mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 12:33:13 +00:00
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* fix(cutover): write Slack secrets into empty Terraform shells DescribeSecret succeeds on HCP-created shells with no version, so skip-if-exists left roster and Slack tokens unset. * feat(infra): migrate afterhours to HCP Terraform (PLAT-74) Replace the mgmt SAM stack with a prod-only HCP workspace, in-repo hcptf IAM, stub Lambdas, and zip CD on push to main. * fix(cutover): retry DDB unprocessed items and skip past at() holidays Unprocessed BatchWriteItem rows and leftover past at() schedules would drop roster data or abort holiday recreation during prod cutover.
50 lines
1.5 KiB
HCL
50 lines
1.5 KiB
HCL
# EventBridge Scheduler execution role. slack-bot creates one-off holiday-*
|
|
# schedules at runtime; Terraform does not create those schedules.
|
|
|
|
data "aws_iam_policy_document" "holiday_scheduler_assume" {
|
|
statement {
|
|
sid = "SchedulerAssume"
|
|
effect = "Allow"
|
|
actions = ["sts:AssumeRole"]
|
|
|
|
principals {
|
|
type = "Service"
|
|
identifiers = ["scheduler.amazonaws.com"]
|
|
}
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "aws:SourceAccount"
|
|
values = [local.account_id]
|
|
}
|
|
|
|
condition {
|
|
test = "ArnLike"
|
|
variable = "aws:SourceArn"
|
|
values = ["arn:aws:scheduler:${var.aws_region}:${local.account_id}:schedule/default/holiday-*"]
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role" "holiday_scheduler" {
|
|
name = local.holiday_scheduler_role_name
|
|
path = "/tf-managed/"
|
|
description = "EventBridge Scheduler assumes this role to invoke afterhours-holiday-router"
|
|
assume_role_policy = data.aws_iam_policy_document.holiday_scheduler_assume.json
|
|
permissions_boundary = aws_iam_policy.lambda_boundary.arn
|
|
}
|
|
|
|
data "aws_iam_policy_document" "holiday_scheduler" {
|
|
statement {
|
|
sid = "InvokeHolidayRouter"
|
|
effect = "Allow"
|
|
actions = ["lambda:InvokeFunction"]
|
|
resources = [local.holiday_router_arn]
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role_policy" "holiday_scheduler" {
|
|
name = "invoke-holiday-router"
|
|
role = aws_iam_role.holiday_scheduler.id
|
|
policy = data.aws_iam_policy_document.holiday_scheduler.json
|
|
}
|