meal-order-manager/terraform/outputs.tf
Adam Moussa d7ad49d00f
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
feat(api): add OpenAPI Redocly contract and VPC outputs (DEV-289) (#206)
* feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289)

Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs
expose the resolved vpc_id and public subnet IDs.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289)

Same extends: recommended ruleset and @redocly/cli 2.52.1 as
internal-portal. Documents current { error: string } JSON errors.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(api): document 4xx and reject invalid form-status weeks (DEV-289)

Health, form-status, and roster document 400. form-status now maps
current and returns 400 for a week that is not current or YYYY-WNN.
Redocly treats 302 as a success response, matching the portal.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* style(test): format VPC contract assertions for ruff (DEV-289)

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289)

Promote operation-4xx-response and the 2xx-or-3xx success rule to error.
Replace unused health and roster 400s with 403, matching portal health.
Form-status keeps its real 400 for invalid week.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(api): split week params and allow live menu nulls (DEV-289)

Menu and form-status take current or YYYY-WNN. Orders take YYYY-WNN or a
calendar date and reject current. Menu payloads may emit null menu_url,
calories, protein, and image_url.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(infra): fail prod apply without the afterhours VPC (DEV-289)

Prod never creates the 10.60 fallback VPC. A terraform_data precondition
fails plan and apply when existing_vpc_id is empty, instead of a check
block that only warns.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:33:48 +00:00

69 lines
2 KiB
HCL

output "api_url" {
description = "Public meals API origin (CloudFront)."
value = local.form_url
}
output "publish_api_url" {
description = "ALB URL for weekly-menu HMAC publish."
value = "http://${aws_lb.api.dns_name}"
}
output "form_url" {
description = "Public order form URL."
value = local.form_url
}
output "distribution_id" {
description = "CloudFront distribution ID, for cache invalidation."
value = aws_cloudfront_distribution.form.id
}
output "distribution_domain_name" {
description = "CloudFront distribution domain name, the DNS target for the custom domain."
value = aws_cloudfront_distribution.form.domain_name
}
output "form_bucket_name" {
description = "S3 bucket holding the order form HTML."
value = aws_s3_bucket.form.id
}
output "reports_bucket_name" {
description = "S3 bucket holding payroll CSVs and weekly summary PDFs."
value = aws_s3_bucket.reports.id
}
output "ecr_repository_url" {
description = "ECR repository for the API image."
value = aws_ecr_repository.api.repository_url
}
output "orders_table_name" {
description = "DynamoDB orders table."
value = aws_dynamodb_table.orders.name
}
output "weekly_menu_role_arn" {
description = "OIDC role ARN for .github/workflows/weekly-menu.yml (repo secret AWS_WEEKLY_MENU_ROLE_ARN)."
value = aws_iam_role.weekly_menu.arn
}
output "github_deploy_role_arn" {
description = "OIDC role ARN for .github/workflows/deploy-api.yaml (Environment DEPLOY_ROLE_ARN)."
value = aws_iam_role.github_deploy.arn
}
output "ecs_task_role_arn" {
description = "ECS task role; paychex-checkcomponents queue policy must allow this ARN."
value = aws_iam_role.ecs_task.arn
}
output "vpc_id" {
description = "VPC the ALB and Fargate tasks run in. Prod attaches to afterhours."
value = local.vpc_id
}
output "public_subnet_ids" {
description = "Public subnet IDs for the ALB and Fargate tasks."
value = local.public_subnet_ids
}