payments-dashboard/terraform/outputs.tf
Adam Moussa 0e3e95c240
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79) (#109)
* feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79)

Replace the mgmt SAM stack with a prod-only HCP workspace using the afterhours stub-plus-zip-CD seam so GitHub Actions owns function code and Terraform owns infrastructure.

* fix(infra): pin secret and CMK ARNs for bootstrap-plan

hcptf-bootstrap-plan cannot ssm:GetParameter or DescribeSecret, so the first plan must not data-source those values.

* fix(infra): add EIP describe and DynamoDB CMK grants for first apply

Scoped apply missed ec2:DescribeAddressesAttribute and kms Encrypt/Decrypt/GenerateDataKey on the table CMK.
2026-09-16 18:29:01 +00:00

54 lines
1.6 KiB
HCL

output "slack_request_url" {
description = "Slack App Home Request URL."
value = "${aws_apigatewayv2_api.http.api_endpoint}/slack/events"
}
output "expense_slack_events_url" {
description = "Expense Approval Bot Slack Request URL."
value = "${aws_apigatewayv2_api.http.api_endpoint}/slack/expense-events"
}
output "api_origin" {
description = "HTTP API origin."
value = aws_apigatewayv2_api.http.api_endpoint
}
output "csv_bucket_name" {
description = "S3 bucket for Stampli CSV uploads."
value = aws_s3_bucket.csv.id
}
output "boa_raw_bucket_name" {
description = "Retain-protected BoA raw archive bucket."
value = aws_s3_bucket.boa_raw.id
}
output "static_outbound_ip" {
description = "NAT EIP for Bank of America CashPro IP whitelist."
value = aws_eip.nat.public_ip
}
output "table_name" {
description = "DynamoDB table name."
value = aws_dynamodb_table.dashboard.name
}
output "github_deploy_role_arn" {
description = "OIDC role ARN for .github/workflows/deploy.yaml (GitHub Environment prod variable DEPLOY_ROLE_ARN)."
value = aws_iam_role.github_deploy.arn
}
output "artifacts_bucket_name" {
description = "Lambda artifacts bucket. deploy.yaml uploads functions/<name>/<sha>.zip."
value = aws_s3_bucket.artifacts.id
}
output "hcptf_apply_role_arn" {
description = "HCP apply role ARN. Set TFC_AWS_APPLY_ROLE_ARN after the bootstrap window."
value = aws_iam_role.hcptf_apply.arn
}
output "hcptf_plan_role_arn" {
description = "HCP plan role ARN. Set TFC_AWS_PLAN_ROLE_ARN after the bootstrap window."
value = aws_iam_role.hcptf_plan.arn
}