data "aws_caller_identity" "current" {} # Resource names in locals.tf embed the account ID. If the workspace is ever # pointed at another account, fail the plan here rather than creating a parallel # set of oddly-named resources somewhere else. check "correct_account" { assert { condition = data.aws_caller_identity.current.account_id == local.account_id error_message = "This configuration targets account ${local.account_id}, but the credentials resolve to ${data.aws_caller_identity.current.account_id}." } } # Alarm sink owned by seahaven-org-baseline, not by this configuration. data "aws_sns_topic" "site_alerts" { name = "site-alerts" } # Shared CloudFront WAF WebACL (audit M-17), published to Parameter Store by the # org baseline. aws_cloudfront_distribution.web_acl_id takes the WAFv2 ARN # despite the attribute name. data "aws_ssm_parameter" "app_web_acl_arn" { name = "/seahaven/waf/app-web-acl-arn" } # Google OAuth client ID used by submit-order and the admin authorizer. The # parameter is created and rotated out-of-band because it varies per # environment; this lookup only asserts that it exists before an apply wires # functions that read it at runtime. Its NAME, not its value, is what reaches # the functions. data "aws_ssm_parameter" "google_client_id" { name = local.google_client_id_param } # Fail closed if the OOB Google client ID parameter is missing or empty. The # functions receive the parameter NAME via env; this check forces the data # source to be evaluated so apply cannot succeed without the parameter. check "google_client_id_present" { assert { condition = length(data.aws_ssm_parameter.google_client_id.value) > 0 error_message = "SSM parameter ${local.google_client_id_param} is missing or empty; create it out of band before apply." } }