d28630d1f1
---ci--- project: acdl phase: 8 milestone: v1.1 status: plan-as-execute persona: lead-developer task: T-8.8 requirements.covered: [REQ-23] ---/ci--- Wave 5: execute the bootstrap against real AWS + fix verify script. - Created S3 bucket acdl-tfstate-581513795199-us-east-1 (versioning enabled) + DynamoDB table acdl-outbox (PAY_PER_REQUEST, PK contractId, SK eventType#eventTs) via create_state_backend.py. - Created IAM user acdl-spike-runner + scoped inline policy (DenyEverythingElse) + initial key via create_iam_user.py. - Rotated the spike key via rotate_spike_key.sh: old key deleted, new key in gitignored .env.secrets (chmod 600). - verify_phase08.sh fixes: (a) heredoc python instead of -c to avoid bash quoting issues; (b) Check 4 uses the bootstrap root key to inspect IAM (the spike key is least-privilege and cannot iam:GetUser - that itself confirms the policy denies non-granted actions); (c) get_user_policy returns PolicyDocument as a dict, not a URL-encoded string in this boto3 version - handle both. - VERIFIED: caller identity is acdl-spike-runner (not root), S3 + DDB + IAM user + Deny-everything-else policy all present, .env.secrets + .bootstrap_state.json gitignored. D-034 closure: user must manually rotate the root key in the AWS IAM console now (the bootstrap root key has served its one-shot purpose).