chore(terraform-substrate): drop prod and dev stacks from CD (PLAT-147) (#165)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

CD must stop deploying seahaven-terraform-substrate before the live stacks are deleted, or the next push recreates them.
This commit is contained in:
Adam Moussa 2026-09-28 20:05:42 +00:00 • committed by GitHub
parent ca179bbdf6
commit f8c8d25050
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 29 additions and 55 deletions

View file

@ -47,7 +47,7 @@ jobs:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7 uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
with: with:
node-version: "24" node-version: "24"
stacks: "dev-baseline deploy-substrate-dev terraform-substrate-dev" stacks: "dev-baseline deploy-substrate-dev"
stack-name: "seahaven-dev-baseline" stack-name: "seahaven-dev-baseline"
secrets: secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_DEV }} deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_DEV }}
@ -57,7 +57,7 @@ jobs:
with: with:
node-version: "24" node-version: "24"
# seahaven-site-hcptf was imported after the roles left terraform-substrate. # seahaven-site-hcptf was imported after the roles left terraform-substrate.
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod seahaven-site-hcptf" stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod app-web-acl-prod seahaven-site-hcptf"
stack-name: "seahaven-prod-baseline" stack-name: "seahaven-prod-baseline"
secrets: secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }} deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }}

View file

@ -31,7 +31,7 @@ are noted):
| `seahaven-backup-offsite` | 328440206208 | us-west-2 | Governance-locked offsite copy vault (C-7) | | `seahaven-backup-offsite` | 328440206208 | us-west-2 | Governance-locked offsite copy vault (C-7) |
| `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) | | `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) |
| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget | | `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget |
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager. The six imported prod pairs are forgotten with `DeletionPolicy: Retain` (PLAT-147). Stacks stay until the delete. New prod/dev HCP IAM is not added here. | | `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Removed from the CDK app and from CD (PLAT-147). Live stacks remain until `scripts/delete-terraform-substrate-prod-dev.sh`. The six imported prod pairs are already forgotten. |
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. | | `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. |
| `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). | | `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). |
| `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) | | `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) |
@ -71,8 +71,6 @@ the TypeScript source — no separate compile step needed for `cdk synth` /
| `prod-baseline` | `seahaven-prod-baseline` | 011934824531 | us-east-1 | `lib/member-baseline-stack.ts` (orgManagedDetection) | | `prod-baseline` | `seahaven-prod-baseline` | 011934824531 | us-east-1 | `lib/member-baseline-stack.ts` (orgManagedDetection) |
| `deploy-substrate-prod` | `seahaven-deploy-substrate` | 011934824531 | us-east-1 | `lib/deploy-substrate-stack.ts` | | `deploy-substrate-prod` | `seahaven-deploy-substrate` | 011934824531 | us-east-1 | `lib/deploy-substrate-stack.ts` |
| `deploy-substrate-dev` | `seahaven-deploy-substrate` | 710827005802 | us-east-1 | `lib/deploy-substrate-stack.ts` | | `deploy-substrate-dev` | `seahaven-deploy-substrate` | 710827005802 | us-east-1 | `lib/deploy-substrate-stack.ts` |
| `terraform-substrate-prod` | `seahaven-terraform-substrate` | 011934824531 | us-east-1 | `lib/terraform-substrate-stack.ts` (pending PLAT-147 delete) |
| `terraform-substrate-dev` | `seahaven-terraform-substrate` | 710827005802 | us-east-1 | `lib/terraform-substrate-stack.ts` (pending PLAT-147 delete) |
| `terraform-substrate-external-dev` | `seahaven-terraform-substrate` | 396287094661 | us-east-1 | `lib/terraform-substrate-stack.ts` | | `terraform-substrate-external-dev` | `seahaven-terraform-substrate` | 396287094661 | us-east-1 | `lib/terraform-substrate-stack.ts` |
| `dynamodb-cmk-prod` | `seahaven-dynamodb-cmk` | 011934824531 | us-east-1 | `lib/dynamodb-cmk-stack.ts` | | `dynamodb-cmk-prod` | `seahaven-dynamodb-cmk` | 011934824531 | us-east-1 | `lib/dynamodb-cmk-stack.ts` |
| `alarm-topic-prod` | `seahaven-alarm-topic` | 011934824531 | us-east-1 | `lib/alarm-topic-stack.ts` | | `alarm-topic-prod` | `seahaven-alarm-topic` | 011934824531 | us-east-1 | `lib/alarm-topic-stack.ts` |
@ -220,9 +218,9 @@ created with the boundary already attached.
### Terraform deploy substrate (per account) ### Terraform deploy substrate (per account)
`lib/terraform-substrate-stack.ts` + `lib/terraform-substrate/terraform-substrate.template.yaml` `lib/terraform-substrate-stack.ts` + `lib/terraform-substrate/terraform-substrate.template.yaml`
deploy `seahaven-terraform-substrate` into member accounts that host deploy `seahaven-terraform-substrate` for external-dev. Prod and dev are
Terraform-managed workloads (currently seahaven-prod, seahaven-dev, and no longer in this app. Their live stacks stay until the PLAT-147 delete.
external-dev; never mgmt — mgmt stays SAM until its stacks migrate out). Never mgmt — mgmt stays SAM until its stacks migrate out.
**Durable owner for prod/dev per-workload HCP IAM is app Terraform (PLAT-144).** **Durable owner for prod/dev per-workload HCP IAM is app Terraform (PLAT-144).**
Console / one-shot CLI owns only: Console / one-shot CLI owns only:
@ -248,14 +246,17 @@ or `shoc-frontend-new`. New external-dev IAM still lands here.
enumerated SAM `StringEquals` allow-list are unchanged. Do not add `ArnLike` enumerated SAM `StringEquals` allow-list are unchanged. Do not add `ArnLike`
there (PLAT-52 AC1). Do not add new HCP workloads to those four Sids. there (PLAT-52 AC1). Do not add new HCP workloads to those four Sids.
Prod/dev still carry, until PLAT-147 deletes those two stacks: Prod/dev stacks are out of `bin/app.ts` and `.github/workflows/deploy.yaml`.
Until the delete script runs, the live stacks still hold:
- the `app.terraform.io` OIDC identity provider (audience - the `app.terraform.io` OIDC identity provider (audience
`aws.workload.identity`; Retain — it is the federation anchor for every `aws.workload.identity`; Retain — it is the federation anchor for every
future `hcptf-*` role), future `hcptf-*` role),
- the `seahaven-hcptf-iam-management` guardrail policy (enumerated - the `seahaven-hcptf-iam-management` guardrail policy (enumerated
`seahaven-lambda-execution-boundary-*` allow-list; frozen, do not append), `seahaven-lambda-execution-boundary-*` allow-list; frozen, do not append).
- no prod `hcptf-<stack>` pairs. The six imported pairs are Retain-removed. `seahaven-site` is `seahaven-site-hcptf`. `sh-openswe-traces` is gone.
The six imported prod pairs are Retain-removed. `seahaven-site` is
`seahaven-site-hcptf`. `sh-openswe-traces` is gone.
External-dev still carries: External-dev still carries:
@ -616,18 +617,14 @@ revoke the extra trust. Lambda `permissions_boundary` may keep pointing
at `seahaven-lambda-execution-boundary-<stack>` in deploy-substrate for this at `seahaven-lambda-execution-boundary-<stack>` in deploy-substrate for this
pass. pass.
**Prod/dev substrate delete (PLAT-147).** After the six imports: **Prod/dev substrate delete (PLAT-147).** Imports, the Retain-remove, and
removal from `bin/app.ts` and `.github/workflows/deploy.yaml` are done.
`terraform-substrate-external-dev` stays.
1. Inventory `seahaven-hcptf-iam-management` attachments Delete stacks in `011934824531` and `710827005802` only, after inventory
(`scripts/delete-terraform-substrate-prod-dev.sh --account prod --inventory`). shows no `seahaven-hcptf-iam-management` attachments
None may remain. (`scripts/delete-terraform-substrate-prod-dev.sh --account prod --inventory`,
2. Remove the six prod role pairs from the template (they already have then `--yes`, then the same for dev). OIDC is Retain.
`DeletionPolicy: Retain`) so CloudFormation forgets them without deleting.
`sh-openswe-traces` and `seahaven-site` are not in this list.
3. Remove `terraform-substrate-prod` and `terraform-substrate-dev` from
`bin/app.ts` and `.github/workflows/deploy.yaml`. Keep
`terraform-substrate-external-dev`.
4. Delete stacks in `011934824531` and `710827005802` only. OIDC is Retain.
`seahaven-hcptf-iam-management` deletes with those stacks. Do not delete `seahaven-hcptf-iam-management` deletes with those stacks. Do not delete
`terraform-substrate-external-dev`. Do not strip SHOC resources from the `terraform-substrate-external-dev`. Do not strip SHOC resources from the
shared YAML while that stack still synthesizes them. shared YAML while that stack still synthesizes them.

View file

@ -195,36 +195,23 @@ new MemberBaselineStack(app, "prod-baseline", {
// seahaven-lambda-execution-boundary policy both returned NoSuchEntity in // seahaven-lambda-execution-boundary policy both returned NoSuchEntity in
// 011934824531 AND 710827005802, so the named creates cannot collide with // 011934824531 AND 710827005802, so the named creates cannot collide with
// out-of-band copies. // out-of-band copies.
const deploySubstrateProd = new DeploySubstrateStack(app, "deploy-substrate-prod", { new DeploySubstrateStack(app, "deploy-substrate-prod", {
stackName: "seahaven-deploy-substrate", stackName: "seahaven-deploy-substrate",
env: { account: PROD_ACCOUNT, region: "us-east-1" }, env: { account: PROD_ACCOUNT, region: "us-east-1" },
createOidcProvider: false, createOidcProvider: false,
}); });
const deploySubstrateDev = new DeploySubstrateStack(app, "deploy-substrate-dev", { new DeploySubstrateStack(app, "deploy-substrate-dev", {
stackName: "seahaven-deploy-substrate", stackName: "seahaven-deploy-substrate",
env: { account: DEV_ACCOUNT, region: "us-east-1" }, env: { account: DEV_ACCOUNT, region: "us-east-1" },
createOidcProvider: false, createOidcProvider: false,
}); });
// ── Per-account HCP Terraform deploy substrate ─────────────────────────────── // Prod/dev seahaven-terraform-substrate is out of this app and out of CD
// Prod/dev instances still exist until PLAT-147: they own the live eight // (PLAT-147). The live stacks stay until scripts/delete-terraform-substrate-prod-dev.sh.
// hcptf-<stack> pairs (DeletionPolicy Retain) and seahaven-hcptf-iam-management. // Do not add them back. Do not add a CDK stack for hcptf-bootstrap (CLI-owned,
// Do not append new prod/dev workspace roles here. Do not add a CDK stack for // PLAT-145). External-dev stays: SHOC IAM is not moving (PLAT-148).
// hcptf-bootstrap (CLI-owned, PLAT-145). External-dev stays: SHOC IAM is not // deploy-substrate stays for remaining SAM (PLAT-150).
// moving (PLAT-148). deploy-substrate stays for remaining SAM (PLAT-150).
// The guardrail policy names seahaven-lambda-execution-boundary ARNs only
// inside Condition strings, so CFN infers no creation edge — the explicit
// dependency below keeps deploy-substrate first while these stacks remain.
const terraformSubstrateProd = new TerraformSubstrateStack(
app,
"terraform-substrate-prod",
{
stackName: "seahaven-terraform-substrate",
env: { account: PROD_ACCOUNT, region: "us-east-1" },
},
);
terraformSubstrateProd.addStackDependency(deploySubstrateProd);
// Shared CloudFront WAF for seahaven-prod (PLAT-92). Same AppWebAcl construct // Shared CloudFront WAF for seahaven-prod (PLAT-92). Same AppWebAcl construct
// as mgmt account-baseline; thin stack so prod does not inherit the full // as mgmt account-baseline; thin stack so prod does not inherit the full
@ -242,16 +229,6 @@ new SeahavenSiteHcptfStack(app, "seahaven-site-hcptf", {
env: { account: PROD_ACCOUNT, region: "us-east-1" }, env: { account: PROD_ACCOUNT, region: "us-east-1" },
}); });
const terraformSubstrateDev = new TerraformSubstrateStack(
app,
"terraform-substrate-dev",
{
stackName: "seahaven-terraform-substrate",
env: { account: DEV_ACCOUNT, region: "us-east-1" },
},
);
terraformSubstrateDev.addStackDependency(deploySubstrateDev);
// External-dev already has app.terraform.io federation. Both role gates start // External-dev already has app.terraform.io federation. Both role gates start
// false in cdk.json: POC is enabled by a normal update; dev/staging only by // false in cdk.json: POC is enabled by a normal update; dev/staging only by
// CloudFormation import after Terraform relinquishes those four live roles. // CloudFormation import after Terraform relinquishes those four live roles.