2026-08-07 19:19:51 -04:00
data " aws_caller_identity " " current " { }
# Resource names in locals.tf embed the account ID. If the workspace is ever
# pointed at another account, fail the plan here rather than creating a parallel
# set of oddly-named resources somewhere else.
check " correct_account " {
assert {
condition = data . aws_caller_identity . current . account_id == local . account_id
2026-09-18 18:38:45 +00:00
error_message = " This configuration targets account ${ local . account_id } ( ${ var . environment } ), but the credentials resolve to ${ data . aws_caller_identity . current . account_id } . "
2026-08-07 19:19:51 -04:00
}
}
# Alarm sink owned by seahaven-org-baseline, not by this configuration.
2026-09-18 18:38:45 +00:00
# Looked up only in prod because CloudWatch alarms are skipped in dev.
2026-08-07 19:19:51 -04:00
data " aws_sns_topic " " site_alerts " {
2026-09-18 18:38:45 +00:00
count = local . is_prod ? 1 : 0
name = " site-alerts "
}
moved {
from = data . aws_sns_topic . site_alerts
to = data . aws_sns_topic . site_alerts [ 0 ]
2026-08-07 19:19:51 -04:00
}
# Shared CloudFront WAF WebACL (audit M-17), published to Parameter Store by the
# org baseline. aws_cloudfront_distribution.web_acl_id takes the WAFv2 ARN
# despite the attribute name.
data " aws_ssm_parameter " " app_web_acl_arn " {
name = " /seahaven/waf/app-web-acl-arn "
}
# Google OAuth client ID used by submit-order and the admin authorizer. The
# parameter is created and rotated out-of-band because it varies per
# environment; this lookup only asserts that it exists before an apply wires
# functions that read it at runtime. Its NAME, not its value, is what reaches
2026-09-21 19:34:24 +00:00
# the ECS task.
2026-08-07 19:19:51 -04:00
data " aws_ssm_parameter " " google_client_id " {
name = local . google_client_id_param
}
2026-08-07 19:28:25 -04:00
# Fail closed if the OOB Google client ID parameter is missing or empty. The
# functions receive the parameter NAME via env; this check forces the data
# source to be evaluated so apply cannot succeed without the parameter.
check " google_client_id_present " {
assert {
condition = length ( data . aws_ssm_parameter . google_client_id . value ) > 0
error_message = " SSM parameter ${ local . google_client_id_param } is missing or empty; create it out of band before apply. "
}
}
2026-09-18 18:38:45 +00:00
check " dev_has_no_paychex " {
assert {
condition = local . is_prod | | var . checkcomponents_queue_url == " "
error_message = " checkcomponents_queue_url must be empty in non-prod so aggregate-orders cannot send to the prod Paychex queue. "
}
}
check " checkcomponents_pair " {
assert {
condition = ( var . checkcomponents_queue_url == " " ) = = ( var . checkcomponents_queue_arn == " " )
error_message = " checkcomponents_queue_url and checkcomponents_queue_arn must both be set or both be empty. "
}
}
check " dev_has_no_custom_domain " {
assert {
condition = local . is_prod | | ! var . attach_custom_domain
error_message = " attach_custom_domain must be false in non-prod; use the CloudFront distribution domain. "
}
}
2026-09-21 21:15:47 +00:00
check " existing_vpc_pair " {
assert {
condition = ( var . existing_vpc_id == " " ) = = ( length ( var . existing_public_subnet_ids ) = = 0 )
error_message = " existing_vpc_id and existing_public_subnet_ids must both be set or both be empty. "
}
}
check " existing_vpc_two_az " {
assert {
condition = var . existing_vpc_id == " " | | length ( var . existing_public_subnet_ids ) > = 2
error_message = " existing_public_subnet_ids must include at least two subnets. "
}
}
check " existing_subnets_in_vpc " {
assert {
condition = alltrue ( [
for subnet in data . aws_subnet . existing_public : subnet . vpc_id == var . existing_vpc_id
] )
error_message = " Every existing_public_subnet_ids value must belong to existing_vpc_id. "
}
}