mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
chore(terraform-substrate): forget imported prod hcptf pairs (PLAT-147) (#164)
The six pairs are already in HCP state and DeletionPolicy is Retain, so CloudFormation drops the logical IDs without deleting the roles.
This commit is contained in:
parent
cc068f3c8d
commit
ca179bbdf6
2 changed files with 18 additions and 1803 deletions
30
README.md
30
README.md
|
|
@ -31,7 +31,7 @@ are noted):
|
|||
| `seahaven-backup-offsite` | 328440206208 | us-west-2 | Governance-locked offsite copy vault (C-7) |
|
||||
| `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) |
|
||||
| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget |
|
||||
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager + eight existing `hcptf-*` pairs (DeletionPolicy Retain). Pending PLAT-147 delete after consumer imports. New prod/dev HCP IAM is not added here. |
|
||||
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager. The six imported prod pairs are forgotten with `DeletionPolicy: Retain` (PLAT-147). Stacks stay until the delete. New prod/dev HCP IAM is not added here. |
|
||||
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. |
|
||||
| `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). |
|
||||
| `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) |
|
||||
|
|
@ -255,7 +255,7 @@ Prod/dev still carry, until PLAT-147 deletes those two stacks:
|
|||
future `hcptf-*` role),
|
||||
- the `seahaven-hcptf-iam-management` guardrail policy (enumerated
|
||||
`seahaven-lambda-execution-boundary-*` allow-list; frozen, do not append),
|
||||
- the eight existing prod `hcptf-<stack>` pairs with `DeletionPolicy: Retain`.
|
||||
- no prod `hcptf-<stack>` pairs. The six imported pairs are Retain-removed. `seahaven-site` is `seahaven-site-hcptf`. `sh-openswe-traces` is gone.
|
||||
|
||||
External-dev still carries:
|
||||
|
||||
|
|
@ -301,10 +301,10 @@ org-level control for the same class is `protect-privileged-roles` on prod
|
|||
and nonprod (PLAT-145), covering `hcptf-bootstrap*` plus the break-glass /
|
||||
CDK / `githubdeploy-*` set already on the security OU.
|
||||
|
||||
The eight existing prod/dev per-workspace pairs are imported into the owning
|
||||
app, not recreated. After import they are Retain-removed from this template
|
||||
and the prod/dev stacks are deleted. See the first-apply and import runbooks
|
||||
below. Do not batch those consumer PRs; pilot is `afi-backup-monitor`.
|
||||
The six live prod pairs are imported into the owning app, not recreated, then
|
||||
Retain-removed from this template. `seahaven-site` is `seahaven-site-hcptf`.
|
||||
`sh-openswe-traces` is not imported. The prod/dev stacks are deleted after
|
||||
that forget. See the first-apply and import runbooks below.
|
||||
|
||||
**External-dev SHOC role adoption is a staged CloudFormation import, not a
|
||||
normal first deploy.** Six roles exist today:
|
||||
|
|
@ -594,13 +594,12 @@ plan-refresh sidecar. Apply role: scoped IAM statements from
|
|||
`lib/hcptf-bootstrap/scoped-apply-iam.json.tmpl` plus prefix-scoped service
|
||||
wildcards. Do not enumerate provider Get* APIs.
|
||||
|
||||
**Import runbook (existing eight prod stacks, PLAT-146).** Import, do not
|
||||
recreate. Role names and `TFC_AWS_*_ROLE_ARN` stay the same. Pilot is
|
||||
`afi-backup-monitor` only; do not batch the remaining seven.
|
||||
|
||||
Repos that must change: `afi-backup-monitor`, `front-integrations`,
|
||||
`paychex-integrations`, `sh-openswe-traces`, `procurement-ingest`,
|
||||
`seahaven-site`, `meal-order-manager`, `seahaven-door-unlock-api`.
|
||||
**Import runbook (PLAT-146).** Import, do not recreate. Role names and
|
||||
`TFC_AWS_*_ROLE_ARN` stay the same. The six live prod pairs are in HCP
|
||||
state: `afi-backup-monitor`, `front-integrations`, `paychex-integrations`,
|
||||
`procurement-ingest`, `meal-order-manager`, `seahaven-door-unlock-api`.
|
||||
`sh-openswe-traces` was decommissioned (PLAT-196) and is not imported.
|
||||
`seahaven-site` is stack `seahaven-site-hcptf` (PLAT-225), not this template.
|
||||
|
||||
Repos that do not change: SHOC (`shoc-backend`, `shoc-frontend-new`),
|
||||
remaining SAM / unmigrated stacks.
|
||||
|
|
@ -617,13 +616,14 @@ revoke the extra trust. Lambda `permissions_boundary` may keep pointing
|
|||
at `seahaven-lambda-execution-boundary-<stack>` in deploy-substrate for this
|
||||
pass.
|
||||
|
||||
**Prod/dev substrate delete (PLAT-147).** After all eight imports:
|
||||
**Prod/dev substrate delete (PLAT-147).** After the six imports:
|
||||
|
||||
1. Inventory `seahaven-hcptf-iam-management` attachments
|
||||
(`scripts/delete-terraform-substrate-prod-dev.sh --account prod --inventory`).
|
||||
None may remain.
|
||||
2. Remove the eight prod role pairs from the template (they already have
|
||||
2. Remove the six prod role pairs from the template (they already have
|
||||
`DeletionPolicy: Retain`) so CloudFormation forgets them without deleting.
|
||||
`sh-openswe-traces` and `seahaven-site` are not in this list.
|
||||
3. Remove `terraform-substrate-prod` and `terraform-substrate-dev` from
|
||||
`bin/app.ts` and `.github/workflows/deploy.yaml`. Keep
|
||||
`terraform-substrate-external-dev`.
|
||||
|
|
|
|||
File diff suppressed because it is too large
Load diff
Loading…
Add table
Reference in a new issue