mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 03:23:15 +00:00
chore(terraform-substrate): drop prod and dev stacks from CD (PLAT-147) (#165)
CD must stop deploying seahaven-terraform-substrate before the live stacks are deleted, or the next push recreates them.
This commit is contained in:
parent
ca179bbdf6
commit
f8c8d25050
3 changed files with 29 additions and 55 deletions
4
.github/workflows/deploy.yaml
vendored
4
.github/workflows/deploy.yaml
vendored
|
|
@ -47,7 +47,7 @@ jobs:
|
|||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
|
||||
with:
|
||||
node-version: "24"
|
||||
stacks: "dev-baseline deploy-substrate-dev terraform-substrate-dev"
|
||||
stacks: "dev-baseline deploy-substrate-dev"
|
||||
stack-name: "seahaven-dev-baseline"
|
||||
secrets:
|
||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_DEV }}
|
||||
|
|
@ -57,7 +57,7 @@ jobs:
|
|||
with:
|
||||
node-version: "24"
|
||||
# seahaven-site-hcptf was imported after the roles left terraform-substrate.
|
||||
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod seahaven-site-hcptf"
|
||||
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod app-web-acl-prod seahaven-site-hcptf"
|
||||
stack-name: "seahaven-prod-baseline"
|
||||
secrets:
|
||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }}
|
||||
|
|
|
|||
43
README.md
43
README.md
|
|
@ -31,7 +31,7 @@ are noted):
|
|||
| `seahaven-backup-offsite` | 328440206208 | us-west-2 | Governance-locked offsite copy vault (C-7) |
|
||||
| `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) |
|
||||
| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget |
|
||||
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager. The six imported prod pairs are forgotten with `DeletionPolicy: Retain` (PLAT-147). Stacks stay until the delete. New prod/dev HCP IAM is not added here. |
|
||||
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Removed from the CDK app and from CD (PLAT-147). Live stacks remain until `scripts/delete-terraform-substrate-prod-dev.sh`. The six imported prod pairs are already forgotten. |
|
||||
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. |
|
||||
| `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). |
|
||||
| `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) |
|
||||
|
|
@ -71,8 +71,6 @@ the TypeScript source — no separate compile step needed for `cdk synth` /
|
|||
| `prod-baseline` | `seahaven-prod-baseline` | 011934824531 | us-east-1 | `lib/member-baseline-stack.ts` (orgManagedDetection) |
|
||||
| `deploy-substrate-prod` | `seahaven-deploy-substrate` | 011934824531 | us-east-1 | `lib/deploy-substrate-stack.ts` |
|
||||
| `deploy-substrate-dev` | `seahaven-deploy-substrate` | 710827005802 | us-east-1 | `lib/deploy-substrate-stack.ts` |
|
||||
| `terraform-substrate-prod` | `seahaven-terraform-substrate` | 011934824531 | us-east-1 | `lib/terraform-substrate-stack.ts` (pending PLAT-147 delete) |
|
||||
| `terraform-substrate-dev` | `seahaven-terraform-substrate` | 710827005802 | us-east-1 | `lib/terraform-substrate-stack.ts` (pending PLAT-147 delete) |
|
||||
| `terraform-substrate-external-dev` | `seahaven-terraform-substrate` | 396287094661 | us-east-1 | `lib/terraform-substrate-stack.ts` |
|
||||
| `dynamodb-cmk-prod` | `seahaven-dynamodb-cmk` | 011934824531 | us-east-1 | `lib/dynamodb-cmk-stack.ts` |
|
||||
| `alarm-topic-prod` | `seahaven-alarm-topic` | 011934824531 | us-east-1 | `lib/alarm-topic-stack.ts` |
|
||||
|
|
@ -220,9 +218,9 @@ created with the boundary already attached.
|
|||
### Terraform deploy substrate (per account)
|
||||
|
||||
`lib/terraform-substrate-stack.ts` + `lib/terraform-substrate/terraform-substrate.template.yaml`
|
||||
deploy `seahaven-terraform-substrate` into member accounts that host
|
||||
Terraform-managed workloads (currently seahaven-prod, seahaven-dev, and
|
||||
external-dev; never mgmt — mgmt stays SAM until its stacks migrate out).
|
||||
deploy `seahaven-terraform-substrate` for external-dev. Prod and dev are
|
||||
no longer in this app. Their live stacks stay until the PLAT-147 delete.
|
||||
Never mgmt — mgmt stays SAM until its stacks migrate out.
|
||||
|
||||
**Durable owner for prod/dev per-workload HCP IAM is app Terraform (PLAT-144).**
|
||||
Console / one-shot CLI owns only:
|
||||
|
|
@ -248,14 +246,17 @@ or `shoc-frontend-new`. New external-dev IAM still lands here.
|
|||
enumerated SAM `StringEquals` allow-list are unchanged. Do not add `ArnLike`
|
||||
there (PLAT-52 AC1). Do not add new HCP workloads to those four Sids.
|
||||
|
||||
Prod/dev still carry, until PLAT-147 deletes those two stacks:
|
||||
Prod/dev stacks are out of `bin/app.ts` and `.github/workflows/deploy.yaml`.
|
||||
Until the delete script runs, the live stacks still hold:
|
||||
|
||||
- the `app.terraform.io` OIDC identity provider (audience
|
||||
`aws.workload.identity`; Retain — it is the federation anchor for every
|
||||
future `hcptf-*` role),
|
||||
- the `seahaven-hcptf-iam-management` guardrail policy (enumerated
|
||||
`seahaven-lambda-execution-boundary-*` allow-list; frozen, do not append),
|
||||
- no prod `hcptf-<stack>` pairs. The six imported pairs are Retain-removed. `seahaven-site` is `seahaven-site-hcptf`. `sh-openswe-traces` is gone.
|
||||
`seahaven-lambda-execution-boundary-*` allow-list; frozen, do not append).
|
||||
|
||||
The six imported prod pairs are Retain-removed. `seahaven-site` is
|
||||
`seahaven-site-hcptf`. `sh-openswe-traces` is gone.
|
||||
|
||||
External-dev still carries:
|
||||
|
||||
|
|
@ -616,21 +617,17 @@ revoke the extra trust. Lambda `permissions_boundary` may keep pointing
|
|||
at `seahaven-lambda-execution-boundary-<stack>` in deploy-substrate for this
|
||||
pass.
|
||||
|
||||
**Prod/dev substrate delete (PLAT-147).** After the six imports:
|
||||
**Prod/dev substrate delete (PLAT-147).** Imports, the Retain-remove, and
|
||||
removal from `bin/app.ts` and `.github/workflows/deploy.yaml` are done.
|
||||
`terraform-substrate-external-dev` stays.
|
||||
|
||||
1. Inventory `seahaven-hcptf-iam-management` attachments
|
||||
(`scripts/delete-terraform-substrate-prod-dev.sh --account prod --inventory`).
|
||||
None may remain.
|
||||
2. Remove the six prod role pairs from the template (they already have
|
||||
`DeletionPolicy: Retain`) so CloudFormation forgets them without deleting.
|
||||
`sh-openswe-traces` and `seahaven-site` are not in this list.
|
||||
3. Remove `terraform-substrate-prod` and `terraform-substrate-dev` from
|
||||
`bin/app.ts` and `.github/workflows/deploy.yaml`. Keep
|
||||
`terraform-substrate-external-dev`.
|
||||
4. Delete stacks in `011934824531` and `710827005802` only. OIDC is Retain.
|
||||
`seahaven-hcptf-iam-management` deletes with those stacks. Do not delete
|
||||
`terraform-substrate-external-dev`. Do not strip SHOC resources from the
|
||||
shared YAML while that stack still synthesizes them.
|
||||
Delete stacks in `011934824531` and `710827005802` only, after inventory
|
||||
shows no `seahaven-hcptf-iam-management` attachments
|
||||
(`scripts/delete-terraform-substrate-prod-dev.sh --account prod --inventory`,
|
||||
then `--yes`, then the same for dev). OIDC is Retain.
|
||||
`seahaven-hcptf-iam-management` deletes with those stacks. Do not delete
|
||||
`terraform-substrate-external-dev`. Do not strip SHOC resources from the
|
||||
shared YAML while that stack still synthesizes them.
|
||||
|
||||
**HCP-side authority is AWS authority.** AWS exposes only `aud`, `sub` and
|
||||
`amr` as trust-policy condition keys for a generic OIDC provider — HCP's
|
||||
|
|
|
|||
37
bin/app.ts
37
bin/app.ts
|
|
@ -195,36 +195,23 @@ new MemberBaselineStack(app, "prod-baseline", {
|
|||
// seahaven-lambda-execution-boundary policy both returned NoSuchEntity in
|
||||
// 011934824531 AND 710827005802, so the named creates cannot collide with
|
||||
// out-of-band copies.
|
||||
const deploySubstrateProd = new DeploySubstrateStack(app, "deploy-substrate-prod", {
|
||||
new DeploySubstrateStack(app, "deploy-substrate-prod", {
|
||||
stackName: "seahaven-deploy-substrate",
|
||||
env: { account: PROD_ACCOUNT, region: "us-east-1" },
|
||||
createOidcProvider: false,
|
||||
});
|
||||
|
||||
const deploySubstrateDev = new DeploySubstrateStack(app, "deploy-substrate-dev", {
|
||||
new DeploySubstrateStack(app, "deploy-substrate-dev", {
|
||||
stackName: "seahaven-deploy-substrate",
|
||||
env: { account: DEV_ACCOUNT, region: "us-east-1" },
|
||||
createOidcProvider: false,
|
||||
});
|
||||
|
||||
// ── Per-account HCP Terraform deploy substrate ───────────────────────────────
|
||||
// Prod/dev instances still exist until PLAT-147: they own the live eight
|
||||
// hcptf-<stack> pairs (DeletionPolicy Retain) and seahaven-hcptf-iam-management.
|
||||
// Do not append new prod/dev workspace roles here. Do not add a CDK stack for
|
||||
// hcptf-bootstrap (CLI-owned, PLAT-145). External-dev stays: SHOC IAM is not
|
||||
// moving (PLAT-148). deploy-substrate stays for remaining SAM (PLAT-150).
|
||||
// The guardrail policy names seahaven-lambda-execution-boundary ARNs only
|
||||
// inside Condition strings, so CFN infers no creation edge — the explicit
|
||||
// dependency below keeps deploy-substrate first while these stacks remain.
|
||||
const terraformSubstrateProd = new TerraformSubstrateStack(
|
||||
app,
|
||||
"terraform-substrate-prod",
|
||||
{
|
||||
stackName: "seahaven-terraform-substrate",
|
||||
env: { account: PROD_ACCOUNT, region: "us-east-1" },
|
||||
},
|
||||
);
|
||||
terraformSubstrateProd.addStackDependency(deploySubstrateProd);
|
||||
// Prod/dev seahaven-terraform-substrate is out of this app and out of CD
|
||||
// (PLAT-147). The live stacks stay until scripts/delete-terraform-substrate-prod-dev.sh.
|
||||
// Do not add them back. Do not add a CDK stack for hcptf-bootstrap (CLI-owned,
|
||||
// PLAT-145). External-dev stays: SHOC IAM is not moving (PLAT-148).
|
||||
// deploy-substrate stays for remaining SAM (PLAT-150).
|
||||
|
||||
// Shared CloudFront WAF for seahaven-prod (PLAT-92). Same AppWebAcl construct
|
||||
// as mgmt account-baseline; thin stack so prod does not inherit the full
|
||||
|
|
@ -242,16 +229,6 @@ new SeahavenSiteHcptfStack(app, "seahaven-site-hcptf", {
|
|||
env: { account: PROD_ACCOUNT, region: "us-east-1" },
|
||||
});
|
||||
|
||||
const terraformSubstrateDev = new TerraformSubstrateStack(
|
||||
app,
|
||||
"terraform-substrate-dev",
|
||||
{
|
||||
stackName: "seahaven-terraform-substrate",
|
||||
env: { account: DEV_ACCOUNT, region: "us-east-1" },
|
||||
},
|
||||
);
|
||||
terraformSubstrateDev.addStackDependency(deploySubstrateDev);
|
||||
|
||||
// External-dev already has app.terraform.io federation. Both role gates start
|
||||
// false in cdk.json: POC is enabled by a normal update; dev/staging only by
|
||||
// CloudFormation import after Terraform relinquishes those four live roles.
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue