diff --git a/terraform/live/README.md b/terraform/live/README.md index 0a03f2d..c6e4880 100644 --- a/terraform/live/README.md +++ b/terraform/live/README.md @@ -96,7 +96,8 @@ tf-poc rehearsal has completed both phases and therefore pins 4. Apply the no-op import only after review. 5. Change the environment root to `adoption_complete=true` and `manage_eb_settings=true` in a reviewed code change, then review the - controlled in-place role, policy, secret, and Elastic Beanstalk update: + controlled in-place role metadata, secret metadata, and Elastic Beanstalk + update: ```bash # Dev example. Omit any address that is not updating. @@ -104,7 +105,6 @@ tf-poc rehearsal has completed both phases and therefore pins --allow-update-address module.environment.aws_iam_instance_profile.runtime \ --allow-update-address module.environment.aws_iam_role.runtime \ --allow-update-address module.environment.aws_iam_role.github_deploy \ - --allow-update-address module.environment.aws_iam_role_policy.github_deploy \ --allow-update-address module.environment.aws_secretsmanager_secret.app_config \ --allow-update-address module.environment.aws_elastic_beanstalk_environment.this ``` @@ -122,14 +122,15 @@ both resources from CloudFormation ownership without deleting them. Never use `ManageGithubDeployRole=true` again after that transfer. The reviewed `adoption_complete=true` change updates ownership tags on IAM -roles, instance profiles, and app-config secrets, and narrows the dev role to -the staging-style S3 bucket and application prefix. Elastic Beanstalk -environment tags remain at their imported values. EB accepts an added -`ManagedBy` tag request but can fail the asynchronous service-managed -CloudFormation propagation after Terraform reports success. Terraform still -manages the declared EB settings. Deploy-role descriptions and immutable -`HcpTerraformWorkspace` tags remain unchanged. Read-only AWS APIs retain -`Resource = "*"` only where AWS does not support resource-level permissions. +roles, instance profiles, and app-config secrets. Dev retains the proven GitHub +Elastic Beanstalk release policy until application CD is migrated in a separate +reviewed change; infrastructure adoption must not silently break the current +manual release path. Elastic Beanstalk environment tags remain at their imported +values. Terraform manages the declared EB settings. Secret values remain +out-of-band even after the secret shell receives `ManagedBy=terraform`. +Deploy-role descriptions and immutable `HcpTerraformWorkspace` tags remain +unchanged. Read-only AWS APIs retain `Resource = "*"` only where AWS does not +support resource-level permissions. ## POC retained identifiers diff --git a/terraform/live/modules/environment-owned/main.tf b/terraform/live/modules/environment-owned/main.tf index d4e4f27..3a2522e 100644 --- a/terraform/live/modules/environment-owned/main.tf +++ b/terraform/live/modules/environment-owned/main.tf @@ -9,7 +9,7 @@ locals { environment_arn = "arn:aws:elasticbeanstalk:${var.aws_region}:${var.aws_account_id}:environment/${var.eb_application_name}/${var.eb_environment_name}" environment_stack_name = "awseb-${var.eb_environment_id}-stack" eb_bucket_name = "elasticbeanstalk-${var.aws_region}-${var.aws_account_id}" - use_legacy_s3_policy = !var.adoption_complete && var.legacy_dev_s3_policy + use_legacy_s3_policy = var.legacy_dev_s3_policy app_config_secret_pattern = "arn:aws:secretsmanager:${var.aws_region}:${var.aws_account_id}:secret:${var.app_config_secret_name}-*" } @@ -141,6 +141,8 @@ resource "aws_iam_instance_profile" "runtime" { } resource "aws_secretsmanager_secret" "app_config" { + # Terraform owns the secret shell and metadata only. Values remain out of + # band and must never be declared in this resource or its callers. name = var.app_config_secret_name description = var.metadata_before_adoption.app_config_description tags = var.adoption_complete ? merge(var.metadata_before_adoption.app_config_tags, { ManagedBy = "terraform" }) : var.metadata_before_adoption.app_config_tags diff --git a/terraform/live/modules/environment-owned/variables.tf b/terraform/live/modules/environment-owned/variables.tf index 49a6066..ecad6eb 100644 --- a/terraform/live/modules/environment-owned/variables.tf +++ b/terraform/live/modules/environment-owned/variables.tf @@ -190,8 +190,9 @@ variable "github_deploy_policy_name" { } variable "legacy_dev_s3_policy" { - type = bool - default = false + type = bool + description = "Retain the proven GitHub Elastic Beanstalk release policy until application CD is migrated separately." + default = false } variable "hosted_zone_id" {