DEPLOY_ROLE_ARN` is the dev
`github_deploy_role_arn`. Environment `prod`: reviewers, branch policy `main`
and `v*`, prod `github_deploy_role_arn`.
Function zips: push to `main` deploys dev. A human
`gh release create vX.Y.Z --target main` deploys prod (`ship-gate` on).
`workflow_dispatch` takes `environment` and `ref`. The caller is
`.github/workflows/deploy.yaml`. It calls org reusable `cd-hcp-lambda.yaml`.
Keep `schedules_enabled=false` until Slack Request URLs and the Stampli
uploader point at the prod stack.
HCP outputs to copy: `slack_request_url`, `expense_slack_events_url`,
`csv_bucket_name`, `static_outbound_ip`, `github_deploy_role_arn`.
## 3. Bank of America IP whitelist
Submit `static_outbound_ip` to CashPro before any real Check Management or
Reporting call. The NAT EIP is new in seahaven-prod; mgmt `52.86.95.107` stays
until cutover.
## 4. Prod cutover (PLAT-79)
Avoid weekday 9am ET and the 16:00/19:00/22:00 UTC intraday slots.
1. Merge this repo's PR (SAM CD is gone). First HCP apply is the bootstrap
window above with `schedules_enabled=false`.
2. Copy DynamoDB `PaymentsDashboard` mgmt → prod. Verify item counts for
`payment#`, `boa_recon#`, and `boa_balance#`. Do not copy
`seahaven-payments-boa-raw-*`.
3. Prod zip update is a human release, or `workflow_dispatch` with
`environment=prod`, after the HCP apply. Re-run if the job raced apply.
4. Instant cut: Slack App Home and Expense bot Request URLs → prod;
Stampli uploader bucket → `seahaven-payments-csv-011934824531`;
`schedules_enabled=true` via a terraform-only merge; disable mgmt
EventBridge.
5. After soak, delete mgmt stack `payments-dashboard`. Expect VPC ENI drain.
Leave mgmt raw bucket as Retain cold archive. Sweep mgmt secrets last.
Leave orphan `githubdeploy-payments-dashboard`.