mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 05:33:12 +00:00
* feat(schedule): align the work week with Sunday-Saturday payroll Saturday night stays in the week that ends Saturday, and the first Flex close skips dates already sent. * fix(slack-bot): show the last pay close on Sunday The Monday 7am row for the week that just ended is not written yet, so /oncall pay now falls back to the prior close.
100 lines
3.1 KiB
HCL
100 lines
3.1 KiB
HCL
# EventBridge Scheduler execution role. slack-bot creates one-off holiday-*
|
|
# schedules at runtime; Terraform does not create those schedules.
|
|
# Recurring jobs use America/New_York Scheduler -> SQS (not dual EST/EDT rules).
|
|
|
|
data "aws_iam_policy_document" "holiday_scheduler_assume" {
|
|
statement {
|
|
sid = "SchedulerAssume"
|
|
effect = "Allow"
|
|
actions = ["sts:AssumeRole"]
|
|
|
|
principals {
|
|
type = "Service"
|
|
identifiers = ["scheduler.amazonaws.com"]
|
|
}
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "aws:SourceAccount"
|
|
values = [local.account_id]
|
|
}
|
|
|
|
condition {
|
|
test = "ArnLike"
|
|
variable = "aws:SourceArn"
|
|
values = ["arn:aws:scheduler:${var.aws_region}:${local.account_id}:schedule/default/holiday-*"]
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role" "holiday_scheduler" {
|
|
name = local.holiday_scheduler_role_name
|
|
path = "/tf-managed/"
|
|
description = "EventBridge Scheduler assumes this role to enqueue holiday jobs or invoke afterhours-holiday-router"
|
|
assume_role_policy = data.aws_iam_policy_document.holiday_scheduler_assume.json
|
|
permissions_boundary = aws_iam_policy.ecs_task_boundary.arn
|
|
}
|
|
|
|
data "aws_iam_policy_document" "holiday_scheduler" {
|
|
statement {
|
|
sid = "SendHolidayJobs"
|
|
effect = "Allow"
|
|
actions = ["sqs:SendMessage"]
|
|
resources = [aws_sqs_queue.jobs.arn]
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role_policy" "holiday_scheduler" {
|
|
name = "invoke-holiday-router"
|
|
role = aws_iam_role.holiday_scheduler.id
|
|
policy = data.aws_iam_policy_document.holiday_scheduler.json
|
|
}
|
|
|
|
locals {
|
|
job_schedules = {
|
|
weekly-post = {
|
|
description = "Post weekly schedule Monday 7am Eastern; closes the Sun-Sat pay week"
|
|
schedule = "cron(0 7 ? * MON *)"
|
|
event = "weekly_post"
|
|
}
|
|
roster-sync = {
|
|
description = "Sync roster from 3CX at 6am Eastern"
|
|
schedule = "cron(0 6 ? * * *)"
|
|
event = "roster_sync"
|
|
}
|
|
ring-scheduler-daily = {
|
|
description = "Update 3CX queue at 8am Eastern"
|
|
schedule = "cron(0 8 ? * * *)"
|
|
event = "ring_scheduler_daily"
|
|
}
|
|
ring-scheduler-weekend = {
|
|
description = "Update 3CX queue at 5pm Eastern weekends"
|
|
schedule = "cron(0 17 ? * SAT,SUN *)"
|
|
event = "ring_scheduler_weekend"
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_scheduler_schedule_group" "jobs" {
|
|
name = local.project
|
|
}
|
|
|
|
resource "aws_scheduler_schedule" "jobs" {
|
|
for_each = local.job_schedules
|
|
|
|
name = "${local.project}-${each.key}"
|
|
group_name = aws_scheduler_schedule_group.jobs.name
|
|
description = each.value.description
|
|
schedule_expression = each.value.schedule
|
|
schedule_expression_timezone = "America/New_York"
|
|
state = var.ecs_schedules_enabled ? "ENABLED" : "DISABLED"
|
|
flexible_time_window {
|
|
mode = "OFF"
|
|
}
|
|
|
|
target {
|
|
arn = aws_sqs_queue.jobs.arn
|
|
role_arn = aws_iam_role.jobs_scheduler.arn
|
|
input = jsonencode({ event = each.value.event })
|
|
}
|
|
}
|