From 3b0ab4aa838df3677883eb185d3b9bbd733563ba Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 25 Sep 2026 16:37:08 -0400 Subject: [PATCH] fix(cd): address review feedback --- scripts/test-terraform-dev-only.py | 20 ++++++++++++++++++-- terraform/alarms.tf | 2 ++ terraform/cognito.tf | 6 ++++-- terraform/locals.tf | 3 +++ terraform/secrets.tf | 14 ++++++++++++++ 5 files changed, 41 insertions(+), 4 deletions(-) diff --git a/scripts/test-terraform-dev-only.py b/scripts/test-terraform-dev-only.py index edf0c59..3ae5f5c 100755 --- a/scripts/test-terraform-dev-only.py +++ b/scripts/test-terraform-dev-only.py @@ -25,8 +25,8 @@ def test_no_hcp_iam_and_no_prod(): variables = (tf_dir / "variables.tf").read_text() assert 'var.environment == "dev"' in variables locals_tf = (tf_dir / "locals.tf").read_text() - assert 'vpc_cidr' in locals_tf and "10.63.0.0/16" in locals_tf - assert 'hcp_workspace' in locals_tf and "seahaven-ap-dev" in locals_tf + assert "vpc_cidr" in locals_tf and "10.63.0.0/16" in locals_tf + assert "hcp_workspace" in locals_tf and "seahaven-ap-dev" in locals_tf ecs = (tf_dir / "ecs.tf").read_text() assert "ignore_changes = [container_definitions]" in ecs assert "ignore_changes = [task_definition, desired_count]" in ecs @@ -35,6 +35,22 @@ def test_no_hcp_iam_and_no_prod(): cloudfront = (tf_dir / "cloudfront.tf").read_text() assert "cloudfront_default_certificate = true" in cloudfront assert "aliases" not in cloudfront + alarms = (tf_dir / "alarms.tf").read_text() + assert alarms.count("alarm_actions = [local.site_alerts_arn]") == 2 + assert "insufficient_data_actions" not in alarms + assert "ok_actions" not in alarms + locals_tf = (tf_dir / "locals.tf").read_text() + assert ( + 'site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts"' + in locals_tf + ) + cognito = (tf_dir / "cognito.tf").read_text() + assert 'supported_identity_providers = ["COGNITO", "Google"]' in cognito + assert '"ALLOW_USER_SRP_AUTH"' in cognito + assert "aws_secretsmanager_secret_version.google_oidc" in cognito + secrets = (tf_dir / "secrets.tf").read_text() + assert 'resource "aws_secretsmanager_secret_version" "google_oidc"' in secrets + assert "ignore_changes = [secret_string]" in secrets github = (tf_dir / "iam_github_deploy.tf").read_text() assert "environment:dev" in github assert "environment:prod" not in github diff --git a/terraform/alarms.tf b/terraform/alarms.tf index 6542005..1322798 100644 --- a/terraform/alarms.tf +++ b/terraform/alarms.tf @@ -9,6 +9,7 @@ resource "aws_cloudwatch_metric_alarm" "alb_5xx" { threshold = 0 treat_missing_data = "notBreaching" alarm_description = "ALB target 5xx for seahaven-ap." + alarm_actions = [local.site_alerts_arn] dimensions = { LoadBalancer = aws_lb.api.arn_suffix @@ -26,6 +27,7 @@ resource "aws_cloudwatch_metric_alarm" "ecs_cpu" { threshold = 80 treat_missing_data = "notBreaching" alarm_description = "seahaven-ap ECS CPU above 80 percent." + alarm_actions = [local.site_alerts_arn] dimensions = { ClusterName = aws_ecs_cluster.api.name diff --git a/terraform/cognito.tf b/terraform/cognito.tf index f7a4532..50439a5 100644 --- a/terraform/cognito.tf +++ b/terraform/cognito.tf @@ -23,6 +23,8 @@ locals { data "aws_secretsmanager_secret_version" "google_oidc" { secret_id = aws_secretsmanager_secret.google_oidc.id + + depends_on = [aws_secretsmanager_secret_version.google_oidc] } data "archive_file" "cognito_presignup" { @@ -163,8 +165,8 @@ resource "aws_cognito_user_pool_client" "portal" { allowed_oauth_flows_user_pool_client = true allowed_oauth_flows = ["code"] allowed_oauth_scopes = ["openid", "email", "profile"] - supported_identity_providers = ["Google"] - explicit_auth_flows = ["ALLOW_REFRESH_TOKEN_AUTH"] + supported_identity_providers = ["COGNITO", "Google"] + explicit_auth_flows = ["ALLOW_REFRESH_TOKEN_AUTH", "ALLOW_USER_SRP_AUTH"] enable_token_revocation = true prevent_user_existence_errors = "ENABLED" diff --git a/terraform/locals.tf b/terraform/locals.tf index 8c456c6..07710e1 100644 --- a/terraform/locals.tf +++ b/terraform/locals.tf @@ -19,6 +19,9 @@ locals { github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com" + # Org-baseline topic in this account. Alarm-only; no OK or insufficient-data action. + site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts" + cache_policy_caching_optimized = "658327ea-f89d-4fab-a63d-7e88639e58f6" cache_policy_caching_disabled = "4135ea2d-6df8-44a3-9df3-4b5a84be39ad" origin_request_all_viewer_except_host = "b689b0a8-53d0-40ab-baf2-68738e2966ac" diff --git a/terraform/secrets.tf b/terraform/secrets.tf index d587bca..3ee9452 100644 --- a/terraform/secrets.tf +++ b/terraform/secrets.tf @@ -3,6 +3,20 @@ resource "aws_secretsmanager_secret" "google_oidc" { description = "Google OIDC client credentials for seahaven-ap Cognito. Value is written outside Terraform." } +# Placeholder so the first apply has an AWSCURRENT version to read. Replace the +# value in Secrets Manager; Terraform will not write this placeholder back. +resource "aws_secretsmanager_secret_version" "google_oidc" { + secret_id = aws_secretsmanager_secret.google_oidc.id + secret_string = jsonencode({ + client_id = "replace-me" + client_secret = "replace-me" + }) + + lifecycle { + ignore_changes = [secret_string] + } +} + resource "aws_secretsmanager_secret" "database" { name = "seahaven-ap/database" description = "Aurora master credentials for seahaven-ap"