Commit graph

2 commits

Author SHA1 Message Date
c1347fcdb5
fix(scripts): account-id assertion in cfn-stack-decommission; complete the aws-cdk-lib 2.262.0 bump (patched brace-expansion); document CMK cutover trap
- cfn-stack-decommission.sh: --account-id is now REQUIRED and asserted
  against sts get-caller-identity before anything runs. Stack names are no
  longer org-unique (seahaven-dynamodb-cmk now exists in mgmt AND prod), so
  a name-only lookup under the wrong ambient profile could report or delete
  the wrong account's stack (security-review LOGIC-001).
- package.json/lock: PR #56's bump-for-patched-brace-expansion landed the
  commit title but not the pin; package.json still said 2.261.0 and the
  lockfile still resolved brace-expansion 5.0.6 (GHSA-3jxr-9vmj-r5cp HIGH,
  blocking the pre-commit scanner). Pin 2.262.0 and regenerate; npm audit
  now clean.
- bin/app.ts comments: slack-bot cutover MUST grant the PROD key ARN, never
  the account-local mgmt SSM param (LOGIC-005); failed-first-create orphan
  CMK recovery note (LOGIC-004).
2026-07-23 14:46:17 -04:00
Adam Moussa
14593440cf
Add cfn-stack-decommission + resource-usage-probe ops scripts (#11)
Some checks are pending
Deploy / deploy (push) Waiting to run
cfn-stack-decommission.sh: report-by-default stack retirement; pre-flight
predicts DeletionPolicy:Retain orphans + consumed-export blocks before delete
(distilled from the LedgerFlow decommission). --execute to act.

resource-usage-probe.sh: is-it-used probe (RDS connections/Lambda invocations/
DDB capacity/EBS attachment) to choose retire-vs-harden before acting on an
encrypt/migrate finding (the database-1 H-19 lesson).
2026-06-03 13:25:44 -04:00