mirror of
https://github.com/Sea-Haven-Industries/seahaven-door-unlock-api.git
synced 2026-09-30 08:13:13 +00:00
* feat(terraform): add hcp terraform for prod door-unlock-api Move deploy off frozen CDK CD onto an HCP workspace that recreates the HTTP API, five Lambdas, disabled EventBridge rules, and alarms in seahaven-prod without a poller VPC. * docs(readme): link the door unlock api ops page * fix(terraform): invoke package build via bash HCP launches the external data source with bash, so the inner build script should not depend on the git executable bit.
104 lines
2.5 KiB
HCL
104 lines
2.5 KiB
HCL
# Lambda packaging.
|
|
#
|
|
# HCP plan and apply run on separate workers, so a zip written during plan is
|
|
# not on disk at apply time. The bytes are therefore carried inside the plan as
|
|
# content_base64 on aws_s3_object and uploaded at apply, and the functions
|
|
# read from S3 rather than from a local file.
|
|
#
|
|
# The build itself runs during plan through an external data source:
|
|
# local-exec provisioners only run on apply, and archive_file needs build/ to
|
|
# already exist when the plan is computed.
|
|
|
|
data "external" "package_build" {
|
|
program = ["bash", "${path.module}/build_packages_external.sh"]
|
|
}
|
|
|
|
resource "aws_s3_bucket" "artifacts" {
|
|
bucket = local.artifacts_bucket_name
|
|
|
|
tags = {
|
|
Purpose = "Lambda deployment packages for door-unlock-api"
|
|
}
|
|
}
|
|
|
|
resource "aws_s3_bucket_public_access_block" "artifacts" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
|
|
block_public_acls = true
|
|
block_public_policy = true
|
|
ignore_public_acls = true
|
|
restrict_public_buckets = true
|
|
}
|
|
|
|
resource "aws_s3_bucket_ownership_controls" "artifacts" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
|
|
rule {
|
|
object_ownership = "BucketOwnerEnforced"
|
|
}
|
|
}
|
|
|
|
resource "aws_s3_bucket_server_side_encryption_configuration" "artifacts" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
|
|
rule {
|
|
apply_server_side_encryption_by_default {
|
|
sse_algorithm = "AES256"
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_s3_bucket_versioning" "artifacts" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
|
|
versioning_configuration {
|
|
status = "Enabled"
|
|
}
|
|
}
|
|
|
|
resource "aws_s3_bucket_lifecycle_configuration" "artifacts" {
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
|
|
rule {
|
|
id = "expire-noncurrent-packages"
|
|
status = "Enabled"
|
|
|
|
filter {}
|
|
|
|
noncurrent_version_expiration {
|
|
noncurrent_days = 180
|
|
}
|
|
}
|
|
|
|
rule {
|
|
id = "abort-incomplete-multipart"
|
|
status = "Enabled"
|
|
|
|
filter {}
|
|
|
|
abort_incomplete_multipart_upload {
|
|
days_after_initiation = 7
|
|
}
|
|
}
|
|
|
|
depends_on = [aws_s3_bucket_versioning.artifacts]
|
|
}
|
|
|
|
data "archive_file" "function" {
|
|
for_each = local.function_packages
|
|
|
|
type = "zip"
|
|
source_dir = "${path.module}/build/functions/${each.key}"
|
|
output_path = "${path.module}/build/packages/${each.key}.zip"
|
|
|
|
depends_on = [data.external.package_build]
|
|
}
|
|
|
|
resource "aws_s3_object" "function" {
|
|
for_each = local.function_packages
|
|
|
|
bucket = aws_s3_bucket.artifacts.id
|
|
key = "functions/${each.key}.zip"
|
|
content_base64 = filebase64(data.archive_file.function[each.key].output_path)
|
|
source_hash = data.archive_file.function[each.key].output_base64sha256
|
|
}
|