2026-08-31 11:51:18 -04:00
|
|
|
variable "aws_account_id" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "aws_region" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "environment" {
|
|
|
|
|
type = string
|
|
|
|
|
|
|
|
|
|
validation {
|
|
|
|
|
condition = contains(["dev", "staging", "tf-poc"], var.environment)
|
|
|
|
|
error_message = "environment must be dev, staging, or tf-poc."
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "adoption_complete" {
|
|
|
|
|
type = bool
|
|
|
|
|
description = "False preserves existing ownership metadata. True changes only documented metadata and the dev deploy S3 policy."
|
|
|
|
|
default = false
|
|
|
|
|
}
|
|
|
|
|
|
2026-08-31 14:05:46 -04:00
|
|
|
variable "manage_eb_settings" {
|
|
|
|
|
type = bool
|
|
|
|
|
description = "False omits managed Elastic Beanstalk settings during the import-only phase."
|
|
|
|
|
default = true
|
|
|
|
|
}
|
|
|
|
|
|
2026-08-31 11:51:18 -04:00
|
|
|
variable "eb_application_name" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "eb_environment_name" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "eb_environment_id" {
|
|
|
|
|
type = string
|
|
|
|
|
description = "Existing environment ID. Empty only before the CDK POC has been provisioned."
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "platform_arn" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "vpc_id" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "instance_subnet_ids" {
|
|
|
|
|
type = list(string)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "load_balancer_subnet_ids" {
|
|
|
|
|
type = list(string)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "instance_security_group_id" {
|
|
|
|
|
type = string
|
|
|
|
|
default = null
|
|
|
|
|
description = "Pinned existing instance SG setting. Null lets Elastic Beanstalk retain its provider-managed generated SG."
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "eb_service_role_name" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "shared_certificate_arn" {
|
|
|
|
|
type = string
|
|
|
|
|
description = "Existing shared certificate for dev/staging, or the POC certificate ARN."
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "runtime_role_name" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "runtime_app_config_policy_name" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "runtime_webhook_policy_name" {
|
|
|
|
|
type = string
|
|
|
|
|
default = null
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "runtime_dynamo_policy_name" {
|
|
|
|
|
type = string
|
|
|
|
|
default = null
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "permissions_boundary_arn" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "github_deploy_permissions_boundary_arn" {
|
|
|
|
|
type = string
|
|
|
|
|
description = "Exact org-baseline permissions boundary ARN for the environment GitHub deploy role."
|
|
|
|
|
|
|
|
|
|
validation {
|
|
|
|
|
condition = can(regex(
|
|
|
|
|
"^arn:aws:iam::${var.aws_account_id}:policy/shoc-backend-${var.environment}-deploy-boundary$",
|
|
|
|
|
var.github_deploy_permissions_boundary_arn,
|
|
|
|
|
))
|
|
|
|
|
error_message = "github_deploy_permissions_boundary_arn must be the exact environment deploy boundary ARN."
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "app_config_secret_name" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "app_config_json_keys" {
|
|
|
|
|
type = set(string)
|
|
|
|
|
description = "Exact JSON keys exposed through Elastic Beanstalk environmentsecrets."
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "app_config_policy_sid" {
|
|
|
|
|
type = string
|
|
|
|
|
default = null
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "webhook_secret_arn" {
|
|
|
|
|
type = string
|
|
|
|
|
default = null
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "work_order_webhook_enabled" {
|
|
|
|
|
type = bool
|
|
|
|
|
default = true
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "webhook_read_policy_sid" {
|
|
|
|
|
type = string
|
|
|
|
|
default = null
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "webhook_decrypt_policy_sid" {
|
|
|
|
|
type = string
|
|
|
|
|
default = null
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "dynamo_reader_role_arn" {
|
|
|
|
|
type = string
|
|
|
|
|
default = null
|
|
|
|
|
description = "Dev-only cross-account role. Null for staging and tf-poc."
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "dynamo_policy_sid" {
|
|
|
|
|
type = string
|
|
|
|
|
default = null
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
check "dynamo_policy_pair" {
|
|
|
|
|
assert {
|
|
|
|
|
condition = (var.runtime_dynamo_policy_name == null) == (var.dynamo_reader_role_arn == null)
|
|
|
|
|
error_message = "runtime_dynamo_policy_name and dynamo_reader_role_arn must both be set or both be null."
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
check "webhook_policy_pair" {
|
|
|
|
|
assert {
|
|
|
|
|
condition = (
|
|
|
|
|
var.work_order_webhook_enabled &&
|
|
|
|
|
var.runtime_webhook_policy_name != null &&
|
|
|
|
|
var.webhook_secret_arn != null
|
|
|
|
|
) || (
|
|
|
|
|
!var.work_order_webhook_enabled &&
|
|
|
|
|
var.runtime_webhook_policy_name == null &&
|
|
|
|
|
var.webhook_secret_arn == null
|
|
|
|
|
)
|
|
|
|
|
error_message = "Enabled webhooks require a runtime policy and secret ARN; disabled webhooks require both to be null."
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "github_repo" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "github_environment" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "github_deploy_role_name" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "github_deploy_policy_name" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "legacy_dev_s3_policy" {
|
2026-08-31 19:18:44 -04:00
|
|
|
type = bool
|
|
|
|
|
description = "Retain the proven GitHub Elastic Beanstalk release policy until application CD is migrated separately."
|
|
|
|
|
default = false
|
2026-08-31 11:51:18 -04:00
|
|
|
}
|
|
|
|
|
|
2026-09-03 10:12:06 -04:00
|
|
|
variable "release_version_label" {
|
|
|
|
|
type = string
|
|
|
|
|
default = null
|
|
|
|
|
nullable = true
|
|
|
|
|
|
|
|
|
|
description = "Immutable Elastic Beanstalk application version. Null VCS plans leave the live version unchanged."
|
|
|
|
|
|
|
|
|
|
validation {
|
|
|
|
|
condition = (
|
|
|
|
|
var.release_version_label == null ||
|
|
|
|
|
can(regex("^[0-9a-f]{40}-[0-9]+-[0-9]+$", var.release_version_label))
|
|
|
|
|
)
|
|
|
|
|
error_message = "release_version_label must be <full-sha>-<run-id>-<attempt>."
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-08-31 11:51:18 -04:00
|
|
|
variable "hosted_zone_id" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "api_domain" {
|
|
|
|
|
type = string
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
variable "api_record_type" {
|
|
|
|
|
type = string
|
|
|
|
|
|
|
|
|
|
validation {
|
|
|
|
|
condition = contains(["A", "CNAME"], var.api_record_type)
|
|
|
|
|
error_message = "api_record_type must be A or CNAME."
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-08-31 14:05:46 -04:00
|
|
|
variable "api_alias_target" {
|
|
|
|
|
type = object({
|
|
|
|
|
name = string
|
|
|
|
|
zone_id = string
|
|
|
|
|
})
|
|
|
|
|
description = "Exact existing Route 53 alias target preserved during import. Null resolves the target from Elastic Beanstalk."
|
|
|
|
|
default = null
|
|
|
|
|
}
|
|
|
|
|
|
2026-08-31 11:51:18 -04:00
|
|
|
variable "metadata_before_adoption" {
|
|
|
|
|
description = "Exact current metadata preserved while adoption_complete is false."
|
|
|
|
|
type = object({
|
|
|
|
|
runtime_role_description = string
|
|
|
|
|
runtime_role_tags = map(string)
|
|
|
|
|
instance_profile_tags = map(string)
|
|
|
|
|
app_config_description = string
|
|
|
|
|
app_config_tags = map(string)
|
|
|
|
|
deploy_role_description = string
|
|
|
|
|
deploy_role_tags = map(string)
|
|
|
|
|
environment_tags = map(string)
|
|
|
|
|
})
|
|
|
|
|
}
|