forgejo/terraform/lambda.tf
Adam Moussa 530bd7210e
feat(terraform): migrate forgejo to HCP Terraform
Move the prod host onto workspace forgejo-prod in the After Hours VPC and freeze CDK push deploys so cutover can happen without applying into seahaven-prod.
2026-09-29 18:36:17 -04:00

105 lines
3.2 KiB
HCL

data "external" "lambda_package" {
program = ["bash", "${path.module}/build_lambda_external.sh"]
}
data "archive_file" "lambda_package" {
type = "zip"
source_dir = "${path.module}/build/function"
output_path = "${path.module}/build/forgejo-backup-verification.zip"
depends_on = [data.external.lambda_package]
}
resource "aws_s3_object" "lambda_package" {
bucket = aws_s3_bucket.artifacts.id
key = "functions/forgejo-backup-verification.zip"
content_base64 = filebase64(data.archive_file.lambda_package.output_path)
source_hash = data.archive_file.lambda_package.output_base64sha256
}
resource "aws_cloudwatch_log_group" "verification" {
name = local.verification_log_group
retention_in_days = 60
}
resource "aws_lambda_function" "verification" {
function_name = "forgejo-backup-verification"
role = aws_iam_role.lambda.arn
runtime = "python3.12"
architectures = ["arm64"]
handler = "app.handler"
memory_size = 512
timeout = 300
s3_bucket = aws_s3_bucket.artifacts.id
s3_key = aws_s3_object.lambda_package.key
source_code_hash = data.archive_file.lambda_package.output_base64sha256
ephemeral_storage {
size = 4096
}
environment {
variables = {
SOURCE_BUCKET = aws_s3_bucket.backups.id
REPLICA_BUCKET = aws_s3_bucket.replica.id
GCS_BUCKET = "forgejo-backups-offsite-seahaven"
GCS_SA_SECRET_NAME = "forgejo/gcs-sa-key"
SLACK_WEBHOOK_SECRET_NAME = "forgejo/slack-webhook"
}
}
depends_on = [
aws_cloudwatch_log_group.verification,
aws_iam_role_policy.lambda,
aws_s3_object.lambda_package,
]
}
resource "aws_cloudwatch_event_rule" "daily" {
name = "forgejo-backup-daily-check"
description = "Daily Forgejo backup verification"
schedule_expression = "cron(0 8 * * ? *)"
state = var.enable_schedules ? "ENABLED" : "DISABLED"
}
resource "aws_cloudwatch_event_target" "daily" {
rule = aws_cloudwatch_event_rule.daily.name
arn = aws_lambda_function.verification.arn
input = jsonencode({
mode = "daily"
})
}
resource "aws_lambda_permission" "daily" {
statement_id = "AllowDailyCheck"
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.verification.function_name
principal = "events.amazonaws.com"
source_arn = aws_cloudwatch_event_rule.daily.arn
}
resource "aws_cloudwatch_event_rule" "monthly" {
name = "forgejo-backup-monthly-restore-test"
description = "Monthly Forgejo restore test"
schedule_expression = "cron(0 9 1 * ? *)"
state = var.enable_schedules ? "ENABLED" : "DISABLED"
}
resource "aws_cloudwatch_event_target" "monthly" {
rule = aws_cloudwatch_event_rule.monthly.name
arn = aws_lambda_function.verification.arn
input = jsonencode({
mode = "restore-test"
})
}
resource "aws_lambda_permission" "monthly" {
statement_id = "AllowMonthlyRestoreTest"
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.verification.function_name
principal = "events.amazonaws.com"
source_arn = aws_cloudwatch_event_rule.monthly.arn
}