mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 07:53:11 +00:00
* feat(api): collapse Slack, portal, and jobs onto Fargate (PLAT-216) Move HTTP and scheduled work onto one always-on Flask task so after-hours loses Lambda cold start without changing the Cognito or roster contracts. * fix(portal-api): keep CORS headers on unexpected 500s Portal SPA error handling needs Access-Control-Allow-Origin even when DynamoDB or other internals fail, otherwise the browser hides the 500. * fix(api): retarget holidays per account and ship App Home changelog (PLAT-216) * fix(iam): list ECS tasks and fail closed on non-prod Paychex (PLAT-216) * fix(portal-api): serve portal JSON with an explicit JSON content type
116 lines
3.5 KiB
HCL
116 lines
3.5 KiB
HCL
variable "aws_region" {
|
|
description = "Region every resource in this configuration is created in."
|
|
type = string
|
|
default = "us-east-1"
|
|
}
|
|
|
|
variable "shift_channel" {
|
|
description = "Slack channel ID for schedule posts and shift notifications. Not a secret."
|
|
type = string
|
|
default = "C0APATP612N"
|
|
}
|
|
|
|
variable "queue_number" {
|
|
description = "3CX queue extension number the ring scheduler updates."
|
|
type = string
|
|
default = "801"
|
|
}
|
|
|
|
variable "timezone" {
|
|
description = "IANA timezone for schedule math and EventBridge cron comments."
|
|
type = string
|
|
default = "America/New_York"
|
|
}
|
|
|
|
variable "pay_report_user" {
|
|
description = "Slack user ID that receives the weekly pay DM."
|
|
type = string
|
|
default = "U0A3SC48T47"
|
|
}
|
|
|
|
variable "sentry_dsn" {
|
|
description = "Sentry DSN. Empty disables the SDK. Set in HCP, never in git."
|
|
type = string
|
|
sensitive = true
|
|
default = ""
|
|
}
|
|
|
|
variable "environment" {
|
|
description = "HCP workspace stage. Selects account and workspace name."
|
|
type = string
|
|
default = "prod"
|
|
|
|
validation {
|
|
condition = contains(["dev", "prod"], var.environment)
|
|
error_message = "environment must be \"dev\" or \"prod\"."
|
|
}
|
|
}
|
|
|
|
variable "domain_name" {
|
|
description = "Public hostname on the ALB when attach_custom_domain is true. Empty selects afterhours.seahaven.com or afterhours.dev.seahaven.com from environment."
|
|
type = string
|
|
default = ""
|
|
}
|
|
|
|
variable "attach_custom_domain" {
|
|
description = "When true, attach an HTTPS listener using the issued wildcard ACM certificate. Keep false until public DNS points at the ALB."
|
|
type = bool
|
|
default = false
|
|
}
|
|
|
|
variable "schedules_enabled" {
|
|
description = "When false, EventBridge Lambda rules exist but do not fire. Keep false until Slack and Paychex point at this stack, and after Fargate jobs are enabled."
|
|
type = bool
|
|
default = false
|
|
}
|
|
|
|
variable "ecs_schedules_enabled" {
|
|
description = "When false, EventBridge Scheduler jobs exist but do not fire. Enable at Fargate cutover after the image is healthy; keep Lambda EventBridge rules disabled."
|
|
type = bool
|
|
default = false
|
|
}
|
|
|
|
variable "github_repo" {
|
|
description = "GitHub owner/name for the deploy OIDC trust."
|
|
type = string
|
|
default = "Sea-Haven-Industries/afterhours-shift-manager"
|
|
}
|
|
|
|
variable "github_deploy_branch" {
|
|
description = "Git branch pinned in job_workflow_ref for the deploy role."
|
|
type = string
|
|
default = "main"
|
|
}
|
|
|
|
variable "checkcomponents_queue_url" {
|
|
description = "paychex-checkcomponents SQS URL. Empty skips the weekly SendMessage."
|
|
type = string
|
|
default = "https://sqs.us-east-1.amazonaws.com/011934824531/paychex-checkcomponents"
|
|
}
|
|
|
|
variable "checkcomponents_queue_arn" {
|
|
description = "paychex-checkcomponents SQS ARN for WeeklyPost SendMessage."
|
|
type = string
|
|
default = "arn:aws:sqs:us-east-1:011934824531:paychex-checkcomponents"
|
|
}
|
|
|
|
variable "portal_cognito_issuer" {
|
|
description = "Trusted portal Cognito user-pool issuer for ID-token verification. Empty disables portal auth."
|
|
type = string
|
|
default = ""
|
|
}
|
|
|
|
variable "portal_cognito_audience" {
|
|
description = "Trusted portal Cognito app client ID for ID-token verification."
|
|
type = string
|
|
default = ""
|
|
}
|
|
|
|
variable "portal_cognito_extra_trust" {
|
|
description = "Additional portal Cognito issuer/audience pairs (dev+prod)."
|
|
type = list(object({
|
|
issuer = string
|
|
audience = string
|
|
}))
|
|
default = []
|
|
}
|