mirror of
https://github.com/Sea-Haven-Industries/file-share.git
synced 2026-10-02 17:43:14 +00:00
* fix(infra): run nightly snapshots as a stack-local DLM role (PLAT-77) The lifecycle policy assumed a service-linked role AWS does not provide, so it stayed in ERROR and never snapshotted the data volume. * fix(infra): scope DLM snapshot sharing to snapshot ARNs ModifySnapshotAttribute on every resource can share a snapshot. The boundary allows it only on snapshot ARNs.
28 lines
856 B
HCL
28 lines
856 B
HCL
locals {
|
|
project = "file-share"
|
|
environment = "prod"
|
|
|
|
hcp_project = "seahaven-prod"
|
|
hcp_workspace = "file-share-prod"
|
|
apply_role = "hcptf-file-share"
|
|
plan_role = "hcptf-file-share-plan"
|
|
stack_name = local.project
|
|
stack_prefix = "file-share-"
|
|
|
|
instance_role_name = "file-share-role"
|
|
instance_profile_name = "file-share-profile"
|
|
boundary_name = "file-share-instance-boundary"
|
|
dlm_role_name = "file-share-dlm"
|
|
dlm_boundary_name = "file-share-dlm-boundary"
|
|
|
|
office_lan_cidrs = ["10.10.0.0/16", "10.30.0.0/16"]
|
|
subnet_cidr = "10.40.20.0/24"
|
|
subnet_az = "us-east-1a"
|
|
|
|
create_instance = var.data_volume_id != ""
|
|
|
|
user_data = templatefile("${path.module}/user_data.sh.tftpl", {
|
|
aws_region = var.aws_region
|
|
filebrowser_version = var.filebrowser_version
|
|
})
|
|
}
|