shoc-backend/terraform/live/modules/environment-owned/variables.tf

237 lines
5.2 KiB
Terraform
Raw Normal View History

variable "aws_account_id" {
type = string
}
variable "aws_region" {
type = string
}
variable "environment" {
type = string
validation {
condition = contains(["dev", "staging", "tf-poc"], var.environment)
error_message = "environment must be dev, staging, or tf-poc."
}
}
variable "adoption_complete" {
type = bool
description = "False preserves existing ownership metadata. True changes only documented metadata and the dev deploy S3 policy."
default = false
}
variable "manage_eb_settings" {
type = bool
description = "False omits managed Elastic Beanstalk settings during the import-only phase."
default = true
}
variable "eb_application_name" {
type = string
}
variable "eb_environment_name" {
type = string
}
variable "eb_environment_id" {
type = string
description = "Existing environment ID. Empty only before the CDK POC has been provisioned."
}
variable "platform_arn" {
type = string
}
variable "vpc_id" {
type = string
}
variable "instance_subnet_ids" {
type = list(string)
}
variable "load_balancer_subnet_ids" {
type = list(string)
}
variable "instance_security_group_id" {
type = string
default = null
description = "Pinned existing instance SG setting. Null lets Elastic Beanstalk retain its provider-managed generated SG."
}
variable "eb_service_role_name" {
type = string
}
variable "shared_certificate_arn" {
type = string
description = "Existing shared certificate for dev/staging, or the POC certificate ARN."
}
variable "runtime_role_name" {
type = string
}
variable "runtime_app_config_policy_name" {
type = string
}
variable "runtime_webhook_policy_name" {
type = string
default = null
}
variable "runtime_dynamo_policy_name" {
type = string
default = null
}
variable "permissions_boundary_arn" {
type = string
}
variable "github_deploy_permissions_boundary_arn" {
type = string
description = "Exact org-baseline permissions boundary ARN for the environment GitHub deploy role."
validation {
condition = can(regex(
"^arn:aws:iam::${var.aws_account_id}:policy/shoc-backend-${var.environment}-deploy-boundary$",
var.github_deploy_permissions_boundary_arn,
))
error_message = "github_deploy_permissions_boundary_arn must be the exact environment deploy boundary ARN."
}
}
variable "app_config_secret_name" {
type = string
}
variable "app_config_json_keys" {
type = set(string)
description = "Exact JSON keys exposed through Elastic Beanstalk environmentsecrets."
}
variable "app_config_policy_sid" {
type = string
default = null
}
variable "webhook_secret_arn" {
type = string
default = null
}
variable "work_order_webhook_enabled" {
type = bool
default = true
}
variable "webhook_read_policy_sid" {
type = string
default = null
}
variable "webhook_decrypt_policy_sid" {
type = string
default = null
}
variable "dynamo_reader_role_arn" {
type = string
default = null
description = "Dev-only cross-account role. Null for staging and tf-poc."
}
variable "dynamo_policy_sid" {
type = string
default = null
}
check "dynamo_policy_pair" {
assert {
condition = (var.runtime_dynamo_policy_name == null) == (var.dynamo_reader_role_arn == null)
error_message = "runtime_dynamo_policy_name and dynamo_reader_role_arn must both be set or both be null."
}
}
check "webhook_policy_pair" {
assert {
condition = (
var.work_order_webhook_enabled &&
var.runtime_webhook_policy_name != null &&
var.webhook_secret_arn != null
) || (
!var.work_order_webhook_enabled &&
var.runtime_webhook_policy_name == null &&
var.webhook_secret_arn == null
)
error_message = "Enabled webhooks require a runtime policy and secret ARN; disabled webhooks require both to be null."
}
}
variable "github_repo" {
type = string
}
variable "github_environment" {
type = string
}
variable "github_deploy_role_name" {
type = string
}
variable "github_deploy_policy_name" {
type = string
}
variable "legacy_dev_s3_policy" {
type = bool
description = "Retain the proven GitHub Elastic Beanstalk release policy until application CD is migrated separately."
default = false
}
variable "hosted_zone_id" {
type = string
}
variable "api_domain" {
type = string
}
variable "api_record_type" {
type = string
validation {
condition = contains(["A", "CNAME"], var.api_record_type)
error_message = "api_record_type must be A or CNAME."
}
}
variable "api_alias_target" {
type = object({
name = string
zone_id = string
})
description = "Exact existing Route 53 alias target preserved during import. Null resolves the target from Elastic Beanstalk."
default = null
}
variable "metadata_before_adoption" {
description = "Exact current metadata preserved while adoption_complete is false."
type = object({
runtime_role_description = string
runtime_role_tags = map(string)
instance_profile_tags = map(string)
app_config_description = string
app_config_tags = map(string)
deploy_role_description = string
deploy_role_tags = map(string)
environment_tags = map(string)
})
}