data "aws_caller_identity" "current" {} # Resource names in locals.tf embed the account ID. If the workspace is ever # pointed at another account, fail the plan here rather than creating a parallel # set of oddly-named resources somewhere else. check "correct_account" { assert { condition = data.aws_caller_identity.current.account_id == local.account_id error_message = "This configuration targets account ${local.account_id} (${var.environment}), but the credentials resolve to ${data.aws_caller_identity.current.account_id}." } } check "dev_has_no_external_side_effects" { assert { condition = local.is_prod || alltrue([ for name in ["SHIFT_CHANNEL", "QUEUE_NUMBER", "PAY_REPORT_USER", "TCX_SECRET_PREFIX"] : one([for env in local.api_environment : env.value if env.name == name]) == "" ]) error_message = "Non-prod must leave SHIFT_CHANNEL, QUEUE_NUMBER, PAY_REPORT_USER, and TCX_SECRET_PREFIX empty so the task cannot post to Slack or move the production phone queue." } } check "dev_has_no_paychex" { assert { condition = local.is_prod || var.checkcomponents_queue_url == "" error_message = "checkcomponents_queue_url must be empty in non-prod so weekly_post cannot send to the prod Paychex queue." } } check "checkcomponents_pair" { assert { condition = (var.checkcomponents_queue_url == "") == (var.checkcomponents_queue_arn == "") error_message = "checkcomponents_queue_url and checkcomponents_queue_arn must both be set or both be empty." } }