data "aws_caller_identity" "current" {} # Resource names in locals.tf embed the account ID. If the workspace is ever # pointed at another account, fail the plan here rather than creating a parallel # set of oddly-named resources somewhere else. check "correct_account" { assert { condition = data.aws_caller_identity.current.account_id == local.account_id error_message = "This configuration targets account ${local.account_id} (${var.environment}), but the credentials resolve to ${data.aws_caller_identity.current.account_id}." } } check "dev_has_no_paychex" { assert { condition = local.is_prod || var.checkcomponents_queue_url == "" error_message = "checkcomponents_queue_url must be empty in non-prod so weekly_post cannot send to the prod Paychex queue." } } check "checkcomponents_pair" { assert { condition = (var.checkcomponents_queue_url == "") == (var.checkcomponents_queue_arn == "") error_message = "checkcomponents_queue_url and checkcomponents_queue_arn must both be set or both be empty." } }