# Deploy role: githubdeploy-procurement-ingest (seahaven-prod) — PARKED > **PLAT-86 (2026-08-07):** CDK CD is retired. HCP Terraform workspace > `procurement-ingest-prod` is the sole mutate path. This OIDC role is an > **unused orphan** retained for a separate IAM-reviewed cleanup (same pattern > as afi-backup-monitor / front-integrations). Do not use it for deploys. Do > not recreate a mgmt twin (deleted in PLAT-67). OIDC deploy role historically used by this repo's GitHub Actions CDK pipeline in AWS account `011934824531` (seahaven-prod), us-east-1. ## Files | File | Purpose | |---|---| | `trust-policy.json` | OIDC trust: `repo:Sea-Haven-Industries/procurement-ingest:ref:refs/heads/main` only | | `permissions-policy.json` | Historical CDK bootstrap AssumeRole + smoke InvokeFunction grants | | `create-deploy-role.sh` | Idempotent create-or-update (do not run unless deliberately restoring) | ## Retirement follow-up 1. Confirm no workflow references `AWS_DEPLOY_ROLE_ARN` / `cd-cdk.yaml`. 2. IAM + security review, then delete the role and drop related substrate entries. 3. Remove this directory in the same cleanup PR.