diff --git a/README.md b/README.md index b167320..676273b 100644 --- a/README.md +++ b/README.md @@ -259,18 +259,24 @@ Prod/dev still carry, until PLAT-147 deletes those two stacks: External-dev still carries: - external-dev-only deploy boundaries - `shoc-backend-{tf-poc,dev,staging}-deploy-boundary`. Each is the maximum + `shoc-backend-{dev,staging}-deploy-boundary`. Each is the maximum current policy for one exact `githubdeploy-shoc-backend-*` role. Dev temporarily retains its live broad `elasticbeanstalk-*` S3 grants so boundary attachment cannot regress deployment before the separately reviewed policy narrowing, - external-dev-only runtime boundaries - `shoc-backend-{tf-poc,dev,staging}-runtime-boundary`. These retain only the + `shoc-backend-{dev,staging}-runtime-boundary`. These retain only the account-scoped S3, environment health/log, and X-Ray portions of `AWSElasticBeanstalkWebTier`, plus each environment's exact secrets/KMS/STS data plane. They deliberately exclude the managed policy's 2026 Bedrock/Marketplace additions. +The retired backend tf-poc deploy/runtime boundaries are no longer declared. +Because their last managed definitions used `DeletionPolicy: Retain`, the +external-dev stack update only removes CloudFormation ownership. Verify both +policies still have zero attachments, then delete the retained physical +policies in a separately approved post-deploy step. + **`seahaven-hcptf-iam-management` derives from `seahaven-cfn-exec-iam-management` but is deliberately stricter — it is not a mirror.** The 2026-07-30 security review confirmed the SAM copy's `Resource: "*"` role grants as a critical @@ -321,16 +327,12 @@ automatic and unchanged. `CreateOIDCProvider=false` is fixed in `bin/app.ts`; the external-dev account therefore creates neither the existing provider, SHOC roles, nor - the prod/dev-only shared IAM policy. The base stack does create all six - retained external-dev deploy/runtime boundary policies. + the prod/dev-only shared IAM policy. The base stack does create the four + retained backend dev/staging deploy/runtime boundary policies. 2. Set `enableShocBackendPocRoles` to `true` in `cdk.json`, leave the live gate `false`, review the synthesized two-role addition, then run the normal external-dev stack update. This creates only the new tf-poc HCP plan/apply - pair. The retained POC CDK stack references - `shoc-backend-tf-poc-deploy-boundary` when it creates - `githubdeploy-shoc-backend-tf-poc` and - `shoc-backend-tf-poc-runtime-boundary` when it creates the POC runtime - role; do not attach the generic account execution boundary to either role. + pair. 3. Prove both tf-poc HCP assumptions and the retained POC import rehearsal before touching the live-role ownership boundary. 4. In a separately approved administrator/CDK migration, tag the existing HCP @@ -344,10 +346,8 @@ automatic and unchanged. and attach `shoc-backend-dev-runtime-boundary` / `shoc-backend-staging-runtime-boundary` to the exact runtime roles. Verify the boundary ceilings before adding the matching manager tag to either - target `githubdeploy-*` role. The POC CDK - creates its deploy role with `HcpTerraformWorkspace=shoc-backend-tf-poc`; - the substrate-created POC apply role already carries the same principal - tag. Verify each effective deployment action before continuing. HCP remains + target `githubdeploy-*` role. Verify each effective deployment action before + continuing. HCP remains blocked while a target tag is missing/different or the target lacks its exact dedicated boundary, so a partial migration cannot authorize policy writes. Complete both runtime/deploy boundary attachments before workload diff --git a/lib/terraform-substrate/terraform-substrate.template.yaml b/lib/terraform-substrate/terraform-substrate.template.yaml index 17f5144..edd2281 100644 --- a/lib/terraform-substrate/terraform-substrate.template.yaml +++ b/lib/terraform-substrate/terraform-substrate.template.yaml @@ -2579,59 +2579,10 @@ Resources: # --------------------------------------------------------------------------- # SHOC backend GitHub deployment permissions boundaries (external-dev only) # - # These are ceilings for the three exact githubdeploy roles, not grants. + # These are ceilings for the dev and staging githubdeploy roles, not grants. # Existing dev/staging roles receive them through a separately approved - # administrator/CDK action before HCP import. The retained POC CDK stack - # attaches its boundary when it creates the POC deploy role. + # administrator/CDK action before HCP import. # --------------------------------------------------------------------------- - ShocBackendPocDeployBoundary: - Type: AWS::IAM::ManagedPolicy - Condition: IsExternalDevAccount - DeletionPolicy: Retain - UpdateReplacePolicy: Retain - Properties: - ManagedPolicyName: shoc-backend-tf-poc-deploy-boundary - Description: Maximum deployment permissions for githubdeploy-shoc-backend-tf-poc. - PolicyDocument: - Version: "2012-10-17" - Statement: - - Sid: DescribeDeploymentResources - Effect: Allow - Action: - - autoscaling:Describe* - - ec2:Describe* - - elasticbeanstalk:DescribeApplicationVersions - - elasticbeanstalk:DescribeEnvironments - - elasticbeanstalk:DescribeEvents - - elasticloadbalancing:Describe* - Resource: "*" - - Sid: CreateApplicationVersion - Effect: Allow - Action: elasticbeanstalk:CreateApplicationVersion - Resource: - - arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend - - arn:aws:elasticbeanstalk:us-east-1:396287094661:applicationversion/shoc-backend/* - - Sid: UpdatePocEnvironment - Effect: Allow - Action: elasticbeanstalk:UpdateEnvironment - Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc - - Sid: UseBeanstalkBucket - Effect: Allow - Action: - - s3:GetBucketLocation - - s3:ListBucket - Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661 - - Sid: UploadApplicationVersion - Effect: Allow - Action: s3:PutObject - Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/shoc-backend/* - - Sid: DenyLiveEnvironments - Effect: Deny - Action: elasticbeanstalk:* - Resource: - - arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-dev - - arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-staging - ShocBackendDevDeployBoundary: Type: AWS::IAM::ManagedPolicy Condition: IsExternalDevAccount @@ -2764,54 +2715,6 @@ Resources: # AWSElasticBeanstalkWebTier while removing its 2026 Bedrock/Marketplace # additions. All S3/log/health resources are pinned to this account and the # exact SHOC environment; X-Ray APIs do not support resource scoping. - ShocBackendPocRuntimeBoundary: - Type: AWS::IAM::ManagedPolicy - Condition: IsExternalDevAccount - DeletionPolicy: Retain - UpdateReplacePolicy: Retain - Properties: - ManagedPolicyName: shoc-backend-tf-poc-runtime-boundary - Description: Maximum runtime permissions for the SHOC backend tf-poc instance role. - PolicyDocument: - Version: "2012-10-17" - Statement: - - Sid: ReadAppConfig - Effect: Allow - Action: secretsmanager:GetSecretValue - Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/tf-poc/app-config-* - - Sid: ElasticBeanstalkBucket - Effect: Allow - Action: - - s3:Get* - - s3:List* - - s3:PutObject - Resource: - - arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661 - - arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/* - - Sid: ElasticBeanstalkHealth - Effect: Allow - Action: elasticbeanstalk:PutInstanceStatistics - Resource: - - arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend - - arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc - - Sid: ElasticBeanstalkLogs - Effect: Allow - Action: - - logs:PutLogEvents - - logs:CreateLogStream - - logs:DescribeLogStreams - - logs:DescribeLogGroups - Resource: arn:aws:logs:us-east-1:396287094661:log-group:/aws/elasticbeanstalk/shoc-backend-tf-poc* - - Sid: XRayTelemetry - Effect: Allow - Action: - - xray:PutTraceSegments - - xray:PutTelemetryRecords - - xray:GetSamplingRules - - xray:GetSamplingTargets - - xray:GetSamplingStatisticSummaries - Resource: "*" - ShocBackendDevRuntimeBoundary: Type: AWS::IAM::ManagedPolicy Condition: IsExternalDevAccount