mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-10-02 14:23:24 +00:00
fix(cd): address review feedback
This commit is contained in:
parent
5c5300a2a8
commit
3b0ab4aa83
5 changed files with 41 additions and 4 deletions
|
|
@ -25,8 +25,8 @@ def test_no_hcp_iam_and_no_prod():
|
|||
variables = (tf_dir / "variables.tf").read_text()
|
||||
assert 'var.environment == "dev"' in variables
|
||||
locals_tf = (tf_dir / "locals.tf").read_text()
|
||||
assert 'vpc_cidr' in locals_tf and "10.63.0.0/16" in locals_tf
|
||||
assert 'hcp_workspace' in locals_tf and "seahaven-ap-dev" in locals_tf
|
||||
assert "vpc_cidr" in locals_tf and "10.63.0.0/16" in locals_tf
|
||||
assert "hcp_workspace" in locals_tf and "seahaven-ap-dev" in locals_tf
|
||||
ecs = (tf_dir / "ecs.tf").read_text()
|
||||
assert "ignore_changes = [container_definitions]" in ecs
|
||||
assert "ignore_changes = [task_definition, desired_count]" in ecs
|
||||
|
|
@ -35,6 +35,22 @@ def test_no_hcp_iam_and_no_prod():
|
|||
cloudfront = (tf_dir / "cloudfront.tf").read_text()
|
||||
assert "cloudfront_default_certificate = true" in cloudfront
|
||||
assert "aliases" not in cloudfront
|
||||
alarms = (tf_dir / "alarms.tf").read_text()
|
||||
assert alarms.count("alarm_actions = [local.site_alerts_arn]") == 2
|
||||
assert "insufficient_data_actions" not in alarms
|
||||
assert "ok_actions" not in alarms
|
||||
locals_tf = (tf_dir / "locals.tf").read_text()
|
||||
assert (
|
||||
'site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts"'
|
||||
in locals_tf
|
||||
)
|
||||
cognito = (tf_dir / "cognito.tf").read_text()
|
||||
assert 'supported_identity_providers = ["COGNITO", "Google"]' in cognito
|
||||
assert '"ALLOW_USER_SRP_AUTH"' in cognito
|
||||
assert "aws_secretsmanager_secret_version.google_oidc" in cognito
|
||||
secrets = (tf_dir / "secrets.tf").read_text()
|
||||
assert 'resource "aws_secretsmanager_secret_version" "google_oidc"' in secrets
|
||||
assert "ignore_changes = [secret_string]" in secrets
|
||||
github = (tf_dir / "iam_github_deploy.tf").read_text()
|
||||
assert "environment:dev" in github
|
||||
assert "environment:prod" not in github
|
||||
|
|
|
|||
|
|
@ -9,6 +9,7 @@ resource "aws_cloudwatch_metric_alarm" "alb_5xx" {
|
|||
threshold = 0
|
||||
treat_missing_data = "notBreaching"
|
||||
alarm_description = "ALB target 5xx for seahaven-ap."
|
||||
alarm_actions = [local.site_alerts_arn]
|
||||
|
||||
dimensions = {
|
||||
LoadBalancer = aws_lb.api.arn_suffix
|
||||
|
|
@ -26,6 +27,7 @@ resource "aws_cloudwatch_metric_alarm" "ecs_cpu" {
|
|||
threshold = 80
|
||||
treat_missing_data = "notBreaching"
|
||||
alarm_description = "seahaven-ap ECS CPU above 80 percent."
|
||||
alarm_actions = [local.site_alerts_arn]
|
||||
|
||||
dimensions = {
|
||||
ClusterName = aws_ecs_cluster.api.name
|
||||
|
|
|
|||
|
|
@ -23,6 +23,8 @@ locals {
|
|||
|
||||
data "aws_secretsmanager_secret_version" "google_oidc" {
|
||||
secret_id = aws_secretsmanager_secret.google_oidc.id
|
||||
|
||||
depends_on = [aws_secretsmanager_secret_version.google_oidc]
|
||||
}
|
||||
|
||||
data "archive_file" "cognito_presignup" {
|
||||
|
|
@ -163,8 +165,8 @@ resource "aws_cognito_user_pool_client" "portal" {
|
|||
allowed_oauth_flows_user_pool_client = true
|
||||
allowed_oauth_flows = ["code"]
|
||||
allowed_oauth_scopes = ["openid", "email", "profile"]
|
||||
supported_identity_providers = ["Google"]
|
||||
explicit_auth_flows = ["ALLOW_REFRESH_TOKEN_AUTH"]
|
||||
supported_identity_providers = ["COGNITO", "Google"]
|
||||
explicit_auth_flows = ["ALLOW_REFRESH_TOKEN_AUTH", "ALLOW_USER_SRP_AUTH"]
|
||||
enable_token_revocation = true
|
||||
prevent_user_existence_errors = "ENABLED"
|
||||
|
||||
|
|
|
|||
|
|
@ -19,6 +19,9 @@ locals {
|
|||
|
||||
github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com"
|
||||
|
||||
# Org-baseline topic in this account. Alarm-only; no OK or insufficient-data action.
|
||||
site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts"
|
||||
|
||||
cache_policy_caching_optimized = "658327ea-f89d-4fab-a63d-7e88639e58f6"
|
||||
cache_policy_caching_disabled = "4135ea2d-6df8-44a3-9df3-4b5a84be39ad"
|
||||
origin_request_all_viewer_except_host = "b689b0a8-53d0-40ab-baf2-68738e2966ac"
|
||||
|
|
|
|||
|
|
@ -3,6 +3,20 @@ resource "aws_secretsmanager_secret" "google_oidc" {
|
|||
description = "Google OIDC client credentials for seahaven-ap Cognito. Value is written outside Terraform."
|
||||
}
|
||||
|
||||
# Placeholder so the first apply has an AWSCURRENT version to read. Replace the
|
||||
# value in Secrets Manager; Terraform will not write this placeholder back.
|
||||
resource "aws_secretsmanager_secret_version" "google_oidc" {
|
||||
secret_id = aws_secretsmanager_secret.google_oidc.id
|
||||
secret_string = jsonencode({
|
||||
client_id = "replace-me"
|
||||
client_secret = "replace-me"
|
||||
})
|
||||
|
||||
lifecycle {
|
||||
ignore_changes = [secret_string]
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_secretsmanager_secret" "database" {
|
||||
name = "seahaven-ap/database"
|
||||
description = "Aurora master credentials for seahaven-ap"
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue