chore(terraform): drop tf-poc from live module and CI

This commit is contained in:
Adam Moussa 2026-09-01 10:43:30 -04:00
parent bf83decce3
commit a478a550d3
No known key found for this signature in database
8 changed files with 41 additions and 106 deletions

View file

@ -45,7 +45,7 @@ jobs:
directories=()
case "${{ github.base_ref }}" in
dev)
directories+=(terraform/live/tf-poc terraform/live/dev)
directories+=(terraform/live/dev)
;;
staging)
directories+=(terraform/live/staging)

View file

@ -56,14 +56,14 @@ The script:
G10 permits only exact approved resource address/type pairs for the
environment-owned boundary: Elastic
Beanstalk environment, IAM role/inline policy/managed-policy attachment/
instance profile, Secrets Manager secret metadata, Route 53 zone/record, and
ACM certificate. Initial mode permits no update. Controlled mode requires one
instance profile, Secrets Manager secret metadata, and Route 53 record.
Initial mode permits no update. Controlled mode requires one
`--allow-update-address` argument per reviewed in-place update. Every invocation
also requires `--environment dev`, `--environment staging`, or
`--environment tf-poc`; an empty or incomplete environment plan fails.
also requires `--environment dev` or `--environment staging`; an empty or
incomplete environment plan fails.
G11 runs `terraform fmt -check -recursive`, `terraform init -backend=false`,
and `terraform validate`. PRs to `dev` validate `live/tf-poc` and `live/dev`.
and `terraform validate`. PRs to `dev` validate `live/dev`.
PRs to `staging` validate only `live/staging`. Org-baseline CloudFormation owns
the HCP role substrate, and Terraform owns the dev deploy role, so no backend
CDK or bootstrap root remains in the matrix.

View file

@ -23,12 +23,6 @@ REQUIRED_RESOURCES = {
"module.environment.aws_iam_role_policy.runtime_webhook[0]": "aws_iam_role_policy",
"module.environment.aws_route53_record.api_cname[0]": "aws_route53_record",
},
"tf-poc": {
**COMMON_RESOURCES,
"aws_acm_certificate.poc": "aws_acm_certificate",
"aws_route53_zone.poc": "aws_route53_zone",
"module.environment.aws_route53_record.api_cname[0]": "aws_route53_record",
},
}
DEV_IMPORT_IDS = {

View file

@ -186,15 +186,6 @@ def main() -> int:
),
0,
),
(
"tf-poc controlled update",
run_case(
"tf-poc",
actions_by_address={controlled_address: ["update"]},
allowed_updates=(controlled_address,),
),
0,
),
(
"wrong controlled address",
run_case(
@ -255,12 +246,12 @@ def main() -> int:
1,
),
(
"live webhook policy in tf-poc",
"staging resource in a dev plan",
run_case(
"tf-poc",
"dev",
extra_resource=(
"module.environment.aws_iam_role_policy.runtime_webhook[0]",
"aws_iam_role_policy",
"module.environment.aws_route53_record.api_cname[0]",
"aws_route53_record",
["no-op"],
),
),

View file

@ -7,8 +7,6 @@ keeping shared and Elastic Beanstalk-generated resources outside state.
- `live/dev/` imports the existing dev environment-owned resources.
- `live/staging/` imports the existing staging environment-owned resources.
- `live/tf-poc/` manages the retained import-rehearsal environment after its
completed transfer from CloudFormation.
Shared RDS, application, VPC, subnet, service-role, shared-certificate, and
Elastic Beanstalk-generated inventory remains data-only or provider-managed.
@ -42,8 +40,6 @@ terraform -chdir=terraform/live/dev init -backend=false
terraform -chdir=terraform/live/dev validate
terraform -chdir=terraform/live/staging init -backend=false
terraform -chdir=terraform/live/staging validate
terraform -chdir=terraform/live/tf-poc init -backend=false
terraform -chdir=terraform/live/tf-poc validate
python scripts/test-terraform-import-plan-check.py
python scripts/test-terraform-release-plan-check.py
```

View file

@ -8,10 +8,6 @@ shared or Elastic Beanstalk-generated infrastructure.
- `dev/` and `staging/` import the existing EB environment, runtime
role/profile/policies, deploy role/policy, app-config secret metadata, and API
record.
- `tf-poc/` manages the retained rehearsal environment after its completed
CloudFormation-to-Terraform transfer, excluding the live-only webhook and
Dynamo policies. It also owns the child zone and DNS-validated ACM
certificate.
- `modules/environment-inventory/` reads and pins only shared resources.
- Org-baseline CloudFormation owns the narrowly scoped HCP Terraform plan/apply
roles.
@ -19,8 +15,7 @@ shared or Elastic Beanstalk-generated infrastructure.
The shared `shoc-backend` Elastic Beanstalk application and
`shoc-sqlserver-shared` RDS instance, VPC, subnets, EB service role, shared
certificate, shared RDS security group, and EB-generated SG/ALB/ASG/CloudFormation
resources must never enter an environment state. The `shoc_tf_poc` SQL catalog
is out of band.
resources must never enter an environment state.
Secret values are not Terraform resources, variables, outputs, or managed EB
settings. Terraform manages the app-config secret shell and maps approved JSON
@ -78,9 +73,7 @@ Terraform does not perform this pre-import mutation.
## Two-phase adoption
Each dev/staging root pins `adoption_complete=false` in reviewed code until its
initial import is proven. It is not an HCP workspace variable. The retained
tf-poc rehearsal has completed both phases and therefore pins
`adoption_complete=true`.
initial import is proven. It is not an HCP workspace variable.
1. Create the HCP workspace and configure dynamic credentials.
2. Run the declarative imports.
@ -169,19 +162,6 @@ This change is the allowed exception that mixes deployable application CD with
the Terraform variable that application CD needs. Later PRs must not mix
deployable application changes with Terraform or CDK changes.
## POC retained identifiers
The tf-poc HCP workspace stores the exact retained environment ID, app-config
secret ARN, child-zone ID, and certificate ARN declared in
`tf-poc/variables.tf`. The declarative import blocks consumed those identifiers
during the completed transfer. Do not guess or replace them, and do not put
credentials or secret values in HCP variables.
ACM DNS validation remains part of the Terraform-owned certificate resource;
its generated validation record is not a separate ownership target. The public
delegation of `tf-poc.seahaven.com` from `seahaven.com` remains outside this
Terraform state.
## Pinned live identities
- Dev: workspace `shoc-backend-dev`; EB environment `shoc-backend-dev`
@ -198,5 +178,3 @@ identifiers make accidental cross-environment reuse fail review and planning.
- Auto-apply remains off.
- Org baseline owns final HCP plan/apply permissions and manager tags.
- Every imported Terraform resource has `prevent_destroy`.
- The tf-poc CloudFormation creator path was removed after its no-op import,
controlled update, and retained-resource ownership transfer completed.

View file

@ -196,7 +196,6 @@ resource "aws_iam_role" "github_deploy" {
data "aws_iam_policy_document" "deploy" {
statement {
sid = var.environment == "tf-poc" ? "DescribeDeploymentResources" : null
effect = "Allow"
actions = [
"autoscaling:Describe*",
@ -210,7 +209,6 @@ data "aws_iam_policy_document" "deploy" {
}
statement {
sid = var.environment == "tf-poc" ? "CreateApplicationVersion" : null
effect = "Allow"
actions = ["elasticbeanstalk:CreateApplicationVersion"]
resources = [
@ -220,45 +218,38 @@ data "aws_iam_policy_document" "deploy" {
}
statement {
sid = var.environment == "tf-poc" ? "UpdatePocEnvironment" : null
effect = "Allow"
actions = ["elasticbeanstalk:UpdateEnvironment"]
resources = [local.environment_arn]
}
dynamic "statement" {
for_each = var.environment != "tf-poc" ? [1] : []
content {
effect = "Allow"
actions = [
"cloudformation:CancelUpdateStack",
"cloudformation:DescribeStackEvents",
"cloudformation:DescribeStackResource",
"cloudformation:DescribeStackResources",
"cloudformation:DescribeStacks",
"cloudformation:GetTemplate",
"cloudformation:ListStackResources",
"cloudformation:UpdateStack",
]
resources = [
"arn:aws:cloudformation:${var.aws_region}:${var.aws_account_id}:stack/${local.environment_stack_name}/*",
]
}
statement {
effect = "Allow"
actions = [
"cloudformation:CancelUpdateStack",
"cloudformation:DescribeStackEvents",
"cloudformation:DescribeStackResource",
"cloudformation:DescribeStackResources",
"cloudformation:DescribeStacks",
"cloudformation:GetTemplate",
"cloudformation:ListStackResources",
"cloudformation:UpdateStack",
]
resources = [
"arn:aws:cloudformation:${var.aws_region}:${var.aws_account_id}:stack/${local.environment_stack_name}/*",
]
}
dynamic "statement" {
for_each = var.environment != "tf-poc" ? [1] : []
content {
effect = "Allow"
actions = [
"autoscaling:PutNotificationConfiguration",
"autoscaling:ResumeProcesses",
"autoscaling:SuspendProcesses",
]
resources = [
"arn:aws:autoscaling:${var.aws_region}:${var.aws_account_id}:autoScalingGroup:*:autoScalingGroupName/${local.environment_stack_name}-*",
]
}
statement {
effect = "Allow"
actions = [
"autoscaling:PutNotificationConfiguration",
"autoscaling:ResumeProcesses",
"autoscaling:SuspendProcesses",
]
resources = [
"arn:aws:autoscaling:${var.aws_region}:${var.aws_account_id}:autoScalingGroup:*:autoScalingGroupName/${local.environment_stack_name}-*",
]
}
dynamic "statement" {
@ -288,7 +279,6 @@ data "aws_iam_policy_document" "deploy" {
dynamic "statement" {
for_each = local.use_legacy_s3_policy ? [] : [1]
content {
sid = var.environment == "tf-poc" ? "UploadApplicationVersion" : null
effect = "Allow"
actions = ["s3:PutObject"]
resources = ["arn:aws:s3:::${local.eb_bucket_name}/${var.eb_application_name}/*"]
@ -298,25 +288,11 @@ data "aws_iam_policy_document" "deploy" {
dynamic "statement" {
for_each = local.use_legacy_s3_policy ? [] : [1]
content {
sid = var.environment == "tf-poc" ? "UseBeanstalkBucket" : null
effect = "Allow"
actions = ["s3:GetBucketLocation", "s3:ListBucket"]
resources = ["arn:aws:s3:::${local.eb_bucket_name}"]
}
}
dynamic "statement" {
for_each = var.environment == "tf-poc" ? [1] : []
content {
sid = "DenyLiveEnvironments"
effect = "Deny"
actions = ["elasticbeanstalk:*"]
resources = [
"arn:aws:elasticbeanstalk:${var.aws_region}:${var.aws_account_id}:environment/${var.eb_application_name}/shoc-backend-dev",
"arn:aws:elasticbeanstalk:${var.aws_region}:${var.aws_account_id}:environment/${var.eb_application_name}/shoc-backend-staging",
]
}
}
}
resource "aws_iam_role_policy" "github_deploy" {

View file

@ -10,8 +10,8 @@ variable "environment" {
type = string
validation {
condition = contains(["dev", "staging", "tf-poc"], var.environment)
error_message = "environment must be dev, staging, or tf-poc."
condition = contains(["dev", "staging"], var.environment)
error_message = "environment must be dev or staging."
}
}
@ -37,7 +37,7 @@ variable "eb_environment_name" {
variable "eb_environment_id" {
type = string
description = "Existing environment ID. Empty only before the CDK POC has been provisioned."
description = "Existing Elastic Beanstalk environment ID."
}
variable "platform_arn" {
@ -143,7 +143,7 @@ variable "webhook_decrypt_policy_sid" {
variable "dynamo_reader_role_arn" {
type = string
default = null
description = "Dev-only cross-account role. Null for staging and tf-poc."
description = "Dev-only cross-account role. Null for staging."
}
variable "dynamo_policy_sid" {