mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 06:03:12 +00:00
fix(terraform): preserve dev release permissions
This commit is contained in:
parent
e25a936da4
commit
3b87bf64eb
3 changed files with 17 additions and 13 deletions
|
|
@ -96,7 +96,8 @@ tf-poc rehearsal has completed both phases and therefore pins
|
|||
4. Apply the no-op import only after review.
|
||||
5. Change the environment root to `adoption_complete=true` and
|
||||
`manage_eb_settings=true` in a reviewed code change, then review the
|
||||
controlled in-place role, policy, secret, and Elastic Beanstalk update:
|
||||
controlled in-place role metadata, secret metadata, and Elastic Beanstalk
|
||||
update:
|
||||
|
||||
```bash
|
||||
# Dev example. Omit any address that is not updating.
|
||||
|
|
@ -104,7 +105,6 @@ tf-poc rehearsal has completed both phases and therefore pins
|
|||
--allow-update-address module.environment.aws_iam_instance_profile.runtime \
|
||||
--allow-update-address module.environment.aws_iam_role.runtime \
|
||||
--allow-update-address module.environment.aws_iam_role.github_deploy \
|
||||
--allow-update-address module.environment.aws_iam_role_policy.github_deploy \
|
||||
--allow-update-address module.environment.aws_secretsmanager_secret.app_config \
|
||||
--allow-update-address module.environment.aws_elastic_beanstalk_environment.this
|
||||
```
|
||||
|
|
@ -122,14 +122,15 @@ both resources from CloudFormation ownership without deleting them. Never use
|
|||
`ManageGithubDeployRole=true` again after that transfer.
|
||||
|
||||
The reviewed `adoption_complete=true` change updates ownership tags on IAM
|
||||
roles, instance profiles, and app-config secrets, and narrows the dev role to
|
||||
the staging-style S3 bucket and application prefix. Elastic Beanstalk
|
||||
environment tags remain at their imported values. EB accepts an added
|
||||
`ManagedBy` tag request but can fail the asynchronous service-managed
|
||||
CloudFormation propagation after Terraform reports success. Terraform still
|
||||
manages the declared EB settings. Deploy-role descriptions and immutable
|
||||
`HcpTerraformWorkspace` tags remain unchanged. Read-only AWS APIs retain
|
||||
`Resource = "*"` only where AWS does not support resource-level permissions.
|
||||
roles, instance profiles, and app-config secrets. Dev retains the proven GitHub
|
||||
Elastic Beanstalk release policy until application CD is migrated in a separate
|
||||
reviewed change; infrastructure adoption must not silently break the current
|
||||
manual release path. Elastic Beanstalk environment tags remain at their imported
|
||||
values. Terraform manages the declared EB settings. Secret values remain
|
||||
out-of-band even after the secret shell receives `ManagedBy=terraform`.
|
||||
Deploy-role descriptions and immutable `HcpTerraformWorkspace` tags remain
|
||||
unchanged. Read-only AWS APIs retain `Resource = "*"` only where AWS does not
|
||||
support resource-level permissions.
|
||||
|
||||
## POC retained identifiers
|
||||
|
||||
|
|
|
|||
|
|
@ -9,7 +9,7 @@ locals {
|
|||
environment_arn = "arn:aws:elasticbeanstalk:${var.aws_region}:${var.aws_account_id}:environment/${var.eb_application_name}/${var.eb_environment_name}"
|
||||
environment_stack_name = "awseb-${var.eb_environment_id}-stack"
|
||||
eb_bucket_name = "elasticbeanstalk-${var.aws_region}-${var.aws_account_id}"
|
||||
use_legacy_s3_policy = !var.adoption_complete && var.legacy_dev_s3_policy
|
||||
use_legacy_s3_policy = var.legacy_dev_s3_policy
|
||||
app_config_secret_pattern = "arn:aws:secretsmanager:${var.aws_region}:${var.aws_account_id}:secret:${var.app_config_secret_name}-*"
|
||||
}
|
||||
|
||||
|
|
@ -141,6 +141,8 @@ resource "aws_iam_instance_profile" "runtime" {
|
|||
}
|
||||
|
||||
resource "aws_secretsmanager_secret" "app_config" {
|
||||
# Terraform owns the secret shell and metadata only. Values remain out of
|
||||
# band and must never be declared in this resource or its callers.
|
||||
name = var.app_config_secret_name
|
||||
description = var.metadata_before_adoption.app_config_description
|
||||
tags = var.adoption_complete ? merge(var.metadata_before_adoption.app_config_tags, { ManagedBy = "terraform" }) : var.metadata_before_adoption.app_config_tags
|
||||
|
|
|
|||
|
|
@ -190,8 +190,9 @@ variable "github_deploy_policy_name" {
|
|||
}
|
||||
|
||||
variable "legacy_dev_s3_policy" {
|
||||
type = bool
|
||||
default = false
|
||||
type = bool
|
||||
description = "Retain the proven GitHub Elastic Beanstalk release policy until application CD is migrated separately."
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "hosted_zone_id" {
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue