variable "aws_region" { description = "Region every resource in this configuration is created in." type = string default = "us-east-1" } variable "domain_name" { description = "Custom domain served by the CloudFront distribution when attach_custom_domain is true. An ISSUED ACM certificate for this domain must already exist in us-east-1 (see acm.tf)." type = string default = "orders.seahaven.com" } variable "attach_custom_domain" { description = "When true, attach domain_name as a CloudFront alias with the ACM viewer certificate. Keep false until DNS cutover so the prod distribution can exist while orders.seahaven.com still points at mgmt." type = bool default = false } variable "payroll_email" { description = "Recipient of the weekly payroll deduction report." type = string default = "payroll@seahavenind.com" } variable "sender_email" { description = "SES-verified From address for the payroll deduction report." type = string default = "adam@seahavenind.com" } variable "slack_bot_secret_arn" { description = "ARN of the Secrets Manager secret holding the Slack bot token. The secret and its value are managed out-of-band; only the ARN enters this configuration." type = string validation { condition = can(regex("^arn:aws:secretsmanager:", var.slack_bot_secret_arn)) error_message = "slack_bot_secret_arn must be a Secrets Manager ARN." } } variable "slack_channel_id" { description = "Slack channel ID for meal order notifications. Written to /meal-order-manager/slack-channel-id." type = string }