mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 15:53:13 +00:00
* feat(api): serve meals on ECS Fargate instead of Lambda Keep the Flask app always-on with in-process jobs so CloudFront no longer fronts a cold-start API Gateway. * fix(jobs): run delayed close and reminder deliveries Wall-clock skip windows dropped the only weekly SQS attempt when Scheduler already fired in Eastern time. Dev schedules stay disabled. * fix(api): return JSON objects and stop logging job payloads Flask now jsonify-s handler dicts so API responses are not HTML, and the worker logs only event and status. * fix(ci): restore the reusable workflow so the required check is named ci / ci Inlining the job reported `ci` instead of the org ruleset's `ci / ci`. * fix(secrets): drop unused os import so ruff check passes * style: apply ruff format so ci-python-app lint passes * fix(infra): give meals its own VPC because prod has none * chore(security): re-key ALB SG checkov suppression after vpc.tf
113 lines
4.3 KiB
HCL
113 lines
4.3 KiB
HCL
locals {
|
|
project = "meal-order-manager"
|
|
is_prod = var.environment == "prod"
|
|
account_id = local.is_prod ? "011934824531" : "710827005802"
|
|
hcp_project = "seahaven-${var.environment}"
|
|
hcp_workspace = "${local.project}-${var.environment}"
|
|
|
|
github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com"
|
|
|
|
# Prod has no default VPC. 10.60 is unused in 011934824531
|
|
# (10.0 proposal-system, 10.20 payments-dashboard, 10.40 syslog, 10.80 apm-wo).
|
|
vpc_cidr = "10.60.0.0/16"
|
|
public_subnet_cidrs = ["10.60.0.0/24", "10.60.1.0/24"]
|
|
|
|
form_bucket_name = "${local.project}-form-${local.account_id}"
|
|
reports_bucket_name = "${local.project}-reports-${local.account_id}"
|
|
|
|
table_name = "${local.project}-orders"
|
|
# Pre-DNS: use the CloudFront domain. After cutover (attach_custom_domain),
|
|
# use the public custom domain.
|
|
form_url = var.attach_custom_domain ? "https://${var.domain_name}" : "https://${aws_cloudfront_distribution.form.domain_name}"
|
|
|
|
ssm_prefix = "/${local.project}"
|
|
slack_channel_param = "${local.ssm_prefix}/slack-channel-id"
|
|
|
|
# google-client-id is created and rotated out-of-band. Terraform reads it
|
|
# (data.tf) but never owns it.
|
|
google_client_id_param = "${local.ssm_prefix}/google-client-id"
|
|
|
|
portal_cognito_issuer_param = "${local.ssm_prefix}/portal-cognito-issuer"
|
|
portal_cognito_audience_param = "${local.ssm_prefix}/portal-cognito-audience"
|
|
portal_cognito_trust_param = "${local.ssm_prefix}/portal-cognito-trust"
|
|
|
|
# shared/slack.py resolves the token by NAME, while the IAM grant is scoped to
|
|
# the ARN in var.slack_bot_secret_arn. Both must refer to the same secret.
|
|
slack_bot_secret_name = "${local.project}/slack-bot-token"
|
|
|
|
ssm_parameter_arn_wildcard = "arn:aws:ssm:${var.aws_region}:${local.account_id}:parameter${local.ssm_prefix}/*"
|
|
|
|
cors_origins = [
|
|
"https://orders.seahaven.com",
|
|
"https://internal.seahaven.com",
|
|
"https://internal.dev.seahaven.com",
|
|
"http://localhost:5173",
|
|
"http://localhost:4173",
|
|
]
|
|
|
|
# AWS managed CachingDisabled / AllViewerExceptHostHeader. Authenticated
|
|
# portal calls must not be cached. ALB origin uses Host of the load balancer
|
|
# DNS name (http-only).
|
|
api_cache_policy_id = "4135ea2d-6df8-44a3-9df3-4b5a84be39ad"
|
|
api_origin_request_policy_id = "b689b0a8-53d0-40ab-baf2-68738e2966ac"
|
|
cloudfront_all_methods = ["DELETE", "GET", "HEAD", "OPTIONS", "PATCH", "POST", "PUT"]
|
|
|
|
# HTTP routes served by the Fargate Flask app. authorizer is in-process now.
|
|
api_routes = {
|
|
submit_order = {
|
|
route_key = "POST /api/submit-order"
|
|
authorizer = "NONE"
|
|
permission_source = "POST/api/submit-order"
|
|
}
|
|
menu = {
|
|
route_key = "GET /api/menu/{week}"
|
|
authorizer = "NONE"
|
|
permission_source = "GET/api/menu/*"
|
|
}
|
|
my_orders = {
|
|
route_key = "GET /api/orders/{week}"
|
|
authorizer = "NONE"
|
|
permission_source = "GET/api/orders/*"
|
|
}
|
|
form_status = {
|
|
route_key = "GET /api/form-status/{week}"
|
|
authorizer = "NONE"
|
|
permission_source = "GET/api/form-status/*"
|
|
}
|
|
roster = {
|
|
route_key = "GET /api/roster"
|
|
authorizer = "NONE"
|
|
permission_source = "GET/api/roster"
|
|
}
|
|
publish_settings = {
|
|
route_key = "GET /api/publish/settings"
|
|
authorizer = "HMAC"
|
|
permission_source = "GET/api/publish/settings"
|
|
}
|
|
publish_menu = {
|
|
route_key = "POST /api/publish/menu"
|
|
authorizer = "HMAC"
|
|
permission_source = "POST/api/publish/menu"
|
|
}
|
|
admin_orders_get = {
|
|
route_key = "GET /api/admin/orders"
|
|
authorizer = "BEARER"
|
|
permission_source = "GET/api/admin/orders"
|
|
}
|
|
admin_orders_put = {
|
|
route_key = "PUT /api/admin/orders"
|
|
authorizer = "BEARER"
|
|
permission_source = "PUT/api/admin/orders"
|
|
}
|
|
admin_orders_delete = {
|
|
route_key = "DELETE /api/admin/orders"
|
|
authorizer = "BEARER"
|
|
permission_source = "DELETE/api/admin/orders"
|
|
}
|
|
admin_summary_pdf = {
|
|
route_key = "GET /api/admin/summary-pdf"
|
|
authorizer = "BEARER"
|
|
permission_source = "GET/api/admin/summary-pdf"
|
|
}
|
|
}
|
|
}
|