procurement-ingest/docs/plat-86/import-map.md

52 lines
3 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# PLAT-86 import map (seahaven-prod `011934824531` / us-east-1)
Frozen from live `DescribeStackResources` on 2026-08-06. CFN resource total: **164** (46 + 62 + 56). Estimated Terraform resources after expansion: ~220–320 — under HCP free-tier **500**.
Workspace: one `procurement-ingest-prod` covering all three former stacks.
## Out-of-band (data source / do not recreate)
| Dependency | Value |
|---|---|
| SES ruleset | `INBOUND_MAIL` |
| SNS | `arn:aws:sns:us-east-1:011934824531:site-alerts` |
| SSM CMK | `/seahaven/dynamodb/cmk-arn` → `arn:aws:kms:us-east-1:011934824531:key/be5fa4cb-c546-40fe-a13d-c7bec79f5d12` |
| SSM ACM | `/procurement-api/custom-domain/certificate-arn` → `arn:aws:acm:us-east-1:011934824531:certificate/9eac4c03-6850-49f1-baa1-6c4e7fffd1c7` |
| Secret (imported shell) | `arn:aws:secretsmanager:us-east-1:011934824531:secret:procurement-ingest/web-ui-auth-token-ApAMmr` |
| Mgmt Route53 | `procurement-api.seahaven.com` alias — stays OOB |
## CFN disposal disposition
| Class | Disposition on CFN stack delete |
|---|---|
| DynamoDB tables, email S3 buckets, Lambda log groups | **RETAIN** (must already be TF-owned; never delete) |
| Named SQS (`workorder-shoc-emitter-*`), SHOC secret/KMS, API GW, Lambdas, alarms, SES receipt rules | TF-owned; remove from CFN via retain-on-delete or deletion_policy before stack delete |
| CDK custom resources (`Custom::S3BucketNotifications`, `BucketNotificationsHandler` Lambda/role) | **Destroy with CFN** — replaced by native `aws_s3_bucket_notification` |
| CDK Metadata | Destroy with CFN |
| CDK-generated IAM roles at path `/` | After Lambda repoint to `/tf-managed/`, delete with CFN or sweep |
## Key physical IDs to preserve
- Lambdas: `po-email-processor`, `po-web-ui`, `po-ingest-site-extractor`, `workorder-email-processor`, `workorder-web-ui`, `workorder-shoc-emitter`, `workorder-shoc-hmac-rotator`, `procurement-api`
- Tables: `purchase-orders`, `verified-sites`, `pending-site-review`, `WorkOrders`, `WorkOrderComments` (PascalCase kept for import)
- Buckets: `po-ingest-emails-011934824531`, `workorder-ingest-emails-011934824531`
- Queues: `workorder-shoc-emitter-failures`, `workorder-shoc-emitter-rejected`, plus CDK-named DLQs
- Domain: `procurement-api.seahaven.com` (mgmt Route53 OOB)
- API REST id: `mvul1efda2`
- SHOC KMS: alias `workorder-ingest-shoc-webhook-kms` (key id in live inventory JSON only)
- Secret: `workorder-ingest/shoc-webhook-hmac`
## Cross-account pins (must stay byte-stable)
- API resource policy principal: `arn:aws:iam::396287094661:role/shoc-backend-dev`
- SHOC KMS decrypt: exact ARN + `kms:ViaService` for Secrets Manager
- Webhook URL: `https://api.dev.seahaven.com/api/webhooks/work-orders`
## Raw dumps
- [`po-ingest-resources.json`](po-ingest-resources.json)
- [`WorkorderIngestStack-resources.json`](WorkorderIngestStack-resources.json)
- [`procurement-api-resources.json`](procurement-api-resources.json)
- [`raw-inventory.tsv`](raw-inventory.tsv)
Import blocks: [`terraform/imports.tf`](../../terraform/imports.tf)