mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 03:43:11 +00:00
chore(terraform): complete staging environment adoption (#156)
* chore(terraform): complete staging environment adoption * test(terraform): include deploy SSM parameters in the import ownership boundary
This commit is contained in:
parent
facc6ef71e
commit
9eb51b528f
4 changed files with 35 additions and 6 deletions
|
|
@ -9,6 +9,10 @@ COMMON_RESOURCES = {
|
||||||
"module.environment.aws_iam_role_policy.runtime_app_config": "aws_iam_role_policy",
|
"module.environment.aws_iam_role_policy.runtime_app_config": "aws_iam_role_policy",
|
||||||
"module.environment.aws_iam_role_policy_attachment.web_tier": "aws_iam_role_policy_attachment",
|
"module.environment.aws_iam_role_policy_attachment.web_tier": "aws_iam_role_policy_attachment",
|
||||||
"module.environment.aws_secretsmanager_secret.app_config": "aws_secretsmanager_secret",
|
"module.environment.aws_secretsmanager_secret.app_config": "aws_secretsmanager_secret",
|
||||||
|
"module.environment.aws_ssm_parameter.deploy_application_name": "aws_ssm_parameter",
|
||||||
|
"module.environment.aws_ssm_parameter.deploy_artifacts_bucket": "aws_ssm_parameter",
|
||||||
|
"module.environment.aws_ssm_parameter.deploy_environment_name": "aws_ssm_parameter",
|
||||||
|
"module.environment.aws_ssm_parameter.deploy_smoke_url": "aws_ssm_parameter",
|
||||||
}
|
}
|
||||||
|
|
||||||
REQUIRED_RESOURCES = {
|
REQUIRED_RESOURCES = {
|
||||||
|
|
@ -52,6 +56,18 @@ DEV_IMPORT_IDS = {
|
||||||
"module.environment.aws_route53_record.api_alias[0]": (
|
"module.environment.aws_route53_record.api_alias[0]": (
|
||||||
"Z07671212N75U4YLPWZR8_api.dev.seahaven.com_A"
|
"Z07671212N75U4YLPWZR8_api.dev.seahaven.com_A"
|
||||||
),
|
),
|
||||||
|
"module.environment.aws_ssm_parameter.deploy_application_name": (
|
||||||
|
"/shoc-backend/dev/deploy/application-name"
|
||||||
|
),
|
||||||
|
"module.environment.aws_ssm_parameter.deploy_artifacts_bucket": (
|
||||||
|
"/shoc-backend/dev/deploy/artifacts-bucket"
|
||||||
|
),
|
||||||
|
"module.environment.aws_ssm_parameter.deploy_environment_name": (
|
||||||
|
"/shoc-backend/dev/deploy/environment-name"
|
||||||
|
),
|
||||||
|
"module.environment.aws_ssm_parameter.deploy_smoke_url": (
|
||||||
|
"/shoc-backend/dev/deploy/smoke-url"
|
||||||
|
),
|
||||||
}
|
}
|
||||||
|
|
||||||
DEV_IMPORT_BASELINE = {
|
DEV_IMPORT_BASELINE = {
|
||||||
|
|
@ -92,6 +108,18 @@ STAGING_IMPORT_IDS = {
|
||||||
"module.environment.aws_route53_record.api_cname[0]": (
|
"module.environment.aws_route53_record.api_cname[0]": (
|
||||||
"Z02602739VQWBWCAGXP4_api.staging.seahaven.com_CNAME"
|
"Z02602739VQWBWCAGXP4_api.staging.seahaven.com_CNAME"
|
||||||
),
|
),
|
||||||
|
"module.environment.aws_ssm_parameter.deploy_application_name": (
|
||||||
|
"/shoc-backend/staging/deploy/application-name"
|
||||||
|
),
|
||||||
|
"module.environment.aws_ssm_parameter.deploy_artifacts_bucket": (
|
||||||
|
"/shoc-backend/staging/deploy/artifacts-bucket"
|
||||||
|
),
|
||||||
|
"module.environment.aws_ssm_parameter.deploy_environment_name": (
|
||||||
|
"/shoc-backend/staging/deploy/environment-name"
|
||||||
|
),
|
||||||
|
"module.environment.aws_ssm_parameter.deploy_smoke_url": (
|
||||||
|
"/shoc-backend/staging/deploy/smoke-url"
|
||||||
|
),
|
||||||
}
|
}
|
||||||
|
|
||||||
STAGING_IMPORT_BASELINE = {
|
STAGING_IMPORT_BASELINE = {
|
||||||
|
|
|
||||||
|
|
@ -37,8 +37,8 @@ only explicitly allowlisted ownership metadata and the narrowed dev deploy S3
|
||||||
policy.
|
policy.
|
||||||
|
|
||||||
The GitHub Environment **variable** `DEPLOY_ROLE_ARN` is the OIDC role used
|
The GitHub Environment **variable** `DEPLOY_ROLE_ARN` is the OIDC role used
|
||||||
by application CD after cutover. Adoption may still have the older
|
by application CD. Environment secrets `TF_API_TOKEN` and
|
||||||
`AWS_DEPLOY_ROLE_ARN` secret until that cutover.
|
`AWS_DEPLOY_ROLE_ARN` were removed at cutover.
|
||||||
|
|
||||||
## Local validation
|
## Local validation
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -142,8 +142,9 @@ cut from **Actions → Release** (`environment`, `bump`, `message`). That
|
||||||
workflow waits for CI, tags `vX.Y.Z-staging` from main HEAD with
|
workflow waits for CI, tags `vX.Y.Z-staging` from main HEAD with
|
||||||
`GITHUB_TOKEN`, then calls deploy. Do not cut prod yet; leave
|
`GITHUB_TOKEN`, then calls deploy. Do not cut prod yet; leave
|
||||||
`PROD_APP_CD_ENABLED` unset and do not create the `prod` GitHub Environment.
|
`PROD_APP_CD_ENABLED` unset and do not create the `prod` GitHub Environment.
|
||||||
Staging remains `adoption_complete=false` with a pinned API CNAME until its
|
Staging import is proven after the first GitHub-owned zip
|
||||||
import apply is proven after the first `vX.Y.Z-staging` GitHub-owned zip.
|
(`v0.0.1-staging`). Terraform now manages the declared Elastic Beanstalk
|
||||||
|
settings. The API CNAME stays pinned to the imported ALB target.
|
||||||
|
|
||||||
HCP workspaces stay VCS-driven with auto-apply on after cutover. Speculative
|
HCP workspaces stay VCS-driven with auto-apply on after cutover. Speculative
|
||||||
plans on every PR are the infra gate. Do not point `TFC_AWS_*` at
|
plans on every PR are the infra gate. Do not point `TFC_AWS_*` at
|
||||||
|
|
|
||||||
|
|
@ -26,8 +26,8 @@ module "environment" {
|
||||||
aws_account_id = local.aws_account_id
|
aws_account_id = local.aws_account_id
|
||||||
aws_region = local.aws_region
|
aws_region = local.aws_region
|
||||||
environment = "staging"
|
environment = "staging"
|
||||||
adoption_complete = false
|
adoption_complete = true
|
||||||
manage_eb_settings = false
|
manage_eb_settings = true
|
||||||
eb_application_name = local.eb_application_name
|
eb_application_name = local.eb_application_name
|
||||||
eb_environment_name = local.eb_environment_name
|
eb_environment_name = local.eb_environment_name
|
||||||
eb_environment_id = local.eb_environment_id
|
eb_environment_id = local.eb_environment_id
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue