afi-backup-monitor/terraform/artifacts.tf
Adam Moussa d853ae8eaf
fix(iac): ship lambda zips via s3 for hcp plan/apply split
HCP plan and apply workers do not share disk; carry archive bytes in the
plan with content_base64 and add IAM depends_on before function create.
2026-08-05 12:18:30 -04:00

37 lines
1.4 KiB
HCL

# HCP plan and apply run on separate workers. archive_file paths from plan are
# not on the apply worker, so zip bytes are carried in the plan via
# content_base64 and uploaded to S3 at apply time for Lambda to consume.
resource "aws_s3_bucket" "artifacts" {
bucket = "afi-backup-monitor-artifacts-${local.account_id}"
}
resource "aws_s3_bucket_public_access_block" "artifacts" {
bucket = aws_s3_bucket.artifacts.id
block_public_acls = true
block_public_policy = true
ignore_public_acls = true
restrict_public_buckets = true
}
resource "aws_s3_object" "shared_layer" {
bucket = aws_s3_bucket.artifacts.id
key = "afi-shared-layer.zip"
content_base64 = filebase64(data.archive_file.shared_layer.output_path)
source_hash = data.archive_file.shared_layer.output_base64sha256
}
resource "aws_s3_object" "auto_protect" {
bucket = aws_s3_bucket.artifacts.id
key = "afi-auto-protect.zip"
content_base64 = filebase64(data.archive_file.auto_protect.output_path)
source_hash = data.archive_file.auto_protect.output_base64sha256
}
resource "aws_s3_object" "health_digest" {
bucket = aws_s3_bucket.artifacts.id
key = "afi-health-digest.zip"
content_base64 = filebase64(data.archive_file.health_digest.output_path)
source_hash = data.archive_file.health_digest.output_base64sha256
}