seahaven-door-unlock-api/terraform/events.tf
Adam Moussa c43bee214c
feat(terraform): add hcp terraform for prod door-unlock-api (PLAT-76) (#81)
* feat(terraform): add hcp terraform for prod door-unlock-api

Move deploy off frozen CDK CD onto an HCP workspace that recreates the HTTP API, five Lambdas, disabled EventBridge rules, and alarms in seahaven-prod without a poller VPC.

* docs(readme): link the door unlock api ops page

* fix(terraform): invoke package build via bash

HCP launches the external data source with bash, so the inner build script should not depend on the git executable bit.
2026-08-27 22:03:12 +00:00

43 lines
1.4 KiB
HCL

locals {
schedules = {
"lockdown-poller-schedule" = {
description = "Poll LenelS2 lockdown status every minute"
schedule = "rate(1 minute)"
function_arn = aws_lambda_function.poller.arn
function_name = aws_lambda_function.poller.function_name
}
"blf-sync-schedule" = {
description = "Sync 3CX department BLFs daily at 09:00 UTC"
schedule = "cron(0 9 * * ? *)"
function_arn = aws_lambda_function.blf_sync.arn
function_name = aws_lambda_function.blf_sync.function_name
}
}
}
resource "aws_cloudwatch_event_rule" "schedule" {
for_each = local.schedules
name = "${local.project}-${each.key}"
description = each.value.description
schedule_expression = each.value.schedule
state = var.enable_schedules ? "ENABLED" : "DISABLED"
}
resource "aws_cloudwatch_event_target" "schedule" {
for_each = local.schedules
rule = aws_cloudwatch_event_rule.schedule[each.key].name
target_id = "${local.project}-${each.key}"
arn = each.value.function_arn
}
resource "aws_lambda_permission" "schedule" {
for_each = local.schedules
statement_id = "AllowEventBridgeInvoke-${each.key}"
action = "lambda:InvokeFunction"
function_name = each.value.function_name
principal = "events.amazonaws.com"
source_arn = aws_cloudwatch_event_rule.schedule[each.key].arn
}