import * as cdk from "aws-cdk-lib"; import * as cfninc from "aws-cdk-lib/cloudformation-include"; import * as path from "path"; import { Construct } from "constructs"; /** * Per-account HCP Terraform deploy substrate: the shared account-level * resources every Terraform workspace pipeline needs - * - app.terraform.io OIDC identity provider (always created; Phase-0 * checks confirmed no account has one), and * - `seahaven-hcptf-iam-management`, the shared boundary-gated IAM * guardrail policy every per-workspace APPLY role attaches. * * Deliberately NOT here: per-workspace hcptf- / hcptf--plan * roles. Those are appended to the template at each stack's migration time * (accumulator pattern, parallel to per-repo githubdeploy-* roles) so an * account never accumulates trust for workspaces that do not deploy to it. * * The IAM guardrail statements mirror seahaven-cfn-exec-iam-management in * lib/deploy-substrate/deploy-substrate.template.yaml - see the provenance * header in lib/terraform-substrate/terraform-substrate.template.yaml for * the reconciliation rule and the boundary-ARN coupling to the * seahaven-deploy-substrate stack (bin/app.ts carries the explicit * addStackDependency; the ARN reference alone creates no CFN edge). */ export class TerraformSubstrateStack extends cdk.Stack { constructor(scope: Construct, id: string, props?: cdk.StackProps) { super(scope, id, props); new cfninc.CfnInclude(this, "Substrate", { templateFile: path.join( __dirname, "terraform-substrate", "terraform-substrate.template.yaml", ), }); cdk.Tags.of(this).add("Project", "account-baseline"); cdk.Tags.of(this).add("Owner", "adam@seahavenind.com"); cdk.Tags.of(this).add("ManagedBy", "cdk"); } }