fix(iam): address review feedback

This commit is contained in:
Adam Moussa 2026-09-25 12:31:40 -04:00
parent ce6b59b552
commit bd36e26369
No known key found for this signature in database
3 changed files with 7 additions and 15 deletions

View file

@ -32,7 +32,7 @@ are noted):
| `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) |
| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget |
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager + eight existing `hcptf-*` pairs (DeletionPolicy Retain). Pending PLAT-147 delete after consumer imports. New prod/dev HCP IAM is not added here. |
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). Adopt with `cdk import` after the site workspace drops them from state. Do not create. |
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. |
| `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). |
| `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) |
| `seahaven-dev-baseline` | 710827005802 | us-east-1 | Member-account baseline for internal dev/staging (org-managed detection — no local GuardDuty/SecurityHub) |

View file

@ -229,8 +229,7 @@ new AppWebAclStack(app, "app-web-acl-prod", {
});
// seahaven-site exec roles (PLAT-225). Not part of terraform-substrate.
// First operation is `cdk import`, after the site workspace drops the roles
// from its state. A create fails because the roles already exist.
// Imported. On the prod deploy job. A create fails because the roles already exist.
new SeahavenSiteHcptfStack(app, "seahaven-site-hcptf", {
stackName: "seahaven-site-hcptf",
env: { account: PROD_ACCOUNT, region: "us-east-1" },

View file

@ -5,19 +5,12 @@ import { Construct } from "constructs";
/**
* Prod exec roles for the seahaven-site HCP workspace (PLAT-225).
*
* These roles already exist. Adopt them. Do not create them. The substrate
* template no longer declares them. Its next deploy drops them from that
* stack and retains the live roles.
* These roles already exist and were imported into this stack. Do not
* create them. A plain create fails because the roles already exist.
* The stack is on the prod deploy job.
*
* Import only after that deploy, and after seahaven-site-prod applies its
* `removed` blocks:
*
* npx cdk import seahaven-site-hcptf
*
* Import identifiers are the role names `hcptf-seahaven-site` and
* `hcptf-seahaven-site-plan`. The stack stays off the prod deploy job until
* that import succeeds. A plain create fails because the roles already
* exist, and a failed create blocks the import.
* Import identifiers were the role names `hcptf-seahaven-site` and
* `hcptf-seahaven-site-plan`.
*/
export class SeahavenSiteHcptfStack extends cdk.Stack {
constructor(scope: Construct, id: string, props: cdk.StackProps) {