mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 07:53:11 +00:00
* feat(infra): export vpc_id and public subnet outputs (DEV-289) Portal Fargate and meals already attach to this VPC. These outputs are the HCP existing_vpc_id / existing_public_subnet_ids values. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289) Same extends: recommended ruleset and @redocly/cli 2.52.1 as internal-portal. Covers health, roster, and portal /api/shifts. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): document 4xx and treat 302 as success in Redocly (DEV-289) Health and CORS preflight document 400. Recommended only counted 2XX, so login-style 302s use a shared 2XX-or-3XX rule. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289) Promote operation-4xx-response and the 2xx-or-3xx success rule to error. Drop unused 400s on health and CORS OPTIONS. Health documents 403 like the portal. CORS stays in Flask and is not part of the employee contract. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
102 lines
4 KiB
HCL
102 lines
4 KiB
HCL
locals {
|
|
project = "afterhours-shift-manager"
|
|
is_prod = var.environment == "prod"
|
|
account_id = local.is_prod ? "011934824531" : "710827005802"
|
|
environment = var.environment
|
|
|
|
hcp_project = "seahaven-${var.environment}"
|
|
hcp_workspace = "${local.project}-${var.environment}"
|
|
apply_role = "hcptf-afterhours-shift-manager"
|
|
plan_role = "hcptf-afterhours-shift-manager-plan"
|
|
deploy_role = "githubdeploy-afterhours-shift-manager"
|
|
stack_name = local.project
|
|
stack_prefix = "afterhours-shift-manager-"
|
|
|
|
artifacts_bucket_name = "afterhours-shift-manager-artifacts-${local.account_id}"
|
|
ssm_prefix = "/afterhours-shift-manager"
|
|
|
|
# Prod has no default VPC. This stack owns 10.70. Meals attaches with
|
|
# existing_vpc_id. Portal Fargate (PLAT-217) should too. Do not mint 10.62.
|
|
vpc_cidr = "10.70.0.0/16"
|
|
public_subnet_cidrs = ["10.70.0.0/24", "10.70.1.0/24"]
|
|
table_name = "afterhours-shifts"
|
|
site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts"
|
|
|
|
github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com"
|
|
# Org has Actions OIDC use_immutable_subject=true.
|
|
github_oidc_subs = [
|
|
"repo:${var.github_repo}:environment:dev",
|
|
"repo:${var.github_repo}:environment:prod",
|
|
"repo:Sea-Haven-Industries@183236204/afterhours-shift-manager@1200846448:environment:dev",
|
|
"repo:Sea-Haven-Industries@183236204/afterhours-shift-manager@1200846448:environment:prod",
|
|
]
|
|
|
|
domain_name = var.domain_name != "" ? var.domain_name : (local.is_prod ? "afterhours.seahaven.com" : "afterhours.dev.seahaven.com")
|
|
acm_wildcard_domain = local.is_prod ? "*.seahaven.com" : "*.dev.seahaven.com"
|
|
api_url = var.attach_custom_domain ? "https://${local.domain_name}" : "http://${aws_lb.api.dns_name}"
|
|
|
|
secret_names = [
|
|
"afterhours-shift-manager/slack-bot-token",
|
|
"afterhours-shift-manager/slack-signing-secret",
|
|
"afterhours-shift-manager/3cx-domain",
|
|
"afterhours-shift-manager/3cx-client-id",
|
|
"afterhours-shift-manager/3cx-client-secret",
|
|
"afterhours-shift-manager/roster-api-token",
|
|
]
|
|
|
|
holiday_router_arn = "arn:aws:lambda:${var.aws_region}:${local.account_id}:function:afterhours-holiday-router"
|
|
holiday_scheduler_role_name = "afterhours-shift-manager-holiday-scheduler"
|
|
holiday_scheduler_role_arn = "arn:aws:iam::${local.account_id}:role/tf-managed/${local.holiday_scheduler_role_name}"
|
|
|
|
functions = {
|
|
slack_bot = {
|
|
function_name = "afterhours-shift-manager"
|
|
role_name = "afterhours-shift-manager-slack-bot"
|
|
handler = "handler.handler"
|
|
timeout = 30
|
|
duration_ms = 24000
|
|
}
|
|
weekly_post = {
|
|
function_name = "afterhours-weekly-post"
|
|
role_name = "afterhours-shift-manager-weekly-post"
|
|
handler = "app.handler"
|
|
timeout = 30
|
|
duration_ms = 24000
|
|
}
|
|
roster_sync = {
|
|
function_name = "afterhours-roster-sync"
|
|
role_name = "afterhours-shift-manager-roster-sync"
|
|
handler = "app.handler"
|
|
timeout = 60
|
|
duration_ms = 48000
|
|
}
|
|
roster_api = {
|
|
function_name = "afterhours-roster-api"
|
|
role_name = "afterhours-shift-manager-roster-api"
|
|
handler = "app.handler"
|
|
timeout = 30
|
|
duration_ms = 24000
|
|
}
|
|
ring_scheduler = {
|
|
function_name = "afterhours-ring-scheduler"
|
|
role_name = "afterhours-shift-manager-ring-scheduler"
|
|
handler = "app.handler"
|
|
timeout = 60
|
|
duration_ms = 48000
|
|
}
|
|
holiday_router = {
|
|
function_name = "afterhours-holiday-router"
|
|
role_name = "afterhours-shift-manager-holiday-router"
|
|
handler = "app.handler"
|
|
timeout = 60
|
|
duration_ms = 48000
|
|
}
|
|
portal_api = {
|
|
function_name = "afterhours-portal-api"
|
|
role_name = "afterhours-shift-manager-portal-api"
|
|
handler = "app.handler"
|
|
timeout = 30
|
|
duration_ms = 24000
|
|
}
|
|
}
|
|
}
|