seahaven-ap/terraform/data.tf

40 lines
1.3 KiB
HCL

data "aws_caller_identity" "current" {}
check "correct_account" {
assert {
condition = data.aws_caller_identity.current.account_id == local.account_id
error_message = "This configuration targets account ${local.account_id} (${var.environment}), but the credentials resolve to ${data.aws_caller_identity.current.account_id}."
}
}
data "aws_ssm_parameter" "app_web_acl_arn" {
name = "/seahaven/waf/app-web-acl-arn"
}
data "aws_iam_policy" "ecs_task_boundary" {
name = "seahaven-ap-ecs-task-boundary"
}
data "aws_iam_policy" "github_deploy_boundary" {
name = "seahaven-ap-githubdeploy-boundary"
}
check "existing_vpc_pair" {
assert {
condition = (
(var.existing_vpc_id == "") == (length(var.existing_public_subnet_ids) == 0) &&
(var.existing_vpc_id == "") == (length(var.existing_private_subnet_ids) == 0)
)
error_message = "existing_vpc_id, existing_public_subnet_ids, and existing_private_subnet_ids must all be set or all be empty."
}
}
check "existing_subnets_in_vpc" {
assert {
condition = alltrue(concat(
[for subnet in data.aws_subnet.existing_public : subnet.vpc_id == var.existing_vpc_id],
[for subnet in data.aws_subnet.existing_private : subnet.vpc_id == var.existing_vpc_id],
))
error_message = "Every existing subnet ID must belong to existing_vpc_id."
}
}