procurement-ingest/docs/plat-86/import-map.md
Adam Moussa 2a2929b835
chore(cd): hard-cut CDK deploy; HCP is sole mutate path (PLAT-86)
Remove push-to-main cd-cdk workflow, document HCP apply + dispose runbook,
and park githubdeploy-procurement-ingest for a later IAM cleanup.
2026-08-07 11:31:34 -04:00

55 lines
3.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# PLAT-86 import map (seahaven-prod `011934824531` / us-east-1)
Frozen from live `DescribeStackResources` on 2026-08-06. CFN resource total: **164** (46 + 62 + 56). Estimated Terraform resources after expansion: ~220–320 — under HCP free-tier **500**.
Workspace: one `procurement-ingest-prod` covering all three former stacks.
## Out-of-band (data source / do not recreate)
| Dependency | Value |
|---|---|
| SES ruleset | `INBOUND_MAIL` |
| SNS | `arn:aws:sns:us-east-1:011934824531:site-alerts` |
| SSM CMK | `/seahaven/dynamodb/cmk-arn` → `arn:aws:kms:us-east-1:011934824531:key/be5fa4cb-c546-40fe-a13d-c7bec79f5d12` |
| SSM ACM | `/procurement-api/custom-domain/certificate-arn` → `arn:aws:acm:us-east-1:011934824531:certificate/9eac4c03-6850-49f1-baa1-6c4e7fffd1c7` |
| Secret (imported shell) | `arn:aws:secretsmanager:us-east-1:011934824531:secret:procurement-ingest/web-ui-auth-token-ApAMmr` |
| Mgmt Route53 | `procurement-api.seahaven.com` alias — stays OOB |
## CFN disposal disposition
Executable runbook: [`cfn-dispose.md`](cfn-dispose.md) + `scripts/plat86-cfn-dispose.sh` (retain-all, then delete-stack; never `cfn-stack-decommission.sh --execute`).
| Class | Disposition on CFN stack delete |
|---|---|
| DynamoDB tables, email S3 buckets, Lambda log groups | **RETAIN** (must already be TF-owned; never delete) |
| Named SQS (`workorder-shoc-emitter-*`), SHOC secret/KMS/**ResourcePolicy**, API GW, Lambdas, alarms, SES receipt rules | TF-owned (import `aws_secretsmanager_secret_policy.shoc_webhook_hmac` before disposal); remove from CFN via retain-on-delete or deletion_policy before stack delete |
| CDK `Custom::S3BucketNotifications` | **Do not destroy via the CFN delete-handler.** That handler calls empty `PutBucketNotificationConfiguration` and wipes TF-owned `aws_s3_bucket_notification` on the PO/WO email buckets. After Terraform apply owns notifications: orphan/retain the custom resource (or otherwise skip its delete cleanup), then destroy `BucketNotificationsHandler` Lambda/role with CFN. Immediately verify `GetBucketNotificationConfiguration` still lists the inbound Lambda triggers; if cleared, re-apply Terraform before accepting traffic. |
| `BucketNotificationsHandler` Lambda/role (+ handler IAM policy) | After retain-all stack delete, sweep orphaned handler Lambdas/roles manually (script step 4) |
| CDK Metadata | Orphaned with retain-all; harmless |
| CDK-generated IAM roles at path `/` | After Lambda repoint to `/tf-managed/`, sweep unused leftovers in a follow-up IAM pass |
## Key physical IDs to preserve
- Lambdas: `po-email-processor`, `po-web-ui`, `po-ingest-site-extractor`, `workorder-email-processor`, `workorder-web-ui`, `workorder-shoc-emitter`, `workorder-shoc-hmac-rotator`, `procurement-api`
- Tables: `purchase-orders`, `verified-sites`, `pending-site-review`, `WorkOrders`, `WorkOrderComments` (PascalCase kept for import)
- Buckets: `po-ingest-emails-011934824531`, `workorder-ingest-emails-011934824531`
- Queues: `workorder-shoc-emitter-failures`, `workorder-shoc-emitter-rejected`, plus CDK-named DLQs
- Domain: `procurement-api.seahaven.com` (mgmt Route53 OOB)
- API REST id: `mvul1efda2`
- SHOC KMS: alias `workorder-ingest-shoc-webhook-kms` (key id in live inventory JSON only)
- Secret: `workorder-ingest/shoc-webhook-hmac`
## Cross-account pins (must stay byte-stable)
- API resource policy principal: `arn:aws:iam::396287094661:role/shoc-backend-dev`
- SHOC KMS decrypt: exact ARN + `kms:ViaService` for Secrets Manager
- Webhook URL: `https://api.dev.seahaven.com/api/webhooks/work-orders`
## Raw dumps
- [`po-ingest-resources.json`](po-ingest-resources.json)
- [`WorkorderIngestStack-resources.json`](WorkorderIngestStack-resources.json)
- [`procurement-api-resources.json`](procurement-api-resources.json)
- [`raw-inventory.tsv`](raw-inventory.tsv)
Import blocks: [`terraform/imports.tf`](../../terraform/imports.tf)