variable "aws_region" { type = string description = "AWS region for all resources" default = "us-east-1" } variable "sentry_dsn" { type = string sensitive = true default = "" description = "Sentry DSN. Empty disables the SDK. Set in HCP, never in git." } variable "web_ui_auth_token_secret_arn" { type = string description = "Secrets Manager ARN for the shared web UI / docs auth token (exact ARN, including suffix)" } variable "shoc_hmac_secret_arn" { type = string description = "Secrets Manager ARN for the SHOC webhook HMAC secret (exact ARN, including suffix)" } variable "shoc_webhook_url" { type = string description = "SHOC webhook HTTPS endpoint URL (required; no default — set explicitly in HCP workspace vars)" } variable "shoc_consumer_role_arns" { type = list(string) description = "Exact IAM role ARNs allowed to GetSecretValue / kms:Decrypt the SHOC HMAC secret and invoke the read API (cross-account consumers). Default is the live pin per docs/shoc-webhook-contract.md; each addition is a deliberate cross-family IAM review. No wildcards." default = [ "arn:aws:iam::396287094661:role/shoc-backend-dev", "arn:aws:iam::396287094661:role/shoc-backend-staging", ] validation { condition = toset(var.shoc_consumer_role_arns) == toset([ "arn:aws:iam::396287094661:role/shoc-backend-dev", "arn:aws:iam::396287094661:role/shoc-backend-staging", ]) error_message = "shoc_consumer_role_arns must be exactly the shoc-backend-dev and shoc-backend-staging role ARNs in account 396287094661; no wildcards, omissions, or extra principals." } }