You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: CLAUDE.md
+19-8Lines changed: 19 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -54,7 +54,9 @@ Migration happens later per-app at developer's pace — apps move from old ALB/E
54
54
-**Clean, generalized implementations**: Always patternize. If something will be used more than once, make it a module, script, or reusable component from the start. No hacky workarounds.
55
55
-**IAM least-privilege**: Scope `Resource` to specific ARNs/regions. If `*` is required by AWS, add a comment explaining why.
56
56
-**Secrets via SSM**: Webhook URLs and secrets in SSM Parameter Store under `/javabin/`. Lambdas read at runtime via `ssm:GetParameter`. Never in env vars, TF variables, or code.
57
-
-**Tags via provider**: All resources get `default_tags` from `providers.tf`. Don't manually add tags that are already in defaults.
57
+
-**Tags via provider**: All resources get `default_tags` from `providers.tf`. Don't manually add tags that are already in defaults. 5 static tags (team, service, repo, environment, managed-by) are set at deploy time; 2 dynamic tags (created-by, commit) are added by the resource-tagger Lambda via EventBridge.
58
+
-**Team-prefixed naming**: App resources use `{team}-{service}` naming. The permission boundary enforces this — apps can only create resources whose names start with their team prefix.
59
+
-**Permission boundary is human-applied**: The boundary lives in `terraform/org/boundary.tf` and is applied manually (not via CI) because its self-protection prevents CI from modifying it.
58
60
-**Pattern matching, not lists**: When categorizing AWS services, use keyword matching. Don't hardcode service name lists.
59
61
-**No `.zip` files in git**: Lambda zips are build artifacts from `archive_file`. They're in `.gitignore`.
60
62
-**Terraform-first**: Everything lives in Terraform from the first resource. No "set up manually, migrate later." Only exception: bootstrap script for state bucket.
@@ -125,6 +127,7 @@ terraform/platform/
125
127
terraform/org/
126
128
main.tf AWS Organizations, SCPs
127
129
identity-center.tf IAM Identity Center, permission sets, ABAC (team attribute from SAML)
@@ -276,7 +284,7 @@ The SA JSON key is at `/javabin/platform/google-admin-sa`, the impersonation tar
276
284
| 1 | Identity (Google + Identity Center + Cognito) |**Deployed** — GCP SA with domain-wide delegation, Identity Center with ABAC + 3 permission sets in `terraform/org/`. Google Workspace SAML IdP for SSO (auto-provisions users, groups synced via CI/team-provisioner). Cognito pool TF exists but not yet applied (needs Google OAuth client). |
| 4 | App Onboarding |**Partially working** — platform-test-app full pipeline passes (plan → review → apply → docker-build), ECS deploy fails on service stabilization |
291
300
292
301
### Known Issues
293
302
-**ECS deploy stabilization**: platform-test-app task registers but service fails health check
294
303
-**Cognito pools not yet applied**: TF exists but needs Google OAuth client credentials
295
304
-**Team provisioner Lambda**: All sync functions working (Google/GitHub/Budget/Cognito/Identity Center). Password-set flow deployed.
296
305
-**`registered_app_repos` manually managed**: Being replaced with team-scoped IAM roles (repo→team resolved via GitHub API at runtime)
306
+
-**Cost allocation tags pending activation**: `repo`, `created-by`, `commit` tags need activation in Billing console (requires billing data to appear first)
307
+
-**Platform-test-app naming migration**: Existing resources have old `javabin-` prefix names, needs state migration to `{team}-{service}` naming
0 commit comments