mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 13:03:14 +00:00
Remove push-to-main cd-cdk workflow, document HCP apply + dispose runbook, and park githubdeploy-procurement-ingest for a later IAM cleanup.
3.8 KiB
3.8 KiB
PLAT-86 import map (seahaven-prod 011934824531 / us-east-1)
Frozen from live DescribeStackResources on 2026-08-06. CFN resource total: 164 (46 + 62 + 56). Estimated Terraform resources after expansion: ~220–320 — under HCP free-tier 500.
Workspace: one procurement-ingest-prod covering all three former stacks.
Out-of-band (data source / do not recreate)
| Dependency | Value |
|---|---|
| SES ruleset | INBOUND_MAIL |
| SNS | arn:aws:sns:us-east-1:011934824531:site-alerts |
| SSM CMK | /seahaven/dynamodb/cmk-arn → arn:aws:kms:us-east-1:011934824531:key/be5fa4cb-c546-40fe-a13d-c7bec79f5d12 |
| SSM ACM | /procurement-api/custom-domain/certificate-arn → arn:aws:acm:us-east-1:011934824531:certificate/9eac4c03-6850-49f1-baa1-6c4e7fffd1c7 |
| Secret (imported shell) | arn:aws:secretsmanager:us-east-1:011934824531:secret:procurement-ingest/web-ui-auth-token-ApAMmr |
| Mgmt Route53 | procurement-api.seahaven.com alias — stays OOB |
CFN disposal disposition
Executable runbook: cfn-dispose.md + scripts/plat86-cfn-dispose.sh (retain-all, then delete-stack; never cfn-stack-decommission.sh --execute).
| Class | Disposition on CFN stack delete |
|---|---|
| DynamoDB tables, email S3 buckets, Lambda log groups | RETAIN (must already be TF-owned; never delete) |
Named SQS (workorder-shoc-emitter-*), SHOC secret/KMS/ResourcePolicy, API GW, Lambdas, alarms, SES receipt rules |
TF-owned (import aws_secretsmanager_secret_policy.shoc_webhook_hmac before disposal); remove from CFN via retain-on-delete or deletion_policy before stack delete |
CDK Custom::S3BucketNotifications |
Do not destroy via the CFN delete-handler. That handler calls empty PutBucketNotificationConfiguration and wipes TF-owned aws_s3_bucket_notification on the PO/WO email buckets. After Terraform apply owns notifications: orphan/retain the custom resource (or otherwise skip its delete cleanup), then destroy BucketNotificationsHandler Lambda/role with CFN. Immediately verify GetBucketNotificationConfiguration still lists the inbound Lambda triggers; if cleared, re-apply Terraform before accepting traffic. |
BucketNotificationsHandler Lambda/role (+ handler IAM policy) |
After retain-all stack delete, sweep orphaned handler Lambdas/roles manually (script step 4) |
| CDK Metadata | Orphaned with retain-all; harmless |
CDK-generated IAM roles at path / |
After Lambda repoint to /tf-managed/, sweep unused leftovers in a follow-up IAM pass |
Key physical IDs to preserve
- Lambdas:
po-email-processor,po-web-ui,po-ingest-site-extractor,workorder-email-processor,workorder-web-ui,workorder-shoc-emitter,workorder-shoc-hmac-rotator,procurement-api - Tables:
purchase-orders,verified-sites,pending-site-review,WorkOrders,WorkOrderComments(PascalCase kept for import) - Buckets:
po-ingest-emails-011934824531,workorder-ingest-emails-011934824531 - Queues:
workorder-shoc-emitter-failures,workorder-shoc-emitter-rejected, plus CDK-named DLQs - Domain:
procurement-api.seahaven.com(mgmt Route53 OOB) - API REST id:
mvul1efda2 - SHOC KMS: alias
workorder-ingest-shoc-webhook-kms(key id in live inventory JSON only) - Secret:
workorder-ingest/shoc-webhook-hmac
Cross-account pins (must stay byte-stable)
- API resource policy principal:
arn:aws:iam::396287094661:role/shoc-backend-dev - SHOC KMS decrypt: exact ARN +
kms:ViaServicefor Secrets Manager - Webhook URL:
https://api.dev.seahaven.com/api/webhooks/work-orders
Raw dumps
po-ingest-resources.jsonWorkorderIngestStack-resources.jsonprocurement-api-resources.jsonraw-inventory.tsv
Import blocks: terraform/imports.tf