Commit graph

7 commits

Author SHA1 Message Date
2cc849024f
fix(terraform): accept dumps that already contain data/forgejo.db
Today's archive has no gitea-db.sqlite3 at the root. Copy that file only when it is present.
2026-09-29 19:37:48 -04:00
30f4b54052
fix(terraform): scope plan object reads and restore on the data volume
The plan role only needs object reads for the verification zip. Unpacking a dump in /tmp fills the root volume.
2026-09-29 19:35:07 -04:00
8eb19b4e55
fix(terraform): let the plan role read object tags and retention
The S3 provider refreshes tagging, ACL, attributes, and Object Lock on the Lambda zip.
2026-09-29 19:28:05 -04:00
566a669c7b
fix(terraform): let the plan role read backup object metadata
HeadObject on the Lambda zip is s3:GetObject. The plan role only had the bucket ARNs.
2026-09-29 19:25:14 -04:00
d511861296
fix(terraform): let the plan role read bucket website config
The S3 provider refreshes GetBucketWebsite. The plan role was denied on the three Forgejo buckets.
2026-09-29 19:22:34 -04:00
8360cfb1db
fix(terraform): allow HCP refresh of the log group and parameter
The scoped apply role can create those resources, but CloudWatch and SSM list them on a wildcard ARN. DescribeLogGroups and DescribeParameters need that resource.
2026-09-29 19:10:08 -04:00
Adam Moussa
e4982b87ad
feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100)
* feat(terraform): migrate forgejo to HCP Terraform

Move the prod host onto workspace forgejo-prod in the After Hours VPC and freeze CDK push deploys so cutover can happen without applying into seahaven-prod.

* fix(terraform): restore forgejo.db from the dump tarball

Boot restore was copying data/ and repos/ and leaving the sqlite file at the archive root, so a volume restore started Forgejo with no database.
2026-09-29 22:49:21 +00:00