docs(readme): describe the boundary floor, not the superseded prefix design

This commit is contained in:
Adam Moussa 2026-07-31 13:23:20 -04:00
parent e791005af0
commit a1086e04fb
No known key found for this signature in database

View file

@ -139,14 +139,17 @@ of truth for mgmt (328440206208) until its stacks migrate out.
**The two copies are no longer at parity, and the old "edit both files" rule no
longer applies uniformly.** Under INFRA-186, `seahaven-lambda-execution-boundary`
in *this* copy was scoped to per-workload prefixes for prod and dev (where
boundary usage was 0, so no live Lambda could break), while mgmt's copy keeps
the account-wide wildcards pending its own separately validated rollout across
26 live boundary-carrying roles. So: **the boundary resource is deliberately
divergent**; every *other* substrate resource (`github-cfn-execution-role`,
`seahaven-cfn-exec-iam-management`) is still expected to change in both files
together. The template's provenance header records which is which — read it
before assuming either parity or divergence.
in *this* copy was reduced to a fleet-wide floor for prod and dev (where
boundary usage was 0, so no live Lambda could break): CloudWatch Logs write on
`/aws/lambda*`, log-group describe, X-Ray, and ENI lifecycle — nothing else.
Each migrating stack adds its own data-plane statements, derived from its own
template, in its own PR (per-workload boundaries are the INFRA-187 end state).
mgmt's copy keeps the account-wide wildcards pending its own separately
validated rollout across 26 live boundary-carrying roles. So: **the boundary
resource is deliberately divergent**; every *other* substrate resource
(`github-cfn-execution-role`, `seahaven-cfn-exec-iam-management`) is still
expected to change in both files together. The template's provenance header
records which is which — read it before assuming either parity or divergence.
Per-repo `githubdeploy-*` deploy roles are deliberately NOT part
of the substrate — they are provisioned per repo at migration/onboarding time