* feat(hcptf): import hcptf-paychex-integrations apply and plan roles into seahaven-hcptf (PLAT-251)
PaychexIntegrationsRoles is nested in the prod seahaven-hcptf stack for the
paychex-integrations-prod workspace. The two roles already exist and are
imported with -c hcptfPaychexImport=true, which names the live inline
policies and omits role tags and outputs. The default template replaces the
inline policies with managed policies at /tf-managed/:
- paychex-integrations-hcptf-iam: the ported scoped IAM document plus
CreateRole and the write set on tf-managed/githubdeploy-paychex-integrations
(no permissions boundary) and iam:GetOpenIDConnectProvider. TagHcptfRoles is
dropped; the roles are no longer Terraform-managed.
- paychex-integrations-hcptf-services: the ported services document plus SSM
writes on /paychex-integrations/deploy/* and DescribeParameters.
- paychex-integrations-hcptf-plan: the ported refresh document plus the deploy
role, the GitHub OIDC provider, and the deploy parameters.
Trust is unchanged. Every resource is Retain.
* docs(hcptf): describe the paychex-integrations import as a sequence
* chore(ci): retrigger checks after the GitHub Actions incident
Add seahaven-hcptf in prod and dev for the imported payments-dashboard HCP roles and Lambda boundary, and move seahaven-site-hcptf inline policies to managed policies.