meal-order-manager/terraform/terraform.tfvars.example
Adam Moussa 44c79fdefd
feat(infra): add lightweight meal-order-manager-dev (PLAT-210) (#195)
* feat(infra): add lightweight meal-order-manager-dev (PLAT-210)

Parameterize the HCP root for seahaven-dev with schedules, PITR, alarms, and Paychex gated off so a second env does not clone production cost or side effects.

* fix(infra): drop prod-only authorizer import so dev can create it (PLAT-210)

The PLAT-102 import is already in meal-order-manager-prod state. A shared import block fails in seahaven-dev because the permission does not exist there.

* fix(iam): allow creating the weekly-menu githubdeploy role in seahaven-dev (PLAT-210)

Prod imported that role. A new account needs CreateRole on tf-managed/githubdeploy-meal-order-manager-weekly-menu.
2026-09-18 18:38:45 +00:00

41 lines
1.8 KiB
Text

# Workspace variable reference for meal-order-manager HCP workspaces.
# Set these as workspace variables; this file is a reference, not an input.
# HCP workspace stage. Selects account 011934824531 (prod) or 710827005802 (dev).
# Required. meal-order-manager-prod must set "prod" in the same cut as this
# variable is added so a prod plan does not target seahaven-dev.
environment = "prod"
# Region every resource is created in.
aws_region = "us-east-1"
# Custom domain for the order form. An ISSUED ACM certificate for this domain
# must already exist in us-east-1 (see acm.tf). Keep false in dev.
domain_name = "orders.seahaven.com"
attach_custom_domain = false
# ARN of the out-of-band Secrets Manager secret holding the Slack bot token.
# Only the ARN is used; the value never enters Terraform state.
slack_bot_secret_arn = "arn:aws:secretsmanager:us-east-1:011934824531:secret:meal-order-manager/slack-bot-token-XXXXXX"
# Slack channel that receives meal order notifications. Written to
# /meal-order-manager/slack-channel-id. Use a sandbox channel in dev.
slack_channel_id = "C00000000000"
# Portal Cognito pools and public app clients accepted by the meals API.
# The primary pair is required. extra_trust lists additional pools so
# portal-dev and portal-prod tokens can both call this meals stack.
portal_cognito_issuer = "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_EXAMPLE"
portal_cognito_audience = "examplepublicappclientid"
portal_cognito_extra_trust = [
{
issuer = "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_EXAMPLEPROD"
audience = "exampleprodappclientid"
},
]
# paychex-checkcomponents SQS. Defaults in variables.tf are the prod queue.
# meal-order-manager-dev must set both to empty so aggregate-orders cannot
# SendMessage to prod Paychex.
# checkcomponents_queue_url = ""
# checkcomponents_queue_arn = ""