* ci: aggregate test and Terraform as ci-complete Converted callers emit that check so this repo can leave the ci / ci ruleset. * ci: add Prettier format and format:check The autofix prettier preset runs npm run format, and CI fails closed when the tree is unformatted.
4.3 KiB
Payments Dashboard — Setup Guide
Two workspaces, one configuration, selected by HCP variable environment:
| Workspace | Project | Account | environment |
boa_base_url |
|---|---|---|---|---|
payments-dashboard-prod |
seahaven-prod |
011934824531 |
prod |
https://api.bofa.com |
payments-dashboard-dev |
seahaven-dev |
710827005802 |
dev |
https://api-sb.bofa.com |
Both carry tag app:payments-dashboard. schedules_enabled stays false until cutover.
1. Secrets
Six Secrets Manager names exist in each account. Terraform pins the exact
ARNs in terraform/locals.tf. Values stay out of state. Dev shells are not
copies of the prod secrets.
| Name | Used by |
|---|---|
payments-dashboard/slack-bot-token |
slackAppHome |
payments-dashboard/slack-signing-secret |
slackAppHome |
payments-dashboard/boa-check-mgmt |
processPaymentCsv |
payments-dashboard/boa-reporting |
fetchBoaTransactions |
payments-dashboard/expense-slack-token |
expenseProcessor |
payments-dashboard/expense-slack-signing-secret |
expenseReceiver |
2. HCP Terraform and GitHub Environments
hcptf-payments-dashboard, hcptf-payments-dashboard-plan, and
payments-dashboard-lambda-boundary live in org-baseline stack
seahaven-hcptf, one pair per account. This repo does not create them.
Prod state already has the old copies. terraform/removed.tf forgets those
addresses and does not destroy them.
- Tag the workspace
app:payments-dashboard. Working directoryterraform. VCS onmain. Trigger prefixterraform/**. Speculative plans on. Setenvironment,schedules_enabled=false, andboa_base_url. No project-level variable set. - Point
TFC_AWS_APPLY_ROLE_ARN/TFC_AWS_PLAN_ROLE_ARNathcptf-payments-dashboard/hcptf-payments-dashboard-planin that account. SetTFC_AWS_PROVIDER_AUTH=true. - Apply only after
seahaven-hcptfhas created those roles andarn:aws:iam::<account>:policy/tf-managed/payments-dashboard-lambda-boundary.
Prod roles already exist. A dev apply waits until the same names exist in
710827005802.
GitHub Environment dev: no reviewers. DEPLOY_ROLE_ARN is the dev
github_deploy_role_arn. Environment prod: reviewers, branch policy main
and v*, prod github_deploy_role_arn.
Function zips: push to main deploys dev. A human
gh release create vX.Y.Z --target main deploys prod (ship-gate on).
workflow_dispatch takes environment and ref. The caller is
.github/workflows/deploy.yaml. It calls org reusable cd-hcp-lambda.yaml.
Keep schedules_enabled=false until Slack Request URLs and the Stampli
uploader point at the prod stack.
HCP outputs to copy: slack_request_url, expense_slack_events_url,
csv_bucket_name, static_outbound_ip, github_deploy_role_arn.
3. Bank of America IP whitelist
Submit static_outbound_ip to CashPro before any real Check Management or
Reporting call. The NAT EIP is new in seahaven-prod; mgmt 52.86.95.107 stays
until cutover.
4. Prod cutover (PLAT-79)
Avoid weekday 9am ET and the 16:00/19:00/22:00 UTC intraday slots.
- Prod infrastructure is already applied. Exec roles stay
hcptf-payments-dashboardandhcptf-payments-dashboard-plan, owned by org-baseline stackseahaven-hcptf.schedules_enabledstays false until cutover. - Copy DynamoDB
PaymentsDashboardmgmt → prod. Verify item counts forpayment#,boa_recon#, andboa_balance#. Do not copyseahaven-payments-boa-raw-*. - Prod zip update is a human release, or
workflow_dispatchwithenvironment=prod, after the HCP apply. Re-run if the job raced apply. - Instant cut: Slack App Home and Expense bot Request URLs → prod;
Stampli uploader bucket →
seahaven-payments-csv-011934824531;schedules_enabled=truevia a terraform-only merge; disable mgmt EventBridge. - After soak, delete mgmt stack
payments-dashboard. Expect VPC ENI drain. Leave mgmt raw bucket as Retain cold archive. Sweep mgmt secrets last. Leave orphangithubdeploy-payments-dashboard.