Imported from zemn-me/monorepo (
ts/pulumi/AGENTS.md). Install upstream withnpx skills add zemn-me/monorepo --skill pulumi. Copyright stays with the author.
Pulumi notes
GitHub Actions secret storage is GCP Secret Manager in extreme-cycling-441523-a9; the WIF provider uses project number 845702659200.
When Pulumi seeds GCP Secret Manager values, prefer secretDataWo with deletionPolicy: "ABANDON" so secret material is not persisted in state and bootstrap versions survive code removal.
After migration, protect the GCP WIF and Secret Manager resources that CI requires; only leave them unprotected during an explicit rollback window.
The AWS GitHub Actions role is intentionally admin for now, but its trust policy must stay pinned to the Submit workflow on refs/heads/main and the Staging workflow on merge-queue refs.
AWS GitHub OIDC trust policies should use AWS-documented GitHub keys like repository_id, workflow, ref, and sub; do not copy GCP-only owner claim checks into AWS.
CloudFront Function physical names only allow [a-zA-Z0-9-_]; set explicit sanitized names for resources derived from domains.
ECS cluster physical names have the same [A-Za-z0-9_-] constraint; use the AWS name sanitizer instead of passing dotted component names through.
Lambda function physical names allow [A-Za-z0-9_-] and max 64 chars; set explicit sanitized names for dotted component-derived functions.
Lambda permission statement IDs derive from the logical name unless set; use explicit sanitized statementId for dotted component-derived permissions.
Use route53domains.Domain to purchase a new domain; RegisteredDomain only adopts existing registrations. Reuse Domain.hostedZoneId because registration creates and delegates a public zone automatically.
Deploy infrastructure through the PR/merge workflow and let CI run Pulumi with its existing credentials. Do not ask for a local Pulumi login to deploy changes.
Bootstrap new domain sites under an already delegated staging zone (for example <site>.staging.zemn.me), because merge-queue staging runs before production purchases the domain. After registration succeeds, move staging to staging.<domain> in the production-owned zone; staging must not own the registration.
