# Wire these as HCP workspace Terraform variables (never commit real .tfvars). # Exact ARNs only; secret VALUES must never appear in this repo. web_ui_auth_token_secret_arn = "arn:aws:secretsmanager:us-east-1:011934824531:secret:procurement-ingest/web-ui-auth-token-ApAMmr" shoc_hmac_secret_arn = "arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB" # Required: no Terraform default. Live emitter target today (contract Rev 2026-07-23). shoc_webhook_url = "https://api.dev.seahaven.com/api/webhooks/work-orders" # Exact-ARN pin for cross-account HMAC/API trust (matches variable default; # docs/shoc-webhook-contract.md). Changing this is a deliberate IAM review. shoc_consumer_role_arn = "arn:aws:iam::396287094661:role/shoc-backend-dev"