meal-order-manager/terraform/ssm.tf
Adam Moussa cc506f3c1f
Some checks are pending
Deploy API / Deploy API to dev (push) Waiting to run
Deploy API / Deploy API to prod (push) Waiting to run
feat(menu): publish the weekly menu from the job worker (PLAT-229) (#219)
* feat(menu): publish the weekly menu from the job worker

Monday publish parses the catalog embedded in the Redefine menu page and runs on the Fargate worker, so the GitHub Actions scrape cron can go away.

* fix(menu): address review feedback

Use the form deadline in the Monday Slack post, and compare that message exactly so CodeQL does not treat the test as URL sanitization.
2026-09-25 22:10:24 +00:00

117 lines
4.1 KiB
HCL

# Parameter Store entries.
#
# /meal-order-manager/google-client-id is deliberately NOT declared here. It is
# created and rotated out-of-band because it varies per environment; data.tf
# reads it. Do not turn that lookup into a resource.
resource "aws_ssm_parameter" "sentry_dsn" {
name = "${local.ssm_prefix}/sentry-dsn"
type = "SecureString"
value = "unset"
description = "Sentry DSN for meal-order-manager. PutParameter writes the live value; Terraform ignores it. Empty or unset disables the SDK."
lifecycle {
ignore_changes = [value]
}
}
resource "aws_ssm_parameter" "slack_channel_id" {
name = local.slack_channel_param
type = "String"
value = var.slack_channel_id
description = "Slack channel ID for meal order notifications"
}
resource "aws_ssm_parameter" "portal_cognito_issuer" {
name = local.portal_cognito_issuer_param
type = "String"
value = var.portal_cognito_issuer
description = "Trusted portal Cognito user-pool issuer for ID-token verification"
}
resource "aws_ssm_parameter" "portal_cognito_audience" {
name = local.portal_cognito_audience_param
type = "String"
value = var.portal_cognito_audience
description = "Trusted portal Cognito app client ID for ID-token verification"
}
resource "aws_ssm_parameter" "portal_cognito_trust" {
name = local.portal_cognito_trust_param
type = "String"
value = jsonencode(concat(
[{ issuer = var.portal_cognito_issuer, audience = var.portal_cognito_audience }],
var.portal_cognito_extra_trust,
))
description = "Trusted portal Cognito issuer/audience pairs for ID-token verification"
}
# ---------------------------------------------------------------------------
# Deploy-time lookups
# ---------------------------------------------------------------------------
#
# Deploy targets for the image workflow and the publish_menu job.
# There is no CloudFormation stack.
resource "aws_ssm_parameter" "deploy_api_url" {
name = "${local.ssm_prefix}/deploy/api-url"
type = "String"
value = "http://${aws_lb.api.dns_name}"
description = "ALB URL for weekly-menu HMAC publish (not on CloudFront)"
}
resource "aws_ssm_parameter" "deploy_cluster" {
name = "${local.ssm_prefix}/deploy/cluster"
type = "String"
value = aws_ecs_cluster.api.name
description = "ECS cluster name for deploy-api.yaml"
}
resource "aws_ssm_parameter" "deploy_service" {
name = "${local.ssm_prefix}/deploy/service"
type = "String"
value = aws_ecs_service.api.name
description = "ECS service name for deploy-api.yaml"
}
resource "aws_ssm_parameter" "deploy_task_family" {
name = "${local.ssm_prefix}/deploy/task-family"
type = "String"
value = aws_ecs_task_definition.api.family
description = "ECS task definition family for deploy-api.yaml"
}
resource "aws_ssm_parameter" "deploy_ecr_repository" {
name = "${local.ssm_prefix}/deploy/ecr-repository"
type = "String"
value = aws_ecr_repository.api.repository_url
description = "ECR repository URL for deploy-api.yaml"
}
resource "aws_ssm_parameter" "deploy_container_name" {
name = "${local.ssm_prefix}/deploy/container-name"
type = "String"
value = local.api_container_name
description = "Container name in the ECS task definition"
}
resource "aws_ssm_parameter" "deploy_form_bucket" {
name = "${local.ssm_prefix}/deploy/form-bucket"
type = "String"
value = aws_s3_bucket.form.id
description = "S3 bucket holding the order form; upload target for the publish_menu job"
}
resource "aws_ssm_parameter" "deploy_distribution_id" {
name = "${local.ssm_prefix}/deploy/distribution-id"
type = "String"
value = aws_cloudfront_distribution.form.id
description = "CloudFront distribution ID; cache-invalidation target for the publish_menu job"
}
resource "aws_ssm_parameter" "deploy_form_url" {
name = "${local.ssm_prefix}/deploy/form-url"
type = "String"
value = local.form_url
description = "Public order form URL; linked from the publish_menu Slack post"
}