afterhours-shift-manager/terraform/secrets.tf
Adam Moussa 13350b72d0
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
feat(infra): migrate afterhours to HCP Terraform (PLAT-74) (#252)
* fix(cutover): write Slack secrets into empty Terraform shells

DescribeSecret succeeds on HCP-created shells with no version, so skip-if-exists left roster and Slack tokens unset.

* feat(infra): migrate afterhours to HCP Terraform (PLAT-74)

Replace the mgmt SAM stack with a prod-only HCP workspace, in-repo hcptf IAM, stub Lambdas, and zip CD on push to main.

* fix(cutover): retry DDB unprocessed items and skip past at() holidays

Unprocessed BatchWriteItem rows and leftover past at() schedules would drop roster data or abort holiday recreation during prod cutover.
2026-09-15 23:31:59 +00:00

15 lines
540 B
HCL

# Secret shells only. Values are set outside Terraform. 3CX secrets may already
# exist in prod from seahaven-door-unlock-api (PLAT-76); import those names
# rather than recreating:
# terraform import 'aws_secretsmanager_secret.this["afterhours-shift-manager/3cx-domain"]' afterhours-shift-manager/3cx-domain
resource "aws_secretsmanager_secret" "this" {
for_each = toset(local.secret_names)
name = each.value
recovery_window_in_days = 30
tags = {
Purpose = "afterhours-shift-manager secret shell"
}
}