meal-order-manager/terraform/ssm.tf
Adam Moussa 265d12b890
feat(menu): publish the weekly menu from the job worker
Monday publish parses the catalog embedded in the Redefine menu page and runs on the Fargate worker, so the GitHub Actions scrape cron can go away.
2026-09-25 17:43:34 -04:00

117 lines
4.1 KiB
HCL

# Parameter Store entries.
#
# /meal-order-manager/google-client-id is deliberately NOT declared here. It is
# created and rotated out-of-band because it varies per environment; data.tf
# reads it. Do not turn that lookup into a resource.
resource "aws_ssm_parameter" "sentry_dsn" {
name = "${local.ssm_prefix}/sentry-dsn"
type = "SecureString"
value = "unset"
description = "Sentry DSN for meal-order-manager. PutParameter writes the live value; Terraform ignores it. Empty or unset disables the SDK."
lifecycle {
ignore_changes = [value]
}
}
resource "aws_ssm_parameter" "slack_channel_id" {
name = local.slack_channel_param
type = "String"
value = var.slack_channel_id
description = "Slack channel ID for meal order notifications"
}
resource "aws_ssm_parameter" "portal_cognito_issuer" {
name = local.portal_cognito_issuer_param
type = "String"
value = var.portal_cognito_issuer
description = "Trusted portal Cognito user-pool issuer for ID-token verification"
}
resource "aws_ssm_parameter" "portal_cognito_audience" {
name = local.portal_cognito_audience_param
type = "String"
value = var.portal_cognito_audience
description = "Trusted portal Cognito app client ID for ID-token verification"
}
resource "aws_ssm_parameter" "portal_cognito_trust" {
name = local.portal_cognito_trust_param
type = "String"
value = jsonencode(concat(
[{ issuer = var.portal_cognito_issuer, audience = var.portal_cognito_audience }],
var.portal_cognito_extra_trust,
))
description = "Trusted portal Cognito issuer/audience pairs for ID-token verification"
}
# ---------------------------------------------------------------------------
# Deploy-time lookups
# ---------------------------------------------------------------------------
#
# Deploy targets for the image workflow and the publish_menu job.
# There is no CloudFormation stack.
resource "aws_ssm_parameter" "deploy_api_url" {
name = "${local.ssm_prefix}/deploy/api-url"
type = "String"
value = "http://${aws_lb.api.dns_name}"
description = "ALB URL for weekly-menu HMAC publish (not on CloudFront)"
}
resource "aws_ssm_parameter" "deploy_cluster" {
name = "${local.ssm_prefix}/deploy/cluster"
type = "String"
value = aws_ecs_cluster.api.name
description = "ECS cluster name for deploy-api.yaml"
}
resource "aws_ssm_parameter" "deploy_service" {
name = "${local.ssm_prefix}/deploy/service"
type = "String"
value = aws_ecs_service.api.name
description = "ECS service name for deploy-api.yaml"
}
resource "aws_ssm_parameter" "deploy_task_family" {
name = "${local.ssm_prefix}/deploy/task-family"
type = "String"
value = aws_ecs_task_definition.api.family
description = "ECS task definition family for deploy-api.yaml"
}
resource "aws_ssm_parameter" "deploy_ecr_repository" {
name = "${local.ssm_prefix}/deploy/ecr-repository"
type = "String"
value = aws_ecr_repository.api.repository_url
description = "ECR repository URL for deploy-api.yaml"
}
resource "aws_ssm_parameter" "deploy_container_name" {
name = "${local.ssm_prefix}/deploy/container-name"
type = "String"
value = local.api_container_name
description = "Container name in the ECS task definition"
}
resource "aws_ssm_parameter" "deploy_form_bucket" {
name = "${local.ssm_prefix}/deploy/form-bucket"
type = "String"
value = aws_s3_bucket.form.id
description = "S3 bucket holding the order form; upload target for the publish_menu job"
}
resource "aws_ssm_parameter" "deploy_distribution_id" {
name = "${local.ssm_prefix}/deploy/distribution-id"
type = "String"
value = aws_cloudfront_distribution.form.id
description = "CloudFront distribution ID; cache-invalidation target for the publish_menu job"
}
resource "aws_ssm_parameter" "deploy_form_url" {
name = "${local.ssm_prefix}/deploy/form-url"
type = "String"
value = local.form_url
description = "Public order form URL; linked from the publish_menu Slack post"
}