mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-09-30 19:43:19 +00:00
40 lines
1.3 KiB
HCL
40 lines
1.3 KiB
HCL
data "aws_caller_identity" "current" {}
|
|
|
|
check "correct_account" {
|
|
assert {
|
|
condition = data.aws_caller_identity.current.account_id == local.account_id
|
|
error_message = "This configuration targets account ${local.account_id} (${var.environment}), but the credentials resolve to ${data.aws_caller_identity.current.account_id}."
|
|
}
|
|
}
|
|
|
|
data "aws_ssm_parameter" "app_web_acl_arn" {
|
|
name = "/seahaven/waf/app-web-acl-arn"
|
|
}
|
|
|
|
data "aws_iam_policy" "ecs_task_boundary" {
|
|
name = "seahaven-ap-ecs-task-boundary"
|
|
}
|
|
|
|
data "aws_iam_policy" "github_deploy_boundary" {
|
|
name = "seahaven-ap-githubdeploy-boundary"
|
|
}
|
|
|
|
check "existing_vpc_pair" {
|
|
assert {
|
|
condition = (
|
|
(var.existing_vpc_id == "") == (length(var.existing_public_subnet_ids) == 0) &&
|
|
(var.existing_vpc_id == "") == (length(var.existing_private_subnet_ids) == 0)
|
|
)
|
|
error_message = "existing_vpc_id, existing_public_subnet_ids, and existing_private_subnet_ids must all be set or all be empty."
|
|
}
|
|
}
|
|
|
|
check "existing_subnets_in_vpc" {
|
|
assert {
|
|
condition = alltrue(concat(
|
|
[for subnet in data.aws_subnet.existing_public : subnet.vpc_id == var.existing_vpc_id],
|
|
[for subnet in data.aws_subnet.existing_private : subnet.vpc_id == var.existing_vpc_id],
|
|
))
|
|
error_message = "Every existing subnet ID must belong to existing_vpc_id."
|
|
}
|
|
}
|