Skip to content

PLT-1456: Bootstrap cdap-test and cdap-prod environments#362

Merged
gfreeman-navapbc merged 9 commits into
mainfrom
gfreeman/PLT-1456
Jan 5, 2026
Merged

PLT-1456: Bootstrap cdap-test and cdap-prod environments#362
gfreeman-navapbc merged 9 commits into
mainfrom
gfreeman/PLT-1456

Conversation

@gfreeman-navapbc

@gfreeman-navapbc gfreeman-navapbc commented Dec 30, 2025

Copy link
Copy Markdown
Contributor

🎫 Ticket

https://jira.cms.gov/browse/PLT-1456

🛠 Changes

  • Adds backends for cdap-prod and cdap-test.
  • Adds standards module to github_actions_role service. (Will update all roles in-place.)
  • Adds permissions for KMS key management and s3 usage.
  • Adds cdap-test and cdap-prod to plan and apply workflows.

ℹ️ Context

We want to move away from the current configuration of all CDAP resources living in the singular cdap-mgmt VPC which exists in the prod account, or overloading bcda-prod and bcda-test in each account. This way we can test changes and not have to bother with peering requests and ingress rules from the management VPC in the lower environments. Also, resources we manage will more clearly be owned by CDAP.

🧪 Validation

See plans

@gfreeman-navapbc gfreeman-navapbc requested a review from a team as a code owner December 30, 2025 18:31
@gfreeman-navapbc gfreeman-navapbc self-assigned this Dec 30, 2025
@gfreeman-navapbc gfreeman-navapbc requested a review from gsf December 30, 2025 18:31

@gsf gsf left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Plans in checks look good! Nicely done

@gfreeman-navapbc gfreeman-navapbc merged commit f7dc69c into main Jan 5, 2026
17 checks passed
@gfreeman-navapbc gfreeman-navapbc deleted the gfreeman/PLT-1456 branch January 5, 2026 21:22
juliareynolds-nava pushed a commit that referenced this pull request Jan 6, 2026
## 🎫 Ticket

https://jira.cms.gov/browse/PLT-1456

## 🛠 Changes

- Adds backends for cdap-prod and cdap-test. 
- Adds standards module to github_actions_role service. _**(Will update
all roles in-place.)**_
- Adds permissions for KMS key management and s3 usage.
- Adds cdap-test and cdap-prod to plan and apply workflows.

## ℹ️ Context

We want to move away from the current configuration of all CDAP
resources living in the singular cdap-mgmt VPC which exists in the prod
account, or overloading `bcda-prod` and `bcda-test` in each account.
This way we can test changes and not have to bother with peering
requests and ingress rules from the management VPC in the lower
environments. Also, resources we manage will more clearly be owned by
CDAP.

## 🧪 Validation

See plans
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants