mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 21:13:15 +00:00
55 lines
1.8 KiB
HCL
55 lines
1.8 KiB
HCL
# HCP plan and apply run on separate workers. archive_file paths from plan are
|
|
# not on the apply worker, so zip bytes are carried in the plan via
|
|
# content_base64 and uploaded to S3 at apply time for Lambda to consume.
|
|
#
|
|
# Package build runs during plan via external data (local-exec provisioners
|
|
# only run on apply; archive_file needs build/ present at plan time).
|
|
|
|
data "external" "package_build" {
|
|
program = ["bash", "${path.module}/build_packages_external.sh"]
|
|
}
|
|
|
|
resource "aws_s3_bucket" "artifacts" {
|
|
bucket = "procurement-ingest-artifacts-${local.account_id}"
|
|
}
|
|
|
|
resource "aws_s3_bucket_public_access_block" "artifacts" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
|
|
block_public_acls = true
|
|
block_public_policy = true
|
|
ignore_public_acls = true
|
|
restrict_public_buckets = true
|
|
}
|
|
|
|
locals {
|
|
lambda_packages = {
|
|
po_email_processor = "po-email-processor.zip"
|
|
po_web_ui = "po-web-ui.zip"
|
|
po_site_extractor = "po-ingest-site-extractor.zip"
|
|
wo_email_processor = "workorder-email-processor.zip"
|
|
wo_web_ui = "workorder-web-ui.zip"
|
|
wo_shoc_emitter = "workorder-shoc-emitter.zip"
|
|
wo_shoc_hmac_rotator = "workorder-shoc-hmac-rotator.zip"
|
|
procurement_api = "procurement-api.zip"
|
|
}
|
|
}
|
|
|
|
data "archive_file" "lambda" {
|
|
for_each = local.lambda_packages
|
|
|
|
type = "zip"
|
|
source_dir = "${path.module}/build/${each.key}"
|
|
output_path = "${path.module}/build/${each.value}"
|
|
|
|
depends_on = [data.external.package_build]
|
|
}
|
|
|
|
resource "aws_s3_object" "lambda" {
|
|
for_each = local.lambda_packages
|
|
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
key = each.value
|
|
content_base64 = filebase64(data.archive_file.lambda[each.key].output_path)
|
|
source_hash = data.archive_file.lambda[each.key].output_base64sha256
|
|
}
|