mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 03:03:12 +00:00
Freeze SAM CD and add greenfield Terraform for seahaven-prod so HCP is the sole stack deploy path.
32 lines
1.3 KiB
HCL
32 lines
1.3 KiB
HCL
data "aws_caller_identity" "current" {}
|
|
|
|
# Resource names in locals.tf embed the account ID. If the workspace is ever
|
|
# pointed at another account, fail the plan here rather than creating a parallel
|
|
# set of oddly-named resources somewhere else.
|
|
check "correct_account" {
|
|
assert {
|
|
condition = data.aws_caller_identity.current.account_id == local.account_id
|
|
error_message = "This configuration targets account ${local.account_id}, but the credentials resolve to ${data.aws_caller_identity.current.account_id}."
|
|
}
|
|
}
|
|
|
|
# Alarm sink owned by seahaven-org-baseline, not by this configuration.
|
|
data "aws_sns_topic" "site_alerts" {
|
|
name = "site-alerts"
|
|
}
|
|
|
|
# Shared CloudFront WAF WebACL (audit M-17), published to Parameter Store by the
|
|
# org baseline. aws_cloudfront_distribution.web_acl_id takes the WAFv2 ARN
|
|
# despite the attribute name.
|
|
data "aws_ssm_parameter" "app_web_acl_arn" {
|
|
name = "/seahaven/waf/app-web-acl-arn"
|
|
}
|
|
|
|
# Google OAuth client ID used by submit-order and the admin authorizer. The
|
|
# parameter is created and rotated out-of-band because it varies per
|
|
# environment; this lookup only asserts that it exists before an apply wires
|
|
# functions that read it at runtime. Its NAME, not its value, is what reaches
|
|
# the functions.
|
|
data "aws_ssm_parameter" "google_client_id" {
|
|
name = local.google_client_id_param
|
|
}
|