chore(terraform): drop tf-poc from live module and CI

This commit is contained in:
Adam Moussa 2026-09-01 10:43:30 -04:00
parent bf83decce3
commit a478a550d3
No known key found for this signature in database
8 changed files with 41 additions and 106 deletions

View file

@ -45,7 +45,7 @@ jobs:
directories=() directories=()
case "${{ github.base_ref }}" in case "${{ github.base_ref }}" in
dev) dev)
directories+=(terraform/live/tf-poc terraform/live/dev) directories+=(terraform/live/dev)
;; ;;
staging) staging)
directories+=(terraform/live/staging) directories+=(terraform/live/staging)

View file

@ -56,14 +56,14 @@ The script:
G10 permits only exact approved resource address/type pairs for the G10 permits only exact approved resource address/type pairs for the
environment-owned boundary: Elastic environment-owned boundary: Elastic
Beanstalk environment, IAM role/inline policy/managed-policy attachment/ Beanstalk environment, IAM role/inline policy/managed-policy attachment/
instance profile, Secrets Manager secret metadata, Route 53 zone/record, and instance profile, Secrets Manager secret metadata, and Route 53 record.
ACM certificate. Initial mode permits no update. Controlled mode requires one Initial mode permits no update. Controlled mode requires one
`--allow-update-address` argument per reviewed in-place update. Every invocation `--allow-update-address` argument per reviewed in-place update. Every invocation
also requires `--environment dev`, `--environment staging`, or also requires `--environment dev` or `--environment staging`; an empty or
`--environment tf-poc`; an empty or incomplete environment plan fails. incomplete environment plan fails.
G11 runs `terraform fmt -check -recursive`, `terraform init -backend=false`, G11 runs `terraform fmt -check -recursive`, `terraform init -backend=false`,
and `terraform validate`. PRs to `dev` validate `live/tf-poc` and `live/dev`. and `terraform validate`. PRs to `dev` validate `live/dev`.
PRs to `staging` validate only `live/staging`. Org-baseline CloudFormation owns PRs to `staging` validate only `live/staging`. Org-baseline CloudFormation owns
the HCP role substrate, and Terraform owns the dev deploy role, so no backend the HCP role substrate, and Terraform owns the dev deploy role, so no backend
CDK or bootstrap root remains in the matrix. CDK or bootstrap root remains in the matrix.

View file

@ -23,12 +23,6 @@ REQUIRED_RESOURCES = {
"module.environment.aws_iam_role_policy.runtime_webhook[0]": "aws_iam_role_policy", "module.environment.aws_iam_role_policy.runtime_webhook[0]": "aws_iam_role_policy",
"module.environment.aws_route53_record.api_cname[0]": "aws_route53_record", "module.environment.aws_route53_record.api_cname[0]": "aws_route53_record",
}, },
"tf-poc": {
**COMMON_RESOURCES,
"aws_acm_certificate.poc": "aws_acm_certificate",
"aws_route53_zone.poc": "aws_route53_zone",
"module.environment.aws_route53_record.api_cname[0]": "aws_route53_record",
},
} }
DEV_IMPORT_IDS = { DEV_IMPORT_IDS = {

View file

@ -186,15 +186,6 @@ def main() -> int:
), ),
0, 0,
), ),
(
"tf-poc controlled update",
run_case(
"tf-poc",
actions_by_address={controlled_address: ["update"]},
allowed_updates=(controlled_address,),
),
0,
),
( (
"wrong controlled address", "wrong controlled address",
run_case( run_case(
@ -255,12 +246,12 @@ def main() -> int:
1, 1,
), ),
( (
"live webhook policy in tf-poc", "staging resource in a dev plan",
run_case( run_case(
"tf-poc", "dev",
extra_resource=( extra_resource=(
"module.environment.aws_iam_role_policy.runtime_webhook[0]", "module.environment.aws_route53_record.api_cname[0]",
"aws_iam_role_policy", "aws_route53_record",
["no-op"], ["no-op"],
), ),
), ),

View file

@ -7,8 +7,6 @@ keeping shared and Elastic Beanstalk-generated resources outside state.
- `live/dev/` imports the existing dev environment-owned resources. - `live/dev/` imports the existing dev environment-owned resources.
- `live/staging/` imports the existing staging environment-owned resources. - `live/staging/` imports the existing staging environment-owned resources.
- `live/tf-poc/` manages the retained import-rehearsal environment after its
completed transfer from CloudFormation.
Shared RDS, application, VPC, subnet, service-role, shared-certificate, and Shared RDS, application, VPC, subnet, service-role, shared-certificate, and
Elastic Beanstalk-generated inventory remains data-only or provider-managed. Elastic Beanstalk-generated inventory remains data-only or provider-managed.
@ -42,8 +40,6 @@ terraform -chdir=terraform/live/dev init -backend=false
terraform -chdir=terraform/live/dev validate terraform -chdir=terraform/live/dev validate
terraform -chdir=terraform/live/staging init -backend=false terraform -chdir=terraform/live/staging init -backend=false
terraform -chdir=terraform/live/staging validate terraform -chdir=terraform/live/staging validate
terraform -chdir=terraform/live/tf-poc init -backend=false
terraform -chdir=terraform/live/tf-poc validate
python scripts/test-terraform-import-plan-check.py python scripts/test-terraform-import-plan-check.py
python scripts/test-terraform-release-plan-check.py python scripts/test-terraform-release-plan-check.py
``` ```

View file

@ -8,10 +8,6 @@ shared or Elastic Beanstalk-generated infrastructure.
- `dev/` and `staging/` import the existing EB environment, runtime - `dev/` and `staging/` import the existing EB environment, runtime
role/profile/policies, deploy role/policy, app-config secret metadata, and API role/profile/policies, deploy role/policy, app-config secret metadata, and API
record. record.
- `tf-poc/` manages the retained rehearsal environment after its completed
CloudFormation-to-Terraform transfer, excluding the live-only webhook and
Dynamo policies. It also owns the child zone and DNS-validated ACM
certificate.
- `modules/environment-inventory/` reads and pins only shared resources. - `modules/environment-inventory/` reads and pins only shared resources.
- Org-baseline CloudFormation owns the narrowly scoped HCP Terraform plan/apply - Org-baseline CloudFormation owns the narrowly scoped HCP Terraform plan/apply
roles. roles.
@ -19,8 +15,7 @@ shared or Elastic Beanstalk-generated infrastructure.
The shared `shoc-backend` Elastic Beanstalk application and The shared `shoc-backend` Elastic Beanstalk application and
`shoc-sqlserver-shared` RDS instance, VPC, subnets, EB service role, shared `shoc-sqlserver-shared` RDS instance, VPC, subnets, EB service role, shared
certificate, shared RDS security group, and EB-generated SG/ALB/ASG/CloudFormation certificate, shared RDS security group, and EB-generated SG/ALB/ASG/CloudFormation
resources must never enter an environment state. The `shoc_tf_poc` SQL catalog resources must never enter an environment state.
is out of band.
Secret values are not Terraform resources, variables, outputs, or managed EB Secret values are not Terraform resources, variables, outputs, or managed EB
settings. Terraform manages the app-config secret shell and maps approved JSON settings. Terraform manages the app-config secret shell and maps approved JSON
@ -78,9 +73,7 @@ Terraform does not perform this pre-import mutation.
## Two-phase adoption ## Two-phase adoption
Each dev/staging root pins `adoption_complete=false` in reviewed code until its Each dev/staging root pins `adoption_complete=false` in reviewed code until its
initial import is proven. It is not an HCP workspace variable. The retained initial import is proven. It is not an HCP workspace variable.
tf-poc rehearsal has completed both phases and therefore pins
`adoption_complete=true`.
1. Create the HCP workspace and configure dynamic credentials. 1. Create the HCP workspace and configure dynamic credentials.
2. Run the declarative imports. 2. Run the declarative imports.
@ -169,19 +162,6 @@ This change is the allowed exception that mixes deployable application CD with
the Terraform variable that application CD needs. Later PRs must not mix the Terraform variable that application CD needs. Later PRs must not mix
deployable application changes with Terraform or CDK changes. deployable application changes with Terraform or CDK changes.
## POC retained identifiers
The tf-poc HCP workspace stores the exact retained environment ID, app-config
secret ARN, child-zone ID, and certificate ARN declared in
`tf-poc/variables.tf`. The declarative import blocks consumed those identifiers
during the completed transfer. Do not guess or replace them, and do not put
credentials or secret values in HCP variables.
ACM DNS validation remains part of the Terraform-owned certificate resource;
its generated validation record is not a separate ownership target. The public
delegation of `tf-poc.seahaven.com` from `seahaven.com` remains outside this
Terraform state.
## Pinned live identities ## Pinned live identities
- Dev: workspace `shoc-backend-dev`; EB environment `shoc-backend-dev` - Dev: workspace `shoc-backend-dev`; EB environment `shoc-backend-dev`
@ -198,5 +178,3 @@ identifiers make accidental cross-environment reuse fail review and planning.
- Auto-apply remains off. - Auto-apply remains off.
- Org baseline owns final HCP plan/apply permissions and manager tags. - Org baseline owns final HCP plan/apply permissions and manager tags.
- Every imported Terraform resource has `prevent_destroy`. - Every imported Terraform resource has `prevent_destroy`.
- The tf-poc CloudFormation creator path was removed after its no-op import,
controlled update, and retained-resource ownership transfer completed.

View file

@ -196,7 +196,6 @@ resource "aws_iam_role" "github_deploy" {
data "aws_iam_policy_document" "deploy" { data "aws_iam_policy_document" "deploy" {
statement { statement {
sid = var.environment == "tf-poc" ? "DescribeDeploymentResources" : null
effect = "Allow" effect = "Allow"
actions = [ actions = [
"autoscaling:Describe*", "autoscaling:Describe*",
@ -210,7 +209,6 @@ data "aws_iam_policy_document" "deploy" {
} }
statement { statement {
sid = var.environment == "tf-poc" ? "CreateApplicationVersion" : null
effect = "Allow" effect = "Allow"
actions = ["elasticbeanstalk:CreateApplicationVersion"] actions = ["elasticbeanstalk:CreateApplicationVersion"]
resources = [ resources = [
@ -220,45 +218,38 @@ data "aws_iam_policy_document" "deploy" {
} }
statement { statement {
sid = var.environment == "tf-poc" ? "UpdatePocEnvironment" : null
effect = "Allow" effect = "Allow"
actions = ["elasticbeanstalk:UpdateEnvironment"] actions = ["elasticbeanstalk:UpdateEnvironment"]
resources = [local.environment_arn] resources = [local.environment_arn]
} }
dynamic "statement" { statement {
for_each = var.environment != "tf-poc" ? [1] : [] effect = "Allow"
content { actions = [
effect = "Allow" "cloudformation:CancelUpdateStack",
actions = [ "cloudformation:DescribeStackEvents",
"cloudformation:CancelUpdateStack", "cloudformation:DescribeStackResource",
"cloudformation:DescribeStackEvents", "cloudformation:DescribeStackResources",
"cloudformation:DescribeStackResource", "cloudformation:DescribeStacks",
"cloudformation:DescribeStackResources", "cloudformation:GetTemplate",
"cloudformation:DescribeStacks", "cloudformation:ListStackResources",
"cloudformation:GetTemplate", "cloudformation:UpdateStack",
"cloudformation:ListStackResources", ]
"cloudformation:UpdateStack", resources = [
] "arn:aws:cloudformation:${var.aws_region}:${var.aws_account_id}:stack/${local.environment_stack_name}/*",
resources = [ ]
"arn:aws:cloudformation:${var.aws_region}:${var.aws_account_id}:stack/${local.environment_stack_name}/*",
]
}
} }
dynamic "statement" { statement {
for_each = var.environment != "tf-poc" ? [1] : [] effect = "Allow"
content { actions = [
effect = "Allow" "autoscaling:PutNotificationConfiguration",
actions = [ "autoscaling:ResumeProcesses",
"autoscaling:PutNotificationConfiguration", "autoscaling:SuspendProcesses",
"autoscaling:ResumeProcesses", ]
"autoscaling:SuspendProcesses", resources = [
] "arn:aws:autoscaling:${var.aws_region}:${var.aws_account_id}:autoScalingGroup:*:autoScalingGroupName/${local.environment_stack_name}-*",
resources = [ ]
"arn:aws:autoscaling:${var.aws_region}:${var.aws_account_id}:autoScalingGroup:*:autoScalingGroupName/${local.environment_stack_name}-*",
]
}
} }
dynamic "statement" { dynamic "statement" {
@ -288,7 +279,6 @@ data "aws_iam_policy_document" "deploy" {
dynamic "statement" { dynamic "statement" {
for_each = local.use_legacy_s3_policy ? [] : [1] for_each = local.use_legacy_s3_policy ? [] : [1]
content { content {
sid = var.environment == "tf-poc" ? "UploadApplicationVersion" : null
effect = "Allow" effect = "Allow"
actions = ["s3:PutObject"] actions = ["s3:PutObject"]
resources = ["arn:aws:s3:::${local.eb_bucket_name}/${var.eb_application_name}/*"] resources = ["arn:aws:s3:::${local.eb_bucket_name}/${var.eb_application_name}/*"]
@ -298,25 +288,11 @@ data "aws_iam_policy_document" "deploy" {
dynamic "statement" { dynamic "statement" {
for_each = local.use_legacy_s3_policy ? [] : [1] for_each = local.use_legacy_s3_policy ? [] : [1]
content { content {
sid = var.environment == "tf-poc" ? "UseBeanstalkBucket" : null
effect = "Allow" effect = "Allow"
actions = ["s3:GetBucketLocation", "s3:ListBucket"] actions = ["s3:GetBucketLocation", "s3:ListBucket"]
resources = ["arn:aws:s3:::${local.eb_bucket_name}"] resources = ["arn:aws:s3:::${local.eb_bucket_name}"]
} }
} }
dynamic "statement" {
for_each = var.environment == "tf-poc" ? [1] : []
content {
sid = "DenyLiveEnvironments"
effect = "Deny"
actions = ["elasticbeanstalk:*"]
resources = [
"arn:aws:elasticbeanstalk:${var.aws_region}:${var.aws_account_id}:environment/${var.eb_application_name}/shoc-backend-dev",
"arn:aws:elasticbeanstalk:${var.aws_region}:${var.aws_account_id}:environment/${var.eb_application_name}/shoc-backend-staging",
]
}
}
} }
resource "aws_iam_role_policy" "github_deploy" { resource "aws_iam_role_policy" "github_deploy" {

View file

@ -10,8 +10,8 @@ variable "environment" {
type = string type = string
validation { validation {
condition = contains(["dev", "staging", "tf-poc"], var.environment) condition = contains(["dev", "staging"], var.environment)
error_message = "environment must be dev, staging, or tf-poc." error_message = "environment must be dev or staging."
} }
} }
@ -37,7 +37,7 @@ variable "eb_environment_name" {
variable "eb_environment_id" { variable "eb_environment_id" {
type = string type = string
description = "Existing environment ID. Empty only before the CDK POC has been provisioned." description = "Existing Elastic Beanstalk environment ID."
} }
variable "platform_arn" { variable "platform_arn" {
@ -143,7 +143,7 @@ variable "webhook_decrypt_policy_sid" {
variable "dynamo_reader_role_arn" { variable "dynamo_reader_role_arn" {
type = string type = string
default = null default = null
description = "Dev-only cross-account role. Null for staging and tf-poc." description = "Dev-only cross-account role. Null for staging."
} }
variable "dynamo_policy_sid" { variable "dynamo_policy_sid" {