Merge pull request #163 from Sea-Haven-Industries/fix/cfn-dispose-s3-template

fix(scripts): stage CFN dispose templates via S3 (PLAT-86)
This commit is contained in:
Adam Moussa 2026-08-07 11:42:48 -04:00 • committed by GitHub
commit e54e53d0e8
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 12 additions and 2 deletions

View file

@ -23,3 +23,6 @@ Never run `cfn-stack-decommission.sh --execute` against these stacks. That scrip
## Script
`scripts/plat86-cfn-dispose.sh` implements steps 1–4 with explicit confirms and post-checks.
Retain-all templates exceed the CloudFormation CLI 51KB inline `--template-body` limit, so the script stages them to `s3://procurement-ingest-artifacts-011934824531/plat86-cfn-dispose/` and updates via `--template-url`.

View file

@ -20,6 +20,9 @@ PROFILE="${AWS_PROFILE:-seahaven-prod}"
STACKS=(po-ingest WorkorderIngestStack procurement-api)
PO_BUCKET="po-ingest-emails-011934824531"
WO_BUCKET="workorder-ingest-emails-011934824531"
# Staging for retain-all templates (inline --template-body is capped at 51KB).
TEMPLATE_BUCKET="${PLAT86_TEMPLATE_BUCKET:-procurement-ingest-artifacts-011934824531}"
TEMPLATE_PREFIX="plat86-cfn-dispose"
MODE=""
aws_cmd() {
@ -126,10 +129,14 @@ for stack in "${STACKS[@]}"; do
echo "dry-run: would update-stack ${stack} then delete-stack"
continue
fi
echo "==> update-stack ${stack} (retain-all)"
echo "==> update-stack ${stack} (retain-all via s3://${TEMPLATE_BUCKET})"
key="${TEMPLATE_PREFIX}/${stack}-retain-$(date -u +%Y%m%dT%H%M%SZ).json"
aws_cmd s3 cp "${work_dir}/${stack}.retain.json" "s3://${TEMPLATE_BUCKET}/${key}" >/dev/null
# us-east-1 regional URL form required by CloudFormation.
template_url="https://${TEMPLATE_BUCKET}.s3.${REGION}.amazonaws.com/${key}"
aws_cmd cloudformation update-stack \
--stack-name "${stack}" \
--template-body "file://${work_dir}/${stack}.retain.json" \
--template-url "${template_url}" \
--capabilities CAPABILITY_NAMED_IAM \
>/dev/null
wait_stack "${stack}" "update-complete"