payments-dashboard/SETUP.md
Adam Moussa 7c2c806339
Some checks are pending
Deploy / Deploy to dev (push) Waiting to run
Deploy / Deploy to prod (push) Waiting to run
refactor(iam): forget in-repo HCP exec roles (#120)
* refactor(iam): forget in-repo HCP exec roles

Org-baseline owns the apply and plan roles, so this workspace can assume them without a bootstrap window. Prod state forgets the old addresses without destroying the live roles.

* ci(terraform): pin the isolation check to v1.0.21

The pre-release pin cloned the private .github repo with the caller token and the Terraform job failed. v1.0.21 loads the checker from the workflow commit.
2026-10-01 21:29:22 -04:00

4 KiB

Payments Dashboard — Setup Guide

Two workspaces, one configuration, selected by HCP variable environment:

Workspace Project Account environment boa_base_url
payments-dashboard-prod seahaven-prod 011934824531 prod https://api.bofa.com
payments-dashboard-dev seahaven-dev 710827005802 dev https://api-sb.bofa.com

Both carry tag app:payments-dashboard. schedules_enabled stays false until cutover.

1. Secrets

Six Secrets Manager names exist in each account. Terraform pins the exact ARNs in terraform/locals.tf. Values stay out of state. Dev shells are not copies of the prod secrets.

Name Used by
payments-dashboard/slack-bot-token slackAppHome
payments-dashboard/slack-signing-secret slackAppHome
payments-dashboard/boa-check-mgmt processPaymentCsv
payments-dashboard/boa-reporting fetchBoaTransactions
payments-dashboard/expense-slack-token expenseProcessor
payments-dashboard/expense-slack-signing-secret expenseReceiver

2. HCP Terraform and GitHub Environments

hcptf-payments-dashboard, hcptf-payments-dashboard-plan, and payments-dashboard-lambda-boundary live in org-baseline stack seahaven-hcptf, one pair per account. This repo does not create them. Prod state already has the old copies. terraform/removed.tf forgets those addresses and does not destroy them.

  1. Tag the workspace app:payments-dashboard. Working directory terraform. VCS on main. Trigger prefix terraform/**. Speculative plans on. Set environment, schedules_enabled=false, and boa_base_url. No project-level variable set.
  2. Point TFC_AWS_APPLY_ROLE_ARN / TFC_AWS_PLAN_ROLE_ARN at hcptf-payments-dashboard / hcptf-payments-dashboard-plan in that account. Set TFC_AWS_PROVIDER_AUTH=true.
  3. Apply only after seahaven-hcptf has created those roles and arn:aws:iam::<account>:policy/tf-managed/payments-dashboard-lambda-boundary.

Prod roles already exist. A dev apply waits until the same names exist in 710827005802.

GitHub Environment dev: no reviewers. DEPLOY_ROLE_ARN is the dev github_deploy_role_arn. Environment prod: reviewers, branch policy main and v*, prod github_deploy_role_arn.

Function zips: push to main deploys dev. A human gh release create vX.Y.Z --target main deploys prod (ship-gate on). workflow_dispatch takes environment and ref. The caller is .github/workflows/deploy.yaml. It calls org reusable cd-hcp-lambda.yaml. Keep schedules_enabled=false until Slack Request URLs and the Stampli uploader point at the prod stack.

HCP outputs to copy: slack_request_url, expense_slack_events_url, csv_bucket_name, static_outbound_ip, github_deploy_role_arn.

3. Bank of America IP whitelist

Submit static_outbound_ip to CashPro before any real Check Management or Reporting call. The NAT EIP is new in seahaven-prod; mgmt 52.86.95.107 stays until cutover.

4. Prod cutover (PLAT-79)

Avoid weekday 9am ET and the 16:00/19:00/22:00 UTC intraday slots.

  1. Prod infrastructure is already applied. Exec roles stay hcptf-payments-dashboard and hcptf-payments-dashboard-plan, owned by org-baseline stack seahaven-hcptf. schedules_enabled stays false until cutover.
  2. Copy DynamoDB PaymentsDashboard mgmt → prod. Verify item counts for payment#, boa_recon#, and boa_balance#. Do not copy seahaven-payments-boa-raw-*.
  3. Prod zip update is a human release, or workflow_dispatch with environment=prod, after the HCP apply. Re-run if the job raced apply.
  4. Instant cut: Slack App Home and Expense bot Request URLs → prod; Stampli uploader bucket → seahaven-payments-csv-011934824531; schedules_enabled=true via a terraform-only merge; disable mgmt EventBridge.
  5. After soak, delete mgmt stack payments-dashboard. Expect VPC ENI drain. Leave mgmt raw bucket as Retain cold archive. Sweep mgmt secrets last. Leave orphan githubdeploy-payments-dashboard.