forgejo/terraform
Adam Moussa b2164d8c7e
fix(terraform): allow HCP refresh of the log group and parameter (PLAT-80) (#101)
* fix(terraform): allow HCP refresh of the log group and parameter

The scoped apply role can create those resources, but CloudWatch and SSM list them on a wildcard ARN. DescribeLogGroups and DescribeParameters need that resource.

* fix(terraform): let the plan role read bucket website config

The S3 provider refreshes GetBucketWebsite. The plan role was denied on the three Forgejo buckets.

* fix(terraform): let the plan role read backup object metadata

HeadObject on the Lambda zip is s3:GetObject. The plan role only had the bucket ARNs.

* fix(terraform): let the plan role read object tags and retention

The S3 provider refreshes tagging, ACL, attributes, and Object Lock on the Lambda zip.

* fix(terraform): scope plan object reads and restore on the data volume

The plan role only needs object reads for the verification zip. Unpacking a dump in /tmp fills the root volume.

* fix(terraform): accept dumps that already contain data/forgejo.db

Today's archive has no gitea-db.sqlite3 at the root. Copy that file only when it is present.

* docs(terraform): keep restore runbook on one bucket and fail closed

Glacier and the download use the prod bucket. GCS unpacks on the data volume. Neither path deletes live repos until the dump has a database.

* docs(terraform): keep optional restore copies from aborting under set -e

if/fi matches user_data.sh. The file comment now says forgejo-services versions also go through the org-account role.

* fix(terraform): restore the dump app.ini with the database

INTERNAL_TOKEN, JWT_SECRET, and LFS_JWT_SECRET live in that file. A restore that keeps the generated file cannot decrypt the dumped secrets.
2026-09-30 00:10:09 +00:00
..
.terraform.lock.hcl feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
alarms.tf feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
alb.tf feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
build_lambda.sh feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
build_lambda_external.sh feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
data.tf feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
ec2.tf feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
hcp_iam.tf fix(terraform): allow HCP refresh of the log group and parameter (PLAT-80) (#101) 2026-09-30 00:10:09 +00:00
iam.tf feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
lambda.tf feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
locals.tf feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
outputs.tf feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
providers.tf feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
s3.tf feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
terraform.tfvars.example feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
user_data.sh fix(terraform): allow HCP refresh of the log group and parameter (PLAT-80) (#101) 2026-09-30 00:10:09 +00:00
variables.tf feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00
versions.tf feat(terraform): migrate forgejo to HCP Terraform (PLAT-80) (#100) 2026-09-29 22:49:21 +00:00