Adam Moussa
5d613c73bc
feat(iam): allow frontend tf-poc HCP apply destroy (PLAT-193) ( #145 )
2026-09-11 21:46:59 +00:00
Adam Moussa
3c54df6341
fix(iam): allow GitHub frontend deploy roles to GetDistribution (PLAT-192) ( #144 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Verify and live-state summary call get-distribution; the identity policy already granted it, but the permissions boundary denied the action.
2026-09-11 19:37:24 +00:00
Adam Moussa
60b978aa2a
feat(iam): allow frontend HCP apply to own release pointer and invalidation (PLAT-188) ( #143 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): allow frontend HCP apply to own release pointer and invalidation (PLAT-188)
Plan and apply roles can read .release/current; apply can PutObject that key and CreateInvalidation on the exact distribution.
* fix(iam): allow frontend HCP roles to tag the release pointer (PLAT-188)
Terraform aws_s3_object lists object tags on every refresh, so plan and apply need GetObjectTagging and apply needs PutObjectTagging on the exact .release/current key.
2026-09-11 17:37:42 +00:00
Adam Moussa
0c6f307b61
feat(iam): allow frontend HCP apply to update exact CloudFront resources (PLAT-187) ( #142 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): allow frontend HCP apply to update exact CloudFront resources (PLAT-187)
Phase 2 ownership tags cannot apply while UpdateDistribution and UpdateFunction are denied on *. Allow those two actions only on the pinned distribution and function ARNs.
* fix(iam): allow PublishFunction on exact frontend CloudFront functions (PLAT-187)
The AWS provider publishes after UpdateFunction, including tag-only applies, so denying PublishFunction on * still blocked Phase 2 function updates.
2026-09-11 15:08:21 +00:00
Adam Moussa
a829854cd0
feat(hcp): flag workspaces that skip source-path file triggers (PLAT-183) ( #141 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-09-10 21:00:33 +00:00
Adam Moussa
fa940e69c6
feat(iam): allow meal-order-manager to send to paychex-checkcomponents (PLAT-135) ( #140 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-09-09 23:58:42 +00:00
Adam Moussa
6bc4f6e095
chore(iam): remove backend tf-poc boundaries ( #139 )
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-09-03 15:04:58 +00:00
Adam Moussa
4f0d84cddb
fix(iam): use unique HCP bootstrap workspace names (PLAT-143) ( #138 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
HCP workspace names are org-unique, so prod and dev cannot both be iam-bootstrap. Pin trust to iam-bootstrap-prod and iam-bootstrap-dev.
2026-09-02 15:51:39 +00:00
Adam Moussa
b02f52b805
feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) ( #137 )
...
* feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143)
* fix(iam): pin HCP boundary ARNs and bootstrap trust window (PLAT-143)
Null on iam:PermissionsBoundary accepted any ceiling, including AdministratorAccess. Import apply cannot self-mutate hcptf-* while bootstrap trust is iam-bootstrap only; add a time-boxed exact StringEquals workspace grant instead of StringLike.
2026-09-02 15:22:48 +00:00
Adam Moussa
35dc61b806
feat(iam): allow tf-poc HCP apply destroy ( #136 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-09-01 16:14:06 +00:00
Adam Moussa
6d5811f08e
fix(iam): codify live terraform-substrate IAM (PLAT-142) ( #135 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): allow frontend import plan to read deploy boundaries
* fix(iam): grant backend apply role EB UpdateEnvironment follow-on perms
2026-09-01 00:16:34 +00:00
Adam Moussa
559eed1e98
fix(iam): allow backend Terraform refresh (PLAT-141) ( #134 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): allow backend import plan reads
* fix(iam): authorize backend EB refresh
* fix(iam): authorize backend EB ownership check
2026-08-31 17:04:00 +00:00
Adam Moussa
6a0713f49d
feat(iam): add frontend Terraform substrate ( #133 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add frontend Terraform substrate
* fix(iam): align frontend Terraform substrate
* feat(iam): enable frontend live Terraform roles
2026-08-31 02:25:47 +00:00
Adam Moussa
08191ded4c
chore(iam): finalize backend role ownership ( #132 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* chore(iam): finalize backend role ownership
* fix(iam): complete backend import permissions
2026-08-30 20:12:54 +00:00
Adam Moussa
dba0871587
feat(iam): add external-dev backend Terraform substrate ( #131 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add external-dev backend terraform substrate
* fix(iam): require boundaries for SHOC policy writes
2026-08-29 21:04:40 +00:00
Adam Moussa
ee233379dd
fix(iam): allow paychex worker ledger dynamodb ( #130 )
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
HCP plan/apply and the paychex Lambda boundary need the paychex-worker-ledger table ARN so PLAT-123 can create and use the identity ledger.
2026-08-28 16:11:23 +00:00
Adam Moussa
e21d08bf23
fix(iam): update paychex boundary in place without fn if (PLAT-122) ( #129 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): update paychex boundary in place without fn if
CloudFormation replaced the named managed policy when the secrets statement was wrapped in Fn::If (409 duplicate name). Keep the six minted ARNs as a static statement so the document updates in place.
* fix(iam): leave paychex boundary description unchanged
Keep the live ManagedPolicy Description so CloudFormation only updates PolicyDocument.
2026-08-27 23:56:49 +00:00
Adam Moussa
f7cc67819b
fix(iam): pin paychex secret arns on lambda boundary ( #128 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
First HCP apply minted the six secret suffixes. Pin GetSecretValue to those ARNs so paychex-placeholder can read oauth-client.
2026-08-27 23:30:43 +00:00
Adam Moussa
2f5e5e6e66
fix(iam): drop unscoped door-unlock domain create ( #127 )
...
CreateDomainName cannot be hostname-pinned, and mgmt still holds doorunlock.seahaven.com. Attach the domain at cutover instead of granting collection POST.
2026-08-27 23:03:35 +00:00
Adam Moussa
23d954369d
fix(iam): allow door-unlock apply to create api domain ( #126 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
CreateDomainName authorizes against the /domainnames collection, so the hostname-pinned ARN cannot complete first apply.
2026-08-27 22:43:48 +00:00
Adam Moussa
28a064966b
fix(iam): allow door-unlock plan to read 3cx secret metadata ( #125 )
...
The AWS secrets data source calls GetResourcePolicy; the first HCP plan failed without it on the three exact 3CX ARNs.
2026-08-27 22:16:11 +00:00
Adam Moussa
e5e7980508
feat(iam): add paychex-integrations hcptf roles and boundary (PLAT-120) ( #124 )
...
* feat(iam): add paychex-integrations hcptf roles and boundary
* fix(iam): split paychex plan lambda list onto Resource *
2026-08-27 21:50:11 +00:00
Adam Moussa
689ec147a3
feat(iam): add door-unlock-api hcptf roles and boundary (PLAT-76) ( #123 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add door-unlock-api hcptf roles and boundary
Give HCP Terraform a prod plan/apply pair, a per-workload Lambda boundary with exact SSM and 3CX ARNs, and API access-log delivery so PLAT-76 can leave the mgmt CDK stack.
* fix(iam): pin door-unlock apigw domain and ssm reads
Stop the apply role from managing every HTTP API custom domain, and keep SecureString door-unlock parameters off HCP plan and apply GetParameter.
2026-08-27 21:26:27 +00:00
Adam Moussa
608c11ed0a
chore(deps): remove dependabot version updates ( #122 )
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
Renovate is the version-update bot. GitHub Dependabot alerts stay.
2026-08-25 11:51:32 -04:00
dependabot[bot]
e13bf89545
chore(deps): bump the minor-and-patch group across 1 directory with 3 updates ( #120 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-08-25 01:23:05 +00:00
Adam Moussa
91fde44ec3
chore(ci): remove pr policy workflow caller ( #119 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-08-24 15:12:40 -04:00
Adam Moussa
dbf72e692b
chore(ci): switch auto-merge from seahaven-bot to Mergify ( #118 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-08-24 13:52:39 -04:00
Adam Moussa
c8e8a3287e
fix(ci): enqueue merge queue as seahaven-bot (PLAT-108) ( #116 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(ci): enqueue merge queue as seahaven-bot
* fix(ci): limit seahaven-bot enqueue to PRs targeting main
2026-08-24 15:17:55 +00:00
Adam Moussa
de0e7456e9
ci: enable squash auto-merge on ready PRs (PLAT-108) ( #115 )
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
* ci: enable squash auto-merge on ready PRs
* fix(ci): grant contents read so auto-merge can query the PR
* fix(ci): restore contents write for enablePullRequestAutoMerge
* fix(ci): serialize auto-merge enable and ignore already-enabled
* fix(ci): request squash auto-merge so PRs enter the merge queue
2026-08-21 23:32:53 +00:00
Adam Moussa
e8f241712a
ci: add merge_group trigger for required ci / ci ( #114 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-08-21 17:41:38 -04:00
Adam Moussa
14bcbc8384
Merge pull request #112 from Sea-Haven-Industries/fix/site-plan-describe-function
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
fix(iam): allow site plan role to describe CF function (PLAT-106)
2026-08-20 15:58:21 -04:00
9bffddfd7b
fix(iam): allow site plan role to describe CF function (PLAT-106)
2026-08-20 15:22:09 -04:00
Adam Moussa
e2b4b635e3
Merge pull request #95 from Sea-Haven-Industries/dependabot/npm_and_yarn/minor-and-patch-32f5f3edd0
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
chore(deps): bump the minor-and-patch group with 4 updates
2026-08-17 16:26:13 -04:00
d1f6f6ac46
fix: bump aws-cdk-lib to 2.265.0
2026-08-17 16:14:53 -04:00
Adam Moussa
314c8e3042
Merge branch 'main' into dependabot/npm_and_yarn/minor-and-patch-32f5f3edd0
2026-08-17 15:49:43 -04:00
dependabot[bot]
411307aaaf
Merge pull request #107 from Sea-Haven-Industries/dependabot/github_actions/Sea-Haven-Industries/dot-github/dot-github/workflows/callable-labeler.yaml-1.0.7
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml from 1.0.6 to 1.0.7
2026-08-14 20:31:36 -04:00
dependabot[bot]
c61f444e8f
chore(deps): bump callable-labeler.yaml from 1.0.6 to 1.0.7
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-14 20:30:19 -04:00
dependabot[bot]
9b1cf9c9e7
chore(deps): bump cd-cdk.yaml from 1.0.6 to 1.0.7
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-14 20:29:55 -04:00
dependabot[bot]
e8e74073c7
chore(deps): bump callable-pr-policy.yaml from 1.0.6 to 1.0.7
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-14 20:29:10 -04:00
dependabot[bot]
9f7b7d522e
chore(deps): bump ci-typescript-cdk.yaml from 1.0.6 to 1.0.7
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-14 20:28:36 -04:00
dependabot[bot]
c52aa5bf99
chore(deps): bump callable-dependency-review.yaml from 1.0.6 to 1.0.7
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-14 20:27:37 -04:00
Adam Moussa
a81acbf18d
Merge pull request #105 from Sea-Haven-Industries/chore/strip-pascalcase-wo-iam-pins
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
chore(iam): drop PascalCase WO Dynamo and alarm ARNs (PLAT-11)
2026-08-14 12:12:48 -04:00
5fa4267798
chore(iam): drop PascalCase WO Dynamo and alarm ARNs
2026-08-14 11:58:41 -04:00
Adam Moussa
a2e9449ef1
Merge pull request #104 from Sea-Haven-Industries/feature/per-workload-lambda-boundaries
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
feat(iam): add per-workload lambda execution boundaries (PLAT-52)
2026-08-13 17:51:53 -04:00
0f84d7808b
feat(iam): add per-workload lambda execution boundaries
...
Shared seahaven-lambda-execution-boundary stays unchanged for live roles.
New named policies plus an enumerated StringEquals allow-list unblock the
next PLAT-71 widen without growing the 6144-character shared document.
2026-08-13 16:47:53 -04:00
Adam Moussa
ef1afab33b
Merge pull request #103 from Sea-Haven-Industries/fix/meal-order-weekly-menu-execute-api
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
fix(iam): meal-order weekly-menu execute-api boundary (PLAT-100)
2026-08-10 16:05:18 -04:00
81cc8eb4f9
fix(iam): consolidate meal-order boundary Sid under PolicySize cap
2026-08-10 15:57:08 -04:00
7c43c867e3
fix(iam): allow execute-api Invoke for meal-order weekly-menu boundary
2026-08-10 15:42:12 -04:00
Adam Moussa
7ad46d9528
Merge pull request #102 from Sea-Haven-Industries/fix/meal-order-log-delivery
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
fix(iam): allow API GW Log Delivery on meal-order apply role (PLAT-99)
2026-08-10 15:27:34 -04:00
b76d0578e0
fix(iam): drop PutResourcePolicy from meal-order apply role
...
Pre-grant delivery.logs write via MealOrderApiAccessLogResourcePolicy on
substrate so the HCP apply role cannot mutate account-wide log resource
policies.
2026-08-10 14:57:17 -04:00