meal-order-manager/terraform/vpc.tf

129 lines
3 KiB
Terraform
Raw Normal View History

data "aws_availability_zones" "available" {
count = local.manage_vpc ? 1 : 0
state = "available"
}
data "aws_vpc" "existing" {
feat(api): add OpenAPI Redocly contract and VPC outputs (DEV-289) (#206) * feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289) Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs expose the resolved vpc_id and public subnet IDs. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289) Same extends: recommended ruleset and @redocly/cli 2.52.1 as internal-portal. Documents current { error: string } JSON errors. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): document 4xx and reject invalid form-status weeks (DEV-289) Health, form-status, and roster document 400. form-status now maps current and returns 400 for a week that is not current or YYYY-WNN. Redocly treats 302 as a success response, matching the portal. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * style(test): format VPC contract assertions for ruff (DEV-289) Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289) Promote operation-4xx-response and the 2xx-or-3xx success rule to error. Replace unused health and roster 400s with 403, matching portal health. Form-status keeps its real 400 for invalid week. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): split week params and allow live menu nulls (DEV-289) Menu and form-status take current or YYYY-WNN. Orders take YYYY-WNN or a calendar date and reject current. Menu payloads may emit null menu_url, calories, protein, and image_url. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(infra): fail prod apply without the afterhours VPC (DEV-289) Prod never creates the 10.60 fallback VPC. A terraform_data precondition fails plan and apply when existing_vpc_id is empty, instead of a check block that only warns. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:33:48 +00:00
count = var.existing_vpc_id == "" ? 0 : 1
id = var.existing_vpc_id
}
data "aws_subnet" "existing_public" {
for_each = toset(var.existing_public_subnet_ids)
id = each.value
}
feat(api): add OpenAPI Redocly contract and VPC outputs (DEV-289) (#206) * feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289) Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs expose the resolved vpc_id and public subnet IDs. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289) Same extends: recommended ruleset and @redocly/cli 2.52.1 as internal-portal. Documents current { error: string } JSON errors. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): document 4xx and reject invalid form-status weeks (DEV-289) Health, form-status, and roster document 400. form-status now maps current and returns 400 for a week that is not current or YYYY-WNN. Redocly treats 302 as a success response, matching the portal. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * style(test): format VPC contract assertions for ruff (DEV-289) Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289) Promote operation-4xx-response and the 2xx-or-3xx success rule to error. Replace unused health and roster 400s with 403, matching portal health. Form-status keeps its real 400 for invalid week. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): split week params and allow live menu nulls (DEV-289) Menu and form-status take current or YYYY-WNN. Orders take YYYY-WNN or a calendar date and reject current. Menu payloads may emit null menu_url, calories, protein, and image_url. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(infra): fail prod apply without the afterhours VPC (DEV-289) Prod never creates the 10.60 fallback VPC. A terraform_data precondition fails plan and apply when existing_vpc_id is empty, instead of a check block that only warns. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:33:48 +00:00
resource "terraform_data" "prod_requires_afterhours_vpc" {
input = var.existing_vpc_id
lifecycle {
precondition {
condition = !local.is_prod || var.existing_vpc_id != ""
error_message = "Prod must set existing_vpc_id to the afterhours VPC. Do not mint 10.60."
}
}
}
resource "aws_vpc" "this" {
count = local.manage_vpc ? 1 : 0
cidr_block = local.vpc_cidr
enable_dns_support = true
enable_dns_hostnames = true
tags = {
Name = "${local.project}-vpc"
}
feat(api): add OpenAPI Redocly contract and VPC outputs (DEV-289) (#206) * feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289) Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs expose the resolved vpc_id and public subnet IDs. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289) Same extends: recommended ruleset and @redocly/cli 2.52.1 as internal-portal. Documents current { error: string } JSON errors. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): document 4xx and reject invalid form-status weeks (DEV-289) Health, form-status, and roster document 400. form-status now maps current and returns 400 for a week that is not current or YYYY-WNN. Redocly treats 302 as a success response, matching the portal. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * style(test): format VPC contract assertions for ruff (DEV-289) Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289) Promote operation-4xx-response and the 2xx-or-3xx success rule to error. Replace unused health and roster 400s with 403, matching portal health. Form-status keeps its real 400 for invalid week. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): split week params and allow live menu nulls (DEV-289) Menu and form-status take current or YYYY-WNN. Orders take YYYY-WNN or a calendar date and reject current. Menu payloads may emit null menu_url, calories, protein, and image_url. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(infra): fail prod apply without the afterhours VPC (DEV-289) Prod never creates the 10.60 fallback VPC. A terraform_data precondition fails plan and apply when existing_vpc_id is empty, instead of a check block that only warns. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:33:48 +00:00
lifecycle {
precondition {
condition = !local.is_prod
error_message = "Prod must set existing_vpc_id to the afterhours VPC. Do not mint 10.60."
}
}
# First apply updates the live hcptf apply role before CreateVpc.
depends_on = [
aws_iam_role_policy_attachments_exclusive.hcptf_apply,
aws_iam_role_policy.hcptf_apply_ec2,
]
}
resource "aws_internet_gateway" "this" {
count = local.manage_vpc ? 1 : 0
vpc_id = aws_vpc.this[0].id
tags = {
Name = "${local.project}-igw"
}
}
resource "aws_subnet" "public" {
count = local.manage_vpc ? length(local.public_subnet_cidrs) : 0
vpc_id = aws_vpc.this[0].id
cidr_block = local.public_subnet_cidrs[count.index]
availability_zone = data.aws_availability_zones.available[0].names[count.index]
map_public_ip_on_launch = true
tags = {
Name = "${local.project}-public-${count.index}"
}
}
resource "aws_route_table" "public" {
count = local.manage_vpc ? 1 : 0
vpc_id = aws_vpc.this[0].id
tags = {
Name = "${local.project}-public"
}
}
resource "aws_route" "public_default" {
count = local.manage_vpc ? 1 : 0
route_table_id = aws_route_table.public[0].id
destination_cidr_block = "0.0.0.0/0"
gateway_id = aws_internet_gateway.this[0].id
}
resource "aws_route_table_association" "public" {
count = local.manage_vpc ? length(local.public_subnet_cidrs) : 0
subnet_id = aws_subnet.public[count.index].id
route_table_id = aws_route_table.public[0].id
}
locals {
feat(api): add OpenAPI Redocly contract and VPC outputs (DEV-289) (#206) * feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289) Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs expose the resolved vpc_id and public subnet IDs. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289) Same extends: recommended ruleset and @redocly/cli 2.52.1 as internal-portal. Documents current { error: string } JSON errors. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): document 4xx and reject invalid form-status weeks (DEV-289) Health, form-status, and roster document 400. form-status now maps current and returns 400 for a week that is not current or YYYY-WNN. Redocly treats 302 as a success response, matching the portal. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * style(test): format VPC contract assertions for ruff (DEV-289) Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289) Promote operation-4xx-response and the 2xx-or-3xx success rule to error. Replace unused health and roster 400s with 403, matching portal health. Form-status keeps its real 400 for invalid week. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): split week params and allow live menu nulls (DEV-289) Menu and form-status take current or YYYY-WNN. Orders take YYYY-WNN or a calendar date and reject current. Menu payloads may emit null menu_url, calories, protein, and image_url. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(infra): fail prod apply without the afterhours VPC (DEV-289) Prod never creates the 10.60 fallback VPC. A terraform_data precondition fails plan and apply when existing_vpc_id is empty, instead of a check block that only warns. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:33:48 +00:00
vpc_id = local.manage_vpc ? aws_vpc.this[0].id : try(data.aws_vpc.existing[0].id, var.existing_vpc_id)
public_subnet_ids = local.manage_vpc ? aws_subnet.public[*].id : var.existing_public_subnet_ids
}
moved {
from = aws_vpc.this
to = aws_vpc.this[0]
}
moved {
from = aws_internet_gateway.this
to = aws_internet_gateway.this[0]
}
moved {
from = aws_route_table.public
to = aws_route_table.public[0]
}
moved {
from = aws_route.public_default
to = aws_route.public_default[0]
}
moved {
from = data.aws_availability_zones.available
to = data.aws_availability_zones.available[0]
}