mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-10-02 03:43:11 +00:00
feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289)
Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs expose the resolved vpc_id and public subnet IDs. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
parent
596e949eef
commit
402541613b
4 changed files with 20 additions and 2 deletions
|
|
@ -69,6 +69,13 @@ check "dev_has_no_custom_domain" {
|
|||
}
|
||||
}
|
||||
|
||||
check "prod_reuses_afterhours_vpc" {
|
||||
assert {
|
||||
condition = !local.is_prod || var.existing_vpc_id != ""
|
||||
error_message = "Prod must set existing_vpc_id to the afterhours VPC. Do not mint 10.60."
|
||||
}
|
||||
}
|
||||
|
||||
check "existing_vpc_pair" {
|
||||
assert {
|
||||
condition = (var.existing_vpc_id == "") == (length(var.existing_public_subnet_ids) == 0)
|
||||
|
|
|
|||
|
|
@ -7,7 +7,8 @@ locals {
|
|||
|
||||
github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com"
|
||||
|
||||
# Created only when existing_vpc_id is empty. 10.60 is unused in 011934824531.
|
||||
# Created only when existing_vpc_id is empty. Prod attaches to afterhours 10.70.
|
||||
# 10.60 is the unused fallback CIDR, not a second prod VPC.
|
||||
manage_vpc = var.existing_vpc_id == ""
|
||||
vpc_cidr = "10.60.0.0/16"
|
||||
public_subnet_cidrs = ["10.60.0.0/24", "10.60.1.0/24"]
|
||||
|
|
|
|||
|
|
@ -57,3 +57,13 @@ output "ecs_task_role_arn" {
|
|||
description = "ECS task role; paychex-checkcomponents queue policy must allow this ARN."
|
||||
value = aws_iam_role.ecs_task.arn
|
||||
}
|
||||
|
||||
output "vpc_id" {
|
||||
description = "VPC the ALB and Fargate tasks run in. Prod attaches to afterhours."
|
||||
value = local.vpc_id
|
||||
}
|
||||
|
||||
output "public_subnet_ids" {
|
||||
description = "Public subnet IDs for the ALB and Fargate tasks."
|
||||
value = local.public_subnet_ids
|
||||
}
|
||||
|
|
|
|||
|
|
@ -93,7 +93,7 @@ variable "checkcomponents_queue_arn" {
|
|||
}
|
||||
|
||||
variable "existing_vpc_id" {
|
||||
description = "When set, place the ALB and Fargate tasks in this VPC instead of creating one."
|
||||
description = "When set, place the ALB and Fargate tasks in this VPC instead of creating one. Prod attaches to the afterhours VPC."
|
||||
type = string
|
||||
default = ""
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue