mirror of
https://github.com/Sea-Haven-Industries/seahaven-site.git
synced 2026-09-30 07:43:16 +00:00
Some checks are pending
Deploy / deploy (push) Waiting to run
* feat(infra): add HCP Terraform for prod static hosting Greenfield S3+CloudFront+ACM+OIDC content-deploy role under /tf-managed/, with OOB mgmt DNS helper for ACM validation and apex alias cutover. * chore(security): suppress pre-existing js-yaml npm audit * feat(ci): retarget content deploy to seahaven-prod origin Point OIDC, S3 sync, and CloudFront invalidation at the HCP-managed prod hosting stack so GHA remains the content publish path after cutover.
32 lines
960 B
HCL
32 lines
960 B
HCL
variable "aws_region" {
|
|
type = string
|
|
description = "AWS region for regional resources (CloudFront/ACM for this stack are us-east-1)"
|
|
default = "us-east-1"
|
|
}
|
|
|
|
variable "domain_name" {
|
|
type = string
|
|
description = "Public apex hostname served by CloudFront (DNS alias stays OOB in mgmt Route53)"
|
|
default = "seahaven.com"
|
|
}
|
|
|
|
variable "github_repo" {
|
|
type = string
|
|
description = "GitHub owner/name for the content-deploy OIDC trust"
|
|
default = "Sea-Haven-Industries/seahaven-site"
|
|
}
|
|
|
|
variable "github_deploy_branch" {
|
|
type = string
|
|
description = "Git branch allowed to assume the content-deploy role"
|
|
default = "main"
|
|
}
|
|
|
|
variable "attach_apex_alias" {
|
|
type = bool
|
|
description = <<EOT
|
|
When true, attach domain_name as a CloudFront alias using the ACM cert.
|
|
Keep false until OOB DNS validation has issued the cert (scripts/setup_seahaven_site_domain.sh cert).
|
|
EOT
|
|
default = false
|
|
}
|