mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 06:33:12 +00:00
* fix(infra): share the afterhours VPC when existing_vpc_id is set Prod is at the account VPC quota, so the v1.0.0 apply destroyed Lambda/API Gateway then failed on CreateVpc. Skip creating a sixth VPC when the workspace supplies afterhours subnets. * style(test): format the VPC terraform assertion for ruff
93 lines
3.4 KiB
HCL
93 lines
3.4 KiB
HCL
data "aws_caller_identity" "current" {}
|
|
|
|
# Resource names in locals.tf embed the account ID. If the workspace is ever
|
|
# pointed at another account, fail the plan here rather than creating a parallel
|
|
# set of oddly-named resources somewhere else.
|
|
check "correct_account" {
|
|
assert {
|
|
condition = data.aws_caller_identity.current.account_id == local.account_id
|
|
error_message = "This configuration targets account ${local.account_id} (${var.environment}), but the credentials resolve to ${data.aws_caller_identity.current.account_id}."
|
|
}
|
|
}
|
|
|
|
# Alarm sink owned by seahaven-org-baseline, not by this configuration.
|
|
# Looked up only in prod because CloudWatch alarms are skipped in dev.
|
|
data "aws_sns_topic" "site_alerts" {
|
|
count = local.is_prod ? 1 : 0
|
|
name = "site-alerts"
|
|
}
|
|
|
|
moved {
|
|
from = data.aws_sns_topic.site_alerts
|
|
to = data.aws_sns_topic.site_alerts[0]
|
|
}
|
|
|
|
# Shared CloudFront WAF WebACL (audit M-17), published to Parameter Store by the
|
|
# org baseline. aws_cloudfront_distribution.web_acl_id takes the WAFv2 ARN
|
|
# despite the attribute name.
|
|
data "aws_ssm_parameter" "app_web_acl_arn" {
|
|
name = "/seahaven/waf/app-web-acl-arn"
|
|
}
|
|
|
|
# Google OAuth client ID used by submit-order and the admin authorizer. The
|
|
# parameter is created and rotated out-of-band because it varies per
|
|
# environment; this lookup only asserts that it exists before an apply wires
|
|
# functions that read it at runtime. Its NAME, not its value, is what reaches
|
|
# the ECS task.
|
|
data "aws_ssm_parameter" "google_client_id" {
|
|
name = local.google_client_id_param
|
|
}
|
|
|
|
# Fail closed if the OOB Google client ID parameter is missing or empty. The
|
|
# functions receive the parameter NAME via env; this check forces the data
|
|
# source to be evaluated so apply cannot succeed without the parameter.
|
|
check "google_client_id_present" {
|
|
assert {
|
|
condition = length(data.aws_ssm_parameter.google_client_id.value) > 0
|
|
error_message = "SSM parameter ${local.google_client_id_param} is missing or empty; create it out of band before apply."
|
|
}
|
|
}
|
|
|
|
check "dev_has_no_paychex" {
|
|
assert {
|
|
condition = local.is_prod || var.checkcomponents_queue_url == ""
|
|
error_message = "checkcomponents_queue_url must be empty in non-prod so aggregate-orders cannot send to the prod Paychex queue."
|
|
}
|
|
}
|
|
|
|
check "checkcomponents_pair" {
|
|
assert {
|
|
condition = (var.checkcomponents_queue_url == "") == (var.checkcomponents_queue_arn == "")
|
|
error_message = "checkcomponents_queue_url and checkcomponents_queue_arn must both be set or both be empty."
|
|
}
|
|
}
|
|
|
|
check "dev_has_no_custom_domain" {
|
|
assert {
|
|
condition = local.is_prod || !var.attach_custom_domain
|
|
error_message = "attach_custom_domain must be false in non-prod; use the CloudFront distribution domain."
|
|
}
|
|
}
|
|
|
|
check "existing_vpc_pair" {
|
|
assert {
|
|
condition = (var.existing_vpc_id == "") == (length(var.existing_public_subnet_ids) == 0)
|
|
error_message = "existing_vpc_id and existing_public_subnet_ids must both be set or both be empty."
|
|
}
|
|
}
|
|
|
|
check "existing_vpc_two_az" {
|
|
assert {
|
|
condition = var.existing_vpc_id == "" || length(var.existing_public_subnet_ids) >= 2
|
|
error_message = "existing_public_subnet_ids must include at least two subnets."
|
|
}
|
|
}
|
|
|
|
check "existing_subnets_in_vpc" {
|
|
assert {
|
|
condition = alltrue([
|
|
for subnet in data.aws_subnet.existing_public : subnet.vpc_id == var.existing_vpc_id
|
|
])
|
|
error_message = "Every existing_public_subnet_ids value must belong to existing_vpc_id."
|
|
}
|
|
}
|