diff --git a/terraform/README.md b/terraform/README.md index d4d2023..d11938b 100644 --- a/terraform/README.md +++ b/terraform/README.md @@ -37,8 +37,8 @@ only explicitly allowlisted ownership metadata and the narrowed dev deploy S3 policy. The GitHub Environment **variable** `DEPLOY_ROLE_ARN` is the OIDC role used -by application CD after cutover. Adoption may still have the older -`AWS_DEPLOY_ROLE_ARN` secret until that cutover. +by application CD. Environment secrets `TF_API_TOKEN` and +`AWS_DEPLOY_ROLE_ARN` were removed at cutover. ## Local validation diff --git a/terraform/live/README.md b/terraform/live/README.md index e7630cd..8f3850b 100644 --- a/terraform/live/README.md +++ b/terraform/live/README.md @@ -142,8 +142,9 @@ cut from **Actions → Release** (`environment`, `bump`, `message`). That workflow waits for CI, tags `vX.Y.Z-staging` from main HEAD with `GITHUB_TOKEN`, then calls deploy. Do not cut prod yet; leave `PROD_APP_CD_ENABLED` unset and do not create the `prod` GitHub Environment. -Staging remains `adoption_complete=false` with a pinned API CNAME until its -import apply is proven after the first `vX.Y.Z-staging` GitHub-owned zip. +Staging import is proven after the first GitHub-owned zip +(`v0.0.1-staging`). Terraform now manages the declared Elastic Beanstalk +settings. The API CNAME stays pinned to the imported ALB target. HCP workspaces stay VCS-driven with auto-apply on after cutover. Speculative plans on every PR are the infra gate. Do not point `TFC_AWS_*` at diff --git a/terraform/live/staging/main.tf b/terraform/live/staging/main.tf index 0368da2..cd64267 100644 --- a/terraform/live/staging/main.tf +++ b/terraform/live/staging/main.tf @@ -26,8 +26,8 @@ module "environment" { aws_account_id = local.aws_account_id aws_region = local.aws_region environment = "staging" - adoption_complete = false - manage_eb_settings = false + adoption_complete = true + manage_eb_settings = true eb_application_name = local.eb_application_name eb_environment_name = local.eb_environment_name eb_environment_id = local.eb_environment_id