payments-dashboard/SETUP.md
Adam Moussa 0e3e95c240
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79) (#109)
* feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79)

Replace the mgmt SAM stack with a prod-only HCP workspace using the afterhours stub-plus-zip-CD seam so GitHub Actions owns function code and Terraform owns infrastructure.

* fix(infra): pin secret and CMK ARNs for bootstrap-plan

hcptf-bootstrap-plan cannot ssm:GetParameter or DescribeSecret, so the first plan must not data-source those values.

* fix(infra): add EIP describe and DynamoDB CMK grants for first apply

Scoped apply missed ec2:DescribeAddressesAttribute and kms Encrypt/Decrypt/GenerateDataKey on the table CMK.
2026-09-16 18:29:01 +00:00

74 lines
3.3 KiB
Markdown

# Payments Dashboard — Setup Guide
Prod only. Workspace `payments-dashboard-prod` in project `seahaven-prod`
(account `011934824531`). No seahaven-dev workspace.
## 1. Secrets
Six Secrets Manager names already exist in seahaven-prod (copied from mgmt
with trailing newlines stripped). Terraform reads them by name; values stay
out of state.
| Name | Used by |
|------|---------|
| `payments-dashboard/slack-bot-token` | slackAppHome |
| `payments-dashboard/slack-signing-secret` | slackAppHome |
| `payments-dashboard/boa-check-mgmt` | processPaymentCsv |
| `payments-dashboard/boa-reporting` | fetchBoaTransactions |
| `payments-dashboard/expense-slack-token` | expenseProcessor |
| `payments-dashboard/expense-slack-signing-secret` | expenseReceiver |
## 2. HCP Terraform and GitHub Environment
First apply uses the hcptf-bootstrap window (exact `StringEquals` trust, never
`StringLike`):
1. Create the HCP workspace. Auto-apply off. No project-level variable set.
Working directory `terraform`. File trigger prefix `terraform/**` only.
Speculative plans on. VCS on `main`.
2. From `seahaven-org-baseline`:
`scripts/create-hcptf-bootstrap-roles.sh --account prod --allow-workspace payments-dashboard-prod`
3. Point workspace `TFC_AWS_APPLY_ROLE_ARN` / `TFC_AWS_PLAN_ROLE_ARN` at
`hcptf-bootstrap` / `hcptf-bootstrap-plan`. Set `TFC_AWS_PROVIDER_AUTH=true`.
4. One manual apply with `schedules_enabled=false`. This creates the scoped
`hcptf-*` roles, the Lambda boundary, VPC/NAT, and the rest of the stack.
5. Retarget `TFC_AWS_*` to `hcptf-payments-dashboard` /
`hcptf-payments-dashboard-plan`. Re-run the create script with no
`--allow-workspace`.
6. Second manual apply as the scoped role. Then seal auto-apply on after
live-path proof.
GitHub Environment `prod`: reviewers, branch policy `main` only, Environment
variable `DEPLOY_ROLE_ARN` = Terraform output `github_deploy_role_arn`.
Function zips: Actions → Deploy on push to `main`, or `workflow_dispatch`.
Keep `schedules_enabled=false` until Slack Request URLs and the Stampli
uploader point at this stack.
HCP outputs to copy: `slack_request_url`, `expense_slack_events_url`,
`csv_bucket_name`, `static_outbound_ip`, `github_deploy_role_arn`.
## 3. Bank of America IP whitelist
Submit `static_outbound_ip` to CashPro before any real Check Management or
Reporting call. The NAT EIP is new in seahaven-prod; mgmt `52.86.95.107` stays
until cutover.
## 4. Prod cutover (PLAT-79)
Avoid weekday 9am ET and the 16:00/19:00/22:00 UTC intraday slots.
1. Merge this repo's PR (SAM CD is gone). First HCP apply is the bootstrap
window above with `schedules_enabled=false`.
2. Copy DynamoDB `PaymentsDashboard` mgmt → prod. Verify item counts for
`payment#`, `boa_recon#`, and `boa_balance#`. Do not copy
`seahaven-payments-boa-raw-*`.
3. GHA `workflow_dispatch` (or the merge deploy; re-run if it raced apply) to
overwrite stubs.
4. Instant cut: Slack App Home and Expense bot Request URLs → prod;
Stampli uploader bucket → `seahaven-payments-csv-011934824531`;
`schedules_enabled=true` via a terraform-only merge; disable mgmt
EventBridge.
5. After soak, delete mgmt stack `payments-dashboard`. Expect VPC ENI drain.
Leave mgmt raw bucket as Retain cold archive. Sweep mgmt secrets last.
Leave orphan `githubdeploy-payments-dashboard`.