From 9eb51b528f9a41aafbd85a9dda79c260c9fbc15c Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 18 Sep 2026 15:13:18 -0400 Subject: [PATCH] chore(terraform): complete staging environment adoption (#156) * chore(terraform): complete staging environment adoption * test(terraform): include deploy SSM parameters in the import ownership boundary --- scripts/terraform_import_plan_resources.py | 28 ++++++++++++++++++++++ terraform/README.md | 4 ++-- terraform/live/README.md | 5 ++-- terraform/live/staging/main.tf | 4 ++-- 4 files changed, 35 insertions(+), 6 deletions(-) diff --git a/scripts/terraform_import_plan_resources.py b/scripts/terraform_import_plan_resources.py index dc66365..2feb00d 100644 --- a/scripts/terraform_import_plan_resources.py +++ b/scripts/terraform_import_plan_resources.py @@ -9,6 +9,10 @@ COMMON_RESOURCES = { "module.environment.aws_iam_role_policy.runtime_app_config": "aws_iam_role_policy", "module.environment.aws_iam_role_policy_attachment.web_tier": "aws_iam_role_policy_attachment", "module.environment.aws_secretsmanager_secret.app_config": "aws_secretsmanager_secret", + "module.environment.aws_ssm_parameter.deploy_application_name": "aws_ssm_parameter", + "module.environment.aws_ssm_parameter.deploy_artifacts_bucket": "aws_ssm_parameter", + "module.environment.aws_ssm_parameter.deploy_environment_name": "aws_ssm_parameter", + "module.environment.aws_ssm_parameter.deploy_smoke_url": "aws_ssm_parameter", } REQUIRED_RESOURCES = { @@ -52,6 +56,18 @@ DEV_IMPORT_IDS = { "module.environment.aws_route53_record.api_alias[0]": ( "Z07671212N75U4YLPWZR8_api.dev.seahaven.com_A" ), + "module.environment.aws_ssm_parameter.deploy_application_name": ( + "/shoc-backend/dev/deploy/application-name" + ), + "module.environment.aws_ssm_parameter.deploy_artifacts_bucket": ( + "/shoc-backend/dev/deploy/artifacts-bucket" + ), + "module.environment.aws_ssm_parameter.deploy_environment_name": ( + "/shoc-backend/dev/deploy/environment-name" + ), + "module.environment.aws_ssm_parameter.deploy_smoke_url": ( + "/shoc-backend/dev/deploy/smoke-url" + ), } DEV_IMPORT_BASELINE = { @@ -92,6 +108,18 @@ STAGING_IMPORT_IDS = { "module.environment.aws_route53_record.api_cname[0]": ( "Z02602739VQWBWCAGXP4_api.staging.seahaven.com_CNAME" ), + "module.environment.aws_ssm_parameter.deploy_application_name": ( + "/shoc-backend/staging/deploy/application-name" + ), + "module.environment.aws_ssm_parameter.deploy_artifacts_bucket": ( + "/shoc-backend/staging/deploy/artifacts-bucket" + ), + "module.environment.aws_ssm_parameter.deploy_environment_name": ( + "/shoc-backend/staging/deploy/environment-name" + ), + "module.environment.aws_ssm_parameter.deploy_smoke_url": ( + "/shoc-backend/staging/deploy/smoke-url" + ), } STAGING_IMPORT_BASELINE = { diff --git a/terraform/README.md b/terraform/README.md index d4d2023..d11938b 100644 --- a/terraform/README.md +++ b/terraform/README.md @@ -37,8 +37,8 @@ only explicitly allowlisted ownership metadata and the narrowed dev deploy S3 policy. The GitHub Environment **variable** `DEPLOY_ROLE_ARN` is the OIDC role used -by application CD after cutover. Adoption may still have the older -`AWS_DEPLOY_ROLE_ARN` secret until that cutover. +by application CD. Environment secrets `TF_API_TOKEN` and +`AWS_DEPLOY_ROLE_ARN` were removed at cutover. ## Local validation diff --git a/terraform/live/README.md b/terraform/live/README.md index e7630cd..8f3850b 100644 --- a/terraform/live/README.md +++ b/terraform/live/README.md @@ -142,8 +142,9 @@ cut from **Actions → Release** (`environment`, `bump`, `message`). That workflow waits for CI, tags `vX.Y.Z-staging` from main HEAD with `GITHUB_TOKEN`, then calls deploy. Do not cut prod yet; leave `PROD_APP_CD_ENABLED` unset and do not create the `prod` GitHub Environment. -Staging remains `adoption_complete=false` with a pinned API CNAME until its -import apply is proven after the first `vX.Y.Z-staging` GitHub-owned zip. +Staging import is proven after the first GitHub-owned zip +(`v0.0.1-staging`). Terraform now manages the declared Elastic Beanstalk +settings. The API CNAME stays pinned to the imported ALB target. HCP workspaces stay VCS-driven with auto-apply on after cutover. Speculative plans on every PR are the infra gate. Do not point `TFC_AWS_*` at diff --git a/terraform/live/staging/main.tf b/terraform/live/staging/main.tf index 0368da2..cd64267 100644 --- a/terraform/live/staging/main.tf +++ b/terraform/live/staging/main.tf @@ -26,8 +26,8 @@ module "environment" { aws_account_id = local.aws_account_id aws_region = local.aws_region environment = "staging" - adoption_complete = false - manage_eb_settings = false + adoption_complete = true + manage_eb_settings = true eb_application_name = local.eb_application_name eb_environment_name = local.eb_environment_name eb_environment_id = local.eb_environment_id