file-share/terraform/variables.tf
Adam Moussa 7c72159f31
feat(infra): add HCP Terraform for the prod file share (PLAT-77) (#56)
* feat(infra): add HCP Terraform for the prod file share (PLAT-77)

The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy.

* fix(infra): pin FileBrowser version to a release tag (PLAT-77)

The version is interpolated into the boot script. Reject anything that is not a vX.Y.Z tag.

* fix(infra): keep the file share off the public internet (PLAT-77)

The instance has no public IP. Office routes use the syslog VPN gateway and other egress uses a NAT gateway. DLM targets the tagged data volume, and replacement detaches stop the instance first.
2026-09-29 22:32:39 +00:00

53 lines
1.9 KiB
HCL

variable "aws_region" {
description = "Region every resource in this configuration is created in."
type = string
default = "us-east-1"
}
variable "ami_id" {
description = "Pinned Amazon Linux 2023 arm64 AMI. Changing this replaces the instance. Snapshot the data volume the same day and confirm before apply."
type = string
default = "ami-0eb45f74aa8a20238"
}
variable "filebrowser_version" {
description = "Pinned FileBrowser release. Do not track releases/latest."
type = string
default = "v2.63.23"
validation {
condition = can(regex("^v[0-9]+\\.[0-9]+\\.[0-9]+$", var.filebrowser_version))
error_message = "filebrowser_version must look like v2.63.23."
}
}
variable "smb_password_secret_arn" {
description = "Exact ARN of file-share/smb-password in this account. Set as an HCP workspace variable. Never the secret value."
type = string
validation {
condition = startswith(var.smb_password_secret_arn, "arn:aws:secretsmanager:")
error_message = "smb_password_secret_arn must be a Secrets Manager ARN."
}
}
variable "filebrowser_password_secret_arn" {
description = "Exact ARN of file-share/filebrowser-password in this account. Set as an HCP workspace variable. Never the secret value."
type = string
validation {
condition = startswith(var.filebrowser_password_secret_arn, "arn:aws:secretsmanager:")
error_message = "filebrowser_password_secret_arn must be a Secrets Manager ARN."
}
}
variable "data_volume_id" {
description = "Imported data volume id. Empty until cutover. Terraform attaches this volume and must not create or delete it."
type = string
default = ""
validation {
condition = var.data_volume_id == "" || startswith(var.data_volume_id, "vol-")
error_message = "data_volume_id must be empty or an EBS volume id."
}
}