procurement-ingest/docs/plat-86/import-map.md

53 lines
3.7 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# PLAT-86 import map (seahaven-prod `011934824531` / us-east-1)
Frozen from live `DescribeStackResources` on 2026-08-06. CFN resource total: **164** (46 + 62 + 56). Estimated Terraform resources after expansion: ~220–320 — under HCP free-tier **500**.
Workspace: one `procurement-ingest-prod` covering all three former stacks.
## Out-of-band (data source / do not recreate)
| Dependency | Value |
|---|---|
| SES ruleset | `INBOUND_MAIL` |
| SNS | `arn:aws:sns:us-east-1:011934824531:site-alerts` |
| SSM CMK | `/seahaven/dynamodb/cmk-arn` → `arn:aws:kms:us-east-1:011934824531:key/be5fa4cb-c546-40fe-a13d-c7bec79f5d12` |
| SSM ACM | `/procurement-api/custom-domain/certificate-arn` → `arn:aws:acm:us-east-1:011934824531:certificate/9eac4c03-6850-49f1-baa1-6c4e7fffd1c7` |
| Secret (imported shell) | `arn:aws:secretsmanager:us-east-1:011934824531:secret:procurement-ingest/web-ui-auth-token-ApAMmr` |
| Mgmt Route53 | `procurement-api.seahaven.com` alias — stays OOB |
## CFN disposal disposition
| Class | Disposition on CFN stack delete |
|---|---|
| DynamoDB tables, email S3 buckets, Lambda log groups | **RETAIN** (must already be TF-owned; never delete) |
| Named SQS (`workorder-shoc-emitter-*`), SHOC secret/KMS/**ResourcePolicy**, API GW, Lambdas, alarms, SES receipt rules | TF-owned (import `aws_secretsmanager_secret_policy.shoc_webhook_hmac` before disposal); remove from CFN via retain-on-delete or deletion_policy before stack delete |
| CDK `Custom::S3BucketNotifications` | **Do not destroy via the CFN delete-handler.** That handler calls empty `PutBucketNotificationConfiguration` and wipes TF-owned `aws_s3_bucket_notification` on the PO/WO email buckets. After Terraform apply owns notifications: orphan/retain the custom resource (or otherwise skip its delete cleanup), then destroy `BucketNotificationsHandler` Lambda/role with CFN. Immediately verify `GetBucketNotificationConfiguration` still lists the inbound Lambda triggers; if cleared, re-apply Terraform before accepting traffic. |
| `BucketNotificationsHandler` Lambda/role (+ handler IAM policy) | Destroy with CFN only after notifications are TF-owned and the custom resource is orphaned/removed without clearing the bucket config |
| CDK Metadata | Destroy with CFN |
| CDK-generated IAM roles at path `/` | After Lambda repoint to `/tf-managed/`, delete with CFN or sweep |
## Key physical IDs to preserve
- Lambdas: `po-email-processor`, `po-web-ui`, `po-ingest-site-extractor`, `workorder-email-processor`, `workorder-web-ui`, `workorder-shoc-emitter`, `workorder-shoc-hmac-rotator`, `procurement-api`
- Tables: `purchase-orders`, `verified-sites`, `pending-site-review`, `WorkOrders`, `WorkOrderComments` (PascalCase kept for import)
- Buckets: `po-ingest-emails-011934824531`, `workorder-ingest-emails-011934824531`
- Queues: `workorder-shoc-emitter-failures`, `workorder-shoc-emitter-rejected`, plus CDK-named DLQs
- Domain: `procurement-api.seahaven.com` (mgmt Route53 OOB)
- API REST id: `mvul1efda2`
- SHOC KMS: alias `workorder-ingest-shoc-webhook-kms` (key id in live inventory JSON only)
- Secret: `workorder-ingest/shoc-webhook-hmac`
## Cross-account pins (must stay byte-stable)
- API resource policy principal: `arn:aws:iam::396287094661:role/shoc-backend-dev`
- SHOC KMS decrypt: exact ARN + `kms:ViaService` for Secrets Manager
- Webhook URL: `https://api.dev.seahaven.com/api/webhooks/work-orders`
## Raw dumps
- [`po-ingest-resources.json`](po-ingest-resources.json)
- [`WorkorderIngestStack-resources.json`](WorkorderIngestStack-resources.json)
- [`procurement-api-resources.json`](procurement-api-resources.json)
- [`raw-inventory.tsv`](raw-inventory.tsv)
Import blocks: [`terraform/imports.tf`](../../terraform/imports.tf)