afterhours-shift-manager/terraform/scheduler.tf
Adam Moussa 470e00affb
Some checks are pending
Deploy API / Deploy API to dev (push) Waiting to run
Deploy API / Deploy API to prod (push) Waiting to run
feat(schedule): align the work week with Sunday-Saturday payroll (DEV-300) (#282)
* feat(schedule): align the work week with Sunday-Saturday payroll

Saturday night stays in the week that ends Saturday, and the first Flex close skips dates already sent.

* fix(slack-bot): show the last pay close on Sunday

The Monday 7am row for the week that just ended is not written yet, so /oncall pay now falls back to the prior close.
2026-09-25 17:56:46 +00:00

100 lines
3.1 KiB
HCL

# EventBridge Scheduler execution role. slack-bot creates one-off holiday-*
# schedules at runtime; Terraform does not create those schedules.
# Recurring jobs use America/New_York Scheduler -> SQS (not dual EST/EDT rules).
data "aws_iam_policy_document" "holiday_scheduler_assume" {
statement {
sid = "SchedulerAssume"
effect = "Allow"
actions = ["sts:AssumeRole"]
principals {
type = "Service"
identifiers = ["scheduler.amazonaws.com"]
}
condition {
test = "StringEquals"
variable = "aws:SourceAccount"
values = [local.account_id]
}
condition {
test = "ArnLike"
variable = "aws:SourceArn"
values = ["arn:aws:scheduler:${var.aws_region}:${local.account_id}:schedule/default/holiday-*"]
}
}
}
resource "aws_iam_role" "holiday_scheduler" {
name = local.holiday_scheduler_role_name
path = "/tf-managed/"
description = "EventBridge Scheduler assumes this role to enqueue holiday jobs or invoke afterhours-holiday-router"
assume_role_policy = data.aws_iam_policy_document.holiday_scheduler_assume.json
permissions_boundary = aws_iam_policy.ecs_task_boundary.arn
}
data "aws_iam_policy_document" "holiday_scheduler" {
statement {
sid = "SendHolidayJobs"
effect = "Allow"
actions = ["sqs:SendMessage"]
resources = [aws_sqs_queue.jobs.arn]
}
}
resource "aws_iam_role_policy" "holiday_scheduler" {
name = "invoke-holiday-router"
role = aws_iam_role.holiday_scheduler.id
policy = data.aws_iam_policy_document.holiday_scheduler.json
}
locals {
job_schedules = {
weekly-post = {
description = "Post weekly schedule Monday 7am Eastern; closes the Sun-Sat pay week"
schedule = "cron(0 7 ? * MON *)"
event = "weekly_post"
}
roster-sync = {
description = "Sync roster from 3CX at 6am Eastern"
schedule = "cron(0 6 ? * * *)"
event = "roster_sync"
}
ring-scheduler-daily = {
description = "Update 3CX queue at 8am Eastern"
schedule = "cron(0 8 ? * * *)"
event = "ring_scheduler_daily"
}
ring-scheduler-weekend = {
description = "Update 3CX queue at 5pm Eastern weekends"
schedule = "cron(0 17 ? * SAT,SUN *)"
event = "ring_scheduler_weekend"
}
}
}
resource "aws_scheduler_schedule_group" "jobs" {
name = local.project
}
resource "aws_scheduler_schedule" "jobs" {
for_each = local.job_schedules
name = "${local.project}-${each.key}"
group_name = aws_scheduler_schedule_group.jobs.name
description = each.value.description
schedule_expression = each.value.schedule
schedule_expression_timezone = "America/New_York"
state = var.ecs_schedules_enabled ? "ENABLED" : "DISABLED"
flexible_time_window {
mode = "OFF"
}
target {
arn = aws_sqs_queue.jobs.arn
role_arn = aws_iam_role.jobs_scheduler.arn
input = jsonencode({ event = each.value.event })
}
}