afterhours-shift-manager/terraform/locals.tf
Adam Moussa 13350b72d0
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
feat(infra): migrate afterhours to HCP Terraform (PLAT-74) (#252)
* fix(cutover): write Slack secrets into empty Terraform shells

DescribeSecret succeeds on HCP-created shells with no version, so skip-if-exists left roster and Slack tokens unset.

* feat(infra): migrate afterhours to HCP Terraform (PLAT-74)

Replace the mgmt SAM stack with a prod-only HCP workspace, in-repo hcptf IAM, stub Lambdas, and zip CD on push to main.

* fix(cutover): retry DDB unprocessed items and skip past at() holidays

Unprocessed BatchWriteItem rows and leftover past at() schedules would drop roster data or abort holiday recreation during prod cutover.
2026-09-15 23:31:59 +00:00

87 lines
3.2 KiB
HCL

locals {
project = "afterhours-shift-manager"
account_id = "011934824531"
environment = "prod"
hcp_project = "seahaven-prod"
hcp_workspace = "afterhours-shift-manager-prod"
apply_role = "hcptf-afterhours-shift-manager"
plan_role = "hcptf-afterhours-shift-manager-plan"
deploy_role = "githubdeploy-afterhours-shift-manager"
stack_name = local.project
stack_prefix = "afterhours-shift-manager-"
artifacts_bucket_name = "afterhours-shift-manager-artifacts-${local.account_id}"
ssm_prefix = "/afterhours-shift-manager"
table_name = "afterhours-shifts"
site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts"
github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com"
# Org has Actions OIDC use_immutable_subject=true.
github_oidc_sub = "repo:Sea-Haven-Industries@183236204/afterhours-shift-manager@1200846448:environment:prod"
secret_names = [
"afterhours-shift-manager/slack-bot-token",
"afterhours-shift-manager/slack-signing-secret",
"afterhours-shift-manager/3cx-domain",
"afterhours-shift-manager/3cx-client-id",
"afterhours-shift-manager/3cx-client-secret",
"afterhours-shift-manager/roster-api-token",
]
holiday_router_arn = "arn:aws:lambda:${var.aws_region}:${local.account_id}:function:afterhours-holiday-router"
holiday_scheduler_role_name = "afterhours-shift-manager-holiday-scheduler"
holiday_scheduler_role_arn = "arn:aws:iam::${local.account_id}:role/tf-managed/${local.holiday_scheduler_role_name}"
functions = {
slack_bot = {
function_name = "afterhours-shift-manager"
role_name = "afterhours-shift-manager-slack-bot"
handler = "handler.handler"
timeout = 30
duration_ms = 24000
}
weekly_post = {
function_name = "afterhours-weekly-post"
role_name = "afterhours-shift-manager-weekly-post"
handler = "app.handler"
timeout = 30
duration_ms = 24000
}
roster_sync = {
function_name = "afterhours-roster-sync"
role_name = "afterhours-shift-manager-roster-sync"
handler = "app.handler"
timeout = 60
duration_ms = 48000
}
roster_api = {
function_name = "afterhours-roster-api"
role_name = "afterhours-shift-manager-roster-api"
handler = "app.handler"
timeout = 30
duration_ms = 24000
}
ring_scheduler = {
function_name = "afterhours-ring-scheduler"
role_name = "afterhours-shift-manager-ring-scheduler"
handler = "app.handler"
timeout = 60
duration_ms = 48000
}
holiday_router = {
function_name = "afterhours-holiday-router"
role_name = "afterhours-shift-manager-holiday-router"
handler = "app.handler"
timeout = 60
duration_ms = 48000
}
release_notifier = {
function_name = "afterhours-release-notifier"
role_name = "afterhours-shift-manager-release-notifier"
handler = "app.handler"
timeout = 30
duration_ms = 24000
}
}
}