2026-09-21 19:13:30 +00:00
data " aws_caller_identity " " current " { }
# Resource names in locals.tf embed the account ID. If the workspace is ever
# pointed at another account, fail the plan here rather than creating a parallel
# set of oddly-named resources somewhere else.
check " correct_account " {
assert {
condition = data . aws_caller_identity . current . account_id == local . account_id
error_message = " This configuration targets account ${ local . account_id } ( ${ var . environment } ), but the credentials resolve to ${ data . aws_caller_identity . current . account_id } . "
}
}
2026-09-29 19:10:21 +00:00
check " dev_has_no_external_side_effects " {
assert {
condition = local . is_prod | | alltrue ( [
for name in [ " SHIFT_CHANNEL " , " QUEUE_NUMBER " , " PAY_REPORT_USER " , " TCX_SECRET_PREFIX " ] :
one ( [ for env in local . api_environment : env . value if env . name == name ] ) = = " "
] )
error_message = " Non-prod must leave SHIFT_CHANNEL, QUEUE_NUMBER, PAY_REPORT_USER, and TCX_SECRET_PREFIX empty so the task cannot post to Slack or move the production phone queue. "
}
}
2026-09-21 19:13:30 +00:00
check " dev_has_no_paychex " {
assert {
condition = local . is_prod | | var . checkcomponents_queue_url == " "
error_message = " checkcomponents_queue_url must be empty in non-prod so weekly_post cannot send to the prod Paychex queue. "
}
}
check " checkcomponents_pair " {
assert {
condition = ( var . checkcomponents_queue_url == " " ) = = ( var . checkcomponents_queue_arn == " " )
error_message = " checkcomponents_queue_url and checkcomponents_queue_arn must both be set or both be empty. "
}
}