gabriel / musehub public
02-aws-account-structure.md markdown
47 lines 2.8 KB
Raw
sha256:9c64dbfd65ef4e8a85f500e5909c06c2e6c65255a69e84188ee73b63f111cecd Merge 'docs/status-banners-closed-tickets' into 'dev' — pro… Human 22 hours ago

Section 2 — AWS Account Structure

Status: CLOSED — production-readiness issue #151, closed 2026-08-25. The single-shared-account decision this ticket originally tracked was reversed and implemented: three separate AWS accounts now exist (Management, Nonproduction, Production — see docs/architecture/musehub-cloud-identity-and-aws-operating-model.md). No follow-up ticket — the decision this doc tracked is fully superseded.

Companion to musehub-production-readiness-checklist.md.

Decision (already made, per your answer during Section 0)

Single AWS account (992382692655) accepted as technical debt. No AWS Organizations, no account split, before this launch. Recorded in the main checklist's Decision Log and Accepted Risks tables.

Why the rest of this section is deferred, not done

Every remaining item in this section (Organization creation, management/production/non-production account split, per-account budget alerts, alternate contacts, region restriction) is scoped underneath the "should we split accounts" decision. Since the answer is "not now," these are correctly deferred rather than partially implemented:

  • Creating an AWS Organization for a single account that isn't splitting yet would add organizational overhead (SCPs, OUs) with no accounts to actually separate.
  • Budget alerts, alternate contacts, and region restriction are still worth doing within the single account — but that's account hygiene, not account structure. Tracking those under Section 15 (Cost Controls) and Section 3 (Identity) instead, where they actually belong given the single-account reality.

What's true about the current single account today

  • Shared with the Stori project — stori-assets-992382692655-useast2 S3 bucket confirmed live alongside musehub-releases. This account is not MuseHub-dedicated.
  • Region usage: MuseHub resources are all in us-east-1. I have no visibility into whether other regions are enabled account-wide or whether Stori uses a different region (its bucket name suggests us-east-2 — worth Gabriel checking region enablement across both projects before restricting regions, since a MuseHub-only region restriction could be fine, but an account-wide one needs to account for Stori too).
  • No account-level budget alerts, alternate contacts, or region restrictions confirmed — the musehub-infra credential can't read budgets:* or account settings to verify either way; this needs Gabriel checking directly in the AWS console.

Revisit trigger

Recorded in Accepted Risks: revisit the single-account decision post-launch, particularly if Stori and MuseHub start to have materially different security/compliance requirements, or if billing/cost attribution between the two projects becomes hard to disentangle.

File History 2 commits
sha256:9c64dbfd65ef4e8a85f500e5909c06c2e6c65255a69e84188ee73b63f111cecd Merge 'docs/status-banners-closed-tickets' into 'dev' — pro… Human 22 hours ago
sha256:13c97d311d044c1295d13814114a6c567816f00255fd1d3b59ea9b5519bfeb55 Merge 'fix/test-suite-real-bugs' into 'dev' — proposal: fix… Human 2 days ago