data "aws_caller_identity" "current" {} check "correct_account" { assert { condition = data.aws_caller_identity.current.account_id == local.account_id error_message = "This configuration targets account ${local.account_id}, but the credentials resolve to ${data.aws_caller_identity.current.account_id}." } } data "aws_sns_topic" "site_alerts" { name = "site-alerts" } # Non-secret door id. Fetching the value is safe for state and fails the plan # closed if the OOB parameter is missing. SecureString parameters are never # read through data sources (that would put secret values in HCP state). data "aws_ssm_parameter" "door_id" { name = local.door_id_param } check "door_id_present" { assert { condition = length(data.aws_ssm_parameter.door_id.value) > 0 error_message = "SSM parameter ${local.door_id_param} is missing or empty; create it out of band before apply." } } # Secret *metadata* only (ARN). Never add aws_secretsmanager_secret_version. data "aws_secretsmanager_secret" "three_cx_domain" { name = local.three_cx_domain_secret_name } data "aws_secretsmanager_secret" "three_cx_client_id" { name = local.three_cx_client_id_secret_name } data "aws_secretsmanager_secret" "three_cx_client_secret" { name = local.three_cx_client_secret_secret_name }