mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 07:13:12 +00:00
chore(terraform): drop tf-poc from live module and CI
This commit is contained in:
parent
bf83decce3
commit
a478a550d3
8 changed files with 41 additions and 106 deletions
2
.github/workflows/ci.yml
vendored
2
.github/workflows/ci.yml
vendored
|
|
@ -45,7 +45,7 @@ jobs:
|
|||
directories=()
|
||||
case "${{ github.base_ref }}" in
|
||||
dev)
|
||||
directories+=(terraform/live/tf-poc terraform/live/dev)
|
||||
directories+=(terraform/live/dev)
|
||||
;;
|
||||
staging)
|
||||
directories+=(terraform/live/staging)
|
||||
|
|
|
|||
|
|
@ -56,14 +56,14 @@ The script:
|
|||
G10 permits only exact approved resource address/type pairs for the
|
||||
environment-owned boundary: Elastic
|
||||
Beanstalk environment, IAM role/inline policy/managed-policy attachment/
|
||||
instance profile, Secrets Manager secret metadata, Route 53 zone/record, and
|
||||
ACM certificate. Initial mode permits no update. Controlled mode requires one
|
||||
instance profile, Secrets Manager secret metadata, and Route 53 record.
|
||||
Initial mode permits no update. Controlled mode requires one
|
||||
`--allow-update-address` argument per reviewed in-place update. Every invocation
|
||||
also requires `--environment dev`, `--environment staging`, or
|
||||
`--environment tf-poc`; an empty or incomplete environment plan fails.
|
||||
also requires `--environment dev` or `--environment staging`; an empty or
|
||||
incomplete environment plan fails.
|
||||
|
||||
G11 runs `terraform fmt -check -recursive`, `terraform init -backend=false`,
|
||||
and `terraform validate`. PRs to `dev` validate `live/tf-poc` and `live/dev`.
|
||||
and `terraform validate`. PRs to `dev` validate `live/dev`.
|
||||
PRs to `staging` validate only `live/staging`. Org-baseline CloudFormation owns
|
||||
the HCP role substrate, and Terraform owns the dev deploy role, so no backend
|
||||
CDK or bootstrap root remains in the matrix.
|
||||
|
|
|
|||
|
|
@ -23,12 +23,6 @@ REQUIRED_RESOURCES = {
|
|||
"module.environment.aws_iam_role_policy.runtime_webhook[0]": "aws_iam_role_policy",
|
||||
"module.environment.aws_route53_record.api_cname[0]": "aws_route53_record",
|
||||
},
|
||||
"tf-poc": {
|
||||
**COMMON_RESOURCES,
|
||||
"aws_acm_certificate.poc": "aws_acm_certificate",
|
||||
"aws_route53_zone.poc": "aws_route53_zone",
|
||||
"module.environment.aws_route53_record.api_cname[0]": "aws_route53_record",
|
||||
},
|
||||
}
|
||||
|
||||
DEV_IMPORT_IDS = {
|
||||
|
|
|
|||
|
|
@ -186,15 +186,6 @@ def main() -> int:
|
|||
),
|
||||
0,
|
||||
),
|
||||
(
|
||||
"tf-poc controlled update",
|
||||
run_case(
|
||||
"tf-poc",
|
||||
actions_by_address={controlled_address: ["update"]},
|
||||
allowed_updates=(controlled_address,),
|
||||
),
|
||||
0,
|
||||
),
|
||||
(
|
||||
"wrong controlled address",
|
||||
run_case(
|
||||
|
|
@ -255,12 +246,12 @@ def main() -> int:
|
|||
1,
|
||||
),
|
||||
(
|
||||
"live webhook policy in tf-poc",
|
||||
"staging resource in a dev plan",
|
||||
run_case(
|
||||
"tf-poc",
|
||||
"dev",
|
||||
extra_resource=(
|
||||
"module.environment.aws_iam_role_policy.runtime_webhook[0]",
|
||||
"aws_iam_role_policy",
|
||||
"module.environment.aws_route53_record.api_cname[0]",
|
||||
"aws_route53_record",
|
||||
["no-op"],
|
||||
),
|
||||
),
|
||||
|
|
|
|||
|
|
@ -7,8 +7,6 @@ keeping shared and Elastic Beanstalk-generated resources outside state.
|
|||
|
||||
- `live/dev/` imports the existing dev environment-owned resources.
|
||||
- `live/staging/` imports the existing staging environment-owned resources.
|
||||
- `live/tf-poc/` manages the retained import-rehearsal environment after its
|
||||
completed transfer from CloudFormation.
|
||||
|
||||
Shared RDS, application, VPC, subnet, service-role, shared-certificate, and
|
||||
Elastic Beanstalk-generated inventory remains data-only or provider-managed.
|
||||
|
|
@ -42,8 +40,6 @@ terraform -chdir=terraform/live/dev init -backend=false
|
|||
terraform -chdir=terraform/live/dev validate
|
||||
terraform -chdir=terraform/live/staging init -backend=false
|
||||
terraform -chdir=terraform/live/staging validate
|
||||
terraform -chdir=terraform/live/tf-poc init -backend=false
|
||||
terraform -chdir=terraform/live/tf-poc validate
|
||||
python scripts/test-terraform-import-plan-check.py
|
||||
python scripts/test-terraform-release-plan-check.py
|
||||
```
|
||||
|
|
|
|||
|
|
@ -8,10 +8,6 @@ shared or Elastic Beanstalk-generated infrastructure.
|
|||
- `dev/` and `staging/` import the existing EB environment, runtime
|
||||
role/profile/policies, deploy role/policy, app-config secret metadata, and API
|
||||
record.
|
||||
- `tf-poc/` manages the retained rehearsal environment after its completed
|
||||
CloudFormation-to-Terraform transfer, excluding the live-only webhook and
|
||||
Dynamo policies. It also owns the child zone and DNS-validated ACM
|
||||
certificate.
|
||||
- `modules/environment-inventory/` reads and pins only shared resources.
|
||||
- Org-baseline CloudFormation owns the narrowly scoped HCP Terraform plan/apply
|
||||
roles.
|
||||
|
|
@ -19,8 +15,7 @@ shared or Elastic Beanstalk-generated infrastructure.
|
|||
The shared `shoc-backend` Elastic Beanstalk application and
|
||||
`shoc-sqlserver-shared` RDS instance, VPC, subnets, EB service role, shared
|
||||
certificate, shared RDS security group, and EB-generated SG/ALB/ASG/CloudFormation
|
||||
resources must never enter an environment state. The `shoc_tf_poc` SQL catalog
|
||||
is out of band.
|
||||
resources must never enter an environment state.
|
||||
|
||||
Secret values are not Terraform resources, variables, outputs, or managed EB
|
||||
settings. Terraform manages the app-config secret shell and maps approved JSON
|
||||
|
|
@ -78,9 +73,7 @@ Terraform does not perform this pre-import mutation.
|
|||
## Two-phase adoption
|
||||
|
||||
Each dev/staging root pins `adoption_complete=false` in reviewed code until its
|
||||
initial import is proven. It is not an HCP workspace variable. The retained
|
||||
tf-poc rehearsal has completed both phases and therefore pins
|
||||
`adoption_complete=true`.
|
||||
initial import is proven. It is not an HCP workspace variable.
|
||||
|
||||
1. Create the HCP workspace and configure dynamic credentials.
|
||||
2. Run the declarative imports.
|
||||
|
|
@ -169,19 +162,6 @@ This change is the allowed exception that mixes deployable application CD with
|
|||
the Terraform variable that application CD needs. Later PRs must not mix
|
||||
deployable application changes with Terraform or CDK changes.
|
||||
|
||||
## POC retained identifiers
|
||||
|
||||
The tf-poc HCP workspace stores the exact retained environment ID, app-config
|
||||
secret ARN, child-zone ID, and certificate ARN declared in
|
||||
`tf-poc/variables.tf`. The declarative import blocks consumed those identifiers
|
||||
during the completed transfer. Do not guess or replace them, and do not put
|
||||
credentials or secret values in HCP variables.
|
||||
|
||||
ACM DNS validation remains part of the Terraform-owned certificate resource;
|
||||
its generated validation record is not a separate ownership target. The public
|
||||
delegation of `tf-poc.seahaven.com` from `seahaven.com` remains outside this
|
||||
Terraform state.
|
||||
|
||||
## Pinned live identities
|
||||
|
||||
- Dev: workspace `shoc-backend-dev`; EB environment `shoc-backend-dev`
|
||||
|
|
@ -198,5 +178,3 @@ identifiers make accidental cross-environment reuse fail review and planning.
|
|||
- Auto-apply remains off.
|
||||
- Org baseline owns final HCP plan/apply permissions and manager tags.
|
||||
- Every imported Terraform resource has `prevent_destroy`.
|
||||
- The tf-poc CloudFormation creator path was removed after its no-op import,
|
||||
controlled update, and retained-resource ownership transfer completed.
|
||||
|
|
|
|||
|
|
@ -196,7 +196,6 @@ resource "aws_iam_role" "github_deploy" {
|
|||
|
||||
data "aws_iam_policy_document" "deploy" {
|
||||
statement {
|
||||
sid = var.environment == "tf-poc" ? "DescribeDeploymentResources" : null
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"autoscaling:Describe*",
|
||||
|
|
@ -210,7 +209,6 @@ data "aws_iam_policy_document" "deploy" {
|
|||
}
|
||||
|
||||
statement {
|
||||
sid = var.environment == "tf-poc" ? "CreateApplicationVersion" : null
|
||||
effect = "Allow"
|
||||
actions = ["elasticbeanstalk:CreateApplicationVersion"]
|
||||
resources = [
|
||||
|
|
@ -220,45 +218,38 @@ data "aws_iam_policy_document" "deploy" {
|
|||
}
|
||||
|
||||
statement {
|
||||
sid = var.environment == "tf-poc" ? "UpdatePocEnvironment" : null
|
||||
effect = "Allow"
|
||||
actions = ["elasticbeanstalk:UpdateEnvironment"]
|
||||
resources = [local.environment_arn]
|
||||
}
|
||||
|
||||
dynamic "statement" {
|
||||
for_each = var.environment != "tf-poc" ? [1] : []
|
||||
content {
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"cloudformation:CancelUpdateStack",
|
||||
"cloudformation:DescribeStackEvents",
|
||||
"cloudformation:DescribeStackResource",
|
||||
"cloudformation:DescribeStackResources",
|
||||
"cloudformation:DescribeStacks",
|
||||
"cloudformation:GetTemplate",
|
||||
"cloudformation:ListStackResources",
|
||||
"cloudformation:UpdateStack",
|
||||
]
|
||||
resources = [
|
||||
"arn:aws:cloudformation:${var.aws_region}:${var.aws_account_id}:stack/${local.environment_stack_name}/*",
|
||||
]
|
||||
}
|
||||
statement {
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"cloudformation:CancelUpdateStack",
|
||||
"cloudformation:DescribeStackEvents",
|
||||
"cloudformation:DescribeStackResource",
|
||||
"cloudformation:DescribeStackResources",
|
||||
"cloudformation:DescribeStacks",
|
||||
"cloudformation:GetTemplate",
|
||||
"cloudformation:ListStackResources",
|
||||
"cloudformation:UpdateStack",
|
||||
]
|
||||
resources = [
|
||||
"arn:aws:cloudformation:${var.aws_region}:${var.aws_account_id}:stack/${local.environment_stack_name}/*",
|
||||
]
|
||||
}
|
||||
|
||||
dynamic "statement" {
|
||||
for_each = var.environment != "tf-poc" ? [1] : []
|
||||
content {
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"autoscaling:PutNotificationConfiguration",
|
||||
"autoscaling:ResumeProcesses",
|
||||
"autoscaling:SuspendProcesses",
|
||||
]
|
||||
resources = [
|
||||
"arn:aws:autoscaling:${var.aws_region}:${var.aws_account_id}:autoScalingGroup:*:autoScalingGroupName/${local.environment_stack_name}-*",
|
||||
]
|
||||
}
|
||||
statement {
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"autoscaling:PutNotificationConfiguration",
|
||||
"autoscaling:ResumeProcesses",
|
||||
"autoscaling:SuspendProcesses",
|
||||
]
|
||||
resources = [
|
||||
"arn:aws:autoscaling:${var.aws_region}:${var.aws_account_id}:autoScalingGroup:*:autoScalingGroupName/${local.environment_stack_name}-*",
|
||||
]
|
||||
}
|
||||
|
||||
dynamic "statement" {
|
||||
|
|
@ -288,7 +279,6 @@ data "aws_iam_policy_document" "deploy" {
|
|||
dynamic "statement" {
|
||||
for_each = local.use_legacy_s3_policy ? [] : [1]
|
||||
content {
|
||||
sid = var.environment == "tf-poc" ? "UploadApplicationVersion" : null
|
||||
effect = "Allow"
|
||||
actions = ["s3:PutObject"]
|
||||
resources = ["arn:aws:s3:::${local.eb_bucket_name}/${var.eb_application_name}/*"]
|
||||
|
|
@ -298,25 +288,11 @@ data "aws_iam_policy_document" "deploy" {
|
|||
dynamic "statement" {
|
||||
for_each = local.use_legacy_s3_policy ? [] : [1]
|
||||
content {
|
||||
sid = var.environment == "tf-poc" ? "UseBeanstalkBucket" : null
|
||||
effect = "Allow"
|
||||
actions = ["s3:GetBucketLocation", "s3:ListBucket"]
|
||||
resources = ["arn:aws:s3:::${local.eb_bucket_name}"]
|
||||
}
|
||||
}
|
||||
|
||||
dynamic "statement" {
|
||||
for_each = var.environment == "tf-poc" ? [1] : []
|
||||
content {
|
||||
sid = "DenyLiveEnvironments"
|
||||
effect = "Deny"
|
||||
actions = ["elasticbeanstalk:*"]
|
||||
resources = [
|
||||
"arn:aws:elasticbeanstalk:${var.aws_region}:${var.aws_account_id}:environment/${var.eb_application_name}/shoc-backend-dev",
|
||||
"arn:aws:elasticbeanstalk:${var.aws_region}:${var.aws_account_id}:environment/${var.eb_application_name}/shoc-backend-staging",
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy" "github_deploy" {
|
||||
|
|
|
|||
|
|
@ -10,8 +10,8 @@ variable "environment" {
|
|||
type = string
|
||||
|
||||
validation {
|
||||
condition = contains(["dev", "staging", "tf-poc"], var.environment)
|
||||
error_message = "environment must be dev, staging, or tf-poc."
|
||||
condition = contains(["dev", "staging"], var.environment)
|
||||
error_message = "environment must be dev or staging."
|
||||
}
|
||||
}
|
||||
|
||||
|
|
@ -37,7 +37,7 @@ variable "eb_environment_name" {
|
|||
|
||||
variable "eb_environment_id" {
|
||||
type = string
|
||||
description = "Existing environment ID. Empty only before the CDK POC has been provisioned."
|
||||
description = "Existing Elastic Beanstalk environment ID."
|
||||
}
|
||||
|
||||
variable "platform_arn" {
|
||||
|
|
@ -143,7 +143,7 @@ variable "webhook_decrypt_policy_sid" {
|
|||
variable "dynamo_reader_role_arn" {
|
||||
type = string
|
||||
default = null
|
||||
description = "Dev-only cross-account role. Null for staging and tf-poc."
|
||||
description = "Dev-only cross-account role. Null for staging."
|
||||
}
|
||||
|
||||
variable "dynamo_policy_sid" {
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue