chore(terraform-substrate): forget imported prod hcptf pairs (PLAT-147) (#164)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

The six pairs are already in HCP state and DeletionPolicy is Retain, so CloudFormation drops the logical IDs without deleting the roles.
This commit is contained in:
Adam Moussa 2026-09-28 15:56:04 -04:00 • committed by GitHub
parent cc068f3c8d
commit ca179bbdf6
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 18 additions and 1803 deletions

View file

@ -31,7 +31,7 @@ are noted):
| `seahaven-backup-offsite` | 328440206208 | us-west-2 | Governance-locked offsite copy vault (C-7) |
| `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) |
| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget |
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager + eight existing `hcptf-*` pairs (DeletionPolicy Retain). Pending PLAT-147 delete after consumer imports. New prod/dev HCP IAM is not added here. |
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager. The six imported prod pairs are forgotten with `DeletionPolicy: Retain` (PLAT-147). Stacks stay until the delete. New prod/dev HCP IAM is not added here. |
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. |
| `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). |
| `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) |
@ -255,7 +255,7 @@ Prod/dev still carry, until PLAT-147 deletes those two stacks:
future `hcptf-*` role),
- the `seahaven-hcptf-iam-management` guardrail policy (enumerated
`seahaven-lambda-execution-boundary-*` allow-list; frozen, do not append),
- the eight existing prod `hcptf-<stack>` pairs with `DeletionPolicy: Retain`.
- no prod `hcptf-<stack>` pairs. The six imported pairs are Retain-removed. `seahaven-site` is `seahaven-site-hcptf`. `sh-openswe-traces` is gone.
External-dev still carries:
@ -301,10 +301,10 @@ org-level control for the same class is `protect-privileged-roles` on prod
and nonprod (PLAT-145), covering `hcptf-bootstrap*` plus the break-glass /
CDK / `githubdeploy-*` set already on the security OU.
The eight existing prod/dev per-workspace pairs are imported into the owning
app, not recreated. After import they are Retain-removed from this template
and the prod/dev stacks are deleted. See the first-apply and import runbooks
below. Do not batch those consumer PRs; pilot is `afi-backup-monitor`.
The six live prod pairs are imported into the owning app, not recreated, then
Retain-removed from this template. `seahaven-site` is `seahaven-site-hcptf`.
`sh-openswe-traces` is not imported. The prod/dev stacks are deleted after
that forget. See the first-apply and import runbooks below.
**External-dev SHOC role adoption is a staged CloudFormation import, not a
normal first deploy.** Six roles exist today:
@ -594,13 +594,12 @@ plan-refresh sidecar. Apply role: scoped IAM statements from
`lib/hcptf-bootstrap/scoped-apply-iam.json.tmpl` plus prefix-scoped service
wildcards. Do not enumerate provider Get* APIs.
**Import runbook (existing eight prod stacks, PLAT-146).** Import, do not
recreate. Role names and `TFC_AWS_*_ROLE_ARN` stay the same. Pilot is
`afi-backup-monitor` only; do not batch the remaining seven.
Repos that must change: `afi-backup-monitor`, `front-integrations`,
`paychex-integrations`, `sh-openswe-traces`, `procurement-ingest`,
`seahaven-site`, `meal-order-manager`, `seahaven-door-unlock-api`.
**Import runbook (PLAT-146).** Import, do not recreate. Role names and
`TFC_AWS_*_ROLE_ARN` stay the same. The six live prod pairs are in HCP
state: `afi-backup-monitor`, `front-integrations`, `paychex-integrations`,
`procurement-ingest`, `meal-order-manager`, `seahaven-door-unlock-api`.
`sh-openswe-traces` was decommissioned (PLAT-196) and is not imported.
`seahaven-site` is stack `seahaven-site-hcptf` (PLAT-225), not this template.
Repos that do not change: SHOC (`shoc-backend`, `shoc-frontend-new`),
remaining SAM / unmigrated stacks.
@ -617,13 +616,14 @@ revoke the extra trust. Lambda `permissions_boundary` may keep pointing
at `seahaven-lambda-execution-boundary-<stack>` in deploy-substrate for this
pass.
**Prod/dev substrate delete (PLAT-147).** After all eight imports:
**Prod/dev substrate delete (PLAT-147).** After the six imports:
1. Inventory `seahaven-hcptf-iam-management` attachments
(`scripts/delete-terraform-substrate-prod-dev.sh --account prod --inventory`).
None may remain.
2. Remove the eight prod role pairs from the template (they already have
2. Remove the six prod role pairs from the template (they already have
`DeletionPolicy: Retain`) so CloudFormation forgets them without deleting.
`sh-openswe-traces` and `seahaven-site` are not in this list.
3. Remove `terraform-substrate-prod` and `terraform-substrate-dev` from
`bin/app.ts` and `.github/workflows/deploy.yaml`. Keep
`terraform-substrate-external-dev`.

File diff suppressed because it is too large Load diff