mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 06:03:14 +00:00
Terraform still pinned only shoc-backend-dev, so the next ingest apply would drop the live staging HMAC grant.
44 lines
1.6 KiB
HCL
44 lines
1.6 KiB
HCL
variable "aws_region" {
|
|
type = string
|
|
description = "AWS region for all resources"
|
|
default = "us-east-1"
|
|
}
|
|
|
|
variable "sentry_dsn" {
|
|
type = string
|
|
sensitive = true
|
|
default = ""
|
|
description = "Sentry DSN. Empty disables the SDK. Set in HCP, never in git."
|
|
}
|
|
|
|
variable "web_ui_auth_token_secret_arn" {
|
|
type = string
|
|
description = "Secrets Manager ARN for the shared web UI / docs auth token (exact ARN, including suffix)"
|
|
}
|
|
|
|
variable "shoc_hmac_secret_arn" {
|
|
type = string
|
|
description = "Secrets Manager ARN for the SHOC webhook HMAC secret (exact ARN, including suffix)"
|
|
}
|
|
|
|
variable "shoc_webhook_url" {
|
|
type = string
|
|
description = "SHOC webhook HTTPS endpoint URL (required; no default — set explicitly in HCP workspace vars)"
|
|
}
|
|
|
|
variable "shoc_consumer_role_arns" {
|
|
type = list(string)
|
|
description = "Exact IAM role ARNs allowed to GetSecretValue / kms:Decrypt the SHOC HMAC secret and invoke the read API (cross-account consumers). Default is the live pin per docs/shoc-webhook-contract.md; each addition is a deliberate cross-family IAM review. No wildcards."
|
|
default = [
|
|
"arn:aws:iam::396287094661:role/shoc-backend-dev",
|
|
"arn:aws:iam::396287094661:role/shoc-backend-staging",
|
|
]
|
|
|
|
validation {
|
|
condition = toset(var.shoc_consumer_role_arns) == toset([
|
|
"arn:aws:iam::396287094661:role/shoc-backend-dev",
|
|
"arn:aws:iam::396287094661:role/shoc-backend-staging",
|
|
])
|
|
error_message = "shoc_consumer_role_arns must be exactly the shoc-backend-dev and shoc-backend-staging role ARNs in account 396287094661; no wildcards, omissions, or extra principals."
|
|
}
|
|
}
|