payments-dashboard/SETUP.md
Adam Moussa 0e3e95c240
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79) (#109)
* feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79)

Replace the mgmt SAM stack with a prod-only HCP workspace using the afterhours stub-plus-zip-CD seam so GitHub Actions owns function code and Terraform owns infrastructure.

* fix(infra): pin secret and CMK ARNs for bootstrap-plan

hcptf-bootstrap-plan cannot ssm:GetParameter or DescribeSecret, so the first plan must not data-source those values.

* fix(infra): add EIP describe and DynamoDB CMK grants for first apply

Scoped apply missed ec2:DescribeAddressesAttribute and kms Encrypt/Decrypt/GenerateDataKey on the table CMK.
2026-09-16 18:29:01 +00:00

3.3 KiB

Payments Dashboard — Setup Guide

Prod only. Workspace payments-dashboard-prod in project seahaven-prod (account 011934824531). No seahaven-dev workspace.

1. Secrets

Six Secrets Manager names already exist in seahaven-prod (copied from mgmt with trailing newlines stripped). Terraform reads them by name; values stay out of state.

Name Used by
payments-dashboard/slack-bot-token slackAppHome
payments-dashboard/slack-signing-secret slackAppHome
payments-dashboard/boa-check-mgmt processPaymentCsv
payments-dashboard/boa-reporting fetchBoaTransactions
payments-dashboard/expense-slack-token expenseProcessor
payments-dashboard/expense-slack-signing-secret expenseReceiver

2. HCP Terraform and GitHub Environment

First apply uses the hcptf-bootstrap window (exact StringEquals trust, never StringLike):

  1. Create the HCP workspace. Auto-apply off. No project-level variable set. Working directory terraform. File trigger prefix terraform/** only. Speculative plans on. VCS on main.
  2. From seahaven-org-baseline: scripts/create-hcptf-bootstrap-roles.sh --account prod --allow-workspace payments-dashboard-prod
  3. Point workspace TFC_AWS_APPLY_ROLE_ARN / TFC_AWS_PLAN_ROLE_ARN at hcptf-bootstrap / hcptf-bootstrap-plan. Set TFC_AWS_PROVIDER_AUTH=true.
  4. One manual apply with schedules_enabled=false. This creates the scoped hcptf-* roles, the Lambda boundary, VPC/NAT, and the rest of the stack.
  5. Retarget TFC_AWS_* to hcptf-payments-dashboard / hcptf-payments-dashboard-plan. Re-run the create script with no --allow-workspace.
  6. Second manual apply as the scoped role. Then seal auto-apply on after live-path proof.

GitHub Environment prod: reviewers, branch policy main only, Environment variable DEPLOY_ROLE_ARN = Terraform output github_deploy_role_arn.

Function zips: Actions → Deploy on push to main, or workflow_dispatch. Keep schedules_enabled=false until Slack Request URLs and the Stampli uploader point at this stack.

HCP outputs to copy: slack_request_url, expense_slack_events_url, csv_bucket_name, static_outbound_ip, github_deploy_role_arn.

3. Bank of America IP whitelist

Submit static_outbound_ip to CashPro before any real Check Management or Reporting call. The NAT EIP is new in seahaven-prod; mgmt 52.86.95.107 stays until cutover.

4. Prod cutover (PLAT-79)

Avoid weekday 9am ET and the 16:00/19:00/22:00 UTC intraday slots.

  1. Merge this repo's PR (SAM CD is gone). First HCP apply is the bootstrap window above with schedules_enabled=false.
  2. Copy DynamoDB PaymentsDashboard mgmt → prod. Verify item counts for payment#, boa_recon#, and boa_balance#. Do not copy seahaven-payments-boa-raw-*.
  3. GHA workflow_dispatch (or the merge deploy; re-run if it raced apply) to overwrite stubs.
  4. Instant cut: Slack App Home and Expense bot Request URLs → prod; Stampli uploader bucket → seahaven-payments-csv-011934824531; schedules_enabled=true via a terraform-only merge; disable mgmt EventBridge.
  5. After soak, delete mgmt stack payments-dashboard. Expect VPC ENI drain. Leave mgmt raw bucket as Retain cold archive. Sweep mgmt secrets last. Leave orphan githubdeploy-payments-dashboard.