diff --git a/docs/plat-86/cfn-dispose.md b/docs/plat-86/cfn-dispose.md index a40a5c7..7464b9d 100644 --- a/docs/plat-86/cfn-dispose.md +++ b/docs/plat-86/cfn-dispose.md @@ -23,3 +23,6 @@ Never run `cfn-stack-decommission.sh --execute` against these stacks. That scrip ## Script `scripts/plat86-cfn-dispose.sh` implements steps 1–4 with explicit confirms and post-checks. + +Retain-all templates exceed the CloudFormation CLI 51KB inline `--template-body` limit, so the script stages them to `s3://procurement-ingest-artifacts-011934824531/plat86-cfn-dispose/` and updates via `--template-url`. + diff --git a/scripts/plat86-cfn-dispose.sh b/scripts/plat86-cfn-dispose.sh index 6b1bde8..f169819 100755 --- a/scripts/plat86-cfn-dispose.sh +++ b/scripts/plat86-cfn-dispose.sh @@ -20,6 +20,9 @@ PROFILE="${AWS_PROFILE:-seahaven-prod}" STACKS=(po-ingest WorkorderIngestStack procurement-api) PO_BUCKET="po-ingest-emails-011934824531" WO_BUCKET="workorder-ingest-emails-011934824531" +# Staging for retain-all templates (inline --template-body is capped at 51KB). +TEMPLATE_BUCKET="${PLAT86_TEMPLATE_BUCKET:-procurement-ingest-artifacts-011934824531}" +TEMPLATE_PREFIX="plat86-cfn-dispose" MODE="" aws_cmd() { @@ -126,10 +129,14 @@ for stack in "${STACKS[@]}"; do echo "dry-run: would update-stack ${stack} then delete-stack" continue fi - echo "==> update-stack ${stack} (retain-all)" + echo "==> update-stack ${stack} (retain-all via s3://${TEMPLATE_BUCKET})" + key="${TEMPLATE_PREFIX}/${stack}-retain-$(date -u +%Y%m%dT%H%M%SZ).json" + aws_cmd s3 cp "${work_dir}/${stack}.retain.json" "s3://${TEMPLATE_BUCKET}/${key}" >/dev/null + # us-east-1 regional URL form required by CloudFormation. + template_url="https://${TEMPLATE_BUCKET}.s3.${REGION}.amazonaws.com/${key}" aws_cmd cloudformation update-stack \ --stack-name "${stack}" \ - --template-body "file://${work_dir}/${stack}.retain.json" \ + --template-url "${template_url}" \ --capabilities CAPABILITY_NAMED_IAM \ >/dev/null wait_stack "${stack}" "update-complete"