# Terraform deployment infrastructure Terraform adopts the environment-owned Sea Haven backend infrastructure while keeping shared and Elastic Beanstalk-generated resources outside state. ## Roots - `live/dev/` imports the existing dev environment-owned resources. - `live/staging/` imports the existing staging environment-owned resources. - `live/tf-poc/` manages the retained import-rehearsal environment after its completed transfer from CloudFormation. Shared RDS, application, VPC, subnet, service-role, shared-certificate, and Elastic Beanstalk-generated inventory remains data-only or provider-managed. Secret metadata is managed, but secret values are never authored in Terraform configuration. Elastic Beanstalk receives secret values through `environmentsecrets` ARN/key references. ## HCP credentials Org-baseline CloudFormation owns the HCP Terraform plan/apply roles and their manager tags. The retired `shoc-backend-bootstrap` workspace and backend bootstrap root were removed after the four dev/staging roles transferred without replacement. ## Environment adoption Follow [`live/README.md`](live/README.md). For each dev/staging adoption, the first plan must import the environment-owned resources with zero create, update, delete, or replacement actions. The second reviewed phase may update only explicitly allowlisted ownership metadata and the narrowed dev deploy S3 policy. The GitHub Environment secret `AWS_DEPLOY_ROLE_ARN` retains the existing role ARN throughout adoption. ## Local validation ```bash terraform -chdir=terraform fmt -check -recursive terraform -chdir=terraform/live/dev init -backend=false terraform -chdir=terraform/live/dev validate terraform -chdir=terraform/live/staging init -backend=false terraform -chdir=terraform/live/staging validate terraform -chdir=terraform/live/tf-poc init -backend=false terraform -chdir=terraform/live/tf-poc validate python scripts/test-terraform-import-plan-check.py ```