seahaven-account-baseline/lib/terraform-substrate-stack.ts
Adam Moussa ea27635ef2
feat(iac): add per-account HCP Terraform deploy substrate for prod and dev
New stack seahaven-terraform-substrate (instances terraform-substrate-prod +
terraform-substrate-dev): app.terraform.io OIDC provider and the shared
boundary-gated guardrail policy seahaven-hcptf-iam-management that
per-workspace Terraform apply roles attach at migration time. No roles are
pre-provisioned (accumulator pattern, parallel to githubdeploy-*).

Guardrail statements mirror seahaven-cfn-exec-iam-management byte-identically
except DenySelfMutation, whose scope extends to hcptf-* alongside the
GitHub-substrate principals. Explicit stack dependency on the same-account
deploy-substrate stack (boundary ARN appears only in Condition strings, so
CFN infers no edge).
2026-07-30 16:31:34 -04:00

42 lines
1.8 KiB
TypeScript

import * as cdk from "aws-cdk-lib";
import * as cfninc from "aws-cdk-lib/cloudformation-include";
import * as path from "path";
import { Construct } from "constructs";
/**
* Per-account HCP Terraform deploy substrate: the shared account-level
* resources every Terraform workspace pipeline needs -
* - app.terraform.io OIDC identity provider (always created; Phase-0
* checks confirmed no account has one), and
* - `seahaven-hcptf-iam-management`, the shared boundary-gated IAM
* guardrail policy every per-workspace APPLY role attaches.
*
* Deliberately NOT here: per-workspace hcptf-<stack> / hcptf-<stack>-plan
* roles. Those are appended to the template at each stack's migration time
* (accumulator pattern, parallel to per-repo githubdeploy-* roles) so an
* account never accumulates trust for workspaces that do not deploy to it.
*
* The IAM guardrail statements mirror seahaven-cfn-exec-iam-management in
* lib/deploy-substrate/deploy-substrate.template.yaml - see the provenance
* header in lib/terraform-substrate/terraform-substrate.template.yaml for
* the reconciliation rule and the boundary-ARN coupling to the
* seahaven-deploy-substrate stack (bin/app.ts carries the explicit
* addStackDependency; the ARN reference alone creates no CFN edge).
*/
export class TerraformSubstrateStack extends cdk.Stack {
constructor(scope: Construct, id: string, props?: cdk.StackProps) {
super(scope, id, props);
new cfninc.CfnInclude(this, "Substrate", {
templateFile: path.join(
__dirname,
"terraform-substrate",
"terraform-substrate.template.yaml",
),
});
cdk.Tags.of(this).add("Project", "account-baseline");
cdk.Tags.of(this).add("Owner", "adam@seahavenind.com");
cdk.Tags.of(this).add("ManagedBy", "cdk");
}
}