mirror of
https://github.com/Sea-Haven-Industries/payments-dashboard.git
synced 2026-10-03 13:53:25 +00:00
* refactor(iam): forget in-repo HCP exec roles Org-baseline owns the apply and plan roles, so this workspace can assume them without a bootstrap window. Prod state forgets the old addresses without destroying the live roles. * ci(terraform): pin the isolation check to v1.0.21 The pre-release pin cloned the private .github repo with the caller token and the Terraform job failed. v1.0.21 loads the checker from the workflow commit.
75 lines
1.1 KiB
HCL
75 lines
1.1 KiB
HCL
# hcptf-payments-dashboard, hcptf-payments-dashboard-plan, and the Lambda
|
|
# boundary moved to the seahaven-hcptf stack in seahaven-org-baseline.
|
|
# Prod state already contains them. Forget them here. Do not delete the live roles.
|
|
|
|
removed {
|
|
from = aws_iam_role.hcptf_apply
|
|
|
|
lifecycle {
|
|
destroy = false
|
|
}
|
|
}
|
|
|
|
removed {
|
|
from = aws_iam_role.hcptf_plan
|
|
|
|
lifecycle {
|
|
destroy = false
|
|
}
|
|
}
|
|
|
|
removed {
|
|
from = aws_iam_role_policy.hcptf_scoped_iam
|
|
|
|
lifecycle {
|
|
destroy = false
|
|
}
|
|
}
|
|
|
|
removed {
|
|
from = aws_iam_role_policy.hcptf_apply_services
|
|
|
|
lifecycle {
|
|
destroy = false
|
|
}
|
|
}
|
|
|
|
removed {
|
|
from = aws_iam_role_policy.hcptf_plan_refresh
|
|
|
|
lifecycle {
|
|
destroy = false
|
|
}
|
|
}
|
|
|
|
removed {
|
|
from = aws_iam_role_policy_attachment.hcptf_plan_view_only
|
|
|
|
lifecycle {
|
|
destroy = false
|
|
}
|
|
}
|
|
|
|
removed {
|
|
from = aws_iam_role_policy_attachments_exclusive.hcptf_apply
|
|
|
|
lifecycle {
|
|
destroy = false
|
|
}
|
|
}
|
|
|
|
removed {
|
|
from = aws_iam_role_policy_attachments_exclusive.hcptf_plan
|
|
|
|
lifecycle {
|
|
destroy = false
|
|
}
|
|
}
|
|
|
|
removed {
|
|
from = aws_iam_policy.lambda_boundary
|
|
|
|
lifecycle {
|
|
destroy = false
|
|
}
|
|
}
|