#!/usr/bin/env bash # Package Lambda zips for HCP plan/apply. Runs on the Terraform worker. set -euo pipefail ROOT="$(cd "$(dirname "$0")" && pwd)" BUILD="${ROOT}/build" SRC="$(cd "${ROOT}/../src" && pwd)" # Copy only regular files that resolve inside SRC (no symlink escape). copy_src_file() { local rel="$1" local dest="$2" local src_path="${SRC}/${rel}" if [[ -L "${src_path}" ]]; then echo "error: refusing symlink source: ${src_path}" >&2 exit 1 fi if [[ ! -f "${src_path}" ]]; then echo "error: missing regular file: ${src_path}" >&2 exit 1 fi local resolved resolved="$(cd "$(dirname "${src_path}")" && pwd)/$(basename "${src_path}")" case "${resolved}" in "${SRC}"/*) ;; *) echo "error: path escapes src tree: ${resolved}" >&2 exit 1 ;; esac mkdir -p "$(dirname "${dest}")" # -P: never follow symlinks if the destination path is replaced mid-run. cp -P "${src_path}" "${dest}" } rm -rf "${BUILD}" mkdir -p "${BUILD}/sla_monitor" "${BUILD}/user_sync" copy_src_file "sla_monitor/app.py" "${BUILD}/sla_monitor/app.py" copy_src_file "user_sync/app.py" "${BUILD}/user_sync/app.py" copy_src_file "user_sync/requirements.txt" "${BUILD}/user_sync/requirements.txt" python3 -m pip install \ --quiet \ --disable-pip-version-check \ -r "${BUILD}/user_sync/requirements.txt" \ -t "${BUILD}/user_sync/" \ --platform manylinux2014_aarch64 \ --implementation cp \ --python-version 3.12 \ --only-binary=:all: \ --upgrade # Runtime provides boto3; drop the copy to keep the zip smaller. rm -rf "${BUILD}/user_sync/boto3" "${BUILD}/user_sync/botocore" \ "${BUILD}/user_sync/s3transfer" "${BUILD}/user_sync/jmespath" \ "${BUILD}/user_sync/"*.dist-info 2>/dev/null || true rm -f "${BUILD}/user_sync/requirements.txt"