fix(terraform): preserve dev release permissions

This commit is contained in:
Adam Moussa 2026-08-31 14:47:58 -04:00
parent e25a936da4
commit 3b87bf64eb
No known key found for this signature in database
3 changed files with 17 additions and 13 deletions

View file

@ -96,7 +96,8 @@ tf-poc rehearsal has completed both phases and therefore pins
4. Apply the no-op import only after review. 4. Apply the no-op import only after review.
5. Change the environment root to `adoption_complete=true` and 5. Change the environment root to `adoption_complete=true` and
`manage_eb_settings=true` in a reviewed code change, then review the `manage_eb_settings=true` in a reviewed code change, then review the
controlled in-place role, policy, secret, and Elastic Beanstalk update: controlled in-place role metadata, secret metadata, and Elastic Beanstalk
update:
```bash ```bash
# Dev example. Omit any address that is not updating. # Dev example. Omit any address that is not updating.
@ -104,7 +105,6 @@ tf-poc rehearsal has completed both phases and therefore pins
--allow-update-address module.environment.aws_iam_instance_profile.runtime \ --allow-update-address module.environment.aws_iam_instance_profile.runtime \
--allow-update-address module.environment.aws_iam_role.runtime \ --allow-update-address module.environment.aws_iam_role.runtime \
--allow-update-address module.environment.aws_iam_role.github_deploy \ --allow-update-address module.environment.aws_iam_role.github_deploy \
--allow-update-address module.environment.aws_iam_role_policy.github_deploy \
--allow-update-address module.environment.aws_secretsmanager_secret.app_config \ --allow-update-address module.environment.aws_secretsmanager_secret.app_config \
--allow-update-address module.environment.aws_elastic_beanstalk_environment.this --allow-update-address module.environment.aws_elastic_beanstalk_environment.this
``` ```
@ -122,14 +122,15 @@ both resources from CloudFormation ownership without deleting them. Never use
`ManageGithubDeployRole=true` again after that transfer. `ManageGithubDeployRole=true` again after that transfer.
The reviewed `adoption_complete=true` change updates ownership tags on IAM The reviewed `adoption_complete=true` change updates ownership tags on IAM
roles, instance profiles, and app-config secrets, and narrows the dev role to roles, instance profiles, and app-config secrets. Dev retains the proven GitHub
the staging-style S3 bucket and application prefix. Elastic Beanstalk Elastic Beanstalk release policy until application CD is migrated in a separate
environment tags remain at their imported values. EB accepts an added reviewed change; infrastructure adoption must not silently break the current
`ManagedBy` tag request but can fail the asynchronous service-managed manual release path. Elastic Beanstalk environment tags remain at their imported
CloudFormation propagation after Terraform reports success. Terraform still values. Terraform manages the declared EB settings. Secret values remain
manages the declared EB settings. Deploy-role descriptions and immutable out-of-band even after the secret shell receives `ManagedBy=terraform`.
`HcpTerraformWorkspace` tags remain unchanged. Read-only AWS APIs retain Deploy-role descriptions and immutable `HcpTerraformWorkspace` tags remain
`Resource = "*"` only where AWS does not support resource-level permissions. unchanged. Read-only AWS APIs retain `Resource = "*"` only where AWS does not
support resource-level permissions.
## POC retained identifiers ## POC retained identifiers

View file

@ -9,7 +9,7 @@ locals {
environment_arn = "arn:aws:elasticbeanstalk:${var.aws_region}:${var.aws_account_id}:environment/${var.eb_application_name}/${var.eb_environment_name}" environment_arn = "arn:aws:elasticbeanstalk:${var.aws_region}:${var.aws_account_id}:environment/${var.eb_application_name}/${var.eb_environment_name}"
environment_stack_name = "awseb-${var.eb_environment_id}-stack" environment_stack_name = "awseb-${var.eb_environment_id}-stack"
eb_bucket_name = "elasticbeanstalk-${var.aws_region}-${var.aws_account_id}" eb_bucket_name = "elasticbeanstalk-${var.aws_region}-${var.aws_account_id}"
use_legacy_s3_policy = !var.adoption_complete && var.legacy_dev_s3_policy use_legacy_s3_policy = var.legacy_dev_s3_policy
app_config_secret_pattern = "arn:aws:secretsmanager:${var.aws_region}:${var.aws_account_id}:secret:${var.app_config_secret_name}-*" app_config_secret_pattern = "arn:aws:secretsmanager:${var.aws_region}:${var.aws_account_id}:secret:${var.app_config_secret_name}-*"
} }
@ -141,6 +141,8 @@ resource "aws_iam_instance_profile" "runtime" {
} }
resource "aws_secretsmanager_secret" "app_config" { resource "aws_secretsmanager_secret" "app_config" {
# Terraform owns the secret shell and metadata only. Values remain out of
# band and must never be declared in this resource or its callers.
name = var.app_config_secret_name name = var.app_config_secret_name
description = var.metadata_before_adoption.app_config_description description = var.metadata_before_adoption.app_config_description
tags = var.adoption_complete ? merge(var.metadata_before_adoption.app_config_tags, { ManagedBy = "terraform" }) : var.metadata_before_adoption.app_config_tags tags = var.adoption_complete ? merge(var.metadata_before_adoption.app_config_tags, { ManagedBy = "terraform" }) : var.metadata_before_adoption.app_config_tags

View file

@ -190,8 +190,9 @@ variable "github_deploy_policy_name" {
} }
variable "legacy_dev_s3_policy" { variable "legacy_dev_s3_policy" {
type = bool type = bool
default = false description = "Retain the proven GitHub Elastic Beanstalk release policy until application CD is migrated separately."
default = false
} }
variable "hosted_zone_id" { variable "hosted_zone_id" {