procurement-ingest/terraform/variables.tf

33 lines
1.2 KiB
HCL

variable "aws_region" {
type = string
description = "AWS region for all resources"
default = "us-east-1"
}
variable "sentry_dsn" {
type = string
sensitive = true
default = ""
description = "Sentry DSN. Empty disables the SDK. Set in HCP, never in git."
}
variable "web_ui_auth_token_secret_arn" {
type = string
description = "Secrets Manager ARN for the shared web UI / docs auth token (exact ARN, including suffix)"
}
variable "shoc_hmac_secret_arn" {
type = string
description = "Secrets Manager ARN for the SHOC webhook HMAC secret (exact ARN, including suffix)"
}
variable "shoc_webhook_url" {
type = string
description = "SHOC webhook HTTPS endpoint URL (required; no default — set explicitly in HCP workspace vars)"
}
variable "shoc_consumer_role_arn" {
type = string
description = "Exact IAM role ARN allowed to GetSecretValue / kms:Decrypt the SHOC HMAC secret and invoke the read API (cross-account consumer). Default is the live pin per docs/shoc-webhook-contract.md; changing it is a deliberate cross-family IAM review."
default = "arn:aws:iam::396287094661:role/shoc-backend-dev"
}