Commit graph

191 commits

Author SHA1 Message Date
Adam Moussa
1e10c40e52
chore(backup): drop the file-share rollback volume from phase 2 (PLAT-77) (#168)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* chore(backup): drop the file-share rollback volume from phase 2 (PLAT-77)

The rollback hold is being deleted now, so the selection must not keep an ARN that will not exist.

* docs(backup): state why the file-share volume leaves phase 2 (PLAT-77)

The comment now matches the cleanup: the missing volume is already gone, and the rollback volume leaves because the hold ended.
2026-09-29 20:23:47 -04:00
Adam Moussa
78e4bcf128
chore(backup): drop the missing file-share volume from phase 2 (PLAT-77) (#167)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* chore(backup): drop retired file-share volumes from phase 2 (PLAT-77)

The 20 GiB volume is already gone and the 500 GiB volume is only a rollback hold, so the backup selection should not include either one.

* fix(backup): keep the file-share rollback volume in phase 2 (PLAT-77)

The 500 GiB disk is the rollback hold until 2026-10-06, so it stays in the offsite selection. Only the missing 20 GiB volume comes out.
2026-09-29 23:51:26 +00:00
Adam Moussa
7e706aef2f
chore(backup): drop retired apm-wo grafana EBS volume (PLAT-75) (#166)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
The mgmt Grafana instance is gone after the HCP cutover, so the org backup
selection no longer needs vol-0488e0bad1f9afbfb.
2026-09-29 22:16:07 +00:00
Adam Moussa
f8c8d25050
chore(terraform-substrate): drop prod and dev stacks from CD (PLAT-147) (#165)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
CD must stop deploying seahaven-terraform-substrate before the live stacks are deleted, or the next push recreates them.
2026-09-28 20:05:42 +00:00
Adam Moussa
ca179bbdf6
chore(terraform-substrate): forget imported prod hcptf pairs (PLAT-147) (#164)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
The six pairs are already in HCP state and DeletionPolicy is Retain, so CloudFormation drops the logical IDs without deleting the roles.
2026-09-28 15:56:04 -04:00
Adam Moussa
cc068f3c8d
chore(terraform-substrate): forget deleted openswe traces roles (PLAT-147) (#163)
The IAM roles are already gone. Removing the logical IDs while DeletionPolicy stays Retain lets CloudFormation drop them without updating missing roles.
2026-09-28 19:30:14 +00:00
Adam Moussa
faa199771f
ci(iam): fail when Access Analyzer credentials are missing (PLAT-234) (#162)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
The policy-check role trust now matches pull request and merge queue
subjects. A failed assume must fail the job instead of skipping
ValidatePolicy and CheckNoNewAccess.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 18:38:21 +00:00
Adam Moussa
ac65a23d9f
docs(agents): document Node 24 for cloud agents (#157)
* docs(agents): document Node 24 for cloud agents

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* docs(agents): keep cdk diff required and exempt docs titles

Cloud agents still review cdk diff when the VM can read the accounts.
Docs, hygiene, and dependency pull requests omit a Jira suffix instead
of opening a ticket only to fill the title.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix: address review comments

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 18:12:07 +00:00
Adam Moussa
055feca605
fix(iam): shrink shared lambda boundary to the four-statement floor (PLAT-52) (#158)
* fix(iam): shrink shared lambda boundary to the four-statement floor (PLAT-52)

PermissionsBoundaryUsageCount is 0 in prod and dev, so the shared
seahaven-lambda-execution-boundary drops the packed IsProdAccount
data-plane statements and keeps CloudWatchLogsWrite,
CloudWatchLogsDescribe, XRay, and Ec2Eni.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* docs(iam): correct shared boundary size and scoping notes (PLAT-52)

The dev floor is the same 708-character document as the shared policy.
691 was stale. The scoping note now says the shared document is the
four-statement floor, and allow-list retirement is a follow-up.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* docs(iam): limit scoping rule to remaining SAM workloads (PLAT-52)

The shared boundary shrink is unchanged. The scoping note now matches
the HCP path already stated later in the same file.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* docs(iam): record the shared floor size as 691 characters (PLAT-52)

The stated measurement, with the account id resolved, is 691 characters
and 4 statements for the shared boundary and for the dev floor copies.
Headroom is 5453.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 13:46:18 -04:00
Adam Moussa
ff492de58d
feat(iam): add platform permission set and org-admin assume alarm (SEC-37) (#161)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add platform permission set and org-admin assume alarm (SEC-37)

Adds an Identity Center platform group and Platform permission set
assigned to the management account, and a CloudTrail alarm on
AssumeRole of OrganizationAccountAccessRole. Scripts still assume
that role. This change is not deployed.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(iam): skip sanctioned org-admin assumes in the alarm (SEC-37)

Count failed assumes for every principal. Do not page on a successful
assume by the Platform permission set or the two repo script sessions.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 16:27:12 +00:00
Adam Moussa
8cbc98d927
feat(scp): deny iam changes on the platform path (PLAT-233) (#159)
* feat(scp): deny iam changes on role/platform unless the platform principal (PLAT-233)

Adds ProtectPlatformPath beside the existing name denies in the
prod/nonprod SCP and the security OU copy. New hcptf-bootstrap
creates use /platform/. Existing roles are not recreated.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(scp): use live bootstrap ARNs and close the platform path gaps (PLAT-233)

Resolve simulate and printed role ARNs from iam:GetRole so a /platform/
create is not reported as an unpathed role. Deny boundary changes on
role/platform/*, and match both Identity Center SSO role ARN shapes.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(scp): deny platform-path changes in bootstrap simulate (PLAT-233)

Add a simulate case for role/platform/hcptf-example and fail when CreateRole,
PutRolePolicy, or DeleteRole is allowed. The unpathed hcptf-* import check stays.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 16:27:10 +00:00
Adam Moussa
8ff8ba1a87
ci(iam): check synthesized policies with Access Analyzer (PLAT-234) (#160)
* ci(iam): check synthesized policies with Access Analyzer (PLAT-234)

Adds a CI job that checks bootstrap trust for StringEquals, rejects
lambda writes on the plan refresh template, and runs ValidatePolicy
plus CheckNoNewAccess when the policy-check role can be assumed.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* ci(iam): fail closed on widened policies (PLAT-234)

Compare new and removed SCPs, and fail when a Deny shrinks or a Condition
changes. Run CheckNoNewAccess on bootstrap templates from the base repo.
Install the base worktree's own dependencies and warn when analyzer
credentials are skipped.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 16:27:08 +00:00
Adam Moussa
d80295c005
docs(agents): drop security review gates (#156)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
Agents no longer treat a security review or a cross-family review as a merge gate.
2026-09-26 17:18:04 -04:00
Adam Moussa
617987c4a8
fix(iam): allow payroll schedule invoke under the paychex boundary (PLAT-228) (#155)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
The live boundary denies lambda:InvokeFunction, so the Monday and Thursday
schedules would be created and would not fire. Allow that action only on
paychex-payroll-schedule, and allow SendMessage on paychex-checkcomponents
so the schedule role can enqueue the flush.
2026-09-25 21:35:19 +00:00
Adam Moussa
2f2858f885
fix(iam): let the site plan role describe SSM parameters (PLAT-225) (#154)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): let the site plan role describe SSM parameters

* fix(iam): address review feedback
2026-09-25 16:40:34 +00:00
Adam Moussa
38ed1bfe00
feat(iam): move seahaven-site exec roles into their own stack (PLAT-225) (#153)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): move seahaven-site exec roles into their own stack (PLAT-225)

Drop the retained roles from the substrate template so the new stack can import them without a second owner.

* fix(iam): address review feedback
2026-09-24 23:37:39 +00:00
Adam Moussa
2b2f09a7f4
chore(ci): remove unused Mergify stub (#152)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-09-22 18:41:28 +00:00
Adam Moussa
7e41625e4b
feat(iam): allow PassRole to ECS tasks and EventBridge Scheduler (#151)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
A first apply of Fargate and Scheduler targets cannot create those service-linked attachments while PassRole is Lambda-only.
2026-09-21 18:59:08 +00:00
Adam Moussa
960e4619b4
fix(iam): allow frontend HCP apply to write deploy SSM and githubdeploy trust (PLAT-212) (#150)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
* fix(iam): allow frontend HCP apply to write deploy SSM and githubdeploy trust (PLAT-212)

* fix(iam): grant frontend HCP plan named SSM describe and tag reads (PLAT-212)

* fix(iam): allow frontend githubdeploy to read deploy SSM (PLAT-212)

HCP apply already writes /shoc-frontend-new/<env>/deploy/*, but the
githubdeploy ceiling omitted GetParameter so Deploy Web cannot resolve
bucket and distribution after origin moves to the bucket root.

* fix(iam): allow staging HCP apply to update the SHOC backend EB stack (PLAT-213)

* fix(iam): allow staging HCP apply to use the Elastic Beanstalk bucket (PLAT-213)

* fix(iam): allow staging HCP apply to copy the current release zip (PLAT-213)

* fix(iam): allow staging HCP apply versioned ACLs on EB env objects (PLAT-213)

* fix(iam): give staging HCP apply the proven Elastic Beanstalk bucket grants (PLAT-213)

* fix(iam): allow staging HCP apply to write CloudFormation template buckets (PLAT-213)

* fix(iam): let staging HCP apply read Elastic Beanstalk service templates (PLAT-213)
2026-09-18 21:37:05 +00:00
Adam Moussa
c63b5e9779
fix(iam): enable meal-order-manager Lambda boundary in seahaven-dev (PLAT-210) (#149)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): enable meal-order-manager Lambda boundary in seahaven-dev (PLAT-210)

The per-workload boundary was floor-only outside prod, so meals-dev Lambdas
were denied DynamoDB. Keep Paychex SQS, SNS, and SES prod-only.

* fix(iam): keep meal-order-manager boundary Description unchanged (PLAT-210)

Named IAM managed-policy Description is immutable. Changing it replaces the
resource and 409s on ManagedPolicyName. PolicyDocument still widens in place.
2026-09-18 18:35:38 +00:00
Adam Moussa
db9465deda
fix(iam): allow shoc-backend HCP apply to write deploy SSM and matching githubdeploy trust (PLAT-148) (#148)
* fix(iam): allow shoc-backend HCP apply to write deploy SSM and matching githubdeploy trust (PLAT-148)

* fix(iam): grant shoc-backend staging plan named inventory reads (PLAT-148)

* fix(iam): allow staging githubdeploy to GetObject release zips (PLAT-148)

* fix(iam): allow staging githubdeploy to write EB processed extensions (PLAT-148)

* fix(iam): allow staging githubdeploy GetObjectAcl on release zips (PLAT-148)

* fix(iam): grant staging githubdeploy named S3 reads on EB resources prefix (PLAT-148)

* fix(iam): allow staging githubdeploy to delete EB version cache objects (PLAT-148)

* fix(iam): scope staging githubdeploy S3 object access to the EB bucket (PLAT-148)

* fix(iam): allow staging githubdeploy PutObjectVersionAcl on EB artifacts (PLAT-148)

* fix(iam): allow staging githubdeploy GetBucketPolicy on the EB bucket (PLAT-148)

* fix(iam): scope staging githubdeploy S3 objects to SHOC and staging EB prefixes (PLAT-148)
2026-09-18 18:13:01 +00:00
Adam Moussa
7a1623e8d4
fix(iam): allow paychex period table and optional secrets (PLAT-195) (#147)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
* fix(iam): allow paychex period table and optional secrets (PLAT-195)

The processor role already allows these ARNs. The live boundary denied
them, so GetSecretValue and period PutItem returned HTTP 400. Sync the
template to the live ceiling and add the missing period table plus
slack-admin and afterhours secret suffixes.

* fix(iam): keep paychex boundary description unchanged (PLAT-195)

IAM managed-policy Description is immutable. Changing it on a named
policy forces replacement and 409s against the live ManagedPolicyName.
Widen PolicyDocument only.
2026-09-14 18:31:08 +00:00
Adam Moussa
a492a45e07
chore(iam): remove frontend tf-poc substrate after teardown (PLAT-194) (#146)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-09-11 22:17:00 +00:00
Adam Moussa
5d613c73bc
feat(iam): allow frontend tf-poc HCP apply destroy (PLAT-193) (#145) 2026-09-11 21:46:59 +00:00
Adam Moussa
3c54df6341
fix(iam): allow GitHub frontend deploy roles to GetDistribution (PLAT-192) (#144)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Verify and live-state summary call get-distribution; the identity policy already granted it, but the permissions boundary denied the action.
2026-09-11 19:37:24 +00:00
Adam Moussa
60b978aa2a
feat(iam): allow frontend HCP apply to own release pointer and invalidation (PLAT-188) (#143)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): allow frontend HCP apply to own release pointer and invalidation (PLAT-188)

Plan and apply roles can read .release/current; apply can PutObject that key and CreateInvalidation on the exact distribution.

* fix(iam): allow frontend HCP roles to tag the release pointer (PLAT-188)

Terraform aws_s3_object lists object tags on every refresh, so plan and apply need GetObjectTagging and apply needs PutObjectTagging on the exact .release/current key.
2026-09-11 17:37:42 +00:00
Adam Moussa
0c6f307b61
feat(iam): allow frontend HCP apply to update exact CloudFront resources (PLAT-187) (#142)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): allow frontend HCP apply to update exact CloudFront resources (PLAT-187)

Phase 2 ownership tags cannot apply while UpdateDistribution and UpdateFunction are denied on *. Allow those two actions only on the pinned distribution and function ARNs.

* fix(iam): allow PublishFunction on exact frontend CloudFront functions (PLAT-187)

The AWS provider publishes after UpdateFunction, including tag-only applies, so denying PublishFunction on * still blocked Phase 2 function updates.
2026-09-11 15:08:21 +00:00
Adam Moussa
a829854cd0
feat(hcp): flag workspaces that skip source-path file triggers (PLAT-183) (#141)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-09-10 21:00:33 +00:00
Adam Moussa
fa940e69c6
feat(iam): allow meal-order-manager to send to paychex-checkcomponents (PLAT-135) (#140)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-09-09 23:58:42 +00:00
Adam Moussa
6bc4f6e095
chore(iam): remove backend tf-poc boundaries (#139)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-09-03 15:04:58 +00:00
Adam Moussa
4f0d84cddb
fix(iam): use unique HCP bootstrap workspace names (PLAT-143) (#138)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
HCP workspace names are org-unique, so prod and dev cannot both be iam-bootstrap. Pin trust to iam-bootstrap-prod and iam-bootstrap-dev.
2026-09-02 15:51:39 +00:00
Adam Moussa
b02f52b805
feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) (#137)
* feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143)

* fix(iam): pin HCP boundary ARNs and bootstrap trust window (PLAT-143)

Null on iam:PermissionsBoundary accepted any ceiling, including AdministratorAccess. Import apply cannot self-mutate hcptf-* while bootstrap trust is iam-bootstrap only; add a time-boxed exact StringEquals workspace grant instead of StringLike.
2026-09-02 15:22:48 +00:00
Adam Moussa
35dc61b806
feat(iam): allow tf-poc HCP apply destroy (#136)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-09-01 16:14:06 +00:00
Adam Moussa
6d5811f08e
fix(iam): codify live terraform-substrate IAM (PLAT-142) (#135)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): allow frontend import plan to read deploy boundaries

* fix(iam): grant backend apply role EB UpdateEnvironment follow-on perms
2026-09-01 00:16:34 +00:00
Adam Moussa
559eed1e98
fix(iam): allow backend Terraform refresh (PLAT-141) (#134)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): allow backend import plan reads

* fix(iam): authorize backend EB refresh

* fix(iam): authorize backend EB ownership check
2026-08-31 17:04:00 +00:00
Adam Moussa
6a0713f49d
feat(iam): add frontend Terraform substrate (#133)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add frontend Terraform substrate

* fix(iam): align frontend Terraform substrate

* feat(iam): enable frontend live Terraform roles
2026-08-31 02:25:47 +00:00
Adam Moussa
08191ded4c
chore(iam): finalize backend role ownership (#132)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* chore(iam): finalize backend role ownership

* fix(iam): complete backend import permissions
2026-08-30 20:12:54 +00:00
Adam Moussa
dba0871587
feat(iam): add external-dev backend Terraform substrate (#131)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add external-dev backend terraform substrate

* fix(iam): require boundaries for SHOC policy writes
2026-08-29 21:04:40 +00:00
Adam Moussa
ee233379dd
fix(iam): allow paychex worker ledger dynamodb (#130)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
HCP plan/apply and the paychex Lambda boundary need the paychex-worker-ledger table ARN so PLAT-123 can create and use the identity ledger.
2026-08-28 16:11:23 +00:00
Adam Moussa
e21d08bf23
fix(iam): update paychex boundary in place without fn if (PLAT-122) (#129)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): update paychex boundary in place without fn if

CloudFormation replaced the named managed policy when the secrets statement was wrapped in Fn::If (409 duplicate name). Keep the six minted ARNs as a static statement so the document updates in place.

* fix(iam): leave paychex boundary description unchanged

Keep the live ManagedPolicy Description so CloudFormation only updates PolicyDocument.
2026-08-27 23:56:49 +00:00
Adam Moussa
f7cc67819b
fix(iam): pin paychex secret arns on lambda boundary (#128)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
First HCP apply minted the six secret suffixes. Pin GetSecretValue to those ARNs so paychex-placeholder can read oauth-client.
2026-08-27 23:30:43 +00:00
Adam Moussa
2f5e5e6e66
fix(iam): drop unscoped door-unlock domain create (#127)
CreateDomainName cannot be hostname-pinned, and mgmt still holds doorunlock.seahaven.com. Attach the domain at cutover instead of granting collection POST.
2026-08-27 23:03:35 +00:00
Adam Moussa
23d954369d
fix(iam): allow door-unlock apply to create api domain (#126)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
CreateDomainName authorizes against the /domainnames collection, so the hostname-pinned ARN cannot complete first apply.
2026-08-27 22:43:48 +00:00
Adam Moussa
28a064966b
fix(iam): allow door-unlock plan to read 3cx secret metadata (#125)
The AWS secrets data source calls GetResourcePolicy; the first HCP plan failed without it on the three exact 3CX ARNs.
2026-08-27 22:16:11 +00:00
Adam Moussa
e5e7980508
feat(iam): add paychex-integrations hcptf roles and boundary (PLAT-120) (#124)
* feat(iam): add paychex-integrations hcptf roles and boundary

* fix(iam): split paychex plan lambda list onto Resource *
2026-08-27 21:50:11 +00:00
Adam Moussa
689ec147a3
feat(iam): add door-unlock-api hcptf roles and boundary (PLAT-76) (#123)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add door-unlock-api hcptf roles and boundary

Give HCP Terraform a prod plan/apply pair, a per-workload Lambda boundary with exact SSM and 3CX ARNs, and API access-log delivery so PLAT-76 can leave the mgmt CDK stack.

* fix(iam): pin door-unlock apigw domain and ssm reads

Stop the apply role from managing every HTTP API custom domain, and keep SecureString door-unlock parameters off HCP plan and apply GetParameter.
2026-08-27 21:26:27 +00:00
Adam Moussa
608c11ed0a
chore(deps): remove dependabot version updates (#122)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
Renovate is the version-update bot. GitHub Dependabot alerts stay.
2026-08-25 11:51:32 -04:00
dependabot[bot]
e13bf89545
chore(deps): bump the minor-and-patch group across 1 directory with 3 updates (#120)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-08-25 01:23:05 +00:00
Adam Moussa
91fde44ec3
chore(ci): remove pr policy workflow caller (#119)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-08-24 15:12:40 -04:00
Adam Moussa
dbf72e692b
chore(ci): switch auto-merge from seahaven-bot to Mergify (#118)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-08-24 13:52:39 -04:00