- cfn-stack-decommission.sh: --account-id is now REQUIRED and asserted
against sts get-caller-identity before anything runs. Stack names are no
longer org-unique (seahaven-dynamodb-cmk now exists in mgmt AND prod), so
a name-only lookup under the wrong ambient profile could report or delete
the wrong account's stack (security-review LOGIC-001).
- package.json/lock: PR #56's bump-for-patched-brace-expansion landed the
commit title but not the pin; package.json still said 2.261.0 and the
lockfile still resolved brace-expansion 5.0.6 (GHSA-3jxr-9vmj-r5cp HIGH,
blocking the pre-commit scanner). Pin 2.262.0 and regenerate; npm audit
now clean.
- bin/app.ts comments: slack-bot cutover MUST grant the PROD key ARN, never
the account-local mgmt SSM param (LOGIC-005); failed-first-create orphan
CMK recovery note (LOGIC-004).
cfn-stack-decommission.sh: report-by-default stack retirement; pre-flight
predicts DeletionPolicy:Retain orphans + consumed-export blocks before delete
(distilled from the LedgerFlow decommission). --execute to act.
resource-usage-probe.sh: is-it-used probe (RDS connections/Lambda invocations/
DDB capacity/EBS attachment) to choose retire-vs-harden before acting on an
encrypt/migrate finding (the database-1 H-19 lesson).
README: document AWS Backup phase-2 (phase2-offsite-everything selection),
remove retired database-1 from phase-1 scope (audit H-19), update roadmap +
verify smoke-test to a live resource.
scripts/iam-user-delete.sh: reusable full IAM user teardown (keys, policies,
groups, MFA, login profile, certs, SSH keys, service creds, then user) with
--profile/--yes and a guard against deleting the caller's own identity. Built
from the Day 4 audit IAM cleanup.