mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 15:53:13 +00:00
* feat(infra): add lightweight meal-order-manager-dev (PLAT-210) Parameterize the HCP root for seahaven-dev with schedules, PITR, alarms, and Paychex gated off so a second env does not clone production cost or side effects. * fix(infra): drop prod-only authorizer import so dev can create it (PLAT-210) The PLAT-102 import is already in meal-order-manager-prod state. A shared import block fails in seahaven-dev because the permission does not exist there. * fix(iam): allow creating the weekly-menu githubdeploy role in seahaven-dev (PLAT-210) Prod imported that role. A new account needs CreateRole on tf-managed/githubdeploy-meal-order-manager-weekly-menu.
41 lines
1.8 KiB
Text
41 lines
1.8 KiB
Text
# Workspace variable reference for meal-order-manager HCP workspaces.
|
|
# Set these as workspace variables; this file is a reference, not an input.
|
|
|
|
# HCP workspace stage. Selects account 011934824531 (prod) or 710827005802 (dev).
|
|
# Required. meal-order-manager-prod must set "prod" in the same cut as this
|
|
# variable is added so a prod plan does not target seahaven-dev.
|
|
environment = "prod"
|
|
|
|
# Region every resource is created in.
|
|
aws_region = "us-east-1"
|
|
|
|
# Custom domain for the order form. An ISSUED ACM certificate for this domain
|
|
# must already exist in us-east-1 (see acm.tf). Keep false in dev.
|
|
domain_name = "orders.seahaven.com"
|
|
attach_custom_domain = false
|
|
|
|
# ARN of the out-of-band Secrets Manager secret holding the Slack bot token.
|
|
# Only the ARN is used; the value never enters Terraform state.
|
|
slack_bot_secret_arn = "arn:aws:secretsmanager:us-east-1:011934824531:secret:meal-order-manager/slack-bot-token-XXXXXX"
|
|
|
|
# Slack channel that receives meal order notifications. Written to
|
|
# /meal-order-manager/slack-channel-id. Use a sandbox channel in dev.
|
|
slack_channel_id = "C00000000000"
|
|
|
|
# Portal Cognito pools and public app clients accepted by the meals API.
|
|
# The primary pair is required. extra_trust lists additional pools so
|
|
# portal-dev and portal-prod tokens can both call this meals stack.
|
|
portal_cognito_issuer = "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_EXAMPLE"
|
|
portal_cognito_audience = "examplepublicappclientid"
|
|
portal_cognito_extra_trust = [
|
|
{
|
|
issuer = "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_EXAMPLEPROD"
|
|
audience = "exampleprodappclientid"
|
|
},
|
|
]
|
|
|
|
# paychex-checkcomponents SQS. Defaults in variables.tf are the prod queue.
|
|
# meal-order-manager-dev must set both to empty so aggregate-orders cannot
|
|
# SendMessage to prod Paychex.
|
|
# checkcomponents_queue_url = ""
|
|
# checkcomponents_queue_arn = ""
|