Commit graph

6 commits

Author SHA1 Message Date
9b53dfa5cc
fix(terraform): pin githubdeploy assume-role policy in import checker
Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
2026-09-18 11:24:37 -04:00
53c1acb19f
refactor(terraform): keep live/dev and live/staging as HCP roots
Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.
2026-09-17 17:13:32 -04:00
2a106d4e9e
ci(cd): convert SPA hosting to handbook HCP and GitHub content CD
Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.
2026-09-17 15:55:25 -04:00
Adam Moussa
69c24c1c2c
feat(terraform): ship dev content CD through Terraform (SH-300) (#180)
* feat(terraform): ship dev content CD through Terraform (SH-300)

GitHub uploads immutable release prefixes; Terraform owns live publish.
Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set.

* fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)
2026-09-11 13:40:14 -04:00
f532aa6059
feat(terraform): complete dev environment adoption (SH-300) 2026-09-11 11:22:28 -04:00
78398482cf
feat(terraform): add dev root and import guard for HCP adoption
Port the reviewed dev root and environment-owned/inventory modules from
111eb556 with the 13 pinned dev identifiers. adoption_complete is pinned
to false in code; the root has no variables so a workspace variable
cannot change what applies. The tf-poc root, staging root, and tf-poc
map entries are dropped; staging constants stay only for the checker's
cross-environment negative tests.
2026-09-10 19:15:09 -04:00