chore(terraform): complete staging environment adoption (#156)
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run

* chore(terraform): complete staging environment adoption

* test(terraform): include deploy SSM parameters in the import ownership boundary
This commit is contained in:
Adam Moussa 2026-09-18 15:13:18 -04:00 • committed by GitHub
parent facc6ef71e
commit 9eb51b528f
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
4 changed files with 35 additions and 6 deletions

View file

@ -9,6 +9,10 @@ COMMON_RESOURCES = {
"module.environment.aws_iam_role_policy.runtime_app_config": "aws_iam_role_policy",
"module.environment.aws_iam_role_policy_attachment.web_tier": "aws_iam_role_policy_attachment",
"module.environment.aws_secretsmanager_secret.app_config": "aws_secretsmanager_secret",
"module.environment.aws_ssm_parameter.deploy_application_name": "aws_ssm_parameter",
"module.environment.aws_ssm_parameter.deploy_artifacts_bucket": "aws_ssm_parameter",
"module.environment.aws_ssm_parameter.deploy_environment_name": "aws_ssm_parameter",
"module.environment.aws_ssm_parameter.deploy_smoke_url": "aws_ssm_parameter",
}
REQUIRED_RESOURCES = {
@ -52,6 +56,18 @@ DEV_IMPORT_IDS = {
"module.environment.aws_route53_record.api_alias[0]": (
"Z07671212N75U4YLPWZR8_api.dev.seahaven.com_A"
),
"module.environment.aws_ssm_parameter.deploy_application_name": (
"/shoc-backend/dev/deploy/application-name"
),
"module.environment.aws_ssm_parameter.deploy_artifacts_bucket": (
"/shoc-backend/dev/deploy/artifacts-bucket"
),
"module.environment.aws_ssm_parameter.deploy_environment_name": (
"/shoc-backend/dev/deploy/environment-name"
),
"module.environment.aws_ssm_parameter.deploy_smoke_url": (
"/shoc-backend/dev/deploy/smoke-url"
),
}
DEV_IMPORT_BASELINE = {
@ -92,6 +108,18 @@ STAGING_IMPORT_IDS = {
"module.environment.aws_route53_record.api_cname[0]": (
"Z02602739VQWBWCAGXP4_api.staging.seahaven.com_CNAME"
),
"module.environment.aws_ssm_parameter.deploy_application_name": (
"/shoc-backend/staging/deploy/application-name"
),
"module.environment.aws_ssm_parameter.deploy_artifacts_bucket": (
"/shoc-backend/staging/deploy/artifacts-bucket"
),
"module.environment.aws_ssm_parameter.deploy_environment_name": (
"/shoc-backend/staging/deploy/environment-name"
),
"module.environment.aws_ssm_parameter.deploy_smoke_url": (
"/shoc-backend/staging/deploy/smoke-url"
),
}
STAGING_IMPORT_BASELINE = {

View file

@ -37,8 +37,8 @@ only explicitly allowlisted ownership metadata and the narrowed dev deploy S3
policy.
The GitHub Environment **variable** `DEPLOY_ROLE_ARN` is the OIDC role used
by application CD after cutover. Adoption may still have the older
`AWS_DEPLOY_ROLE_ARN` secret until that cutover.
by application CD. Environment secrets `TF_API_TOKEN` and
`AWS_DEPLOY_ROLE_ARN` were removed at cutover.
## Local validation

View file

@ -142,8 +142,9 @@ cut from **Actions → Release** (`environment`, `bump`, `message`). That
workflow waits for CI, tags `vX.Y.Z-staging` from main HEAD with
`GITHUB_TOKEN`, then calls deploy. Do not cut prod yet; leave
`PROD_APP_CD_ENABLED` unset and do not create the `prod` GitHub Environment.
Staging remains `adoption_complete=false` with a pinned API CNAME until its
import apply is proven after the first `vX.Y.Z-staging` GitHub-owned zip.
Staging import is proven after the first GitHub-owned zip
(`v0.0.1-staging`). Terraform now manages the declared Elastic Beanstalk
settings. The API CNAME stays pinned to the imported ALB target.
HCP workspaces stay VCS-driven with auto-apply on after cutover. Speculative
plans on every PR are the infra gate. Do not point `TFC_AWS_*` at

View file

@ -26,8 +26,8 @@ module "environment" {
aws_account_id = local.aws_account_id
aws_region = local.aws_region
environment = "staging"
adoption_complete = false
manage_eb_settings = false
adoption_complete = true
manage_eb_settings = true
eb_application_name = local.eb_application_name
eb_environment_name = local.eb_environment_name
eb_environment_id = local.eb_environment_id