From a1086e04fbab5011b37ca5236c4026ca4eb3fcd8 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 31 Jul 2026 13:23:20 -0400 Subject: [PATCH] docs(readme): describe the boundary floor, not the superseded prefix design --- README.md | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) diff --git a/README.md b/README.md index 627f686..abf1f9c 100644 --- a/README.md +++ b/README.md @@ -139,14 +139,17 @@ of truth for mgmt (328440206208) until its stacks migrate out. **The two copies are no longer at parity, and the old "edit both files" rule no longer applies uniformly.** Under INFRA-186, `seahaven-lambda-execution-boundary` -in *this* copy was scoped to per-workload prefixes for prod and dev (where -boundary usage was 0, so no live Lambda could break), while mgmt's copy keeps -the account-wide wildcards pending its own separately validated rollout across -26 live boundary-carrying roles. So: **the boundary resource is deliberately -divergent**; every *other* substrate resource (`github-cfn-execution-role`, -`seahaven-cfn-exec-iam-management`) is still expected to change in both files -together. The template's provenance header records which is which — read it -before assuming either parity or divergence. +in *this* copy was reduced to a fleet-wide floor for prod and dev (where +boundary usage was 0, so no live Lambda could break): CloudWatch Logs write on +`/aws/lambda*`, log-group describe, X-Ray, and ENI lifecycle — nothing else. +Each migrating stack adds its own data-plane statements, derived from its own +template, in its own PR (per-workload boundaries are the INFRA-187 end state). +mgmt's copy keeps the account-wide wildcards pending its own separately +validated rollout across 26 live boundary-carrying roles. So: **the boundary +resource is deliberately divergent**; every *other* substrate resource +(`github-cfn-execution-role`, `seahaven-cfn-exec-iam-management`) is still +expected to change in both files together. The template's provenance header +records which is which — read it before assuming either parity or divergence. Per-repo `githubdeploy-*` deploy roles are deliberately NOT part of the substrate — they are provisioned per repo at migration/onboarding time