mirror of
https://github.com/Sea-Haven-Industries/seahaven-account-baseline.git
synced 2026-08-04 16:56:14 +00:00
New stack seahaven-terraform-substrate (instances terraform-substrate-prod + terraform-substrate-dev): app.terraform.io OIDC provider and the shared boundary-gated guardrail policy seahaven-hcptf-iam-management that per-workspace Terraform apply roles attach at migration time. No roles are pre-provisioned (accumulator pattern, parallel to githubdeploy-*). Guardrail statements mirror seahaven-cfn-exec-iam-management byte-identically except DenySelfMutation, whose scope extends to hcptf-* alongside the GitHub-substrate principals. Explicit stack dependency on the same-account deploy-substrate stack (boundary ARN appears only in Condition strings, so CFN infers no edge).
42 lines
1.8 KiB
TypeScript
42 lines
1.8 KiB
TypeScript
import * as cdk from "aws-cdk-lib";
|
|
import * as cfninc from "aws-cdk-lib/cloudformation-include";
|
|
import * as path from "path";
|
|
import { Construct } from "constructs";
|
|
|
|
/**
|
|
* Per-account HCP Terraform deploy substrate: the shared account-level
|
|
* resources every Terraform workspace pipeline needs -
|
|
* - app.terraform.io OIDC identity provider (always created; Phase-0
|
|
* checks confirmed no account has one), and
|
|
* - `seahaven-hcptf-iam-management`, the shared boundary-gated IAM
|
|
* guardrail policy every per-workspace APPLY role attaches.
|
|
*
|
|
* Deliberately NOT here: per-workspace hcptf-<stack> / hcptf-<stack>-plan
|
|
* roles. Those are appended to the template at each stack's migration time
|
|
* (accumulator pattern, parallel to per-repo githubdeploy-* roles) so an
|
|
* account never accumulates trust for workspaces that do not deploy to it.
|
|
*
|
|
* The IAM guardrail statements mirror seahaven-cfn-exec-iam-management in
|
|
* lib/deploy-substrate/deploy-substrate.template.yaml - see the provenance
|
|
* header in lib/terraform-substrate/terraform-substrate.template.yaml for
|
|
* the reconciliation rule and the boundary-ARN coupling to the
|
|
* seahaven-deploy-substrate stack (bin/app.ts carries the explicit
|
|
* addStackDependency; the ARN reference alone creates no CFN edge).
|
|
*/
|
|
export class TerraformSubstrateStack extends cdk.Stack {
|
|
constructor(scope: Construct, id: string, props?: cdk.StackProps) {
|
|
super(scope, id, props);
|
|
|
|
new cfninc.CfnInclude(this, "Substrate", {
|
|
templateFile: path.join(
|
|
__dirname,
|
|
"terraform-substrate",
|
|
"terraform-substrate.template.yaml",
|
|
),
|
|
});
|
|
|
|
cdk.Tags.of(this).add("Project", "account-baseline");
|
|
cdk.Tags.of(this).add("Owner", "adam@seahavenind.com");
|
|
cdk.Tags.of(this).add("ManagedBy", "cdk");
|
|
}
|
|
}
|