* feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79) Replace the mgmt SAM stack with a prod-only HCP workspace using the afterhours stub-plus-zip-CD seam so GitHub Actions owns function code and Terraform owns infrastructure. * fix(infra): pin secret and CMK ARNs for bootstrap-plan hcptf-bootstrap-plan cannot ssm:GetParameter or DescribeSecret, so the first plan must not data-source those values. * fix(infra): add EIP describe and DynamoDB CMK grants for first apply Scoped apply missed ec2:DescribeAddressesAttribute and kms Encrypt/Decrypt/GenerateDataKey on the table CMK.
3.3 KiB
Payments Dashboard — Setup Guide
Prod only. Workspace payments-dashboard-prod in project seahaven-prod
(account 011934824531). No seahaven-dev workspace.
1. Secrets
Six Secrets Manager names already exist in seahaven-prod (copied from mgmt with trailing newlines stripped). Terraform reads them by name; values stay out of state.
| Name | Used by |
|---|---|
payments-dashboard/slack-bot-token |
slackAppHome |
payments-dashboard/slack-signing-secret |
slackAppHome |
payments-dashboard/boa-check-mgmt |
processPaymentCsv |
payments-dashboard/boa-reporting |
fetchBoaTransactions |
payments-dashboard/expense-slack-token |
expenseProcessor |
payments-dashboard/expense-slack-signing-secret |
expenseReceiver |
2. HCP Terraform and GitHub Environment
First apply uses the hcptf-bootstrap window (exact StringEquals trust, never
StringLike):
- Create the HCP workspace. Auto-apply off. No project-level variable set.
Working directory
terraform. File trigger prefixterraform/**only. Speculative plans on. VCS onmain. - From
seahaven-org-baseline:scripts/create-hcptf-bootstrap-roles.sh --account prod --allow-workspace payments-dashboard-prod - Point workspace
TFC_AWS_APPLY_ROLE_ARN/TFC_AWS_PLAN_ROLE_ARNathcptf-bootstrap/hcptf-bootstrap-plan. SetTFC_AWS_PROVIDER_AUTH=true. - One manual apply with
schedules_enabled=false. This creates the scopedhcptf-*roles, the Lambda boundary, VPC/NAT, and the rest of the stack. - Retarget
TFC_AWS_*tohcptf-payments-dashboard/hcptf-payments-dashboard-plan. Re-run the create script with no--allow-workspace. - Second manual apply as the scoped role. Then seal auto-apply on after live-path proof.
GitHub Environment prod: reviewers, branch policy main only, Environment
variable DEPLOY_ROLE_ARN = Terraform output github_deploy_role_arn.
Function zips: Actions → Deploy on push to main, or workflow_dispatch.
Keep schedules_enabled=false until Slack Request URLs and the Stampli
uploader point at this stack.
HCP outputs to copy: slack_request_url, expense_slack_events_url,
csv_bucket_name, static_outbound_ip, github_deploy_role_arn.
3. Bank of America IP whitelist
Submit static_outbound_ip to CashPro before any real Check Management or
Reporting call. The NAT EIP is new in seahaven-prod; mgmt 52.86.95.107 stays
until cutover.
4. Prod cutover (PLAT-79)
Avoid weekday 9am ET and the 16:00/19:00/22:00 UTC intraday slots.
- Merge this repo's PR (SAM CD is gone). First HCP apply is the bootstrap
window above with
schedules_enabled=false. - Copy DynamoDB
PaymentsDashboardmgmt → prod. Verify item counts forpayment#,boa_recon#, andboa_balance#. Do not copyseahaven-payments-boa-raw-*. - GHA
workflow_dispatch(or the merge deploy; re-run if it raced apply) to overwrite stubs. - Instant cut: Slack App Home and Expense bot Request URLs → prod;
Stampli uploader bucket →
seahaven-payments-csv-011934824531;schedules_enabled=truevia a terraform-only merge; disable mgmt EventBridge. - After soak, delete mgmt stack
payments-dashboard. Expect VPC ENI drain. Leave mgmt raw bucket as Retain cold archive. Sweep mgmt secrets last. Leave orphangithubdeploy-payments-dashboard.