* feat(iam): import hcptf roles into app Terraform (PLAT-146)
Move the existing hcptf pair into this repo so app Terraform owns prod IAM after the substrate handoff.
* fix(iam): attach scoped IAM as a managed policy (PLAT-146)
The apply role's services inline already uses 6894 of 10240 bytes, so a second inline policy cannot hold scoped IAM.
* fix(iam): add apply-role IAM list permissions (PLAT-146)
IamReadOnly omitted ListRoleTags and ListInstanceProfilesForRole needed after detaching the substrate guardrail.
* fix(iam): allow ListPolicyTags on scoped IAM policy (PLAT-146)
tagged managed scoped IAM is refreshed with ListPolicyTags; apply IamReadOnly and plan-refresh omitted it.