afi-backup-monitor/terraform/lambda.tf
Adam Moussa d853ae8eaf
fix(iac): ship lambda zips via s3 for hcp plan/apply split
HCP plan and apply workers do not share disk; carry archive bytes in the
plan with content_base64 and add IAM depends_on before function create.
2026-08-05 12:18:30 -04:00

85 lines
2.5 KiB
HCL

data "archive_file" "shared_layer" {
type = "zip"
source_dir = "${path.module}/../src/shared"
output_path = "${path.module}/build/afi-shared-layer.zip"
}
data "archive_file" "auto_protect" {
type = "zip"
source_dir = "${path.module}/../src/auto_protect"
output_path = "${path.module}/build/afi-auto-protect.zip"
excludes = ["requirements.txt"]
}
data "archive_file" "health_digest" {
type = "zip"
source_dir = "${path.module}/../src/health_digest"
output_path = "${path.module}/build/afi-health-digest.zip"
excludes = ["requirements.txt"]
}
resource "aws_lambda_layer_version" "shared" {
layer_name = "afi-shared"
description = "Shared Afi API client and utilities"
s3_bucket = aws_s3_bucket.artifacts.id
s3_key = aws_s3_object.shared_layer.key
source_code_hash = data.archive_file.shared_layer.output_base64sha256
compatible_runtimes = ["python3.12"]
compatible_architectures = ["arm64"]
depends_on = [aws_s3_object.shared_layer]
}
resource "aws_lambda_function" "auto_protect" {
function_name = "afi-auto-protect"
role = aws_iam_role.auto_protect.arn
handler = "app.handler"
runtime = "python3.12"
architectures = ["arm64"]
memory_size = 256
timeout = 120
s3_bucket = aws_s3_bucket.artifacts.id
s3_key = aws_s3_object.auto_protect.key
source_code_hash = data.archive_file.auto_protect.output_base64sha256
layers = [aws_lambda_layer_version.shared.arn]
environment {
variables = merge(local.common_env, {
AFI_POLICY_ID = var.afi_policy_id
})
}
depends_on = [
aws_s3_object.auto_protect,
aws_iam_role_policy_attachment.auto_protect_basic,
aws_iam_role_policy.auto_protect_secrets,
]
}
resource "aws_lambda_function" "health_digest" {
function_name = "afi-health-digest"
role = aws_iam_role.health_digest.arn
handler = "app.handler"
runtime = "python3.12"
architectures = ["arm64"]
memory_size = 256
timeout = 120
s3_bucket = aws_s3_bucket.artifacts.id
s3_key = aws_s3_object.health_digest.key
source_code_hash = data.archive_file.health_digest.output_base64sha256
layers = [aws_lambda_layer_version.shared.arn]
environment {
variables = local.common_env
}
depends_on = [
aws_s3_object.health_digest,
aws_iam_role_policy_attachment.health_digest_basic,
aws_iam_role_policy.health_digest_secrets,
]
}