seahaven-org-baseline/scripts
Cursor Agent e3adfc3cdc
feat(scp): deny iam changes on role/platform unless the platform principal (PLAT-233)
Adds ProtectPlatformPath beside the existing name denies in the
prod/nonprod SCP and the security OU copy. New hcptf-bootstrap
creates use /platform/. Existing roles are not recreated.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 00:49:48 +00:00
..
cfn-stack-decommission.sh feat(prod): seahaven-prod DynamoDB CMK + site-alerts alarm topic (procurement-ingest migration Phase 0a) (#57) 2026-07-23 15:29:55 -04:00
check_hcp_workspace_triggers.py feat(hcp): flag workspaces that skip source-path file triggers (PLAT-183) (#141) 2026-09-10 21:00:33 +00:00
create-hcptf-bootstrap-roles.sh feat(scp): deny iam changes on role/platform unless the platform principal (PLAT-233) 2026-09-28 00:49:48 +00:00
delete-terraform-substrate-prod-dev.sh feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) (#137) 2026-09-02 15:22:48 +00:00
iam-user-delete.sh chore(security): add explicit workflow permissions and bump aws-cdk-lib to 2.262.0 (#56) 2026-07-23 17:38:17 +00:00
resource-usage-probe.sh Add cfn-stack-decommission + resource-usage-probe ops scripts (#11) 2026-06-03 13:25:44 -04:00
test_check_hcp_workspace_triggers.py feat(hcp): flag workspaces that skip source-path file triggers (PLAT-183) (#141) 2026-09-10 21:00:33 +00:00