proposal-system/infra/lib
Adam Moussa 8aed244cc6
chore(infra): retarget prod to seahaven-prod account + OIDC deploy-role artifacts
Retarget the CDK prod env from mgmt (328440206208, now frozen for workloads) to the
dedicated seahaven-prod workload account (011934824531). proposal-system is the org's
first prod tenant. Hard-block env=staging (still targets frozen mgmt) in resolveConfig
until it is retargeted to seahaven-dev (710827005802). Add a WARN-only out-of-pipeline
deploy guard in bin/app.ts.

Add infra/deploy-role/: OIDC trust policy (sub scoped to
Sea-Haven-Industries/proposal-system:ref:refs/heads/main), least-privilege permissions
policy (AssumeRole on the verified cdk-hnb659fds bootstrap roles, deterministic site
bucket, account-scoped CloudFront invalidation), and an idempotent creation script.
Verified against live prod: bootstrap qualifier hnb659fds v32, OIDC provider present.
Passed GPT-4.1 cross-review (APPROVE) and workflow red-team (CLEAN). Role NOT yet created
— gated on /sh-security-review + the deploy go-ahead.

Docs: README + CLAUDE.md reflect the prod account and pipeline-only deploy.
2026-07-14 19:41:49 -04:00
..
compute-stack.ts feat: proposal delivery — email customers the PDF on Mark as Sent (#126) 2026-06-18 12:40:55 -04:00
config.ts chore(infra): retarget prod to seahaven-prod account + OIDC deploy-role artifacts 2026-07-14 19:41:49 -04:00
foundation-stack.ts fix(infra): distinct Aurora construct ID; group + unpause Dependabot (#129) 2026-06-18 13:57:15 -04:00
frontend-stack.ts feat(infra): parameterize stacks for multi-env (prod/staging) (#123) 2026-06-12 18:04:53 -04:00