data "aws_caller_identity" "current" {} # Resource names in locals.tf embed the account ID. If the workspace is ever # pointed at another account, fail the plan here rather than creating a parallel # set of oddly-named resources somewhere else. check "correct_account" { assert { condition = data.aws_caller_identity.current.account_id == local.account_id error_message = "This configuration targets account ${local.account_id} (${var.environment}), but the credentials resolve to ${data.aws_caller_identity.current.account_id}." } } # Alarm sink owned by seahaven-org-baseline, not by this configuration. # Looked up only in prod because CloudWatch alarms are skipped in dev. data "aws_sns_topic" "site_alerts" { count = local.is_prod ? 1 : 0 name = "site-alerts" } moved { from = data.aws_sns_topic.site_alerts to = data.aws_sns_topic.site_alerts[0] } # Shared CloudFront WAF WebACL (audit M-17), published to Parameter Store by the # org baseline. aws_cloudfront_distribution.web_acl_id takes the WAFv2 ARN # despite the attribute name. data "aws_ssm_parameter" "app_web_acl_arn" { name = "/seahaven/waf/app-web-acl-arn" } # Google OAuth client ID used by submit-order and the admin authorizer. The # parameter is created and rotated out-of-band because it varies per # environment; this lookup only asserts that it exists before an apply wires # functions that read it at runtime. Its NAME, not its value, is what reaches # the ECS task. data "aws_ssm_parameter" "google_client_id" { name = local.google_client_id_param } # Fail closed if the OOB Google client ID parameter is missing or empty. The # functions receive the parameter NAME via env; this check forces the data # source to be evaluated so apply cannot succeed without the parameter. check "google_client_id_present" { assert { condition = length(data.aws_ssm_parameter.google_client_id.value) > 0 error_message = "SSM parameter ${local.google_client_id_param} is missing or empty; create it out of band before apply." } } check "dev_has_no_paychex" { assert { condition = local.is_prod || var.checkcomponents_queue_url == "" error_message = "checkcomponents_queue_url must be empty in non-prod so aggregate-orders cannot send to the prod Paychex queue." } } check "checkcomponents_pair" { assert { condition = (var.checkcomponents_queue_url == "") == (var.checkcomponents_queue_arn == "") error_message = "checkcomponents_queue_url and checkcomponents_queue_arn must both be set or both be empty." } } check "dev_has_no_custom_domain" { assert { condition = local.is_prod || !var.attach_custom_domain error_message = "attach_custom_domain must be false in non-prod; use the CloudFront distribution domain." } } check "prod_reuses_afterhours_vpc" { assert { condition = !local.is_prod || var.existing_vpc_id != "" error_message = "Prod must set existing_vpc_id to the afterhours VPC. Do not mint 10.60." } } check "existing_vpc_pair" { assert { condition = (var.existing_vpc_id == "") == (length(var.existing_public_subnet_ids) == 0) error_message = "existing_vpc_id and existing_public_subnet_ids must both be set or both be empty." } } check "existing_vpc_two_az" { assert { condition = var.existing_vpc_id == "" || length(var.existing_public_subnet_ids) >= 2 error_message = "existing_public_subnet_ids must include at least two subnets." } } check "existing_subnets_in_vpc" { assert { condition = alltrue([ for subnet in data.aws_subnet.existing_public : subnet.vpc_id == var.existing_vpc_id ]) error_message = "Every existing_public_subnet_ids value must belong to existing_vpc_id." } }