docs(readme): describe the boundary floor, not the superseded prefix design

This commit is contained in:
Adam Moussa 2026-07-31 13:23:20 -04:00
parent e791005af0
commit a1086e04fb
No known key found for this signature in database

View file

@ -139,14 +139,17 @@ of truth for mgmt (328440206208) until its stacks migrate out.
**The two copies are no longer at parity, and the old "edit both files" rule no **The two copies are no longer at parity, and the old "edit both files" rule no
longer applies uniformly.** Under INFRA-186, `seahaven-lambda-execution-boundary` longer applies uniformly.** Under INFRA-186, `seahaven-lambda-execution-boundary`
in *this* copy was scoped to per-workload prefixes for prod and dev (where in *this* copy was reduced to a fleet-wide floor for prod and dev (where
boundary usage was 0, so no live Lambda could break), while mgmt's copy keeps boundary usage was 0, so no live Lambda could break): CloudWatch Logs write on
the account-wide wildcards pending its own separately validated rollout across `/aws/lambda*`, log-group describe, X-Ray, and ENI lifecycle — nothing else.
26 live boundary-carrying roles. So: **the boundary resource is deliberately Each migrating stack adds its own data-plane statements, derived from its own
divergent**; every *other* substrate resource (`github-cfn-execution-role`, template, in its own PR (per-workload boundaries are the INFRA-187 end state).
`seahaven-cfn-exec-iam-management`) is still expected to change in both files mgmt's copy keeps the account-wide wildcards pending its own separately
together. The template's provenance header records which is which — read it validated rollout across 26 live boundary-carrying roles. So: **the boundary
before assuming either parity or divergence. resource is deliberately divergent**; every *other* substrate resource
(`github-cfn-execution-role`, `seahaven-cfn-exec-iam-management`) is still
expected to change in both files together. The template's provenance header
records which is which — read it before assuming either parity or divergence.
Per-repo `githubdeploy-*` deploy roles are deliberately NOT part Per-repo `githubdeploy-*` deploy roles are deliberately NOT part
of the substrate — they are provisioned per repo at migration/onboarding time of the substrate — they are provisioned per repo at migration/onboarding time