mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 16:33:14 +00:00
Remove push-to-main cd-cdk workflow, document HCP apply + dispose runbook, and park githubdeploy-procurement-ingest for a later IAM cleanup.
55 lines
3.8 KiB
Markdown
55 lines
3.8 KiB
Markdown
# PLAT-86 import map (seahaven-prod `011934824531` / us-east-1)
|
||
|
||
Frozen from live `DescribeStackResources` on 2026-08-06. CFN resource total: **164** (46 + 62 + 56). Estimated Terraform resources after expansion: ~220–320 — under HCP free-tier **500**.
|
||
|
||
Workspace: one `procurement-ingest-prod` covering all three former stacks.
|
||
|
||
## Out-of-band (data source / do not recreate)
|
||
|
||
| Dependency | Value |
|
||
|---|---|
|
||
| SES ruleset | `INBOUND_MAIL` |
|
||
| SNS | `arn:aws:sns:us-east-1:011934824531:site-alerts` |
|
||
| SSM CMK | `/seahaven/dynamodb/cmk-arn` → `arn:aws:kms:us-east-1:011934824531:key/be5fa4cb-c546-40fe-a13d-c7bec79f5d12` |
|
||
| SSM ACM | `/procurement-api/custom-domain/certificate-arn` → `arn:aws:acm:us-east-1:011934824531:certificate/9eac4c03-6850-49f1-baa1-6c4e7fffd1c7` |
|
||
| Secret (imported shell) | `arn:aws:secretsmanager:us-east-1:011934824531:secret:procurement-ingest/web-ui-auth-token-ApAMmr` |
|
||
| Mgmt Route53 | `procurement-api.seahaven.com` alias — stays OOB |
|
||
|
||
## CFN disposal disposition
|
||
|
||
Executable runbook: [`cfn-dispose.md`](cfn-dispose.md) + `scripts/plat86-cfn-dispose.sh` (retain-all, then delete-stack; never `cfn-stack-decommission.sh --execute`).
|
||
|
||
| Class | Disposition on CFN stack delete |
|
||
|---|---|
|
||
| DynamoDB tables, email S3 buckets, Lambda log groups | **RETAIN** (must already be TF-owned; never delete) |
|
||
| Named SQS (`workorder-shoc-emitter-*`), SHOC secret/KMS/**ResourcePolicy**, API GW, Lambdas, alarms, SES receipt rules | TF-owned (import `aws_secretsmanager_secret_policy.shoc_webhook_hmac` before disposal); remove from CFN via retain-on-delete or deletion_policy before stack delete |
|
||
| CDK `Custom::S3BucketNotifications` | **Do not destroy via the CFN delete-handler.** That handler calls empty `PutBucketNotificationConfiguration` and wipes TF-owned `aws_s3_bucket_notification` on the PO/WO email buckets. After Terraform apply owns notifications: orphan/retain the custom resource (or otherwise skip its delete cleanup), then destroy `BucketNotificationsHandler` Lambda/role with CFN. Immediately verify `GetBucketNotificationConfiguration` still lists the inbound Lambda triggers; if cleared, re-apply Terraform before accepting traffic. |
|
||
| `BucketNotificationsHandler` Lambda/role (+ handler IAM policy) | After retain-all stack delete, sweep orphaned handler Lambdas/roles manually (script step 4) |
|
||
| CDK Metadata | Orphaned with retain-all; harmless |
|
||
| CDK-generated IAM roles at path `/` | After Lambda repoint to `/tf-managed/`, sweep unused leftovers in a follow-up IAM pass |
|
||
|
||
## Key physical IDs to preserve
|
||
|
||
- Lambdas: `po-email-processor`, `po-web-ui`, `po-ingest-site-extractor`, `workorder-email-processor`, `workorder-web-ui`, `workorder-shoc-emitter`, `workorder-shoc-hmac-rotator`, `procurement-api`
|
||
- Tables: `purchase-orders`, `verified-sites`, `pending-site-review`, `WorkOrders`, `WorkOrderComments` (PascalCase kept for import)
|
||
- Buckets: `po-ingest-emails-011934824531`, `workorder-ingest-emails-011934824531`
|
||
- Queues: `workorder-shoc-emitter-failures`, `workorder-shoc-emitter-rejected`, plus CDK-named DLQs
|
||
- Domain: `procurement-api.seahaven.com` (mgmt Route53 OOB)
|
||
- API REST id: `mvul1efda2`
|
||
- SHOC KMS: alias `workorder-ingest-shoc-webhook-kms` (key id in live inventory JSON only)
|
||
- Secret: `workorder-ingest/shoc-webhook-hmac`
|
||
|
||
## Cross-account pins (must stay byte-stable)
|
||
|
||
- API resource policy principal: `arn:aws:iam::396287094661:role/shoc-backend-dev`
|
||
- SHOC KMS decrypt: exact ARN + `kms:ViaService` for Secrets Manager
|
||
- Webhook URL: `https://api.dev.seahaven.com/api/webhooks/work-orders`
|
||
|
||
## Raw dumps
|
||
|
||
- [`po-ingest-resources.json`](po-ingest-resources.json)
|
||
- [`WorkorderIngestStack-resources.json`](WorkorderIngestStack-resources.json)
|
||
- [`procurement-api-resources.json`](procurement-api-resources.json)
|
||
- [`raw-inventory.tsv`](raw-inventory.tsv)
|
||
|
||
Import blocks: [`terraform/imports.tf`](../../terraform/imports.tf)
|