2026-08-31 11:51:18 -04:00
variable " aws_account_id " {
type = string
}
variable " aws_region " {
type = string
}
variable " environment " {
type = string
validation {
2026-09-03 10:40:32 -04:00
condition = contains ( [ " dev " , " staging " ] , var . environment )
error_message = " environment must be dev or staging. "
2026-08-31 11:51:18 -04:00
}
}
variable " adoption_complete " {
type = bool
description = " False preserves existing ownership metadata. True changes only documented metadata and the dev deploy S3 policy. "
default = false
}
2026-08-31 14:05:46 -04:00
variable " manage_eb_settings " {
type = bool
description = " False omits managed Elastic Beanstalk settings during the import-only phase. "
default = true
}
2026-08-31 11:51:18 -04:00
variable " eb_application_name " {
type = string
}
variable " eb_environment_name " {
type = string
}
variable " eb_environment_id " {
type = string
2026-09-03 10:40:32 -04:00
description = " Existing Elastic Beanstalk environment ID. "
2026-08-31 11:51:18 -04:00
}
variable " platform_arn " {
type = string
}
variable " vpc_id " {
type = string
}
variable " instance_subnet_ids " {
type = list ( string )
}
variable " load_balancer_subnet_ids " {
type = list ( string )
}
variable " instance_security_group_id " {
type = string
default = null
description = " Pinned existing instance SG setting. Null lets Elastic Beanstalk retain its provider-managed generated SG. "
}
variable " eb_service_role_name " {
type = string
}
variable " shared_certificate_arn " {
type = string
2026-09-03 10:40:32 -04:00
description = " Existing shared certificate for dev/staging "
2026-08-31 11:51:18 -04:00
}
2026-09-04 14:11:32 -03:00
variable " sentry_dsn " {
type = string
description = " Sentry DSN for error and transaction monitoring. The DSN is public ingestion configuration, not a secret: it is safe to expose and is delivered as a plain Elastic Beanstalk environment setting instead of Secrets Manager. "
}
2026-08-31 11:51:18 -04:00
variable " runtime_role_name " {
type = string
}
variable " runtime_app_config_policy_name " {
type = string
}
variable " runtime_webhook_policy_name " {
type = string
default = null
}
variable " runtime_dynamo_policy_name " {
type = string
default = null
}
variable " permissions_boundary_arn " {
type = string
}
variable " github_deploy_permissions_boundary_arn " {
type = string
description = " Exact org-baseline permissions boundary ARN for the environment GitHub deploy role. "
validation {
condition = can ( regex (
" ^arn:aws:iam:: ${ var . aws_account_id } :policy/shoc-backend- ${ var . environment } -deploy-boundary $ " ,
var . github_deploy_permissions_boundary_arn ,
) )
error_message = " github_deploy_permissions_boundary_arn must be the exact environment deploy boundary ARN. "
}
}
variable " app_config_secret_name " {
type = string
}
variable " app_config_json_keys " {
type = set ( string )
description = " Exact JSON keys exposed through Elastic Beanstalk environmentsecrets. "
}
variable " app_config_policy_sid " {
type = string
default = null
}
variable " webhook_secret_arn " {
type = string
default = null
}
variable " work_order_webhook_enabled " {
type = bool
default = true
}
variable " webhook_read_policy_sid " {
type = string
default = null
}
variable " webhook_decrypt_policy_sid " {
type = string
default = null
}
variable " dynamo_reader_role_arn " {
type = string
default = null
2026-09-03 10:40:32 -04:00
description = " Dev-only cross-account role. Null for staging. "
2026-08-31 11:51:18 -04:00
}
variable " dynamo_policy_sid " {
type = string
default = null
}
check " dynamo_policy_pair " {
assert {
condition = ( var . runtime_dynamo_policy_name == null ) = = ( var . dynamo_reader_role_arn == null )
error_message = " runtime_dynamo_policy_name and dynamo_reader_role_arn must both be set or both be null. "
}
}
check " webhook_policy_pair " {
assert {
condition = (
var . work_order_webhook_enabled &&
var . runtime_webhook_policy_name ! = null &&
var . webhook_secret_arn ! = null
) | | (
! var . work_order_webhook_enabled &&
var . runtime_webhook_policy_name == null &&
var . webhook_secret_arn == null
)
error_message = " Enabled webhooks require a runtime policy and secret ARN; disabled webhooks require both to be null. "
}
}
variable " github_repo " {
type = string
}
variable " github_environment " {
type = string
}
variable " github_deploy_role_name " {
type = string
}
variable " github_deploy_policy_name " {
type = string
}
variable " legacy_dev_s3_policy " {
2026-08-31 19:18:44 -04:00
type = bool
description = " Retain the proven GitHub Elastic Beanstalk release policy until application CD is migrated separately. "
default = false
2026-08-31 11:51:18 -04:00
}
2026-09-16 14:02:46 -04:00
variable " smoke_url " {
type = string
description = " HTTPS origin used by post-deploy smoke checks. Written to SSM for GitHub Actions. "
2026-09-03 10:12:06 -04:00
}
2026-08-31 11:51:18 -04:00
variable " hosted_zone_id " {
type = string
}
variable " api_domain " {
type = string
}
variable " api_record_type " {
type = string
validation {
condition = contains ( [ " A " , " CNAME " ] , var . api_record_type )
error_message = " api_record_type must be A or CNAME. "
}
}
2026-08-31 14:05:46 -04:00
variable " api_alias_target " {
type = object ( {
name = string
zone_id = string
} )
description = " Exact existing Route 53 alias target preserved during import. Null resolves the target from Elastic Beanstalk. "
default = null
}
2026-09-16 15:52:02 -03:00
variable " api_cname_target " {
type = string
description = " Exact existing Route 53 CNAME target preserved during import. Null resolves the target from Elastic Beanstalk. "
default = null
}
2026-08-31 11:51:18 -04:00
variable " metadata_before_adoption " {
description = " Exact current metadata preserved while adoption_complete is false. "
type = object ( {
runtime_role_description = string
runtime_role_tags = map ( string )
instance_profile_tags = map ( string )
app_config_description = string
app_config_tags = map ( string )
deploy_role_description = string
deploy_role_tags = map ( string )
environment_tags = map ( string )
} )
}