mirror of
https://github.com/Sea-Haven-Industries/payments-dashboard.git
synced 2026-09-30 07:43:12 +00:00
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79) Replace the mgmt SAM stack with a prod-only HCP workspace using the afterhours stub-plus-zip-CD seam so GitHub Actions owns function code and Terraform owns infrastructure. * fix(infra): pin secret and CMK ARNs for bootstrap-plan hcptf-bootstrap-plan cannot ssm:GetParameter or DescribeSecret, so the first plan must not data-source those values. * fix(infra): add EIP describe and DynamoDB CMK grants for first apply Scoped apply missed ec2:DescribeAddressesAttribute and kms Encrypt/Decrypt/GenerateDataKey on the table CMK.
47 lines
1.5 KiB
HCL
47 lines
1.5 KiB
HCL
# EventBridge schedules. Keep schedules_enabled=false until Slack Request URLs
|
|
# and the Stampli uploader point at this stack.
|
|
|
|
locals {
|
|
schedules = {
|
|
daily = {
|
|
description = "Fetch BoA previous day transactions at 9am ET (13:00 UTC)"
|
|
schedule = "cron(0 13 ? * MON-FRI *)"
|
|
function_key = "fetch_boa"
|
|
input = null
|
|
}
|
|
intraday = {
|
|
description = "Intraday BoA current-day sweep (~12pm/3pm/6pm ET)"
|
|
schedule = "cron(0 16,19,22 ? * MON-FRI *)"
|
|
function_key = "fetch_boa"
|
|
input = jsonencode({ endpoint = "current-day" })
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_cloudwatch_event_rule" "schedule" {
|
|
for_each = local.schedules
|
|
|
|
name = "${local.project}-${each.key}"
|
|
description = each.value.description
|
|
schedule_expression = each.value.schedule
|
|
state = var.schedules_enabled ? "ENABLED" : "DISABLED"
|
|
}
|
|
|
|
resource "aws_cloudwatch_event_target" "schedule" {
|
|
for_each = local.schedules
|
|
|
|
rule = aws_cloudwatch_event_rule.schedule[each.key].name
|
|
target_id = "${local.project}-${each.key}"
|
|
arn = aws_lambda_function.this[each.value.function_key].arn
|
|
input = each.value.input
|
|
}
|
|
|
|
resource "aws_lambda_permission" "schedule" {
|
|
for_each = local.schedules
|
|
|
|
statement_id = "AllowEventBridgeInvoke-${each.key}"
|
|
action = "lambda:InvokeFunction"
|
|
function_name = aws_lambda_function.this[each.value.function_key].function_name
|
|
principal = "events.amazonaws.com"
|
|
source_arn = aws_cloudwatch_event_rule.schedule[each.key].arn
|
|
}
|