seahaven-door-unlock-api/terraform/data.tf
Adam Moussa c43bee214c
feat(terraform): add hcp terraform for prod door-unlock-api (PLAT-76) (#81)
* feat(terraform): add hcp terraform for prod door-unlock-api

Move deploy off frozen CDK CD onto an HCP workspace that recreates the HTTP API, five Lambdas, disabled EventBridge rules, and alarms in seahaven-prod without a poller VPC.

* docs(readme): link the door unlock api ops page

* fix(terraform): invoke package build via bash

HCP launches the external data source with bash, so the inner build script should not depend on the git executable bit.
2026-08-27 22:03:12 +00:00

39 lines
1.3 KiB
HCL

data "aws_caller_identity" "current" {}
check "correct_account" {
assert {
condition = data.aws_caller_identity.current.account_id == local.account_id
error_message = "This configuration targets account ${local.account_id}, but the credentials resolve to ${data.aws_caller_identity.current.account_id}."
}
}
data "aws_sns_topic" "site_alerts" {
name = "site-alerts"
}
# Non-secret door id. Fetching the value is safe for state and fails the plan
# closed if the OOB parameter is missing. SecureString parameters are never
# read through data sources (that would put secret values in HCP state).
data "aws_ssm_parameter" "door_id" {
name = local.door_id_param
}
check "door_id_present" {
assert {
condition = length(data.aws_ssm_parameter.door_id.value) > 0
error_message = "SSM parameter ${local.door_id_param} is missing or empty; create it out of band before apply."
}
}
# Secret *metadata* only (ARN). Never add aws_secretsmanager_secret_version.
data "aws_secretsmanager_secret" "three_cx_domain" {
name = local.three_cx_domain_secret_name
}
data "aws_secretsmanager_secret" "three_cx_client_id" {
name = local.three_cx_client_id_secret_name
}
data "aws_secretsmanager_secret" "three_cx_client_secret" {
name = local.three_cx_client_secret_secret_name
}