apm-wo-analysis/terraform/variables.tf
Adam Moussa f13d2e3ff1
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
feat(infra): migrate pipeline and Grafana to HCP Terraform (PLAT-75) (#57)
* feat(infra): migrate pipeline and Grafana to HCP Terraform (PLAT-75)

Move apm-wo-analysis into seahaven-prod under workspace apm-wo-analysis-prod
with in-repo hcptf/githubdeploy IAM, stub Lambdas, and GitHub Actions zip CD.

* chore(iam): add Checkov skip comments for HCP IAM documents

Pre-push HIGH findings are the DLM snapshot describe, tagged EC2 creates,
exec boundary DescribeLogGroups star, and the drop-uploader user policy.
2026-09-16 20:33:24 +00:00

53 lines
1.5 KiB
HCL

variable "aws_region" {
description = "Region every resource in this configuration is created in."
type = string
default = "us-east-1"
}
variable "github_repo" {
description = "GitHub owner/name for the deploy OIDC trust."
type = string
default = "Sea-Haven-Industries/apm-wo-analysis"
}
variable "github_deploy_branch" {
description = "Git branch pinned in job_workflow_ref for the deploy role."
type = string
default = "main"
}
variable "office_cidrs" {
description = "Office CIDRs allowed to reach the Grafana ALB on 443."
type = list(string)
default = ["47.21.61.4/32", "96.250.164.146/32"]
}
variable "slack_interactions_domain" {
description = "Custom domain for the Slack interactivity HTTP API."
type = string
default = "apm-wo.seahaven.com"
}
variable "grafana_domain" {
description = "Public hostname for the Grafana ALB."
type = string
default = "grafana.seahaven.com"
}
variable "athena_plugin_version" {
description = "Pinned grafana-athena-datasource plugin version installed by user-data."
type = string
default = "3.2.0"
}
variable "attach_custom_domains" {
description = "Attach the Slack HTTP API custom domain. False until mgmt releases apm-wo.seahaven.com at cutover. Grafana HTTPS does not use this flag."
type = bool
default = true
}
variable "vpc_cidr" {
description = "CIDR for the dedicated Grafana VPC."
type = string
default = "10.80.0.0/16"
}