mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 06:43:12 +00:00
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* fix(cutover): write Slack secrets into empty Terraform shells DescribeSecret succeeds on HCP-created shells with no version, so skip-if-exists left roster and Slack tokens unset. * feat(infra): migrate afterhours to HCP Terraform (PLAT-74) Replace the mgmt SAM stack with a prod-only HCP workspace, in-repo hcptf IAM, stub Lambdas, and zip CD on push to main. * fix(cutover): retry DDB unprocessed items and skip past at() holidays Unprocessed BatchWriteItem rows and leftover past at() schedules would drop roster data or abort holiday recreation during prod cutover.
118 lines
2.7 KiB
HCL
118 lines
2.7 KiB
HCL
# Lambda artifacts bucket. Terraform ships only the bootstrap stub.
|
|
# .github/workflows/deploy.yaml uploads functions/<name>/<sha>.zip and calls
|
|
# update-function-code. Functions ignore code attributes afterwards.
|
|
|
|
resource "aws_s3_bucket" "artifacts" {
|
|
bucket = local.artifacts_bucket_name
|
|
|
|
tags = {
|
|
Purpose = "Lambda deployment packages for afterhours-shift-manager"
|
|
}
|
|
}
|
|
|
|
resource "aws_s3_bucket_public_access_block" "artifacts" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
|
|
block_public_acls = true
|
|
block_public_policy = true
|
|
ignore_public_acls = true
|
|
restrict_public_buckets = true
|
|
}
|
|
|
|
resource "aws_s3_bucket_ownership_controls" "artifacts" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
|
|
rule {
|
|
object_ownership = "BucketOwnerEnforced"
|
|
}
|
|
}
|
|
|
|
resource "aws_s3_bucket_server_side_encryption_configuration" "artifacts" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
|
|
rule {
|
|
apply_server_side_encryption_by_default {
|
|
sse_algorithm = "AES256"
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_s3_bucket_versioning" "artifacts" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
|
|
versioning_configuration {
|
|
status = "Enabled"
|
|
}
|
|
}
|
|
|
|
resource "aws_s3_bucket_lifecycle_configuration" "artifacts" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
|
|
rule {
|
|
id = "expire-noncurrent-packages"
|
|
status = "Enabled"
|
|
|
|
filter {}
|
|
|
|
noncurrent_version_expiration {
|
|
noncurrent_days = 180
|
|
}
|
|
}
|
|
|
|
rule {
|
|
id = "abort-incomplete-multipart"
|
|
status = "Enabled"
|
|
|
|
filter {}
|
|
|
|
abort_incomplete_multipart_upload {
|
|
days_after_initiation = 7
|
|
}
|
|
}
|
|
|
|
depends_on = [aws_s3_bucket_versioning.artifacts]
|
|
}
|
|
|
|
data "aws_iam_policy_document" "artifacts" {
|
|
statement {
|
|
sid = "DenyInsecureTransport"
|
|
effect = "Deny"
|
|
|
|
principals {
|
|
type = "*"
|
|
identifiers = ["*"]
|
|
}
|
|
|
|
actions = ["s3:*"]
|
|
resources = [
|
|
aws_s3_bucket.artifacts.arn,
|
|
"${aws_s3_bucket.artifacts.arn}/*",
|
|
]
|
|
|
|
condition {
|
|
test = "Bool"
|
|
variable = "aws:SecureTransport"
|
|
values = ["false"]
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_s3_bucket_policy" "artifacts" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
policy = data.aws_iam_policy_document.artifacts.json
|
|
|
|
depends_on = [aws_s3_bucket_public_access_block.artifacts]
|
|
}
|
|
|
|
data "archive_file" "bootstrap_stub" {
|
|
type = "zip"
|
|
source_dir = "${path.module}/bootstrap/stub"
|
|
output_path = "${path.module}/build/packages/bootstrap-stub.zip"
|
|
}
|
|
|
|
resource "aws_s3_object" "bootstrap_stub" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
key = "functions/bootstrap-stub.zip"
|
|
content_base64 = filebase64(data.archive_file.bootstrap_stub.output_path)
|
|
source_hash = data.archive_file.bootstrap_stub.output_base64sha256
|
|
}
|