chore(terraform-substrate): forget imported prod hcptf pairs (PLAT-147) (#164)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

The six pairs are already in HCP state and DeletionPolicy is Retain, so CloudFormation drops the logical IDs without deleting the roles.
This commit is contained in:
Adam Moussa 2026-09-28 15:56:04 -04:00 • committed by GitHub
parent cc068f3c8d
commit ca179bbdf6
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 18 additions and 1803 deletions

View file

@ -31,7 +31,7 @@ are noted):
| `seahaven-backup-offsite` | 328440206208 | us-west-2 | Governance-locked offsite copy vault (C-7) | | `seahaven-backup-offsite` | 328440206208 | us-west-2 | Governance-locked offsite copy vault (C-7) |
| `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) | | `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) |
| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget | | `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget |
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager + eight existing `hcptf-*` pairs (DeletionPolicy Retain). Pending PLAT-147 delete after consumer imports. New prod/dev HCP IAM is not added here. | | `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager. The six imported prod pairs are forgotten with `DeletionPolicy: Retain` (PLAT-147). Stacks stay until the delete. New prod/dev HCP IAM is not added here. |
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. | | `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. |
| `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). | | `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). |
| `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) | | `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) |
@ -255,7 +255,7 @@ Prod/dev still carry, until PLAT-147 deletes those two stacks:
future `hcptf-*` role), future `hcptf-*` role),
- the `seahaven-hcptf-iam-management` guardrail policy (enumerated - the `seahaven-hcptf-iam-management` guardrail policy (enumerated
`seahaven-lambda-execution-boundary-*` allow-list; frozen, do not append), `seahaven-lambda-execution-boundary-*` allow-list; frozen, do not append),
- the eight existing prod `hcptf-<stack>` pairs with `DeletionPolicy: Retain`. - no prod `hcptf-<stack>` pairs. The six imported pairs are Retain-removed. `seahaven-site` is `seahaven-site-hcptf`. `sh-openswe-traces` is gone.
External-dev still carries: External-dev still carries:
@ -301,10 +301,10 @@ org-level control for the same class is `protect-privileged-roles` on prod
and nonprod (PLAT-145), covering `hcptf-bootstrap*` plus the break-glass / and nonprod (PLAT-145), covering `hcptf-bootstrap*` plus the break-glass /
CDK / `githubdeploy-*` set already on the security OU. CDK / `githubdeploy-*` set already on the security OU.
The eight existing prod/dev per-workspace pairs are imported into the owning The six live prod pairs are imported into the owning app, not recreated, then
app, not recreated. After import they are Retain-removed from this template Retain-removed from this template. `seahaven-site` is `seahaven-site-hcptf`.
and the prod/dev stacks are deleted. See the first-apply and import runbooks `sh-openswe-traces` is not imported. The prod/dev stacks are deleted after
below. Do not batch those consumer PRs; pilot is `afi-backup-monitor`. that forget. See the first-apply and import runbooks below.
**External-dev SHOC role adoption is a staged CloudFormation import, not a **External-dev SHOC role adoption is a staged CloudFormation import, not a
normal first deploy.** Six roles exist today: normal first deploy.** Six roles exist today:
@ -594,13 +594,12 @@ plan-refresh sidecar. Apply role: scoped IAM statements from
`lib/hcptf-bootstrap/scoped-apply-iam.json.tmpl` plus prefix-scoped service `lib/hcptf-bootstrap/scoped-apply-iam.json.tmpl` plus prefix-scoped service
wildcards. Do not enumerate provider Get* APIs. wildcards. Do not enumerate provider Get* APIs.
**Import runbook (existing eight prod stacks, PLAT-146).** Import, do not **Import runbook (PLAT-146).** Import, do not recreate. Role names and
recreate. Role names and `TFC_AWS_*_ROLE_ARN` stay the same. Pilot is `TFC_AWS_*_ROLE_ARN` stay the same. The six live prod pairs are in HCP
`afi-backup-monitor` only; do not batch the remaining seven. state: `afi-backup-monitor`, `front-integrations`, `paychex-integrations`,
`procurement-ingest`, `meal-order-manager`, `seahaven-door-unlock-api`.
Repos that must change: `afi-backup-monitor`, `front-integrations`, `sh-openswe-traces` was decommissioned (PLAT-196) and is not imported.
`paychex-integrations`, `sh-openswe-traces`, `procurement-ingest`, `seahaven-site` is stack `seahaven-site-hcptf` (PLAT-225), not this template.
`seahaven-site`, `meal-order-manager`, `seahaven-door-unlock-api`.
Repos that do not change: SHOC (`shoc-backend`, `shoc-frontend-new`), Repos that do not change: SHOC (`shoc-backend`, `shoc-frontend-new`),
remaining SAM / unmigrated stacks. remaining SAM / unmigrated stacks.
@ -617,13 +616,14 @@ revoke the extra trust. Lambda `permissions_boundary` may keep pointing
at `seahaven-lambda-execution-boundary-<stack>` in deploy-substrate for this at `seahaven-lambda-execution-boundary-<stack>` in deploy-substrate for this
pass. pass.
**Prod/dev substrate delete (PLAT-147).** After all eight imports: **Prod/dev substrate delete (PLAT-147).** After the six imports:
1. Inventory `seahaven-hcptf-iam-management` attachments 1. Inventory `seahaven-hcptf-iam-management` attachments
(`scripts/delete-terraform-substrate-prod-dev.sh --account prod --inventory`). (`scripts/delete-terraform-substrate-prod-dev.sh --account prod --inventory`).
None may remain. None may remain.
2. Remove the eight prod role pairs from the template (they already have 2. Remove the six prod role pairs from the template (they already have
`DeletionPolicy: Retain`) so CloudFormation forgets them without deleting. `DeletionPolicy: Retain`) so CloudFormation forgets them without deleting.
`sh-openswe-traces` and `seahaven-site` are not in this list.
3. Remove `terraform-substrate-prod` and `terraform-substrate-dev` from 3. Remove `terraform-substrate-prod` and `terraform-substrate-dev` from
`bin/app.ts` and `.github/workflows/deploy.yaml`. Keep `bin/app.ts` and `.github/workflows/deploy.yaml`. Keep
`terraform-substrate-external-dev`. `terraform-substrate-external-dev`.

File diff suppressed because it is too large Load diff