mirror of
https://github.com/Sea-Haven-Industries/apm-wo-analysis.git
synced 2026-09-30 06:33:14 +00:00
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* feat(infra): migrate pipeline and Grafana to HCP Terraform (PLAT-75) Move apm-wo-analysis into seahaven-prod under workspace apm-wo-analysis-prod with in-repo hcptf/githubdeploy IAM, stub Lambdas, and GitHub Actions zip CD. * chore(iam): add Checkov skip comments for HCP IAM documents Pre-push HIGH findings are the DLM snapshot describe, tagged EC2 creates, exec boundary DescribeLogGroups star, and the drop-uploader user policy.
31 lines
738 B
HCL
31 lines
738 B
HCL
resource "aws_sqs_queue" "classifier_dlq" {
|
|
name = "apm-wo-analysis-classifier-dlq"
|
|
message_retention_seconds = 1209600
|
|
sqs_managed_sse_enabled = true
|
|
}
|
|
|
|
data "aws_iam_policy_document" "classifier_dlq" {
|
|
statement {
|
|
sid = "DenyInsecureTransport"
|
|
effect = "Deny"
|
|
|
|
principals {
|
|
type = "*"
|
|
identifiers = ["*"]
|
|
}
|
|
|
|
actions = ["sqs:*"]
|
|
resources = [aws_sqs_queue.classifier_dlq.arn]
|
|
|
|
condition {
|
|
test = "Bool"
|
|
variable = "aws:SecureTransport"
|
|
values = ["false"]
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_sqs_queue_policy" "classifier_dlq" {
|
|
queue_url = aws_sqs_queue.classifier_dlq.id
|
|
policy = data.aws_iam_policy_document.classifier_dlq.json
|
|
}
|