afterhours-shift-manager/terraform/variables.tf
Adam Moussa 969ebf90de
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
feat(portal-api): add Cognito shift API for the employee portal (DEV-287) (#255)
* feat(portal-api): add Cognito shift API for the employee portal (DEV-287)

Employees and admins can pick, drop, swap, and manage coverage through
GET/POST/DELETE /api/shifts. Roster PUT accepts optional email for portal
identity. Slack slash commands and App Home admin modals stay in place.

Co-authored-by: adam <adam@seahavenind.com>

* fix(portal-api): preserve shift and deployment invariants (DEV-287)

Co-authored-by: adam <adam@seahavenind.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-09-21 17:50:57 +00:00

87 lines
2.5 KiB
HCL

variable "aws_region" {
description = "Region every resource in this configuration is created in."
type = string
default = "us-east-1"
}
variable "shift_channel" {
description = "Slack channel ID for schedule posts and shift notifications. Not a secret."
type = string
default = "C0APATP612N"
}
variable "queue_number" {
description = "3CX queue extension number the ring scheduler updates."
type = string
default = "801"
}
variable "timezone" {
description = "IANA timezone for schedule math and EventBridge cron comments."
type = string
default = "America/New_York"
}
variable "pay_report_user" {
description = "Slack user ID that receives the weekly pay DM."
type = string
default = "U0A3SC48T47"
}
variable "sentry_dsn" {
description = "Sentry DSN. Empty disables the SDK. Set in HCP, never in git."
type = string
sensitive = true
default = ""
}
variable "schedules_enabled" {
description = "When false, EventBridge rules exist but do not fire. Keep false until Slack and Paychex point at this stack."
type = bool
default = false
}
variable "github_repo" {
description = "GitHub owner/name for the deploy OIDC trust."
type = string
default = "Sea-Haven-Industries/afterhours-shift-manager"
}
variable "github_deploy_branch" {
description = "Git branch pinned in job_workflow_ref for the deploy role."
type = string
default = "main"
}
variable "checkcomponents_queue_url" {
description = "paychex-checkcomponents SQS URL. Empty skips the weekly SendMessage."
type = string
default = "https://sqs.us-east-1.amazonaws.com/011934824531/paychex-checkcomponents"
}
variable "checkcomponents_queue_arn" {
description = "paychex-checkcomponents SQS ARN for WeeklyPost SendMessage."
type = string
default = "arn:aws:sqs:us-east-1:011934824531:paychex-checkcomponents"
}
variable "portal_cognito_issuer" {
description = "Trusted portal Cognito user-pool issuer for ID-token verification. Empty disables portal auth."
type = string
default = ""
}
variable "portal_cognito_audience" {
description = "Trusted portal Cognito app client ID for ID-token verification."
type = string
default = ""
}
variable "portal_cognito_extra_trust" {
description = "Additional portal Cognito issuer/audience pairs (dev+prod)."
type = list(object({
issuer = string
audience = string
}))
default = []
}