mirror of
https://github.com/Sea-Haven-Industries/file-share.git
synced 2026-09-30 03:13:11 +00:00
* feat(infra): add HCP Terraform for the prod file share (PLAT-77) The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy. * fix(infra): pin FileBrowser version to a release tag (PLAT-77) The version is interpolated into the boot script. Reject anything that is not a vX.Y.Z tag. * fix(infra): keep the file share off the public internet (PLAT-77) The instance has no public IP. Office routes use the syslog VPN gateway and other egress uses a NAT gateway. DLM targets the tagged data volume, and replacement detaches stop the instance first.
53 lines
1.9 KiB
HCL
53 lines
1.9 KiB
HCL
variable "aws_region" {
|
|
description = "Region every resource in this configuration is created in."
|
|
type = string
|
|
default = "us-east-1"
|
|
}
|
|
|
|
variable "ami_id" {
|
|
description = "Pinned Amazon Linux 2023 arm64 AMI. Changing this replaces the instance. Snapshot the data volume the same day and confirm before apply."
|
|
type = string
|
|
default = "ami-0eb45f74aa8a20238"
|
|
}
|
|
|
|
variable "filebrowser_version" {
|
|
description = "Pinned FileBrowser release. Do not track releases/latest."
|
|
type = string
|
|
default = "v2.63.23"
|
|
|
|
validation {
|
|
condition = can(regex("^v[0-9]+\\.[0-9]+\\.[0-9]+$", var.filebrowser_version))
|
|
error_message = "filebrowser_version must look like v2.63.23."
|
|
}
|
|
}
|
|
|
|
variable "smb_password_secret_arn" {
|
|
description = "Exact ARN of file-share/smb-password in this account. Set as an HCP workspace variable. Never the secret value."
|
|
type = string
|
|
|
|
validation {
|
|
condition = startswith(var.smb_password_secret_arn, "arn:aws:secretsmanager:")
|
|
error_message = "smb_password_secret_arn must be a Secrets Manager ARN."
|
|
}
|
|
}
|
|
|
|
variable "filebrowser_password_secret_arn" {
|
|
description = "Exact ARN of file-share/filebrowser-password in this account. Set as an HCP workspace variable. Never the secret value."
|
|
type = string
|
|
|
|
validation {
|
|
condition = startswith(var.filebrowser_password_secret_arn, "arn:aws:secretsmanager:")
|
|
error_message = "filebrowser_password_secret_arn must be a Secrets Manager ARN."
|
|
}
|
|
}
|
|
|
|
variable "data_volume_id" {
|
|
description = "Imported data volume id. Empty until cutover. Terraform attaches this volume and must not create or delete it."
|
|
type = string
|
|
default = ""
|
|
|
|
validation {
|
|
condition = var.data_volume_id == "" || startswith(var.data_volume_id, "vol-")
|
|
error_message = "data_volume_id must be empty or an EBS volume id."
|
|
}
|
|
}
|