Skip to content

Commit 7a5e5c1

Browse files
Update CLAUDE.md: naming, boundary, tags, known issues (#85)
## Summary - Naming table updated to team-prefixed convention - Working rules: document 7 tags (5 static + 2 dynamic), boundary location, naming enforcement - Add boundary.tf to org file listing - Task status: tags/naming/ABAC marked done - Known issues: cost allocation tags pending, test app naming migration
1 parent b626976 commit 7a5e5c1

1 file changed

Lines changed: 19 additions & 8 deletions

File tree

‎CLAUDE.md‎

Lines changed: 19 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,9 @@ Migration happens later per-app at developer's pace — apps move from old ALB/E
5454
- **Clean, generalized implementations**: Always patternize. If something will be used more than once, make it a module, script, or reusable component from the start. No hacky workarounds.
5555
- **IAM least-privilege**: Scope `Resource` to specific ARNs/regions. If `*` is required by AWS, add a comment explaining why.
5656
- **Secrets via SSM**: Webhook URLs and secrets in SSM Parameter Store under `/javabin/`. Lambdas read at runtime via `ssm:GetParameter`. Never in env vars, TF variables, or code.
57-
- **Tags via provider**: All resources get `default_tags` from `providers.tf`. Don't manually add tags that are already in defaults.
57+
- **Tags via provider**: All resources get `default_tags` from `providers.tf`. Don't manually add tags that are already in defaults. 5 static tags (team, service, repo, environment, managed-by) are set at deploy time; 2 dynamic tags (created-by, commit) are added by the resource-tagger Lambda via EventBridge.
58+
- **Team-prefixed naming**: App resources use `{team}-{service}` naming. The permission boundary enforces this — apps can only create resources whose names start with their team prefix.
59+
- **Permission boundary is human-applied**: The boundary lives in `terraform/org/boundary.tf` and is applied manually (not via CI) because its self-protection prevents CI from modifying it.
5860
- **Pattern matching, not lists**: When categorizing AWS services, use keyword matching. Don't hardcode service name lists.
5961
- **No `.zip` files in git**: Lambda zips are build artifacts from `archive_file`. They're in `.gitignore`.
6062
- **Terraform-first**: Everything lives in Terraform from the first resource. No "set up manually, migrate later." Only exception: bootstrap script for state bucket.
@@ -125,6 +127,7 @@ terraform/platform/
125127
terraform/org/
126128
main.tf AWS Organizations, SCPs
127129
identity-center.tf IAM Identity Center, permission sets, ABAC (team attribute from SAML)
130+
boundary.tf Permission boundary policy (human-applied, self-protecting)
128131
cloudtrail.tf CloudTrail trail + S3 bucket
129132
providers.tf Provider config
130133
variables.tf Variables
@@ -207,14 +210,19 @@ terraform/state/
207210

208211
| Type | Pattern |
209212
|------|---------|
210-
| Resources | `javabin-{purpose}` |
211-
| IAM roles | `javabin-ci-{purpose}` (CI — 6 roles including `ci-infra` / `ci-infra-plan` split), `javabin-{service}` (runtime) |
213+
| Platform resources | `javabin-{purpose}` |
214+
| App resources | `{team}-{service}` or `{team}-{service}-{suffix}` |
215+
| IAM CI roles | `javabin-ci-{purpose}` |
216+
| App IAM roles | `{team}-{service}` |
212217
| Lambdas | `javabin-{function}` |
213-
| S3 buckets | `javabin-{purpose}-{account_id}` |
214-
| SSM params | `/javabin/{namespace}/{name}` |
218+
| S3 buckets (platform) | `javabin-{purpose}-{account_id}` |
219+
| S3 buckets (app) | `{team}-{purpose}-{account_id}` |
220+
| SSM params (platform) | `/javabin/{namespace}/{name}` |
221+
| SSM params (app) | `/javabin/apps/{team}/{service}/{name}` |
215222
| ECS cluster | `javabin-platform` |
216-
| ECR repos | `{service-name}` |
217-
| SNS topics | `javabin-{alerts,security}` |
223+
| ECR repos | `{team}-{service}` |
224+
| SNS topics | `javabin-{alerts,security,budget-enforcement}` |
225+
| Log groups | `/ecs/{team}/{service}` |
218226

219227
## Alert Routing
220228

@@ -276,7 +284,7 @@ The SA JSON key is at `/javabin/platform/google-admin-sa`, the impersonation tar
276284
| 1 | Identity (Google + Identity Center + Cognito) | **Deployed** — GCP SA with domain-wide delegation, Identity Center with ABAC + 3 permission sets in `terraform/org/`. Google Workspace SAML IdP for SSO (auto-provisions users, groups synced via CI/team-provisioner). Cognito pool TF exists but not yet applied (needs Google OAuth client). |
277285
| 2a | Networking | **Deployed** — VPC, subnets, NAT |
278286
| 2b | Ingress | **Deployed** — ALB + ACM cert |
279-
| 2c | IAM / OIDC | **Deployed** — 6 CI roles (infra, infra-plan, per-app, deploy, override-approver, registry) |
287+
| 2c | IAM / OIDC | **Deployed** — 6 CI roles (infra, infra-plan, per-app, deploy, override-approver, registry), team-prefixed naming + permission boundary |
280288
| 2d | Compute | **Deployed** — ECS cluster + ECR repos |
281289
| 2e | Monitoring | **Deployed** — GuardDuty, Security Hub, Config, SNS |
282290
| 2f | Lambda Functions | **Deployed** — 11 functions (budget-enforcer, resource-tagger, ci-broker added; Google/GitHub/Budget/Cognito/Identity Center sync live) |
@@ -287,13 +295,16 @@ The SA JSON key is at `/javabin/platform/google-admin-sa`, the impersonation tar
287295
| 3d | Registry Repo | **Working** — repo exists, dispatch uses GitHub App token, team provisioner invoked |
288296
| 3e | javabin CLI | **Code done** — 4 commands (register, init, status, whoami) in javaBin/javabin-cli |
289297
| 3f | CI Images + Supporting Repos | Not started |
298+
| 3g | Tags, Naming, ABAC | **Done** — 5 static + 2 dynamic tags, team-prefixed naming enforced by permission boundary, resource-tagger Lambda for created-by/commit |
290299
| 4 | App Onboarding | **Partially working** — platform-test-app full pipeline passes (plan → review → apply → docker-build), ECS deploy fails on service stabilization |
291300

292301
### Known Issues
293302
- **ECS deploy stabilization**: platform-test-app task registers but service fails health check
294303
- **Cognito pools not yet applied**: TF exists but needs Google OAuth client credentials
295304
- **Team provisioner Lambda**: All sync functions working (Google/GitHub/Budget/Cognito/Identity Center). Password-set flow deployed.
296305
- **`registered_app_repos` manually managed**: Being replaced with team-scoped IAM roles (repo→team resolved via GitHub API at runtime)
306+
- **Cost allocation tags pending activation**: `repo`, `created-by`, `commit` tags need activation in Billing console (requires billing data to appear first)
307+
- **Platform-test-app naming migration**: Existing resources have old `javabin-` prefix names, needs state migration to `{team}-{service}` naming
297308

298309
## Agent Guidelines
299310

0 commit comments

Comments
 (0)