procurement-ingest/docs/plat-86/cfn-dispose.md
Adam Moussa 2a2929b835
chore(cd): hard-cut CDK deploy; HCP is sole mutate path (PLAT-86)
Remove push-to-main cd-cdk workflow, document HCP apply + dispose runbook,
and park githubdeploy-procurement-ingest for a later IAM cleanup.
2026-08-07 11:31:34 -04:00

25 lines
1.7 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# PLAT-86 CFN dispose runbook (import-in-place)
Prerequisites (already proven 2026-08-07):
- HCP workspace `procurement-ingest-prod` Manual apply green; verification plan **0/0/0**
- Lambdas on `/tf-managed/` roles
- TF owns `aws_s3_bucket_notification` on both email buckets (`*-inbound` ids)
- Soft-freeze replaced by hard-cut (`.github/workflows/deploy.yaml` removed)
- Smoke green for `po-email-processor`, `workorder-email-processor`, `procurement-api`
## Rule
Never run `cfn-stack-decommission.sh --execute` against these stacks. That script purges RETAIN orphans after delete. Here RETAIN orphans are the live TF-owned data plane.
## Method
1. **Retain-all update** — for each stack (`po-ingest`, `WorkorderIngestStack`, `procurement-api`), set `DeletionPolicy: Retain` and `UpdateReplacePolicy: Retain` on every resource in the live template, then `update-stack`. This includes `Custom::S3BucketNotifications` so CFN will not invoke the empty `PutBucketNotificationConfiguration` delete handler.
2. **Delete stack** — `delete-stack` after `UPDATE_COMPLETE`. All resources leave CFN without destruction.
3. **Verify immediately** — `GetBucketNotificationConfiguration` still lists inbound Lambda triggers; SES receipt rules for PO/WO still present on `INBOUND_MAIL`; named Lambdas/tables/buckets still exist; smoke script green.
4. **Sweep CDK helpers only** — delete orphaned `*BucketNotificationsHandler*` Lambda functions and their IAM roles/policies (both stacks). Do not delete TF-owned Lambdas, tables, buckets, API GW, SES rules, or SHOC secret/KMS.
5. **Park** `githubdeploy-procurement-ingest` for a separate IAM-reviewed cleanup (do not block dispose).
## Script
`scripts/plat86-cfn-dispose.sh` implements steps 1–4 with explicit confirms and post-checks.