Commit graph

22 commits

Author SHA1 Message Date
renovate[bot]
1f7ca2848f
chore(deps): update terraform aws to ~> 6.65 (#215)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-21 15:44:48 +00:00
Adam Moussa
0c1dcd7844
fix(terraform): grant shoc-backend-staging HMAC and API access (PLAT-211) (#212)
Terraform still pinned only shoc-backend-dev, so the next ingest apply would drop the live staging HMAC grant.
2026-09-18 18:27:55 +00:00
Adam Moussa
650c84baa1
feat(iam): import hcptf roles into app Terraform (PLAT-146) (#206)
* feat(iam): import hcptf roles into app Terraform (PLAT-146)

Move the existing hcptf pair into this repo so app Terraform owns prod IAM after the substrate handoff.

* fix(iam): attach scoped IAM as a managed policy (PLAT-146)

The apply role's services inline already uses 6894 of 10240 bytes, so a second inline policy cannot hold scoped IAM.

* fix(iam): add apply-role IAM list permissions (PLAT-146)

IamReadOnly omitted ListRoleTags and ListInstanceProfilesForRole needed after detaching the substrate guardrail.

* fix(iam): allow ListPolicyTags on scoped IAM policy (PLAT-146)

tagged managed scoped IAM is refreshed with ListPolicyTags; apply IamReadOnly and plan-refresh omitted it.
2026-09-02 22:07:32 +00:00
Adam Moussa
f5c09757f3
feat(lambda): report unhandled Lambda errors to Sentry (PLAT-138) (#203)
* feat(lambda): report unhandled Lambda errors to Sentry

* fix(lambda): strip Sentry stack-frame locals

* style(tests): wrap long lines in sentry_init tests
2026-08-29 20:02:54 +00:00
renovate[bot]
53750fda29
chore(deps): update terraform minor and patch (#200) 2026-08-24 23:17:00 +00:00
Adam Moussa
b7bb135d7c
fix(iam): attach per-workload lambda permissions boundary (PLAT-52) (#192) 2026-08-20 16:03:04 -04:00
dependabot[bot]
c80b0a1a6e
chore(deps): bump the minor-and-patch group in /terraform with 2 updates
Bumps the minor-and-patch group in /terraform with 2 updates: [hashicorp/aws](https://github.com/hashicorp/terraform-provider-aws) and [hashicorp/external](https://github.com/hashicorp/terraform-provider-external).


Updates `hashicorp/aws` from 6.58.0 to 6.60.0
- [Release notes](https://github.com/hashicorp/terraform-provider-aws/releases)
- [Changelog](https://github.com/hashicorp/terraform-provider-aws/blob/main/CHANGELOG.md)
- [Commits](https://github.com/hashicorp/terraform-provider-aws/compare/v6.58.0...v6.60.0)

Updates `hashicorp/external` from 2.4.0 to 2.4.1
- [Release notes](https://github.com/hashicorp/terraform-provider-external/releases)
- [Changelog](https://github.com/hashicorp/terraform-provider-external/blob/main/CHANGELOG.md)
- [Commits](https://github.com/hashicorp/terraform-provider-external/compare/v2.4.0...v2.4.1)

---
updated-dependencies:
- dependency-name: hashicorp/aws
  dependency-version: 6.60.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: hashicorp/external
  dependency-version: 2.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-18 06:47:17 +00:00
cf2ba7be51
fix(terraform): codify dynamodb pitr and deletion protection 2026-08-14 12:49:31 -04:00
03926f56db
docs(infra): record kebab-only WO tables after PascalCase destroy 2026-08-14 11:32:55 -04:00
817c86d58a
chore(infra): remove PascalCase WO Dynamo table resources
Destroy WorkOrders / WorkOrderComments under HCP after the kebab soak.
Kebab work-orders / work-order-comments remain the sole live tables.
2026-08-14 11:28:38 -04:00
Adam Moussa
3f0ff8e82b
fix(wo): add DLQ age alarm before 14-day expiry 2026-08-13 17:39:06 -04:00
Adam Moussa
5464d66d19
chore(infra): tag legacy WO tables pending PLAT-11 destroy (#177)
Force an in-place DynamoDB update so HCP state records
prevent_destroy=false before the post-soak resource removal.
2026-08-07 14:44:16 -04:00
Adam Moussa
7d0f272901
chore(infra): lift prevent_destroy on legacy WO tables for PLAT-11 (#176)
Writers already use kebab tables. Allow HCP to destroy PascalCase
WorkOrders / WorkOrderComments after the ≥24h kebab soak. Docs scrub
to kebab as the live physical names; GitHub #24 noted superseded.
2026-08-07 14:26:44 -04:00
Adam Moussa
ebd5c40a34
fix(infra): import kebab-stream SHOC emitter ESMs after cutover recovery (#175)
Cutover apply updated Lambda env/IAM but ESM recreate failed until the
lambda execution boundary included kebab table ARNs. Import the
out-of-band Enabled mappings so HCP state matches live.
2026-08-07 14:20:01 -04:00
Adam Moussa
419293b8ed
feat(infra): retarget WO writers and ESMs to kebab tables (PLAT-11) (#174)
* feat(infra): retarget WO writers and ESMs to kebab Dynamo tables

Point Lambda env, IAM, emitter streams, and DDB alarms at work-orders /
work-order-comments for the PLAT-11 freeze cutover. Legacy PascalCase
tables remain in state until the decommission soak.

* style(infra): terraform fmt wo_ddb alarm map alignment
2026-08-07 14:07:57 -04:00
Adam Moussa
2e7cdc64e6
fix(infra): import PLAT-11 kebab WO Dynamo tables into HCP state (#173)
Tables were created in seahaven-prod after hcptf-procurement-ingest lacked
CreateTable on kebab ARNs; import blocks bring work-orders and
work-order-comments under Terraform ownership.
2026-08-07 13:49:27 -04:00
Adam Moussa
13efee9682
feat(infra): add kebab WO tables and PLAT-11 cutover tooling (PLAT-11) (#172)
* feat(infra): add kebab WO tables and PLAT-11 cutover tooling

Create empty work-orders/work-order-comments under Terraform while writers
stay on PascalCase; make emitter table classification env-driven and add
same-account migrate/verify plus cutover runbook.

* style(test): ruff-format shoc emitter envelope tests
2026-08-07 13:42:35 -04:00
Adam Moussa
5a3729c583
chore(infra): remove cdk tree after hcp cutover (PLAT-89) (#164)
* chore(infra): remove cdk tree after hcp cutover

Delete retired CDK sources, retarget bundle/principal contract tests to
Terraform packaging, disable CDK synth in CI, and scrub deploy-adjacent docs.

* fix(test): restore exact SHOC principal pin in terraform

Pin shoc_consumer_role_arn's Terraform default and example to the trusted
ARN, and require grant sites to consume local.shoc_consumer_role_arn only.
2026-08-07 12:20:29 -04:00
6ac10f125e
fix(infra): hash live API GW attrs for redeploy triggers 2026-08-06 20:13:06 -04:00
21e939e8e1
fix(infra): bind SES bucket policies to receipt rule ARNs 2026-08-06 19:58:19 -04:00
dd07bb973b
fix(infra): import SHOC secret policy; guard S3 cutover 2026-08-06 19:58:19 -04:00
0ba3600177
feat(infra): add HCP Terraform for procurement-ingest import-in-place 2026-08-06 17:07:40 -04:00