mirror of
https://github.com/Sea-Haven-Industries/payments-dashboard.git
synced 2026-10-03 05:43:28 +00:00
* refactor(iam): forget in-repo HCP exec roles Org-baseline owns the apply and plan roles, so this workspace can assume them without a bootstrap window. Prod state forgets the old addresses without destroying the live roles. * ci(terraform): pin the isolation check to v1.0.21 The pre-release pin cloned the private .github repo with the caller token and the Terraform job failed. v1.0.21 loads the checker from the workflow commit.
87 lines
4 KiB
Markdown
87 lines
4 KiB
Markdown
# Payments Dashboard — Setup Guide
|
|
|
|
Two workspaces, one configuration, selected by HCP variable `environment`:
|
|
|
|
| Workspace | Project | Account | `environment` | `boa_base_url` |
|
|
|-----------|---------|---------|---------------|----------------|
|
|
| `payments-dashboard-prod` | `seahaven-prod` | `011934824531` | `prod` | `https://api.bofa.com` |
|
|
| `payments-dashboard-dev` | `seahaven-dev` | `710827005802` | `dev` | `https://api-sb.bofa.com` |
|
|
|
|
Both carry tag `app:payments-dashboard`. `schedules_enabled` stays false until cutover.
|
|
|
|
## 1. Secrets
|
|
|
|
Six Secrets Manager names exist in each account. Terraform pins the exact
|
|
ARNs in `terraform/locals.tf`. Values stay out of state. Dev shells are not
|
|
copies of the prod secrets.
|
|
|
|
| Name | Used by |
|
|
|------|---------|
|
|
| `payments-dashboard/slack-bot-token` | slackAppHome |
|
|
| `payments-dashboard/slack-signing-secret` | slackAppHome |
|
|
| `payments-dashboard/boa-check-mgmt` | processPaymentCsv |
|
|
| `payments-dashboard/boa-reporting` | fetchBoaTransactions |
|
|
| `payments-dashboard/expense-slack-token` | expenseProcessor |
|
|
| `payments-dashboard/expense-slack-signing-secret` | expenseReceiver |
|
|
|
|
## 2. HCP Terraform and GitHub Environments
|
|
|
|
`hcptf-payments-dashboard`, `hcptf-payments-dashboard-plan`, and
|
|
`payments-dashboard-lambda-boundary` live in org-baseline stack
|
|
`seahaven-hcptf`, one pair per account. This repo does not create them.
|
|
Prod state already has the old copies. `terraform/removed.tf` forgets those
|
|
addresses and does not destroy them.
|
|
|
|
1. Tag the workspace `app:payments-dashboard`. Working directory `terraform`.
|
|
VCS on `main`. Trigger prefix `terraform/**`. Speculative plans on.
|
|
Set `environment`, `schedules_enabled=false`, and `boa_base_url`.
|
|
No project-level variable set.
|
|
2. Point `TFC_AWS_APPLY_ROLE_ARN` / `TFC_AWS_PLAN_ROLE_ARN` at
|
|
`hcptf-payments-dashboard` / `hcptf-payments-dashboard-plan` in that
|
|
account. Set `TFC_AWS_PROVIDER_AUTH=true`.
|
|
3. Apply only after `seahaven-hcptf` has created those roles and
|
|
`arn:aws:iam::<account>:policy/tf-managed/payments-dashboard-lambda-boundary`.
|
|
|
|
Prod roles already exist. A dev apply waits until the same names exist in
|
|
`710827005802`.
|
|
|
|
GitHub Environment `dev`: no reviewers. `DEPLOY_ROLE_ARN` is the dev
|
|
`github_deploy_role_arn`. Environment `prod`: reviewers, branch policy `main`
|
|
and `v*`, prod `github_deploy_role_arn`.
|
|
|
|
Function zips: push to `main` deploys dev. A human
|
|
`gh release create vX.Y.Z --target main` deploys prod (`ship-gate` on).
|
|
`workflow_dispatch` takes `environment` and `ref`. The caller is
|
|
`.github/workflows/deploy.yaml`. It calls org reusable `cd-hcp-lambda.yaml`.
|
|
Keep `schedules_enabled=false` until Slack Request URLs and the Stampli
|
|
uploader point at the prod stack.
|
|
|
|
HCP outputs to copy: `slack_request_url`, `expense_slack_events_url`,
|
|
`csv_bucket_name`, `static_outbound_ip`, `github_deploy_role_arn`.
|
|
|
|
## 3. Bank of America IP whitelist
|
|
|
|
Submit `static_outbound_ip` to CashPro before any real Check Management or
|
|
Reporting call. The NAT EIP is new in seahaven-prod; mgmt `52.86.95.107` stays
|
|
until cutover.
|
|
|
|
## 4. Prod cutover (PLAT-79)
|
|
|
|
Avoid weekday 9am ET and the 16:00/19:00/22:00 UTC intraday slots.
|
|
|
|
1. Prod infrastructure is already applied. Exec roles stay
|
|
`hcptf-payments-dashboard` and `hcptf-payments-dashboard-plan`, owned by
|
|
org-baseline stack `seahaven-hcptf`. `schedules_enabled` stays false until
|
|
cutover.
|
|
2. Copy DynamoDB `PaymentsDashboard` mgmt → prod. Verify item counts for
|
|
`payment#`, `boa_recon#`, and `boa_balance#`. Do not copy
|
|
`seahaven-payments-boa-raw-*`.
|
|
3. Prod zip update is a human release, or `workflow_dispatch` with
|
|
`environment=prod`, after the HCP apply. Re-run if the job raced apply.
|
|
4. Instant cut: Slack App Home and Expense bot Request URLs → prod;
|
|
Stampli uploader bucket → `seahaven-payments-csv-011934824531`;
|
|
`schedules_enabled=true` via a terraform-only merge; disable mgmt
|
|
EventBridge.
|
|
5. After soak, delete mgmt stack `payments-dashboard`. Expect VPC ENI drain.
|
|
Leave mgmt raw bucket as Retain cold archive. Sweep mgmt secrets last.
|
|
Leave orphan `githubdeploy-payments-dashboard`.
|