mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-10-07 11:38:53 +00:00
fix(cd): address review feedback
This commit is contained in:
parent
5c5300a2a8
commit
3b0ab4aa83
5 changed files with 41 additions and 4 deletions
|
|
@ -25,8 +25,8 @@ def test_no_hcp_iam_and_no_prod():
|
||||||
variables = (tf_dir / "variables.tf").read_text()
|
variables = (tf_dir / "variables.tf").read_text()
|
||||||
assert 'var.environment == "dev"' in variables
|
assert 'var.environment == "dev"' in variables
|
||||||
locals_tf = (tf_dir / "locals.tf").read_text()
|
locals_tf = (tf_dir / "locals.tf").read_text()
|
||||||
assert 'vpc_cidr' in locals_tf and "10.63.0.0/16" in locals_tf
|
assert "vpc_cidr" in locals_tf and "10.63.0.0/16" in locals_tf
|
||||||
assert 'hcp_workspace' in locals_tf and "seahaven-ap-dev" in locals_tf
|
assert "hcp_workspace" in locals_tf and "seahaven-ap-dev" in locals_tf
|
||||||
ecs = (tf_dir / "ecs.tf").read_text()
|
ecs = (tf_dir / "ecs.tf").read_text()
|
||||||
assert "ignore_changes = [container_definitions]" in ecs
|
assert "ignore_changes = [container_definitions]" in ecs
|
||||||
assert "ignore_changes = [task_definition, desired_count]" in ecs
|
assert "ignore_changes = [task_definition, desired_count]" in ecs
|
||||||
|
|
@ -35,6 +35,22 @@ def test_no_hcp_iam_and_no_prod():
|
||||||
cloudfront = (tf_dir / "cloudfront.tf").read_text()
|
cloudfront = (tf_dir / "cloudfront.tf").read_text()
|
||||||
assert "cloudfront_default_certificate = true" in cloudfront
|
assert "cloudfront_default_certificate = true" in cloudfront
|
||||||
assert "aliases" not in cloudfront
|
assert "aliases" not in cloudfront
|
||||||
|
alarms = (tf_dir / "alarms.tf").read_text()
|
||||||
|
assert alarms.count("alarm_actions = [local.site_alerts_arn]") == 2
|
||||||
|
assert "insufficient_data_actions" not in alarms
|
||||||
|
assert "ok_actions" not in alarms
|
||||||
|
locals_tf = (tf_dir / "locals.tf").read_text()
|
||||||
|
assert (
|
||||||
|
'site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts"'
|
||||||
|
in locals_tf
|
||||||
|
)
|
||||||
|
cognito = (tf_dir / "cognito.tf").read_text()
|
||||||
|
assert 'supported_identity_providers = ["COGNITO", "Google"]' in cognito
|
||||||
|
assert '"ALLOW_USER_SRP_AUTH"' in cognito
|
||||||
|
assert "aws_secretsmanager_secret_version.google_oidc" in cognito
|
||||||
|
secrets = (tf_dir / "secrets.tf").read_text()
|
||||||
|
assert 'resource "aws_secretsmanager_secret_version" "google_oidc"' in secrets
|
||||||
|
assert "ignore_changes = [secret_string]" in secrets
|
||||||
github = (tf_dir / "iam_github_deploy.tf").read_text()
|
github = (tf_dir / "iam_github_deploy.tf").read_text()
|
||||||
assert "environment:dev" in github
|
assert "environment:dev" in github
|
||||||
assert "environment:prod" not in github
|
assert "environment:prod" not in github
|
||||||
|
|
|
||||||
|
|
@ -9,6 +9,7 @@ resource "aws_cloudwatch_metric_alarm" "alb_5xx" {
|
||||||
threshold = 0
|
threshold = 0
|
||||||
treat_missing_data = "notBreaching"
|
treat_missing_data = "notBreaching"
|
||||||
alarm_description = "ALB target 5xx for seahaven-ap."
|
alarm_description = "ALB target 5xx for seahaven-ap."
|
||||||
|
alarm_actions = [local.site_alerts_arn]
|
||||||
|
|
||||||
dimensions = {
|
dimensions = {
|
||||||
LoadBalancer = aws_lb.api.arn_suffix
|
LoadBalancer = aws_lb.api.arn_suffix
|
||||||
|
|
@ -26,6 +27,7 @@ resource "aws_cloudwatch_metric_alarm" "ecs_cpu" {
|
||||||
threshold = 80
|
threshold = 80
|
||||||
treat_missing_data = "notBreaching"
|
treat_missing_data = "notBreaching"
|
||||||
alarm_description = "seahaven-ap ECS CPU above 80 percent."
|
alarm_description = "seahaven-ap ECS CPU above 80 percent."
|
||||||
|
alarm_actions = [local.site_alerts_arn]
|
||||||
|
|
||||||
dimensions = {
|
dimensions = {
|
||||||
ClusterName = aws_ecs_cluster.api.name
|
ClusterName = aws_ecs_cluster.api.name
|
||||||
|
|
|
||||||
|
|
@ -23,6 +23,8 @@ locals {
|
||||||
|
|
||||||
data "aws_secretsmanager_secret_version" "google_oidc" {
|
data "aws_secretsmanager_secret_version" "google_oidc" {
|
||||||
secret_id = aws_secretsmanager_secret.google_oidc.id
|
secret_id = aws_secretsmanager_secret.google_oidc.id
|
||||||
|
|
||||||
|
depends_on = [aws_secretsmanager_secret_version.google_oidc]
|
||||||
}
|
}
|
||||||
|
|
||||||
data "archive_file" "cognito_presignup" {
|
data "archive_file" "cognito_presignup" {
|
||||||
|
|
@ -163,8 +165,8 @@ resource "aws_cognito_user_pool_client" "portal" {
|
||||||
allowed_oauth_flows_user_pool_client = true
|
allowed_oauth_flows_user_pool_client = true
|
||||||
allowed_oauth_flows = ["code"]
|
allowed_oauth_flows = ["code"]
|
||||||
allowed_oauth_scopes = ["openid", "email", "profile"]
|
allowed_oauth_scopes = ["openid", "email", "profile"]
|
||||||
supported_identity_providers = ["Google"]
|
supported_identity_providers = ["COGNITO", "Google"]
|
||||||
explicit_auth_flows = ["ALLOW_REFRESH_TOKEN_AUTH"]
|
explicit_auth_flows = ["ALLOW_REFRESH_TOKEN_AUTH", "ALLOW_USER_SRP_AUTH"]
|
||||||
enable_token_revocation = true
|
enable_token_revocation = true
|
||||||
prevent_user_existence_errors = "ENABLED"
|
prevent_user_existence_errors = "ENABLED"
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -19,6 +19,9 @@ locals {
|
||||||
|
|
||||||
github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com"
|
github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com"
|
||||||
|
|
||||||
|
# Org-baseline topic in this account. Alarm-only; no OK or insufficient-data action.
|
||||||
|
site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts"
|
||||||
|
|
||||||
cache_policy_caching_optimized = "658327ea-f89d-4fab-a63d-7e88639e58f6"
|
cache_policy_caching_optimized = "658327ea-f89d-4fab-a63d-7e88639e58f6"
|
||||||
cache_policy_caching_disabled = "4135ea2d-6df8-44a3-9df3-4b5a84be39ad"
|
cache_policy_caching_disabled = "4135ea2d-6df8-44a3-9df3-4b5a84be39ad"
|
||||||
origin_request_all_viewer_except_host = "b689b0a8-53d0-40ab-baf2-68738e2966ac"
|
origin_request_all_viewer_except_host = "b689b0a8-53d0-40ab-baf2-68738e2966ac"
|
||||||
|
|
|
||||||
|
|
@ -3,6 +3,20 @@ resource "aws_secretsmanager_secret" "google_oidc" {
|
||||||
description = "Google OIDC client credentials for seahaven-ap Cognito. Value is written outside Terraform."
|
description = "Google OIDC client credentials for seahaven-ap Cognito. Value is written outside Terraform."
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Placeholder so the first apply has an AWSCURRENT version to read. Replace the
|
||||||
|
# value in Secrets Manager; Terraform will not write this placeholder back.
|
||||||
|
resource "aws_secretsmanager_secret_version" "google_oidc" {
|
||||||
|
secret_id = aws_secretsmanager_secret.google_oidc.id
|
||||||
|
secret_string = jsonencode({
|
||||||
|
client_id = "replace-me"
|
||||||
|
client_secret = "replace-me"
|
||||||
|
})
|
||||||
|
|
||||||
|
lifecycle {
|
||||||
|
ignore_changes = [secret_string]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
resource "aws_secretsmanager_secret" "database" {
|
resource "aws_secretsmanager_secret" "database" {
|
||||||
name = "seahaven-ap/database"
|
name = "seahaven-ap/database"
|
||||||
description = "Aurora master credentials for seahaven-ap"
|
description = "Aurora master credentials for seahaven-ap"
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue