payments-dashboard/terraform/data.tf
Adam Moussa 0e3e95c240
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79) (#109)
* feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79)

Replace the mgmt SAM stack with a prod-only HCP workspace using the afterhours stub-plus-zip-CD seam so GitHub Actions owns function code and Terraform owns infrastructure.

* fix(infra): pin secret and CMK ARNs for bootstrap-plan

hcptf-bootstrap-plan cannot ssm:GetParameter or DescribeSecret, so the first plan must not data-source those values.

* fix(infra): add EIP describe and DynamoDB CMK grants for first apply

Scoped apply missed ec2:DescribeAddressesAttribute and kms Encrypt/Decrypt/GenerateDataKey on the table CMK.
2026-09-16 18:29:01 +00:00

52 lines
1.1 KiB
HCL

resource "aws_dynamodb_table" "dashboard" {
name = local.table_name
billing_mode = "PAY_PER_REQUEST"
hash_key = "pk"
attribute {
name = "pk"
type = "S"
}
ttl {
attribute_name = "ttl"
enabled = true
}
server_side_encryption {
enabled = true
kms_key_arn = local.dynamodb_cmk_arn
}
}
resource "aws_sqs_queue" "process_csv_dlq" {
name = "payments-processPaymentCsv-async-dlq"
message_retention_seconds = 1209600
sqs_managed_sse_enabled = true
}
data "aws_iam_policy_document" "process_csv_dlq" {
statement {
sid = "AllowLambdaOnFailure"
effect = "Allow"
principals {
type = "Service"
identifiers = ["lambda.amazonaws.com"]
}
actions = ["sqs:SendMessage"]
resources = [aws_sqs_queue.process_csv_dlq.arn]
condition {
test = "ArnEquals"
variable = "aws:SourceArn"
values = [aws_lambda_function.this["process_csv"].arn]
}
}
}
resource "aws_sqs_queue_policy" "process_csv_dlq" {
queue_url = aws_sqs_queue.process_csv_dlq.id
policy = data.aws_iam_policy_document.process_csv_dlq.json
}