Commit graph

1 commit

Author SHA1 Message Date
Adam Moussa
227a5d91a2
feat(hcptf): import hcptf-paychex-integrations apply and plan roles into seahaven-hcptf (PLAT-251) (#179)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(hcptf): import hcptf-paychex-integrations apply and plan roles into seahaven-hcptf (PLAT-251)

PaychexIntegrationsRoles is nested in the prod seahaven-hcptf stack for the
paychex-integrations-prod workspace. The two roles already exist and are
imported with -c hcptfPaychexImport=true, which names the live inline
policies and omits role tags and outputs. The default template replaces the
inline policies with managed policies at /tf-managed/:

- paychex-integrations-hcptf-iam: the ported scoped IAM document plus
  CreateRole and the write set on tf-managed/githubdeploy-paychex-integrations
  (no permissions boundary) and iam:GetOpenIDConnectProvider. TagHcptfRoles is
  dropped; the roles are no longer Terraform-managed.
- paychex-integrations-hcptf-services: the ported services document plus SSM
  writes on /paychex-integrations/deploy/* and DescribeParameters.
- paychex-integrations-hcptf-plan: the ported refresh document plus the deploy
  role, the GitHub OIDC provider, and the deploy parameters.

Trust is unchanged. Every resource is Retain.

* docs(hcptf): describe the paychex-integrations import as a sequence

* chore(ci): retrigger checks after the GitHub Actions incident
2026-10-05 21:53:58 +00:00