front-integrations/terraform/build_packages.sh
Adam Moussa 7bbdbabe3a
feat(terraform): migrate front-integrations to HCP Terraform (PLAT-72) (#41)
* feat(terraform): migrate front-integrations to HCP Terraform

Freeze SAM CD and add Terraform for seahaven-prod (Lambdas, DynamoDB,
EventBridge, alarms) so HCP becomes the sole deploy path. Include prod
secret ARNs in the tfvars example for workspace wiring.

* fix(terraform): reject symlink sources in Lambda package build
2026-08-05 18:48:16 -04:00

61 lines
1.8 KiB
Bash
Executable file

#!/usr/bin/env bash
# Package Lambda zips for HCP plan/apply. Runs on the Terraform worker.
set -euo pipefail
ROOT="$(cd "$(dirname "$0")" && pwd)"
BUILD="${ROOT}/build"
SRC="$(cd "${ROOT}/../src" && pwd)"
# Copy only regular files that resolve inside SRC (no symlink escape).
copy_src_file() {
local rel="$1"
local dest="$2"
local src_path="${SRC}/${rel}"
if [[ -L "${src_path}" ]]; then
echo "error: refusing symlink source: ${src_path}" >&2
exit 1
fi
if [[ ! -f "${src_path}" ]]; then
echo "error: missing regular file: ${src_path}" >&2
exit 1
fi
local resolved
resolved="$(cd "$(dirname "${src_path}")" && pwd)/$(basename "${src_path}")"
case "${resolved}" in
"${SRC}"/*) ;;
*)
echo "error: path escapes src tree: ${resolved}" >&2
exit 1
;;
esac
mkdir -p "$(dirname "${dest}")"
# -P: never follow symlinks if the destination path is replaced mid-run.
cp -P "${src_path}" "${dest}"
}
rm -rf "${BUILD}"
mkdir -p "${BUILD}/sla_monitor" "${BUILD}/user_sync"
copy_src_file "sla_monitor/app.py" "${BUILD}/sla_monitor/app.py"
copy_src_file "user_sync/app.py" "${BUILD}/user_sync/app.py"
copy_src_file "user_sync/requirements.txt" "${BUILD}/user_sync/requirements.txt"
python3 -m pip install \
--quiet \
--disable-pip-version-check \
-r "${BUILD}/user_sync/requirements.txt" \
-t "${BUILD}/user_sync/" \
--platform manylinux2014_aarch64 \
--implementation cp \
--python-version 3.12 \
--only-binary=:all: \
--upgrade
# Runtime provides boto3; drop the copy to keep the zip smaller.
rm -rf "${BUILD}/user_sync/boto3" "${BUILD}/user_sync/botocore" \
"${BUILD}/user_sync/s3transfer" "${BUILD}/user_sync/jmespath" \
"${BUILD}/user_sync/"*.dist-info 2>/dev/null || true
rm -f "${BUILD}/user_sync/requirements.txt"