mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 06:03:12 +00:00
49 lines
1.9 KiB
Markdown
49 lines
1.9 KiB
Markdown
|
|
# Terraform deployment infrastructure
|
||
|
|
|
||
|
|
Terraform adopts the environment-owned Sea Haven backend infrastructure while
|
||
|
|
keeping shared and Elastic Beanstalk-generated resources outside state.
|
||
|
|
|
||
|
|
## Roots
|
||
|
|
|
||
|
|
- `live/dev/` imports the existing dev environment-owned resources.
|
||
|
|
- `live/staging/` imports the existing staging environment-owned resources.
|
||
|
|
- `live/tf-poc/` manages the retained import-rehearsal environment after its
|
||
|
|
completed transfer from CloudFormation.
|
||
|
|
|
||
|
|
Shared RDS, application, VPC, subnet, service-role, shared-certificate, and
|
||
|
|
Elastic Beanstalk-generated inventory remains data-only or provider-managed.
|
||
|
|
Secret metadata is managed, but secret values are never authored in Terraform
|
||
|
|
configuration. Elastic Beanstalk receives secret values through
|
||
|
|
`environmentsecrets` ARN/key references.
|
||
|
|
|
||
|
|
## HCP credentials
|
||
|
|
|
||
|
|
Org-baseline CloudFormation owns the HCP Terraform plan/apply roles and their
|
||
|
|
manager tags. The retired `shoc-backend-bootstrap` workspace and backend
|
||
|
|
bootstrap root were removed after the four dev/staging roles transferred
|
||
|
|
without replacement.
|
||
|
|
|
||
|
|
## Environment adoption
|
||
|
|
|
||
|
|
Follow [`live/README.md`](live/README.md). For each dev/staging adoption, the
|
||
|
|
first plan must import the environment-owned resources with zero create,
|
||
|
|
update, delete, or replacement actions. The second reviewed phase may update
|
||
|
|
only explicitly allowlisted ownership metadata and the narrowed dev deploy S3
|
||
|
|
policy.
|
||
|
|
|
||
|
|
The GitHub Environment secret `AWS_DEPLOY_ROLE_ARN` retains the existing role
|
||
|
|
ARN throughout adoption.
|
||
|
|
|
||
|
|
## Local validation
|
||
|
|
|
||
|
|
```bash
|
||
|
|
terraform -chdir=terraform fmt -check -recursive
|
||
|
|
terraform -chdir=terraform/live/dev init -backend=false
|
||
|
|
terraform -chdir=terraform/live/dev validate
|
||
|
|
terraform -chdir=terraform/live/staging init -backend=false
|
||
|
|
terraform -chdir=terraform/live/staging validate
|
||
|
|
terraform -chdir=terraform/live/tf-poc init -backend=false
|
||
|
|
terraform -chdir=terraform/live/tf-poc validate
|
||
|
|
python scripts/test-terraform-import-plan-check.py
|
||
|
|
```
|