mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 04:13:12 +00:00
* feat(api): serve meals on ECS Fargate instead of Lambda Keep the Flask app always-on with in-process jobs so CloudFront no longer fronts a cold-start API Gateway. * fix(jobs): run delayed close and reminder deliveries Wall-clock skip windows dropped the only weekly SQS attempt when Scheduler already fired in Eastern time. Dev schedules stay disabled. * fix(api): return JSON objects and stop logging job payloads Flask now jsonify-s handler dicts so API responses are not HTML, and the worker logs only event and status. * fix(ci): restore the reusable workflow so the required check is named ci / ci Inlining the job reported `ci` instead of the org ruleset's `ci / ci`. * fix(secrets): drop unused os import so ruff check passes * style: apply ruff format so ci-python-app lint passes * fix(infra): give meals its own VPC because prod has none * chore(security): re-key ALB SG checkov suppression after vpc.tf
107 lines
3.9 KiB
HCL
107 lines
3.9 KiB
HCL
# Parameter Store entries.
|
|
#
|
|
# /meal-order-manager/google-client-id is deliberately NOT declared here. It is
|
|
# created and rotated out-of-band because it varies per environment; data.tf
|
|
# reads it. Do not turn that lookup into a resource.
|
|
|
|
resource "aws_ssm_parameter" "slack_channel_id" {
|
|
name = local.slack_channel_param
|
|
type = "String"
|
|
value = var.slack_channel_id
|
|
description = "Slack channel ID for meal order notifications"
|
|
}
|
|
|
|
resource "aws_ssm_parameter" "portal_cognito_issuer" {
|
|
name = local.portal_cognito_issuer_param
|
|
type = "String"
|
|
value = var.portal_cognito_issuer
|
|
description = "Trusted portal Cognito user-pool issuer for ID-token verification"
|
|
}
|
|
|
|
resource "aws_ssm_parameter" "portal_cognito_audience" {
|
|
name = local.portal_cognito_audience_param
|
|
type = "String"
|
|
value = var.portal_cognito_audience
|
|
description = "Trusted portal Cognito app client ID for ID-token verification"
|
|
}
|
|
|
|
resource "aws_ssm_parameter" "portal_cognito_trust" {
|
|
name = local.portal_cognito_trust_param
|
|
type = "String"
|
|
value = jsonencode(concat(
|
|
[{ issuer = var.portal_cognito_issuer, audience = var.portal_cognito_audience }],
|
|
var.portal_cognito_extra_trust,
|
|
))
|
|
description = "Trusted portal Cognito issuer/audience pairs for ID-token verification"
|
|
}
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Deploy-time lookups
|
|
# ---------------------------------------------------------------------------
|
|
#
|
|
# These replace the CloudFormation stack outputs that
|
|
# .github/workflows/weekly-menu.yml used to read, so the job can resolve its
|
|
# deploy targets without a CloudFormation stack.
|
|
|
|
resource "aws_ssm_parameter" "deploy_api_url" {
|
|
name = "${local.ssm_prefix}/deploy/api-url"
|
|
type = "String"
|
|
value = "http://${aws_lb.api.dns_name}"
|
|
description = "ALB URL for weekly-menu HMAC publish (not on CloudFront)"
|
|
}
|
|
|
|
resource "aws_ssm_parameter" "deploy_cluster" {
|
|
name = "${local.ssm_prefix}/deploy/cluster"
|
|
type = "String"
|
|
value = aws_ecs_cluster.api.name
|
|
description = "ECS cluster name for deploy-api.yaml"
|
|
}
|
|
|
|
resource "aws_ssm_parameter" "deploy_service" {
|
|
name = "${local.ssm_prefix}/deploy/service"
|
|
type = "String"
|
|
value = aws_ecs_service.api.name
|
|
description = "ECS service name for deploy-api.yaml"
|
|
}
|
|
|
|
resource "aws_ssm_parameter" "deploy_task_family" {
|
|
name = "${local.ssm_prefix}/deploy/task-family"
|
|
type = "String"
|
|
value = aws_ecs_task_definition.api.family
|
|
description = "ECS task definition family for deploy-api.yaml"
|
|
}
|
|
|
|
resource "aws_ssm_parameter" "deploy_ecr_repository" {
|
|
name = "${local.ssm_prefix}/deploy/ecr-repository"
|
|
type = "String"
|
|
value = aws_ecr_repository.api.repository_url
|
|
description = "ECR repository URL for deploy-api.yaml"
|
|
}
|
|
|
|
resource "aws_ssm_parameter" "deploy_container_name" {
|
|
name = "${local.ssm_prefix}/deploy/container-name"
|
|
type = "String"
|
|
value = local.api_container_name
|
|
description = "Container name in the ECS task definition"
|
|
}
|
|
|
|
resource "aws_ssm_parameter" "deploy_form_bucket" {
|
|
name = "${local.ssm_prefix}/deploy/form-bucket"
|
|
type = "String"
|
|
value = aws_s3_bucket.form.id
|
|
description = "S3 bucket holding the order form; sync target for the weekly-menu deploy job"
|
|
}
|
|
|
|
resource "aws_ssm_parameter" "deploy_distribution_id" {
|
|
name = "${local.ssm_prefix}/deploy/distribution-id"
|
|
type = "String"
|
|
value = aws_cloudfront_distribution.form.id
|
|
description = "CloudFront distribution ID; cache-invalidation target for the weekly-menu deploy job"
|
|
}
|
|
|
|
resource "aws_ssm_parameter" "deploy_form_url" {
|
|
name = "${local.ssm_prefix}/deploy/form-url"
|
|
type = "String"
|
|
value = local.form_url
|
|
description = "Public order form URL; reported by the weekly-menu deploy job"
|
|
}
|