meal-order-manager/terraform/acm.tf
Adam Moussa 44c79fdefd
feat(infra): add lightweight meal-order-manager-dev (PLAT-210) (#195)
* feat(infra): add lightweight meal-order-manager-dev (PLAT-210)

Parameterize the HCP root for seahaven-dev with schedules, PITR, alarms, and Paychex gated off so a second env does not clone production cost or side effects.

* fix(infra): drop prod-only authorizer import so dev can create it (PLAT-210)

The PLAT-102 import is already in meal-order-manager-prod state. A shared import block fails in seahaven-dev because the permission does not exist there.

* fix(iam): allow creating the weekly-menu githubdeploy role in seahaven-dev (PLAT-210)

Prod imported that role. A new account needs CreateRole on tf-managed/githubdeploy-meal-order-manager-weekly-menu.
2026-09-18 18:38:45 +00:00

26 lines
1.1 KiB
HCL

# ACM certificate for the order form's custom domain.
#
# The certificate is an out-of-band bootstrap dependency and is deliberately NOT
# created here. It was requested in the prod account ahead of this configuration
# (arn:aws:acm:us-east-1:011934824531:certificate/4edac16c-0e19-4307-a34a-f6da257ccda3)
# and validated by DNS. Declaring an aws_acm_certificate resource as well would
# request a second certificate for the same domain on the first apply, so this
# configuration only reads the issued one.
#
# Bootstrap order, if the domain is ever rebuilt from nothing:
# 1. aws acm request-certificate --domain-name orders.seahaven.com \
# --validation-method DNS --region us-east-1
# 2. Publish the CNAME validation record and wait for status ISSUED.
# 3. Run terraform apply. Until step 2 completes, this data source finds no
# ISSUED certificate and the plan fails closed.
data "aws_acm_certificate" "orders" {
count = var.attach_custom_domain ? 1 : 0
domain = var.domain_name
statuses = ["ISSUED"]
most_recent = true
}
moved {
from = data.aws_acm_certificate.orders
to = data.aws_acm_certificate.orders[0]
}