From 6cf47bd5337fd0cffc8ca446fb650c3cf9c79a20 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 2 Oct 2026 14:24:36 -0400 Subject: [PATCH] chore(terraform): drop forgotten site exec-role state blocks (#73) The PLAT-225 apply already removed these addresses from seahaven-site-prod. Point the README at seahaven-hcptf, which now owns the roles. --- README.md | 2 +- terraform/removed.tf | 67 -------------------------------------------- 2 files changed, 1 insertion(+), 68 deletions(-) delete mode 100644 terraform/removed.tf diff --git a/README.md b/README.md index ead5445..6d7a01e 100644 --- a/README.md +++ b/README.md @@ -15,7 +15,7 @@ A clean static website for Sea Haven Industries — authored as [Eleventy](https ## Infrastructure -HCP Terraform workspace `seahaven-site-prod` applies `terraform/` when `terraform/**` changes on `main`. Speculative plans run on pull requests. The workspace writes `/seahaven-site/deploy/bucket` and `/seahaven-site/deploy/distribution-id`. GitHub Environment `prod` holds `DEPLOY_ROLE_ARN`. Exec roles `hcptf-seahaven-site` and `hcptf-seahaven-site-plan` live in the `seahaven-site-hcptf` stack. +HCP Terraform workspace `seahaven-site-prod` applies `terraform/` when `terraform/**` changes on `main`. Speculative plans run on pull requests. The workspace writes `/seahaven-site/deploy/bucket` and `/seahaven-site/deploy/distribution-id`. GitHub Environment `prod` holds `DEPLOY_ROLE_ARN`. Exec roles `hcptf-seahaven-site` and `hcptf-seahaven-site-plan` live in the `seahaven-hcptf` stack. ## Develop ```bash diff --git a/terraform/removed.tf b/terraform/removed.tf deleted file mode 100644 index 9beb0a5..0000000 --- a/terraform/removed.tf +++ /dev/null @@ -1,67 +0,0 @@ -# hcptf-seahaven-site and hcptf-seahaven-site-plan moved to the -# seahaven-site-hcptf stack in seahaven-org-baseline (PLAT-225). -# Forget them here. Do not delete the live roles. - -removed { - from = aws_iam_role.hcptf_apply - - lifecycle { - destroy = false - } -} - -removed { - from = aws_iam_role.hcptf_plan - - lifecycle { - destroy = false - } -} - -removed { - from = aws_iam_role_policy.hcptf_apply_services - - lifecycle { - destroy = false - } -} - -removed { - from = aws_iam_role_policy.hcptf_scoped_iam - - lifecycle { - destroy = false - } -} - -removed { - from = aws_iam_role_policy.hcptf_plan_refresh - - lifecycle { - destroy = false - } -} - -removed { - from = aws_iam_role_policy_attachment.hcptf_plan_viewonly - - lifecycle { - destroy = false - } -} - -removed { - from = aws_iam_role_policy_attachments_exclusive.hcptf_apply - - lifecycle { - destroy = false - } -} - -removed { - from = aws_iam_role_policy_attachments_exclusive.hcptf_plan - - lifecycle { - destroy = false - } -}