variable "aws_region" { description = "Region every resource in this configuration is created in." type = string default = "us-east-1" } variable "environment" { description = "HCP workspace stage. Selects account and workspace name." type = string validation { condition = contains(["dev", "prod"], var.environment) error_message = "environment must be \"dev\" or \"prod\"." } } variable "domain_name" { description = "Custom domain served by the CloudFront distribution when attach_custom_domain is true. An ISSUED ACM certificate for this domain must already exist in us-east-1 (see acm.tf)." type = string default = "orders.seahaven.com" } variable "attach_custom_domain" { description = "When true, attach domain_name as a CloudFront alias with the ACM viewer certificate. Keep false until DNS cutover so the prod distribution can exist while orders.seahaven.com still points at mgmt." type = bool default = false } variable "slack_bot_secret_arn" { description = "ARN of the Secrets Manager secret holding the Slack bot token. The secret and its value are managed out-of-band; only the ARN enters this configuration." type = string validation { condition = can(regex("^arn:aws:secretsmanager:", var.slack_bot_secret_arn)) error_message = "slack_bot_secret_arn must be a Secrets Manager ARN." } } variable "slack_channel_id" { description = "Slack channel ID for meal order notifications. Written to /meal-order-manager/slack-channel-id." type = string } variable "portal_cognito_issuer" { description = "Exact issuer URL for the portal Cognito user pool whose ID tokens meal-order-manager accepts." type = string validation { condition = can(regex("^https://cognito-idp\\.[a-z0-9-]+\\.amazonaws\\.com/[A-Za-z0-9_-]+$", var.portal_cognito_issuer)) error_message = "portal_cognito_issuer must be an exact Cognito user-pool issuer URL without a trailing slash." } } variable "portal_cognito_audience" { description = "Portal Cognito app client ID required in accepted ID-token aud claims." type = string validation { condition = length(trimspace(var.portal_cognito_audience)) > 0 error_message = "portal_cognito_audience must not be empty." } } variable "portal_cognito_extra_trust" { description = "Additional portal Cognito issuer/audience pairs trusted by the meals API. Use this so portal-dev and portal-prod tokens both work against the single prod meals stack." type = list(object({ issuer = string audience = string })) default = [] validation { condition = alltrue([ for pair in var.portal_cognito_extra_trust : ( can(regex("^https://cognito-idp\\.[a-z0-9-]+\\.amazonaws\\.com/[A-Za-z0-9_-]+$", pair.issuer)) && length(trimspace(pair.audience)) > 0 ) ]) error_message = "Each extra trust entry must be a Cognito issuer URL without a trailing slash and a non-empty audience." } } variable "checkcomponents_queue_url" { description = "paychex-checkcomponents SQS URL. Empty skips the weekly SendMessage." type = string default = "https://sqs.us-east-1.amazonaws.com/011934824531/paychex-checkcomponents" } variable "checkcomponents_queue_arn" { description = "paychex-checkcomponents SQS ARN for aggregate-orders SendMessage." type = string default = "arn:aws:sqs:us-east-1:011934824531:paychex-checkcomponents" }