# HCP plan and apply run on separate workers. archive_file paths from plan are # not on the apply worker, so zip bytes are carried in the plan via # content_base64 and uploaded to S3 at apply time for Lambda to consume. # # Package build runs during plan via external data (local-exec provisioners # only run on apply; archive_file needs build/ present at plan time). data "external" "package_build" { program = ["bash", "${path.module}/build_packages_external.sh"] } resource "aws_s3_bucket" "artifacts" { bucket = "front-integrations-artifacts-${local.account_id}" } resource "aws_s3_bucket_public_access_block" "artifacts" { bucket = aws_s3_bucket.artifacts.id block_public_acls = true block_public_policy = true ignore_public_acls = true restrict_public_buckets = true } data "archive_file" "sla_monitor" { type = "zip" source_dir = "${path.module}/build/sla_monitor" output_path = "${path.module}/build/front-sla-monitor.zip" depends_on = [data.external.package_build] } data "archive_file" "user_sync" { type = "zip" source_dir = "${path.module}/build/user_sync" output_path = "${path.module}/build/front-user-sync.zip" depends_on = [data.external.package_build] } resource "aws_s3_object" "sla_monitor" { bucket = aws_s3_bucket.artifacts.id key = "front-sla-monitor.zip" content_base64 = filebase64(data.archive_file.sla_monitor.output_path) source_hash = data.archive_file.sla_monitor.output_base64sha256 } resource "aws_s3_object" "user_sync" { bucket = aws_s3_bucket.artifacts.id key = "front-user-sync.zip" content_base64 = filebase64(data.archive_file.user_sync.output_path) source_hash = data.archive_file.user_sync.output_base64sha256 }