mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-03 23:33:12 +00:00
fix(iam): address review feedback
This commit is contained in:
parent
ce6b59b552
commit
bd36e26369
3 changed files with 7 additions and 15 deletions
|
|
@ -32,7 +32,7 @@ are noted):
|
|||
| `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) |
|
||||
| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget |
|
||||
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager + eight existing `hcptf-*` pairs (DeletionPolicy Retain). Pending PLAT-147 delete after consumer imports. New prod/dev HCP IAM is not added here. |
|
||||
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). Adopt with `cdk import` after the site workspace drops them from state. Do not create. |
|
||||
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. |
|
||||
| `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). |
|
||||
| `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) |
|
||||
| `seahaven-dev-baseline` | 710827005802 | us-east-1 | Member-account baseline for internal dev/staging (org-managed detection — no local GuardDuty/SecurityHub) |
|
||||
|
|
|
|||
|
|
@ -229,8 +229,7 @@ new AppWebAclStack(app, "app-web-acl-prod", {
|
|||
});
|
||||
|
||||
// seahaven-site exec roles (PLAT-225). Not part of terraform-substrate.
|
||||
// First operation is `cdk import`, after the site workspace drops the roles
|
||||
// from its state. A create fails because the roles already exist.
|
||||
// Imported. On the prod deploy job. A create fails because the roles already exist.
|
||||
new SeahavenSiteHcptfStack(app, "seahaven-site-hcptf", {
|
||||
stackName: "seahaven-site-hcptf",
|
||||
env: { account: PROD_ACCOUNT, region: "us-east-1" },
|
||||
|
|
|
|||
|
|
@ -5,19 +5,12 @@ import { Construct } from "constructs";
|
|||
/**
|
||||
* Prod exec roles for the seahaven-site HCP workspace (PLAT-225).
|
||||
*
|
||||
* These roles already exist. Adopt them. Do not create them. The substrate
|
||||
* template no longer declares them. Its next deploy drops them from that
|
||||
* stack and retains the live roles.
|
||||
* These roles already exist and were imported into this stack. Do not
|
||||
* create them. A plain create fails because the roles already exist.
|
||||
* The stack is on the prod deploy job.
|
||||
*
|
||||
* Import only after that deploy, and after seahaven-site-prod applies its
|
||||
* `removed` blocks:
|
||||
*
|
||||
* npx cdk import seahaven-site-hcptf
|
||||
*
|
||||
* Import identifiers are the role names `hcptf-seahaven-site` and
|
||||
* `hcptf-seahaven-site-plan`. The stack stays off the prod deploy job until
|
||||
* that import succeeds. A plain create fails because the roles already
|
||||
* exist, and a failed create blocks the import.
|
||||
* Import identifiers were the role names `hcptf-seahaven-site` and
|
||||
* `hcptf-seahaven-site-plan`.
|
||||
*/
|
||||
export class SeahavenSiteHcptfStack extends cdk.Stack {
|
||||
constructor(scope: Construct, id: string, props: cdk.StackProps) {
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue