mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 06:33:12 +00:00
fix(infra): fail prod apply without the afterhours VPC (DEV-289)
Prod never creates the 10.60 fallback VPC. A terraform_data precondition fails plan and apply when existing_vpc_id is empty, instead of a check block that only warns. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
parent
abe34de3d5
commit
7bb5cb73aa
3 changed files with 27 additions and 4 deletions
|
|
@ -9,7 +9,7 @@ locals {
|
|||
|
||||
# Created only when existing_vpc_id is empty. Prod attaches to afterhours 10.70.
|
||||
# 10.60 is the unused fallback CIDR, not a second prod VPC.
|
||||
manage_vpc = var.existing_vpc_id == ""
|
||||
manage_vpc = var.existing_vpc_id == "" && !local.is_prod
|
||||
vpc_cidr = "10.60.0.0/16"
|
||||
public_subnet_cidrs = ["10.60.0.0/24", "10.60.1.0/24"]
|
||||
|
||||
|
|
|
|||
|
|
@ -4,7 +4,7 @@ data "aws_availability_zones" "available" {
|
|||
}
|
||||
|
||||
data "aws_vpc" "existing" {
|
||||
count = local.manage_vpc ? 0 : 1
|
||||
count = var.existing_vpc_id == "" ? 0 : 1
|
||||
id = var.existing_vpc_id
|
||||
}
|
||||
|
||||
|
|
@ -13,6 +13,17 @@ data "aws_subnet" "existing_public" {
|
|||
id = each.value
|
||||
}
|
||||
|
||||
resource "terraform_data" "prod_requires_afterhours_vpc" {
|
||||
input = var.existing_vpc_id
|
||||
|
||||
lifecycle {
|
||||
precondition {
|
||||
condition = !local.is_prod || var.existing_vpc_id != ""
|
||||
error_message = "Prod must set existing_vpc_id to the afterhours VPC. Do not mint 10.60."
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_vpc" "this" {
|
||||
count = local.manage_vpc ? 1 : 0
|
||||
|
||||
|
|
@ -24,6 +35,13 @@ resource "aws_vpc" "this" {
|
|||
Name = "${local.project}-vpc"
|
||||
}
|
||||
|
||||
lifecycle {
|
||||
precondition {
|
||||
condition = !local.is_prod
|
||||
error_message = "Prod must set existing_vpc_id to the afterhours VPC. Do not mint 10.60."
|
||||
}
|
||||
}
|
||||
|
||||
# First apply updates the live hcptf apply role before CreateVpc.
|
||||
depends_on = [
|
||||
aws_iam_role_policy_attachments_exclusive.hcptf_apply,
|
||||
|
|
@ -80,7 +98,7 @@ resource "aws_route_table_association" "public" {
|
|||
}
|
||||
|
||||
locals {
|
||||
vpc_id = local.manage_vpc ? aws_vpc.this[0].id : data.aws_vpc.existing[0].id
|
||||
vpc_id = local.manage_vpc ? aws_vpc.this[0].id : try(data.aws_vpc.existing[0].id, var.existing_vpc_id)
|
||||
public_subnet_ids = local.manage_vpc ? aws_subnet.public[*].id : var.existing_public_subnet_ids
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -21,7 +21,9 @@ def test_meals_owns_a_vpc_instead_of_looking_up_default():
|
|||
assert "count = local.manage_vpc ? 1 : 0" in vpc
|
||||
assert 'variable "existing_vpc_id"' in variables
|
||||
assert 'variable "existing_public_subnet_ids"' in variables
|
||||
assert 'manage_vpc = var.existing_vpc_id == ""' in locals_tf
|
||||
assert (
|
||||
'manage_vpc = var.existing_vpc_id == "" && !local.is_prod' in locals_tf
|
||||
)
|
||||
assert 'data "aws_vpc" "default"' not in ecs
|
||||
assert "data.aws_vpc.default" not in ecs
|
||||
assert "data.aws_subnets.default" not in ecs
|
||||
|
|
@ -38,3 +40,6 @@ def test_meals_owns_a_vpc_instead_of_looking_up_default():
|
|||
assert "value = local.vpc_id" in outputs
|
||||
assert 'output "public_subnet_ids"' in outputs
|
||||
assert 'check "prod_reuses_afterhours_vpc"' in data
|
||||
assert "prod_requires_afterhours_vpc" in vpc
|
||||
assert "Do not mint 10.60." in vpc
|
||||
assert 'count = var.existing_vpc_id == "" ? 0 : 1' in vpc
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue