seahaven-org-baseline/lib
Adam Moussa 227a5d91a2
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
feat(hcptf): import hcptf-paychex-integrations apply and plan roles into seahaven-hcptf (PLAT-251) (#179)
* feat(hcptf): import hcptf-paychex-integrations apply and plan roles into seahaven-hcptf (PLAT-251)

PaychexIntegrationsRoles is nested in the prod seahaven-hcptf stack for the
paychex-integrations-prod workspace. The two roles already exist and are
imported with -c hcptfPaychexImport=true, which names the live inline
policies and omits role tags and outputs. The default template replaces the
inline policies with managed policies at /tf-managed/:

- paychex-integrations-hcptf-iam: the ported scoped IAM document plus
  CreateRole and the write set on tf-managed/githubdeploy-paychex-integrations
  (no permissions boundary) and iam:GetOpenIDConnectProvider. TagHcptfRoles is
  dropped; the roles are no longer Terraform-managed.
- paychex-integrations-hcptf-services: the ported services document plus SSM
  writes on /paychex-integrations/deploy/* and DescribeParameters.
- paychex-integrations-hcptf-plan: the ported refresh document plus the deploy
  role, the GitHub OIDC provider, and the deploy parameters.

Trust is unchanged. Every resource is Retain.

* docs(hcptf): describe the paychex-integrations import as a sequence

* chore(ci): retrigger checks after the GitHub Actions incident
2026-10-05 21:53:58 +00:00
..
deploy-substrate feat(paychex): allow the payroll schedule queue on the execution boundary (PLAT-238) (#177) 2026-10-05 16:31:57 +00:00
hcptf-bootstrap feat(iam): allow PassRole to ECS tasks and EventBridge Scheduler (#151) 2026-09-21 18:59:08 +00:00
scp feat(scp): deny iam changes on the platform path (PLAT-233) (#159) 2026-09-28 16:27:10 +00:00
terraform-substrate refactor(iam): fold seahaven-site roles into seahaven-hcptf (#175) 2026-10-02 17:30:52 +00:00
account-baseline-stack.ts fix(baseline): remove the management account web acl from the baseline (#173) 2026-10-02 00:25:04 +00:00
alarm-topic-stack.ts feat(prod): seahaven-prod DynamoDB CMK + site-alerts alarm topic (procurement-ingest migration Phase 0a) (#57) 2026-07-23 15:29:55 -04:00
app-web-acl-stack.ts fix(baseline): remove the management account web acl from the baseline (#173) 2026-10-02 00:25:04 +00:00
backup-offsite-stack.ts Add AWS Backup with offsite vault (audit C-7) (#3) 2026-05-29 18:06:17 -04:00
backup-stack.ts fix(baseline): drop departed mgmt resources and retain drifted web acl (#171) 2026-10-01 23:57:42 +00:00
bedrock-logging-regional.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
bedrock-logging.ts Add Bedrock invocation logging destinations (#12) 2026-06-03 15:17:39 -04:00
cis-monitoring.ts feat(iam): add platform permission set and org-admin assume alarm (SEC-37) (#161) 2026-09-28 16:27:12 +00:00
deploy-substrate-stack.ts fix(deploy-substrate): move boundary-gated IAM policy off the role's inline budget 2026-07-27 16:43:15 -04:00
detective-controls.ts seahaven-dev account baseline with org-managed detection (Phase 4) (#49) 2026-07-14 16:41:36 -04:00
dynamodb-cmk-stack.ts [INFRA-95] Shared DynamoDB CMK for sensitive finance/PII tables (M-3) (#21) 2026-06-08 19:04:42 -04:00
engineering-access-stack.ts feat(iam): scope engineering prod view to day-one projects (PLAT-236) (#170) 2026-10-02 00:01:21 +00:00
flow-logs.ts fix(baseline): drop departed mgmt resources and retain drifted web acl (#171) 2026-10-01 23:57:42 +00:00
governance-toggles.ts Merge external-dev member baseline; rename to seahaven-org-baseline (#43) 2026-07-14 13:53:07 -04:00
hcptf-policy-aspect.ts refactor(iam): fold seahaven-site roles into seahaven-hcptf (#175) 2026-10-02 17:30:52 +00:00
logs-key.ts [INFRA-96] CMK-encrypt sensitive CloudWatch log groups (M-24) (#20) 2026-06-08 19:04:36 -04:00
member-baseline-stack.ts seahaven-prod account baseline (Phase 5) (#50) 2026-07-14 17:17:55 -04:00
mta-sts-hcptf-stack.ts feat(hcptf): add hcptf-mta-sts apply and plan roles to seahaven-hcptf (PLAT-243) (#178) 2026-10-05 18:42:33 +00:00
org-governance-stack.ts feat(scp): deny iam changes on the platform path (PLAT-233) (#159) 2026-09-28 16:27:10 +00:00
paychex-integrations-hcptf-stack.ts feat(hcptf): import hcptf-paychex-integrations apply and plan roles into seahaven-hcptf (PLAT-251) (#179) 2026-10-05 21:53:58 +00:00
platform-access-stack.ts feat(iam): add platform permission set and org-admin assume alarm (SEC-37) (#161) 2026-09-28 16:27:12 +00:00
regional-baseline-stack.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
seahaven-hcptf-stack.ts feat(hcptf): import hcptf-paychex-integrations apply and plan roles into seahaven-hcptf (PLAT-251) (#179) 2026-10-05 21:53:58 +00:00
seahaven-site-hcptf-stack.ts refactor(iam): fold seahaven-site roles into seahaven-hcptf (#175) 2026-10-02 17:30:52 +00:00
ses-monitoring.ts Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6) 2026-06-02 15:16:24 -04:00
terraform-substrate-stack.ts feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) (#137) 2026-09-02 15:22:48 +00:00
view-access-stack.ts feat(iam): add view-only access across all five accounts (PLAT-237) (#176) 2026-10-02 18:25:22 +00:00
web-acl.ts fix(baseline): remove the management account web acl from the baseline (#173) 2026-10-02 00:25:04 +00:00