afterhours-shift-manager/terraform/events.tf
Adam Moussa 13350b72d0
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
feat(infra): migrate afterhours to HCP Terraform (PLAT-74) (#252)
* fix(cutover): write Slack secrets into empty Terraform shells

DescribeSecret succeeds on HCP-created shells with no version, so skip-if-exists left roster and Slack tokens unset.

* feat(infra): migrate afterhours to HCP Terraform (PLAT-74)

Replace the mgmt SAM stack with a prod-only HCP workspace, in-repo hcptf IAM, stub Lambdas, and zip CD on push to main.

* fix(cutover): retry DDB unprocessed items and skip past at() holidays

Unprocessed BatchWriteItem rows and leftover past at() schedules would drop roster data or abort holiday recreation during prod cutover.
2026-09-15 23:31:59 +00:00

76 lines
2.5 KiB
HCL

# EventBridge schedules. Every schedule is an EST/EDT pair firing the same
# function one hour apart in UTC: EventBridge cron has no timezone. Both fire
# year-round and the handlers are idempotent. Keep schedules_enabled=false
# until Slack and Paychex point at this stack.
locals {
schedules = {
weekly-post-est = {
description = "Post weekly schedule Monday 7am EST"
schedule = "cron(0 12 ? * MON *)"
function_key = "weekly_post"
}
weekly-post-edt = {
description = "Post weekly schedule Monday 7am EDT"
schedule = "cron(0 11 ? * MON *)"
function_key = "weekly_post"
}
roster-sync-est = {
description = "Sync roster from 3CX at 6am EST"
schedule = "cron(0 11 ? * * *)"
function_key = "roster_sync"
}
roster-sync-edt = {
description = "Sync roster from 3CX at 6am EDT"
schedule = "cron(0 10 ? * * *)"
function_key = "roster_sync"
}
ring-scheduler-daily-est = {
description = "Update 3CX queue at 8am EST"
schedule = "cron(0 13 ? * * *)"
function_key = "ring_scheduler"
}
ring-scheduler-daily-edt = {
description = "Update 3CX queue at 8am EDT"
schedule = "cron(0 12 ? * * *)"
function_key = "ring_scheduler"
}
ring-scheduler-weekend-est = {
description = "Update 3CX queue at 5pm EST weekends"
schedule = "cron(0 22 ? * SAT,SUN *)"
function_key = "ring_scheduler"
}
ring-scheduler-weekend-edt = {
description = "Update 3CX queue at 5pm EDT weekends"
schedule = "cron(0 21 ? * SAT,SUN *)"
function_key = "ring_scheduler"
}
}
}
resource "aws_cloudwatch_event_rule" "schedule" {
for_each = local.schedules
name = "${local.project}-${each.key}"
description = each.value.description
schedule_expression = each.value.schedule
state = var.schedules_enabled ? "ENABLED" : "DISABLED"
}
resource "aws_cloudwatch_event_target" "schedule" {
for_each = local.schedules
rule = aws_cloudwatch_event_rule.schedule[each.key].name
target_id = "${local.project}-${each.key}"
arn = aws_lambda_function.this[each.value.function_key].arn
}
resource "aws_lambda_permission" "schedule" {
for_each = local.schedules
statement_id = "AllowEventBridgeInvoke-${each.key}"
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.this[each.value.function_key].function_name
principal = "events.amazonaws.com"
source_arn = aws_cloudwatch_event_rule.schedule[each.key].arn
}