fix(cd): address review feedback

This commit is contained in:
Adam Moussa 2026-09-25 16:37:08 -04:00
parent 5c5300a2a8
commit 3b0ab4aa83
No known key found for this signature in database
5 changed files with 41 additions and 4 deletions

View file

@ -25,8 +25,8 @@ def test_no_hcp_iam_and_no_prod():
variables = (tf_dir / "variables.tf").read_text()
assert 'var.environment == "dev"' in variables
locals_tf = (tf_dir / "locals.tf").read_text()
assert 'vpc_cidr' in locals_tf and "10.63.0.0/16" in locals_tf
assert 'hcp_workspace' in locals_tf and "seahaven-ap-dev" in locals_tf
assert "vpc_cidr" in locals_tf and "10.63.0.0/16" in locals_tf
assert "hcp_workspace" in locals_tf and "seahaven-ap-dev" in locals_tf
ecs = (tf_dir / "ecs.tf").read_text()
assert "ignore_changes = [container_definitions]" in ecs
assert "ignore_changes = [task_definition, desired_count]" in ecs
@ -35,6 +35,22 @@ def test_no_hcp_iam_and_no_prod():
cloudfront = (tf_dir / "cloudfront.tf").read_text()
assert "cloudfront_default_certificate = true" in cloudfront
assert "aliases" not in cloudfront
alarms = (tf_dir / "alarms.tf").read_text()
assert alarms.count("alarm_actions = [local.site_alerts_arn]") == 2
assert "insufficient_data_actions" not in alarms
assert "ok_actions" not in alarms
locals_tf = (tf_dir / "locals.tf").read_text()
assert (
'site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts"'
in locals_tf
)
cognito = (tf_dir / "cognito.tf").read_text()
assert 'supported_identity_providers = ["COGNITO", "Google"]' in cognito
assert '"ALLOW_USER_SRP_AUTH"' in cognito
assert "aws_secretsmanager_secret_version.google_oidc" in cognito
secrets = (tf_dir / "secrets.tf").read_text()
assert 'resource "aws_secretsmanager_secret_version" "google_oidc"' in secrets
assert "ignore_changes = [secret_string]" in secrets
github = (tf_dir / "iam_github_deploy.tf").read_text()
assert "environment:dev" in github
assert "environment:prod" not in github

View file

@ -9,6 +9,7 @@ resource "aws_cloudwatch_metric_alarm" "alb_5xx" {
threshold = 0
treat_missing_data = "notBreaching"
alarm_description = "ALB target 5xx for seahaven-ap."
alarm_actions = [local.site_alerts_arn]
dimensions = {
LoadBalancer = aws_lb.api.arn_suffix
@ -26,6 +27,7 @@ resource "aws_cloudwatch_metric_alarm" "ecs_cpu" {
threshold = 80
treat_missing_data = "notBreaching"
alarm_description = "seahaven-ap ECS CPU above 80 percent."
alarm_actions = [local.site_alerts_arn]
dimensions = {
ClusterName = aws_ecs_cluster.api.name

View file

@ -23,6 +23,8 @@ locals {
data "aws_secretsmanager_secret_version" "google_oidc" {
secret_id = aws_secretsmanager_secret.google_oidc.id
depends_on = [aws_secretsmanager_secret_version.google_oidc]
}
data "archive_file" "cognito_presignup" {
@ -163,8 +165,8 @@ resource "aws_cognito_user_pool_client" "portal" {
allowed_oauth_flows_user_pool_client = true
allowed_oauth_flows = ["code"]
allowed_oauth_scopes = ["openid", "email", "profile"]
supported_identity_providers = ["Google"]
explicit_auth_flows = ["ALLOW_REFRESH_TOKEN_AUTH"]
supported_identity_providers = ["COGNITO", "Google"]
explicit_auth_flows = ["ALLOW_REFRESH_TOKEN_AUTH", "ALLOW_USER_SRP_AUTH"]
enable_token_revocation = true
prevent_user_existence_errors = "ENABLED"

View file

@ -19,6 +19,9 @@ locals {
github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com"
# Org-baseline topic in this account. Alarm-only; no OK or insufficient-data action.
site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts"
cache_policy_caching_optimized = "658327ea-f89d-4fab-a63d-7e88639e58f6"
cache_policy_caching_disabled = "4135ea2d-6df8-44a3-9df3-4b5a84be39ad"
origin_request_all_viewer_except_host = "b689b0a8-53d0-40ab-baf2-68738e2966ac"

View file

@ -3,6 +3,20 @@ resource "aws_secretsmanager_secret" "google_oidc" {
description = "Google OIDC client credentials for seahaven-ap Cognito. Value is written outside Terraform."
}
# Placeholder so the first apply has an AWSCURRENT version to read. Replace the
# value in Secrets Manager; Terraform will not write this placeholder back.
resource "aws_secretsmanager_secret_version" "google_oidc" {
secret_id = aws_secretsmanager_secret.google_oidc.id
secret_string = jsonencode({
client_id = "replace-me"
client_secret = "replace-me"
})
lifecycle {
ignore_changes = [secret_string]
}
}
resource "aws_secretsmanager_secret" "database" {
name = "seahaven-ap/database"
description = "Aurora master credentials for seahaven-ap"