From f8c8d250506571ec9310324db9b3ae5b0780d23b Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 28 Sep 2026 20:05:42 +0000 Subject: [PATCH] chore(terraform-substrate): drop prod and dev stacks from CD (PLAT-147) (#165) CD must stop deploying seahaven-terraform-substrate before the live stacks are deleted, or the next push recreates them. --- .github/workflows/deploy.yaml | 4 ++-- README.md | 43 ++++++++++++++++------------------- bin/app.ts | 37 ++++++------------------------ 3 files changed, 29 insertions(+), 55 deletions(-) diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml index e8dd908..e4cea1b 100644 --- a/.github/workflows/deploy.yaml +++ b/.github/workflows/deploy.yaml @@ -47,7 +47,7 @@ jobs: uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7 with: node-version: "24" - stacks: "dev-baseline deploy-substrate-dev terraform-substrate-dev" + stacks: "dev-baseline deploy-substrate-dev" stack-name: "seahaven-dev-baseline" secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_DEV }} @@ -57,7 +57,7 @@ jobs: with: node-version: "24" # seahaven-site-hcptf was imported after the roles left terraform-substrate. - stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod seahaven-site-hcptf" + stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod app-web-acl-prod seahaven-site-hcptf" stack-name: "seahaven-prod-baseline" secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }} diff --git a/README.md b/README.md index 98fb62b..05d45dc 100644 --- a/README.md +++ b/README.md @@ -31,7 +31,7 @@ are noted): | `seahaven-backup-offsite` | 328440206208 | us-west-2 | Governance-locked offsite copy vault (C-7) | | `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) | | `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget | -| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager. The six imported prod pairs are forgotten with `DeletionPolicy: Retain` (PLAT-147). Stacks stay until the delete. New prod/dev HCP IAM is not added here. | +| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Removed from the CDK app and from CD (PLAT-147). Live stacks remain until `scripts/delete-terraform-substrate-prod-dev.sh`. The six imported prod pairs are already forgotten. | | `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. | | `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). | | `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) | @@ -71,8 +71,6 @@ the TypeScript source — no separate compile step needed for `cdk synth` / | `prod-baseline` | `seahaven-prod-baseline` | 011934824531 | us-east-1 | `lib/member-baseline-stack.ts` (orgManagedDetection) | | `deploy-substrate-prod` | `seahaven-deploy-substrate` | 011934824531 | us-east-1 | `lib/deploy-substrate-stack.ts` | | `deploy-substrate-dev` | `seahaven-deploy-substrate` | 710827005802 | us-east-1 | `lib/deploy-substrate-stack.ts` | -| `terraform-substrate-prod` | `seahaven-terraform-substrate` | 011934824531 | us-east-1 | `lib/terraform-substrate-stack.ts` (pending PLAT-147 delete) | -| `terraform-substrate-dev` | `seahaven-terraform-substrate` | 710827005802 | us-east-1 | `lib/terraform-substrate-stack.ts` (pending PLAT-147 delete) | | `terraform-substrate-external-dev` | `seahaven-terraform-substrate` | 396287094661 | us-east-1 | `lib/terraform-substrate-stack.ts` | | `dynamodb-cmk-prod` | `seahaven-dynamodb-cmk` | 011934824531 | us-east-1 | `lib/dynamodb-cmk-stack.ts` | | `alarm-topic-prod` | `seahaven-alarm-topic` | 011934824531 | us-east-1 | `lib/alarm-topic-stack.ts` | @@ -220,9 +218,9 @@ created with the boundary already attached. ### Terraform deploy substrate (per account) `lib/terraform-substrate-stack.ts` + `lib/terraform-substrate/terraform-substrate.template.yaml` -deploy `seahaven-terraform-substrate` into member accounts that host -Terraform-managed workloads (currently seahaven-prod, seahaven-dev, and -external-dev; never mgmt — mgmt stays SAM until its stacks migrate out). +deploy `seahaven-terraform-substrate` for external-dev. Prod and dev are +no longer in this app. Their live stacks stay until the PLAT-147 delete. +Never mgmt — mgmt stays SAM until its stacks migrate out. **Durable owner for prod/dev per-workload HCP IAM is app Terraform (PLAT-144).** Console / one-shot CLI owns only: @@ -248,14 +246,17 @@ or `shoc-frontend-new`. New external-dev IAM still lands here. enumerated SAM `StringEquals` allow-list are unchanged. Do not add `ArnLike` there (PLAT-52 AC1). Do not add new HCP workloads to those four Sids. -Prod/dev still carry, until PLAT-147 deletes those two stacks: +Prod/dev stacks are out of `bin/app.ts` and `.github/workflows/deploy.yaml`. +Until the delete script runs, the live stacks still hold: - the `app.terraform.io` OIDC identity provider (audience `aws.workload.identity`; Retain — it is the federation anchor for every future `hcptf-*` role), - the `seahaven-hcptf-iam-management` guardrail policy (enumerated - `seahaven-lambda-execution-boundary-*` allow-list; frozen, do not append), -- no prod `hcptf-` pairs. The six imported pairs are Retain-removed. `seahaven-site` is `seahaven-site-hcptf`. `sh-openswe-traces` is gone. + `seahaven-lambda-execution-boundary-*` allow-list; frozen, do not append). + +The six imported prod pairs are Retain-removed. `seahaven-site` is +`seahaven-site-hcptf`. `sh-openswe-traces` is gone. External-dev still carries: @@ -616,21 +617,17 @@ revoke the extra trust. Lambda `permissions_boundary` may keep pointing at `seahaven-lambda-execution-boundary-` in deploy-substrate for this pass. -**Prod/dev substrate delete (PLAT-147).** After the six imports: +**Prod/dev substrate delete (PLAT-147).** Imports, the Retain-remove, and +removal from `bin/app.ts` and `.github/workflows/deploy.yaml` are done. +`terraform-substrate-external-dev` stays. -1. Inventory `seahaven-hcptf-iam-management` attachments - (`scripts/delete-terraform-substrate-prod-dev.sh --account prod --inventory`). - None may remain. -2. Remove the six prod role pairs from the template (they already have - `DeletionPolicy: Retain`) so CloudFormation forgets them without deleting. - `sh-openswe-traces` and `seahaven-site` are not in this list. -3. Remove `terraform-substrate-prod` and `terraform-substrate-dev` from - `bin/app.ts` and `.github/workflows/deploy.yaml`. Keep - `terraform-substrate-external-dev`. -4. Delete stacks in `011934824531` and `710827005802` only. OIDC is Retain. - `seahaven-hcptf-iam-management` deletes with those stacks. Do not delete - `terraform-substrate-external-dev`. Do not strip SHOC resources from the - shared YAML while that stack still synthesizes them. +Delete stacks in `011934824531` and `710827005802` only, after inventory +shows no `seahaven-hcptf-iam-management` attachments +(`scripts/delete-terraform-substrate-prod-dev.sh --account prod --inventory`, +then `--yes`, then the same for dev). OIDC is Retain. +`seahaven-hcptf-iam-management` deletes with those stacks. Do not delete +`terraform-substrate-external-dev`. Do not strip SHOC resources from the +shared YAML while that stack still synthesizes them. **HCP-side authority is AWS authority.** AWS exposes only `aud`, `sub` and `amr` as trust-policy condition keys for a generic OIDC provider — HCP's diff --git a/bin/app.ts b/bin/app.ts index 974391a..998392e 100644 --- a/bin/app.ts +++ b/bin/app.ts @@ -195,36 +195,23 @@ new MemberBaselineStack(app, "prod-baseline", { // seahaven-lambda-execution-boundary policy both returned NoSuchEntity in // 011934824531 AND 710827005802, so the named creates cannot collide with // out-of-band copies. -const deploySubstrateProd = new DeploySubstrateStack(app, "deploy-substrate-prod", { +new DeploySubstrateStack(app, "deploy-substrate-prod", { stackName: "seahaven-deploy-substrate", env: { account: PROD_ACCOUNT, region: "us-east-1" }, createOidcProvider: false, }); -const deploySubstrateDev = new DeploySubstrateStack(app, "deploy-substrate-dev", { +new DeploySubstrateStack(app, "deploy-substrate-dev", { stackName: "seahaven-deploy-substrate", env: { account: DEV_ACCOUNT, region: "us-east-1" }, createOidcProvider: false, }); -// ── Per-account HCP Terraform deploy substrate ─────────────────────────────── -// Prod/dev instances still exist until PLAT-147: they own the live eight -// hcptf- pairs (DeletionPolicy Retain) and seahaven-hcptf-iam-management. -// Do not append new prod/dev workspace roles here. Do not add a CDK stack for -// hcptf-bootstrap (CLI-owned, PLAT-145). External-dev stays: SHOC IAM is not -// moving (PLAT-148). deploy-substrate stays for remaining SAM (PLAT-150). -// The guardrail policy names seahaven-lambda-execution-boundary ARNs only -// inside Condition strings, so CFN infers no creation edge — the explicit -// dependency below keeps deploy-substrate first while these stacks remain. -const terraformSubstrateProd = new TerraformSubstrateStack( - app, - "terraform-substrate-prod", - { - stackName: "seahaven-terraform-substrate", - env: { account: PROD_ACCOUNT, region: "us-east-1" }, - }, -); -terraformSubstrateProd.addStackDependency(deploySubstrateProd); +// Prod/dev seahaven-terraform-substrate is out of this app and out of CD +// (PLAT-147). The live stacks stay until scripts/delete-terraform-substrate-prod-dev.sh. +// Do not add them back. Do not add a CDK stack for hcptf-bootstrap (CLI-owned, +// PLAT-145). External-dev stays: SHOC IAM is not moving (PLAT-148). +// deploy-substrate stays for remaining SAM (PLAT-150). // Shared CloudFront WAF for seahaven-prod (PLAT-92). Same AppWebAcl construct // as mgmt account-baseline; thin stack so prod does not inherit the full @@ -242,16 +229,6 @@ new SeahavenSiteHcptfStack(app, "seahaven-site-hcptf", { env: { account: PROD_ACCOUNT, region: "us-east-1" }, }); -const terraformSubstrateDev = new TerraformSubstrateStack( - app, - "terraform-substrate-dev", - { - stackName: "seahaven-terraform-substrate", - env: { account: DEV_ACCOUNT, region: "us-east-1" }, - }, -); -terraformSubstrateDev.addStackDependency(deploySubstrateDev); - // External-dev already has app.terraform.io federation. Both role gates start // false in cdk.json: POC is enabled by a normal update; dev/staging only by // CloudFormation import after Terraform relinquishes those four live roles.