meal-order-manager/terraform/ssm.tf

118 lines
4.1 KiB
Terraform
Raw Normal View History

# Parameter Store entries.
#
# /meal-order-manager/google-client-id is deliberately NOT declared here. It is
# created and rotated out-of-band because it varies per environment; data.tf
# reads it. Do not turn that lookup into a resource.
resource "aws_ssm_parameter" "sentry_dsn" {
name = "${local.ssm_prefix}/sentry-dsn"
type = "SecureString"
value = "unset"
description = "Sentry DSN for meal-order-manager. PutParameter writes the live value; Terraform ignores it. Empty or unset disables the SDK."
lifecycle {
ignore_changes = [value]
}
}
resource "aws_ssm_parameter" "slack_channel_id" {
name = local.slack_channel_param
type = "String"
value = var.slack_channel_id
description = "Slack channel ID for meal order notifications"
}
resource "aws_ssm_parameter" "portal_cognito_issuer" {
name = local.portal_cognito_issuer_param
type = "String"
value = var.portal_cognito_issuer
description = "Trusted portal Cognito user-pool issuer for ID-token verification"
}
resource "aws_ssm_parameter" "portal_cognito_audience" {
name = local.portal_cognito_audience_param
type = "String"
value = var.portal_cognito_audience
description = "Trusted portal Cognito app client ID for ID-token verification"
}
resource "aws_ssm_parameter" "portal_cognito_trust" {
name = local.portal_cognito_trust_param
type = "String"
value = jsonencode(concat(
[{ issuer = var.portal_cognito_issuer, audience = var.portal_cognito_audience }],
var.portal_cognito_extra_trust,
))
description = "Trusted portal Cognito issuer/audience pairs for ID-token verification"
}
# ---------------------------------------------------------------------------
# Deploy-time lookups
# ---------------------------------------------------------------------------
#
# Deploy targets for the image workflow and the publish_menu job.
# There is no CloudFormation stack.
resource "aws_ssm_parameter" "deploy_api_url" {
name = "${local.ssm_prefix}/deploy/api-url"
type = "String"
value = "http://${aws_lb.api.dns_name}"
description = "ALB URL for weekly-menu HMAC publish (not on CloudFront)"
}
resource "aws_ssm_parameter" "deploy_cluster" {
name = "${local.ssm_prefix}/deploy/cluster"
type = "String"
value = aws_ecs_cluster.api.name
description = "ECS cluster name for deploy-api.yaml"
}
resource "aws_ssm_parameter" "deploy_service" {
name = "${local.ssm_prefix}/deploy/service"
type = "String"
value = aws_ecs_service.api.name
description = "ECS service name for deploy-api.yaml"
}
resource "aws_ssm_parameter" "deploy_task_family" {
name = "${local.ssm_prefix}/deploy/task-family"
type = "String"
value = aws_ecs_task_definition.api.family
description = "ECS task definition family for deploy-api.yaml"
}
resource "aws_ssm_parameter" "deploy_ecr_repository" {
name = "${local.ssm_prefix}/deploy/ecr-repository"
type = "String"
value = aws_ecr_repository.api.repository_url
description = "ECR repository URL for deploy-api.yaml"
}
resource "aws_ssm_parameter" "deploy_container_name" {
name = "${local.ssm_prefix}/deploy/container-name"
type = "String"
value = local.api_container_name
description = "Container name in the ECS task definition"
}
resource "aws_ssm_parameter" "deploy_form_bucket" {
name = "${local.ssm_prefix}/deploy/form-bucket"
type = "String"
value = aws_s3_bucket.form.id
description = "S3 bucket holding the order form; upload target for the publish_menu job"
}
resource "aws_ssm_parameter" "deploy_distribution_id" {
name = "${local.ssm_prefix}/deploy/distribution-id"
type = "String"
value = aws_cloudfront_distribution.form.id
description = "CloudFront distribution ID; cache-invalidation target for the publish_menu job"
}
resource "aws_ssm_parameter" "deploy_form_url" {
name = "${local.ssm_prefix}/deploy/form-url"
type = "String"
value = local.form_url
description = "Public order form URL; linked from the publish_menu Slack post"
}