# HCP plan and apply run on separate workers. archive_file paths from plan are # not on the apply worker, so zip bytes are carried in the plan via # content_base64 and uploaded to S3 at apply time for Lambda to consume. resource "aws_s3_bucket" "artifacts" { bucket = "afi-backup-monitor-artifacts-${local.account_id}" } resource "aws_s3_bucket_public_access_block" "artifacts" { bucket = aws_s3_bucket.artifacts.id block_public_acls = true block_public_policy = true ignore_public_acls = true restrict_public_buckets = true } resource "aws_s3_object" "shared_layer" { bucket = aws_s3_bucket.artifacts.id key = "afi-shared-layer.zip" content_base64 = filebase64(data.archive_file.shared_layer.output_path) source_hash = data.archive_file.shared_layer.output_base64sha256 } resource "aws_s3_object" "auto_protect" { bucket = aws_s3_bucket.artifacts.id key = "afi-auto-protect.zip" content_base64 = filebase64(data.archive_file.auto_protect.output_path) source_hash = data.archive_file.auto_protect.output_base64sha256 } resource "aws_s3_object" "health_digest" { bucket = aws_s3_bucket.artifacts.id key = "afi-health-digest.zip" content_base64 = filebase64(data.archive_file.health_digest.output_path) source_hash = data.archive_file.health_digest.output_base64sha256 }