mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 17:13:12 +00:00
* feat(api): collapse Slack, portal, and jobs onto Fargate (PLAT-216) Move HTTP and scheduled work onto one always-on Flask task so after-hours loses Lambda cold start without changing the Cognito or roster contracts. * fix(portal-api): keep CORS headers on unexpected 500s Portal SPA error handling needs Access-Control-Allow-Origin even when DynamoDB or other internals fail, otherwise the browser hides the 500. * fix(api): retarget holidays per account and ship App Home changelog (PLAT-216) * fix(iam): list ECS tasks and fail closed on non-prod Paychex (PLAT-216) * fix(portal-api): serve portal JSON with an explicit JSON content type
25 lines
1 KiB
HCL
25 lines
1 KiB
HCL
data "aws_caller_identity" "current" {}
|
|
|
|
# Resource names in locals.tf embed the account ID. If the workspace is ever
|
|
# pointed at another account, fail the plan here rather than creating a parallel
|
|
# set of oddly-named resources somewhere else.
|
|
check "correct_account" {
|
|
assert {
|
|
condition = data.aws_caller_identity.current.account_id == local.account_id
|
|
error_message = "This configuration targets account ${local.account_id} (${var.environment}), but the credentials resolve to ${data.aws_caller_identity.current.account_id}."
|
|
}
|
|
}
|
|
|
|
check "dev_has_no_paychex" {
|
|
assert {
|
|
condition = local.is_prod || var.checkcomponents_queue_url == ""
|
|
error_message = "checkcomponents_queue_url must be empty in non-prod so weekly_post cannot send to the prod Paychex queue."
|
|
}
|
|
}
|
|
|
|
check "checkcomponents_pair" {
|
|
assert {
|
|
condition = (var.checkcomponents_queue_url == "") == (var.checkcomponents_queue_arn == "")
|
|
error_message = "checkcomponents_queue_url and checkcomponents_queue_arn must both be set or both be empty."
|
|
}
|
|
}
|