# PLAT-86 import map (seahaven-prod `011934824531` / us-east-1) Frozen from live `DescribeStackResources` on 2026-08-06. CFN resource total: **164** (46 + 62 + 56). Estimated Terraform resources after expansion: ~220–320 — under HCP free-tier **500**. Workspace: one `procurement-ingest-prod` covering all three former stacks. ## Out-of-band (data source / do not recreate) | Dependency | Value | |---|---| | SES ruleset | `INBOUND_MAIL` | | SNS | `arn:aws:sns:us-east-1:011934824531:site-alerts` | | SSM CMK | `/seahaven/dynamodb/cmk-arn` → `arn:aws:kms:us-east-1:011934824531:key/be5fa4cb-c546-40fe-a13d-c7bec79f5d12` | | SSM ACM | `/procurement-api/custom-domain/certificate-arn` → `arn:aws:acm:us-east-1:011934824531:certificate/9eac4c03-6850-49f1-baa1-6c4e7fffd1c7` | | Secret (imported shell) | `arn:aws:secretsmanager:us-east-1:011934824531:secret:procurement-ingest/web-ui-auth-token-ApAMmr` | | Mgmt Route53 | `procurement-api.seahaven.com` alias — stays OOB | ## CFN disposal disposition Executable runbook: [`cfn-dispose.md`](cfn-dispose.md) + `scripts/plat86-cfn-dispose.sh` (retain-all, then delete-stack; never `cfn-stack-decommission.sh --execute`). | Class | Disposition on CFN stack delete | |---|---| | DynamoDB tables, email S3 buckets, Lambda log groups | **RETAIN** (must already be TF-owned; never delete) | | Named SQS (`workorder-shoc-emitter-*`), SHOC secret/KMS/**ResourcePolicy**, API GW, Lambdas, alarms, SES receipt rules | TF-owned (import `aws_secretsmanager_secret_policy.shoc_webhook_hmac` before disposal); remove from CFN via retain-on-delete or deletion_policy before stack delete | | CDK `Custom::S3BucketNotifications` | **Do not destroy via the CFN delete-handler.** That handler calls empty `PutBucketNotificationConfiguration` and wipes TF-owned `aws_s3_bucket_notification` on the PO/WO email buckets. After Terraform apply owns notifications: orphan/retain the custom resource (or otherwise skip its delete cleanup), then destroy `BucketNotificationsHandler` Lambda/role with CFN. Immediately verify `GetBucketNotificationConfiguration` still lists the inbound Lambda triggers; if cleared, re-apply Terraform before accepting traffic. | | `BucketNotificationsHandler` Lambda/role (+ handler IAM policy) | After retain-all stack delete, sweep orphaned handler Lambdas/roles manually (script step 4) | | CDK Metadata | Orphaned with retain-all; harmless | | CDK-generated IAM roles at path `/` | After Lambda repoint to `/tf-managed/`, sweep unused leftovers in a follow-up IAM pass | ## Key physical IDs to preserve - Lambdas: `po-email-processor`, `po-web-ui`, `po-ingest-site-extractor`, `workorder-email-processor`, `workorder-web-ui`, `workorder-shoc-emitter`, `workorder-shoc-hmac-rotator`, `procurement-api` - Tables: `purchase-orders`, `verified-sites`, `pending-site-review`, `WorkOrders`, `WorkOrderComments` (PascalCase kept for import) - Buckets: `po-ingest-emails-011934824531`, `workorder-ingest-emails-011934824531` - Queues: `workorder-shoc-emitter-failures`, `workorder-shoc-emitter-rejected`, plus CDK-named DLQs - Domain: `procurement-api.seahaven.com` (mgmt Route53 OOB) - API REST id: `mvul1efda2` - SHOC KMS: alias `workorder-ingest-shoc-webhook-kms` (key id in live inventory JSON only) - Secret: `workorder-ingest/shoc-webhook-hmac` ## Cross-account pins (must stay byte-stable) - API resource policy principal: `arn:aws:iam::396287094661:role/shoc-backend-dev` - SHOC KMS decrypt: exact ARN + `kms:ViaService` for Secrets Manager - Webhook URL: `https://api.dev.seahaven.com/api/webhooks/work-orders` ## Raw dumps - [`po-ingest-resources.json`](po-ingest-resources.json) - [`WorkorderIngestStack-resources.json`](WorkorderIngestStack-resources.json) - [`procurement-api-resources.json`](procurement-api-resources.json) - [`raw-inventory.tsv`](raw-inventory.tsv) Import blocks: [`terraform/imports.tf`](../../terraform/imports.tf)