mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 06:33:12 +00:00
Prod never creates the 10.60 fallback VPC. A terraform_data precondition fails plan and apply when existing_vpc_id is empty, instead of a check block that only warns. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
128 lines
3 KiB
HCL
128 lines
3 KiB
HCL
data "aws_availability_zones" "available" {
|
|
count = local.manage_vpc ? 1 : 0
|
|
state = "available"
|
|
}
|
|
|
|
data "aws_vpc" "existing" {
|
|
count = var.existing_vpc_id == "" ? 0 : 1
|
|
id = var.existing_vpc_id
|
|
}
|
|
|
|
data "aws_subnet" "existing_public" {
|
|
for_each = toset(var.existing_public_subnet_ids)
|
|
id = each.value
|
|
}
|
|
|
|
resource "terraform_data" "prod_requires_afterhours_vpc" {
|
|
input = var.existing_vpc_id
|
|
|
|
lifecycle {
|
|
precondition {
|
|
condition = !local.is_prod || var.existing_vpc_id != ""
|
|
error_message = "Prod must set existing_vpc_id to the afterhours VPC. Do not mint 10.60."
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_vpc" "this" {
|
|
count = local.manage_vpc ? 1 : 0
|
|
|
|
cidr_block = local.vpc_cidr
|
|
enable_dns_support = true
|
|
enable_dns_hostnames = true
|
|
|
|
tags = {
|
|
Name = "${local.project}-vpc"
|
|
}
|
|
|
|
lifecycle {
|
|
precondition {
|
|
condition = !local.is_prod
|
|
error_message = "Prod must set existing_vpc_id to the afterhours VPC. Do not mint 10.60."
|
|
}
|
|
}
|
|
|
|
# First apply updates the live hcptf apply role before CreateVpc.
|
|
depends_on = [
|
|
aws_iam_role_policy_attachments_exclusive.hcptf_apply,
|
|
aws_iam_role_policy.hcptf_apply_ec2,
|
|
]
|
|
}
|
|
|
|
resource "aws_internet_gateway" "this" {
|
|
count = local.manage_vpc ? 1 : 0
|
|
|
|
vpc_id = aws_vpc.this[0].id
|
|
|
|
tags = {
|
|
Name = "${local.project}-igw"
|
|
}
|
|
}
|
|
|
|
resource "aws_subnet" "public" {
|
|
count = local.manage_vpc ? length(local.public_subnet_cidrs) : 0
|
|
|
|
vpc_id = aws_vpc.this[0].id
|
|
cidr_block = local.public_subnet_cidrs[count.index]
|
|
availability_zone = data.aws_availability_zones.available[0].names[count.index]
|
|
map_public_ip_on_launch = true
|
|
|
|
tags = {
|
|
Name = "${local.project}-public-${count.index}"
|
|
}
|
|
}
|
|
|
|
resource "aws_route_table" "public" {
|
|
count = local.manage_vpc ? 1 : 0
|
|
|
|
vpc_id = aws_vpc.this[0].id
|
|
|
|
tags = {
|
|
Name = "${local.project}-public"
|
|
}
|
|
}
|
|
|
|
resource "aws_route" "public_default" {
|
|
count = local.manage_vpc ? 1 : 0
|
|
|
|
route_table_id = aws_route_table.public[0].id
|
|
destination_cidr_block = "0.0.0.0/0"
|
|
gateway_id = aws_internet_gateway.this[0].id
|
|
}
|
|
|
|
resource "aws_route_table_association" "public" {
|
|
count = local.manage_vpc ? length(local.public_subnet_cidrs) : 0
|
|
|
|
subnet_id = aws_subnet.public[count.index].id
|
|
route_table_id = aws_route_table.public[0].id
|
|
}
|
|
|
|
locals {
|
|
vpc_id = local.manage_vpc ? aws_vpc.this[0].id : try(data.aws_vpc.existing[0].id, var.existing_vpc_id)
|
|
public_subnet_ids = local.manage_vpc ? aws_subnet.public[*].id : var.existing_public_subnet_ids
|
|
}
|
|
|
|
moved {
|
|
from = aws_vpc.this
|
|
to = aws_vpc.this[0]
|
|
}
|
|
|
|
moved {
|
|
from = aws_internet_gateway.this
|
|
to = aws_internet_gateway.this[0]
|
|
}
|
|
|
|
moved {
|
|
from = aws_route_table.public
|
|
to = aws_route_table.public[0]
|
|
}
|
|
|
|
moved {
|
|
from = aws_route.public_default
|
|
to = aws_route.public_default[0]
|
|
}
|
|
|
|
moved {
|
|
from = data.aws_availability_zones.available
|
|
to = data.aws_availability_zones.available[0]
|
|
}
|