seahaven-account-baseline/.github/workflows
Adam Moussa ea27635ef2
feat(iac): add per-account HCP Terraform deploy substrate for prod and dev
New stack seahaven-terraform-substrate (instances terraform-substrate-prod +
terraform-substrate-dev): app.terraform.io OIDC provider and the shared
boundary-gated guardrail policy seahaven-hcptf-iam-management that
per-workspace Terraform apply roles attach at migration time. No roles are
pre-provisioned (accumulator pattern, parallel to githubdeploy-*).

Guardrail statements mirror seahaven-cfn-exec-iam-management byte-identically
except DenySelfMutation, whose scope extends to hcptf-* alongside the
GitHub-substrate principals. Explicit stack dependency on the same-account
deploy-substrate stack (boundary ARN appears only in Condition strings, so
CFN infers no edge).
2026-07-30 16:31:34 -04:00
..
ci.yaml ci(deps): pin org reusable workflows to v1.0.2 2026-07-28 17:57:16 -04:00
dependency-review.yml ci(deps): pin org reusable workflows to v1.0.2 2026-07-28 17:57:16 -04:00
deploy.yaml feat(iac): add per-account HCP Terraform deploy substrate for prod and dev 2026-07-30 16:31:34 -04:00
labeler.yml style(ci): normalize workflow block spacing 2026-07-28 18:07:11 -04:00