mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 16:33:14 +00:00
* chore(infra): remove cdk tree after hcp cutover Delete retired CDK sources, retarget bundle/principal contract tests to Terraform packaging, disable CDK synth in CI, and scrub deploy-adjacent docs. * fix(test): restore exact SHOC principal pin in terraform Pin shoc_consumer_role_arn's Terraform default and example to the trusted ARN, and require grant sites to consume local.shoc_consumer_role_arn only.
26 lines
1,019 B
HCL
26 lines
1,019 B
HCL
variable "aws_region" {
|
|
type = string
|
|
description = "AWS region for all resources"
|
|
default = "us-east-1"
|
|
}
|
|
|
|
variable "web_ui_auth_token_secret_arn" {
|
|
type = string
|
|
description = "Secrets Manager ARN for the shared web UI / docs auth token (exact ARN, including suffix)"
|
|
}
|
|
|
|
variable "shoc_hmac_secret_arn" {
|
|
type = string
|
|
description = "Secrets Manager ARN for the SHOC webhook HMAC secret (exact ARN, including suffix)"
|
|
}
|
|
|
|
variable "shoc_webhook_url" {
|
|
type = string
|
|
description = "SHOC webhook HTTPS endpoint URL (required; no default — set explicitly in HCP workspace vars)"
|
|
}
|
|
|
|
variable "shoc_consumer_role_arn" {
|
|
type = string
|
|
description = "Exact IAM role ARN allowed to GetSecretValue / kms:Decrypt the SHOC HMAC secret and invoke the read API (cross-account consumer). Default is the live pin per docs/shoc-webhook-contract.md; changing it is a deliberate cross-family IAM review."
|
|
default = "arn:aws:iam::396287094661:role/shoc-backend-dev"
|
|
}
|