mirror of
https://github.com/Sea-Haven-Industries/seahaven-door-unlock-api.git
synced 2026-09-30 07:03:12 +00:00
40 lines
1.3 KiB
Terraform
40 lines
1.3 KiB
Terraform
|
|
data "aws_caller_identity" "current" {}
|
||
|
|
|
||
|
|
check "correct_account" {
|
||
|
|
assert {
|
||
|
|
condition = data.aws_caller_identity.current.account_id == local.account_id
|
||
|
|
error_message = "This configuration targets account ${local.account_id}, but the credentials resolve to ${data.aws_caller_identity.current.account_id}."
|
||
|
|
}
|
||
|
|
}
|
||
|
|
|
||
|
|
data "aws_sns_topic" "site_alerts" {
|
||
|
|
name = "site-alerts"
|
||
|
|
}
|
||
|
|
|
||
|
|
# Non-secret door id. Fetching the value is safe for state and fails the plan
|
||
|
|
# closed if the OOB parameter is missing. SecureString parameters are never
|
||
|
|
# read through data sources (that would put secret values in HCP state).
|
||
|
|
data "aws_ssm_parameter" "door_id" {
|
||
|
|
name = local.door_id_param
|
||
|
|
}
|
||
|
|
|
||
|
|
check "door_id_present" {
|
||
|
|
assert {
|
||
|
|
condition = length(data.aws_ssm_parameter.door_id.value) > 0
|
||
|
|
error_message = "SSM parameter ${local.door_id_param} is missing or empty; create it out of band before apply."
|
||
|
|
}
|
||
|
|
}
|
||
|
|
|
||
|
|
# Secret *metadata* only (ARN). Never add aws_secretsmanager_secret_version.
|
||
|
|
data "aws_secretsmanager_secret" "three_cx_domain" {
|
||
|
|
name = local.three_cx_domain_secret_name
|
||
|
|
}
|
||
|
|
|
||
|
|
data "aws_secretsmanager_secret" "three_cx_client_id" {
|
||
|
|
name = local.three_cx_client_id_secret_name
|
||
|
|
}
|
||
|
|
|
||
|
|
data "aws_secretsmanager_secret" "three_cx_client_secret" {
|
||
|
|
name = local.three_cx_client_secret_secret_name
|
||
|
|
}
|