meal-order-manager/terraform/terraform.tfvars.example
Adam Moussa 12f1eb881f
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
fix(auth): accept federated portal Cognito tokens for meals admin (DEV-283) (#194)
* fix(auth): accept federated portal Cognito tokens for meals admin

Google Workspace federation stores email_verified=false, which 403'd the
portal Admin probe while the public menu still loaded.

* fix(iam): grant plan role CloudFront DescribeFunction
2026-09-18 15:31:17 +00:00

30 lines
1.3 KiB
Text

# Values for the meal-order-manager-prod HCP Terraform workspace.
# Set these as workspace variables; this file is a reference, not an input.
# Region every resource is created in.
aws_region = "us-east-1"
# Custom domain for the order form. An ISSUED ACM certificate for this domain
# must already exist in us-east-1 (see acm.tf). Attach only at DNS cutover.
domain_name = "orders.seahaven.com"
attach_custom_domain = false
# ARN of the out-of-band Secrets Manager secret holding the Slack bot token.
# Only the ARN is used; the value never enters Terraform state.
slack_bot_secret_arn = "arn:aws:secretsmanager:us-east-1:011934824531:secret:meal-order-manager/slack-bot-token-XXXXXX"
# Slack channel that receives meal order notifications. Written to
# /meal-order-manager/slack-channel-id.
slack_channel_id = "C00000000000"
# Portal Cognito pools and public app clients accepted by the meals API.
# The primary pair is required. extra_trust lists additional pools so
# portal-dev and portal-prod tokens can both call this prod meals stack.
portal_cognito_issuer = "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_EXAMPLE"
portal_cognito_audience = "examplepublicappclientid"
portal_cognito_extra_trust = [
{
issuer = "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_EXAMPLEPROD"
audience = "exampleprodappclientid"
},
]