mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 06:03:14 +00:00
fix(infra): import SHOC secret policy; guard S3 cutover
This commit is contained in:
parent
0ba3600177
commit
dd07bb973b
2 changed files with 8 additions and 2 deletions
|
|
@ -20,8 +20,9 @@ Workspace: one `procurement-ingest-prod` covering all three former stacks.
|
|||
| Class | Disposition on CFN stack delete |
|
||||
|---|---|
|
||||
| DynamoDB tables, email S3 buckets, Lambda log groups | **RETAIN** (must already be TF-owned; never delete) |
|
||||
| Named SQS (`workorder-shoc-emitter-*`), SHOC secret/KMS, API GW, Lambdas, alarms, SES receipt rules | TF-owned; remove from CFN via retain-on-delete or deletion_policy before stack delete |
|
||||
| CDK custom resources (`Custom::S3BucketNotifications`, `BucketNotificationsHandler` Lambda/role) | **Destroy with CFN** — replaced by native `aws_s3_bucket_notification` |
|
||||
| Named SQS (`workorder-shoc-emitter-*`), SHOC secret/KMS/**ResourcePolicy**, API GW, Lambdas, alarms, SES receipt rules | TF-owned (import `aws_secretsmanager_secret_policy.shoc_webhook_hmac` before disposal); remove from CFN via retain-on-delete or deletion_policy before stack delete |
|
||||
| CDK `Custom::S3BucketNotifications` | **Do not destroy via the CFN delete-handler.** That handler calls empty `PutBucketNotificationConfiguration` and wipes TF-owned `aws_s3_bucket_notification` on the PO/WO email buckets. After Terraform apply owns notifications: orphan/retain the custom resource (or otherwise skip its delete cleanup), then destroy `BucketNotificationsHandler` Lambda/role with CFN. Immediately verify `GetBucketNotificationConfiguration` still lists the inbound Lambda triggers; if cleared, re-apply Terraform before accepting traffic. |
|
||||
| `BucketNotificationsHandler` Lambda/role (+ handler IAM policy) | Destroy with CFN only after notifications are TF-owned and the custom resource is orphaned/removed without clearing the bucket config |
|
||||
| CDK Metadata | Destroy with CFN |
|
||||
| CDK-generated IAM roles at path `/` | After Lambda repoint to `/tf-managed/`, delete with CFN or sweep |
|
||||
|
||||
|
|
|
|||
|
|
@ -184,6 +184,11 @@ import {
|
|||
id = "arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_secretsmanager_secret_policy.shoc_webhook_hmac
|
||||
id = "arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_secretsmanager_secret_rotation.shoc_webhook_hmac
|
||||
id = "arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB"
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue