chore(terraform-substrate): forget imported prod hcptf pairs (PLAT-147)

The six pairs are already in HCP state and DeletionPolicy is Retain, so CloudFormation drops the logical IDs without deleting the roles.
This commit is contained in:
Adam Moussa 2026-09-28 15:38:14 -04:00
parent cc068f3c8d
commit f6791c15f6
No known key found for this signature in database
2 changed files with 18 additions and 1803 deletions

View file

@ -31,7 +31,7 @@ are noted):
| `seahaven-backup-offsite` | 328440206208 | us-west-2 | Governance-locked offsite copy vault (C-7) |
| `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) |
| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget |
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager + eight existing `hcptf-*` pairs (DeletionPolicy Retain). Pending PLAT-147 delete after consumer imports. New prod/dev HCP IAM is not added here. |
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager. The six imported prod pairs are forgotten with `DeletionPolicy: Retain` (PLAT-147). Stacks stay until the delete. New prod/dev HCP IAM is not added here. |
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. |
| `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). |
| `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) |
@ -255,7 +255,7 @@ Prod/dev still carry, until PLAT-147 deletes those two stacks:
future `hcptf-*` role),
- the `seahaven-hcptf-iam-management` guardrail policy (enumerated
`seahaven-lambda-execution-boundary-*` allow-list; frozen, do not append),
- the eight existing prod `hcptf-<stack>` pairs with `DeletionPolicy: Retain`.
- no prod `hcptf-<stack>` pairs. The six imported pairs are Retain-removed. `seahaven-site` is `seahaven-site-hcptf`. `sh-openswe-traces` is gone.
External-dev still carries:
@ -301,10 +301,10 @@ org-level control for the same class is `protect-privileged-roles` on prod
and nonprod (PLAT-145), covering `hcptf-bootstrap*` plus the break-glass /
CDK / `githubdeploy-*` set already on the security OU.
The eight existing prod/dev per-workspace pairs are imported into the owning
app, not recreated. After import they are Retain-removed from this template
and the prod/dev stacks are deleted. See the first-apply and import runbooks
below. Do not batch those consumer PRs; pilot is `afi-backup-monitor`.
The six live prod pairs are imported into the owning app, not recreated, then
Retain-removed from this template. `seahaven-site` is `seahaven-site-hcptf`.
`sh-openswe-traces` is not imported. The prod/dev stacks are deleted after
that forget. See the first-apply and import runbooks below.
**External-dev SHOC role adoption is a staged CloudFormation import, not a
normal first deploy.** Six roles exist today:
@ -594,13 +594,12 @@ plan-refresh sidecar. Apply role: scoped IAM statements from
`lib/hcptf-bootstrap/scoped-apply-iam.json.tmpl` plus prefix-scoped service
wildcards. Do not enumerate provider Get* APIs.
**Import runbook (existing eight prod stacks, PLAT-146).** Import, do not
recreate. Role names and `TFC_AWS_*_ROLE_ARN` stay the same. Pilot is
`afi-backup-monitor` only; do not batch the remaining seven.
Repos that must change: `afi-backup-monitor`, `front-integrations`,
`paychex-integrations`, `sh-openswe-traces`, `procurement-ingest`,
`seahaven-site`, `meal-order-manager`, `seahaven-door-unlock-api`.
**Import runbook (PLAT-146).** Import, do not recreate. Role names and
`TFC_AWS_*_ROLE_ARN` stay the same. The six live prod pairs are in HCP
state: `afi-backup-monitor`, `front-integrations`, `paychex-integrations`,
`procurement-ingest`, `meal-order-manager`, `seahaven-door-unlock-api`.
`sh-openswe-traces` was decommissioned (PLAT-196) and is not imported.
`seahaven-site` is stack `seahaven-site-hcptf` (PLAT-225), not this template.
Repos that do not change: SHOC (`shoc-backend`, `shoc-frontend-new`),
remaining SAM / unmigrated stacks.
@ -617,13 +616,14 @@ revoke the extra trust. Lambda `permissions_boundary` may keep pointing
at `seahaven-lambda-execution-boundary-<stack>` in deploy-substrate for this
pass.
**Prod/dev substrate delete (PLAT-147).** After all eight imports:
**Prod/dev substrate delete (PLAT-147).** After the six imports:
1. Inventory `seahaven-hcptf-iam-management` attachments
(`scripts/delete-terraform-substrate-prod-dev.sh --account prod --inventory`).
None may remain.
2. Remove the eight prod role pairs from the template (they already have
2. Remove the six prod role pairs from the template (they already have
`DeletionPolicy: Retain`) so CloudFormation forgets them without deleting.
`sh-openswe-traces` and `seahaven-site` are not in this list.
3. Remove `terraform-substrate-prod` and `terraform-substrate-dev` from
`bin/app.ts` and `.github/workflows/deploy.yaml`. Keep
`terraform-substrate-external-dev`.

File diff suppressed because it is too large Load diff