mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 20:33:13 +00:00
* feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289)
Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs
expose the resolved vpc_id and public subnet IDs.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289)
Same extends: recommended ruleset and @redocly/cli 2.52.1 as
internal-portal. Documents current { error: string } JSON errors.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* fix(api): document 4xx and reject invalid form-status weeks (DEV-289)
Health, form-status, and roster document 400. form-status now maps
current and returns 400 for a week that is not current or YYYY-WNN.
Redocly treats 302 as a success response, matching the portal.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* style(test): format VPC contract assertions for ruff (DEV-289)
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289)
Promote operation-4xx-response and the 2xx-or-3xx success rule to error.
Replace unused health and roster 400s with 403, matching portal health.
Form-status keeps its real 400 for invalid week.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* fix(api): split week params and allow live menu nulls (DEV-289)
Menu and form-status take current or YYYY-WNN. Orders take YYYY-WNN or a
calendar date and reject current. Menu payloads may emit null menu_url,
calories, protein, and image_url.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* fix(infra): fail prod apply without the afterhours VPC (DEV-289)
Prod never creates the 10.60 fallback VPC. A terraform_data precondition
fails plan and apply when existing_vpc_id is empty, instead of a check
block that only warns.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
105 lines
3.8 KiB
HCL
105 lines
3.8 KiB
HCL
variable "aws_region" {
|
|
description = "Region every resource in this configuration is created in."
|
|
type = string
|
|
default = "us-east-1"
|
|
}
|
|
|
|
variable "environment" {
|
|
description = "HCP workspace stage. Selects account and workspace name."
|
|
type = string
|
|
|
|
validation {
|
|
condition = contains(["dev", "prod"], var.environment)
|
|
error_message = "environment must be \"dev\" or \"prod\"."
|
|
}
|
|
}
|
|
|
|
variable "domain_name" {
|
|
description = "Custom domain served by the CloudFront distribution when attach_custom_domain is true. An ISSUED ACM certificate for this domain must already exist in us-east-1 (see acm.tf)."
|
|
type = string
|
|
default = "orders.seahaven.com"
|
|
}
|
|
|
|
variable "attach_custom_domain" {
|
|
description = "When true, attach domain_name as a CloudFront alias with the ACM viewer certificate. Keep false until DNS cutover so the prod distribution can exist while orders.seahaven.com still points at mgmt."
|
|
type = bool
|
|
default = false
|
|
}
|
|
|
|
variable "slack_bot_secret_arn" {
|
|
description = "ARN of the Secrets Manager secret holding the Slack bot token. The secret and its value are managed out-of-band; only the ARN enters this configuration."
|
|
type = string
|
|
|
|
validation {
|
|
condition = can(regex("^arn:aws:secretsmanager:", var.slack_bot_secret_arn))
|
|
error_message = "slack_bot_secret_arn must be a Secrets Manager ARN."
|
|
}
|
|
}
|
|
|
|
variable "slack_channel_id" {
|
|
description = "Slack channel ID for meal order notifications. Written to /meal-order-manager/slack-channel-id."
|
|
type = string
|
|
}
|
|
|
|
variable "portal_cognito_issuer" {
|
|
description = "Exact issuer URL for the portal Cognito user pool whose ID tokens meal-order-manager accepts."
|
|
type = string
|
|
|
|
validation {
|
|
condition = can(regex("^https://cognito-idp\\.[a-z0-9-]+\\.amazonaws\\.com/[A-Za-z0-9_-]+$", var.portal_cognito_issuer))
|
|
error_message = "portal_cognito_issuer must be an exact Cognito user-pool issuer URL without a trailing slash."
|
|
}
|
|
}
|
|
|
|
variable "portal_cognito_audience" {
|
|
description = "Portal Cognito app client ID required in accepted ID-token aud claims."
|
|
type = string
|
|
|
|
validation {
|
|
condition = length(trimspace(var.portal_cognito_audience)) > 0
|
|
error_message = "portal_cognito_audience must not be empty."
|
|
}
|
|
}
|
|
|
|
variable "portal_cognito_extra_trust" {
|
|
description = "Additional portal Cognito issuer/audience pairs trusted by the meals API. Use this so portal-dev and portal-prod tokens both work against the single prod meals stack."
|
|
type = list(object({
|
|
issuer = string
|
|
audience = string
|
|
}))
|
|
default = []
|
|
|
|
validation {
|
|
condition = alltrue([
|
|
for pair in var.portal_cognito_extra_trust : (
|
|
can(regex("^https://cognito-idp\\.[a-z0-9-]+\\.amazonaws\\.com/[A-Za-z0-9_-]+$", pair.issuer))
|
|
&& length(trimspace(pair.audience)) > 0
|
|
)
|
|
])
|
|
error_message = "Each extra trust entry must be a Cognito issuer URL without a trailing slash and a non-empty audience."
|
|
}
|
|
}
|
|
|
|
variable "checkcomponents_queue_url" {
|
|
description = "paychex-checkcomponents SQS URL. Empty skips the weekly SendMessage."
|
|
type = string
|
|
default = "https://sqs.us-east-1.amazonaws.com/011934824531/paychex-checkcomponents"
|
|
}
|
|
|
|
variable "checkcomponents_queue_arn" {
|
|
description = "paychex-checkcomponents SQS ARN for aggregate-orders SendMessage."
|
|
type = string
|
|
default = "arn:aws:sqs:us-east-1:011934824531:paychex-checkcomponents"
|
|
}
|
|
|
|
variable "existing_vpc_id" {
|
|
description = "When set, place the ALB and Fargate tasks in this VPC instead of creating one. Prod attaches to the afterhours VPC."
|
|
type = string
|
|
default = ""
|
|
}
|
|
|
|
variable "existing_public_subnet_ids" {
|
|
description = "Public subnet IDs in existing_vpc_id. Required with existing_vpc_id; ignored when that variable is empty."
|
|
type = list(string)
|
|
default = []
|
|
}
|