diff --git a/docs/plat-86/import-map.md b/docs/plat-86/import-map.md index 0b3e998..f5d002b 100644 --- a/docs/plat-86/import-map.md +++ b/docs/plat-86/import-map.md @@ -20,8 +20,9 @@ Workspace: one `procurement-ingest-prod` covering all three former stacks. | Class | Disposition on CFN stack delete | |---|---| | DynamoDB tables, email S3 buckets, Lambda log groups | **RETAIN** (must already be TF-owned; never delete) | -| Named SQS (`workorder-shoc-emitter-*`), SHOC secret/KMS, API GW, Lambdas, alarms, SES receipt rules | TF-owned; remove from CFN via retain-on-delete or deletion_policy before stack delete | -| CDK custom resources (`Custom::S3BucketNotifications`, `BucketNotificationsHandler` Lambda/role) | **Destroy with CFN** — replaced by native `aws_s3_bucket_notification` | +| Named SQS (`workorder-shoc-emitter-*`), SHOC secret/KMS/**ResourcePolicy**, API GW, Lambdas, alarms, SES receipt rules | TF-owned (import `aws_secretsmanager_secret_policy.shoc_webhook_hmac` before disposal); remove from CFN via retain-on-delete or deletion_policy before stack delete | +| CDK `Custom::S3BucketNotifications` | **Do not destroy via the CFN delete-handler.** That handler calls empty `PutBucketNotificationConfiguration` and wipes TF-owned `aws_s3_bucket_notification` on the PO/WO email buckets. After Terraform apply owns notifications: orphan/retain the custom resource (or otherwise skip its delete cleanup), then destroy `BucketNotificationsHandler` Lambda/role with CFN. Immediately verify `GetBucketNotificationConfiguration` still lists the inbound Lambda triggers; if cleared, re-apply Terraform before accepting traffic. | +| `BucketNotificationsHandler` Lambda/role (+ handler IAM policy) | Destroy with CFN only after notifications are TF-owned and the custom resource is orphaned/removed without clearing the bucket config | | CDK Metadata | Destroy with CFN | | CDK-generated IAM roles at path `/` | After Lambda repoint to `/tf-managed/`, delete with CFN or sweep | diff --git a/terraform/imports.tf b/terraform/imports.tf index 7351759..527bce2 100644 --- a/terraform/imports.tf +++ b/terraform/imports.tf @@ -184,6 +184,11 @@ import { id = "arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB" } +import { + to = aws_secretsmanager_secret_policy.shoc_webhook_hmac + id = "arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB" +} + import { to = aws_secretsmanager_secret_rotation.shoc_webhook_hmac id = "arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB"