mirror of
https://github.com/Sea-Haven-Industries/seahaven-account-baseline.git
synced 2026-08-04 16:56:14 +00:00
New stack seahaven-terraform-substrate (instances terraform-substrate-prod + terraform-substrate-dev): app.terraform.io OIDC provider and the shared boundary-gated guardrail policy seahaven-hcptf-iam-management that per-workspace Terraform apply roles attach at migration time. No roles are pre-provisioned (accumulator pattern, parallel to githubdeploy-*). Guardrail statements mirror seahaven-cfn-exec-iam-management byte-identically except DenySelfMutation, whose scope extends to hcptf-* alongside the GitHub-substrate principals. Explicit stack dependency on the same-account deploy-substrate stack (boundary ARN appears only in Condition strings, so CFN infers no edge). |
||
|---|---|---|
| .. | ||
| terraform-substrate.template.yaml | ||