proposal-system/infra
Adam Moussa 8aed244cc6
chore(infra): retarget prod to seahaven-prod account + OIDC deploy-role artifacts
Retarget the CDK prod env from mgmt (328440206208, now frozen for workloads) to the
dedicated seahaven-prod workload account (011934824531). proposal-system is the org's
first prod tenant. Hard-block env=staging (still targets frozen mgmt) in resolveConfig
until it is retargeted to seahaven-dev (710827005802). Add a WARN-only out-of-pipeline
deploy guard in bin/app.ts.

Add infra/deploy-role/: OIDC trust policy (sub scoped to
Sea-Haven-Industries/proposal-system:ref:refs/heads/main), least-privilege permissions
policy (AssumeRole on the verified cdk-hnb659fds bootstrap roles, deterministic site
bucket, account-scoped CloudFront invalidation), and an idempotent creation script.
Verified against live prod: bootstrap qualifier hnb659fds v32, OIDC provider present.
Passed GPT-4.1 cross-review (APPROVE) and workflow red-team (CLEAN). Role NOT yet created
— gated on /sh-security-review + the deploy go-ahead.

Docs: README + CLAUDE.md reflect the prod account and pipeline-only deploy.
2026-07-14 19:41:49 -04:00
..
bin chore(infra): retarget prod to seahaven-prod account + OIDC deploy-role artifacts 2026-07-14 19:41:49 -04:00
deploy-role chore(infra): retarget prod to seahaven-prod account + OIDC deploy-role artifacts 2026-07-14 19:41:49 -04:00
lib chore(infra): retarget prod to seahaven-prod account + OIDC deploy-role artifacts 2026-07-14 19:41:49 -04:00
cdk.context.json Initial scaffold: monorepo structure, CDK stacks, CI/CD, domain model 2026-05-16 18:40:46 -04:00
cdk.json fix(infra): run CDK app via tsx to support TypeScript 7 2026-07-08 16:51:54 -04:00
package-lock.json build(deps-dev): bump aws-cdk in /infra in the infra group 2026-07-11 04:32:54 +00:00
package.json build(deps-dev): bump aws-cdk in /infra in the infra group 2026-07-11 04:32:54 +00:00
tsconfig.json Initial scaffold: monorepo structure, CDK stacks, CI/CD, domain model 2026-05-16 18:40:46 -04:00