mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-05 17:42:10 +00:00
chore(terraform): drop tf-poc from live module and CI
This commit is contained in:
parent
bf83decce3
commit
a478a550d3
8 changed files with 41 additions and 106 deletions
2
.github/workflows/ci.yml
vendored
2
.github/workflows/ci.yml
vendored
|
|
@ -45,7 +45,7 @@ jobs:
|
||||||
directories=()
|
directories=()
|
||||||
case "${{ github.base_ref }}" in
|
case "${{ github.base_ref }}" in
|
||||||
dev)
|
dev)
|
||||||
directories+=(terraform/live/tf-poc terraform/live/dev)
|
directories+=(terraform/live/dev)
|
||||||
;;
|
;;
|
||||||
staging)
|
staging)
|
||||||
directories+=(terraform/live/staging)
|
directories+=(terraform/live/staging)
|
||||||
|
|
|
||||||
|
|
@ -56,14 +56,14 @@ The script:
|
||||||
G10 permits only exact approved resource address/type pairs for the
|
G10 permits only exact approved resource address/type pairs for the
|
||||||
environment-owned boundary: Elastic
|
environment-owned boundary: Elastic
|
||||||
Beanstalk environment, IAM role/inline policy/managed-policy attachment/
|
Beanstalk environment, IAM role/inline policy/managed-policy attachment/
|
||||||
instance profile, Secrets Manager secret metadata, Route 53 zone/record, and
|
instance profile, Secrets Manager secret metadata, and Route 53 record.
|
||||||
ACM certificate. Initial mode permits no update. Controlled mode requires one
|
Initial mode permits no update. Controlled mode requires one
|
||||||
`--allow-update-address` argument per reviewed in-place update. Every invocation
|
`--allow-update-address` argument per reviewed in-place update. Every invocation
|
||||||
also requires `--environment dev`, `--environment staging`, or
|
also requires `--environment dev` or `--environment staging`; an empty or
|
||||||
`--environment tf-poc`; an empty or incomplete environment plan fails.
|
incomplete environment plan fails.
|
||||||
|
|
||||||
G11 runs `terraform fmt -check -recursive`, `terraform init -backend=false`,
|
G11 runs `terraform fmt -check -recursive`, `terraform init -backend=false`,
|
||||||
and `terraform validate`. PRs to `dev` validate `live/tf-poc` and `live/dev`.
|
and `terraform validate`. PRs to `dev` validate `live/dev`.
|
||||||
PRs to `staging` validate only `live/staging`. Org-baseline CloudFormation owns
|
PRs to `staging` validate only `live/staging`. Org-baseline CloudFormation owns
|
||||||
the HCP role substrate, and Terraform owns the dev deploy role, so no backend
|
the HCP role substrate, and Terraform owns the dev deploy role, so no backend
|
||||||
CDK or bootstrap root remains in the matrix.
|
CDK or bootstrap root remains in the matrix.
|
||||||
|
|
|
||||||
|
|
@ -23,12 +23,6 @@ REQUIRED_RESOURCES = {
|
||||||
"module.environment.aws_iam_role_policy.runtime_webhook[0]": "aws_iam_role_policy",
|
"module.environment.aws_iam_role_policy.runtime_webhook[0]": "aws_iam_role_policy",
|
||||||
"module.environment.aws_route53_record.api_cname[0]": "aws_route53_record",
|
"module.environment.aws_route53_record.api_cname[0]": "aws_route53_record",
|
||||||
},
|
},
|
||||||
"tf-poc": {
|
|
||||||
**COMMON_RESOURCES,
|
|
||||||
"aws_acm_certificate.poc": "aws_acm_certificate",
|
|
||||||
"aws_route53_zone.poc": "aws_route53_zone",
|
|
||||||
"module.environment.aws_route53_record.api_cname[0]": "aws_route53_record",
|
|
||||||
},
|
|
||||||
}
|
}
|
||||||
|
|
||||||
DEV_IMPORT_IDS = {
|
DEV_IMPORT_IDS = {
|
||||||
|
|
|
||||||
|
|
@ -186,15 +186,6 @@ def main() -> int:
|
||||||
),
|
),
|
||||||
0,
|
0,
|
||||||
),
|
),
|
||||||
(
|
|
||||||
"tf-poc controlled update",
|
|
||||||
run_case(
|
|
||||||
"tf-poc",
|
|
||||||
actions_by_address={controlled_address: ["update"]},
|
|
||||||
allowed_updates=(controlled_address,),
|
|
||||||
),
|
|
||||||
0,
|
|
||||||
),
|
|
||||||
(
|
(
|
||||||
"wrong controlled address",
|
"wrong controlled address",
|
||||||
run_case(
|
run_case(
|
||||||
|
|
@ -255,12 +246,12 @@ def main() -> int:
|
||||||
1,
|
1,
|
||||||
),
|
),
|
||||||
(
|
(
|
||||||
"live webhook policy in tf-poc",
|
"staging resource in a dev plan",
|
||||||
run_case(
|
run_case(
|
||||||
"tf-poc",
|
"dev",
|
||||||
extra_resource=(
|
extra_resource=(
|
||||||
"module.environment.aws_iam_role_policy.runtime_webhook[0]",
|
"module.environment.aws_route53_record.api_cname[0]",
|
||||||
"aws_iam_role_policy",
|
"aws_route53_record",
|
||||||
["no-op"],
|
["no-op"],
|
||||||
),
|
),
|
||||||
),
|
),
|
||||||
|
|
|
||||||
|
|
@ -7,8 +7,6 @@ keeping shared and Elastic Beanstalk-generated resources outside state.
|
||||||
|
|
||||||
- `live/dev/` imports the existing dev environment-owned resources.
|
- `live/dev/` imports the existing dev environment-owned resources.
|
||||||
- `live/staging/` imports the existing staging environment-owned resources.
|
- `live/staging/` imports the existing staging environment-owned resources.
|
||||||
- `live/tf-poc/` manages the retained import-rehearsal environment after its
|
|
||||||
completed transfer from CloudFormation.
|
|
||||||
|
|
||||||
Shared RDS, application, VPC, subnet, service-role, shared-certificate, and
|
Shared RDS, application, VPC, subnet, service-role, shared-certificate, and
|
||||||
Elastic Beanstalk-generated inventory remains data-only or provider-managed.
|
Elastic Beanstalk-generated inventory remains data-only or provider-managed.
|
||||||
|
|
@ -42,8 +40,6 @@ terraform -chdir=terraform/live/dev init -backend=false
|
||||||
terraform -chdir=terraform/live/dev validate
|
terraform -chdir=terraform/live/dev validate
|
||||||
terraform -chdir=terraform/live/staging init -backend=false
|
terraform -chdir=terraform/live/staging init -backend=false
|
||||||
terraform -chdir=terraform/live/staging validate
|
terraform -chdir=terraform/live/staging validate
|
||||||
terraform -chdir=terraform/live/tf-poc init -backend=false
|
|
||||||
terraform -chdir=terraform/live/tf-poc validate
|
|
||||||
python scripts/test-terraform-import-plan-check.py
|
python scripts/test-terraform-import-plan-check.py
|
||||||
python scripts/test-terraform-release-plan-check.py
|
python scripts/test-terraform-release-plan-check.py
|
||||||
```
|
```
|
||||||
|
|
|
||||||
|
|
@ -8,10 +8,6 @@ shared or Elastic Beanstalk-generated infrastructure.
|
||||||
- `dev/` and `staging/` import the existing EB environment, runtime
|
- `dev/` and `staging/` import the existing EB environment, runtime
|
||||||
role/profile/policies, deploy role/policy, app-config secret metadata, and API
|
role/profile/policies, deploy role/policy, app-config secret metadata, and API
|
||||||
record.
|
record.
|
||||||
- `tf-poc/` manages the retained rehearsal environment after its completed
|
|
||||||
CloudFormation-to-Terraform transfer, excluding the live-only webhook and
|
|
||||||
Dynamo policies. It also owns the child zone and DNS-validated ACM
|
|
||||||
certificate.
|
|
||||||
- `modules/environment-inventory/` reads and pins only shared resources.
|
- `modules/environment-inventory/` reads and pins only shared resources.
|
||||||
- Org-baseline CloudFormation owns the narrowly scoped HCP Terraform plan/apply
|
- Org-baseline CloudFormation owns the narrowly scoped HCP Terraform plan/apply
|
||||||
roles.
|
roles.
|
||||||
|
|
@ -19,8 +15,7 @@ shared or Elastic Beanstalk-generated infrastructure.
|
||||||
The shared `shoc-backend` Elastic Beanstalk application and
|
The shared `shoc-backend` Elastic Beanstalk application and
|
||||||
`shoc-sqlserver-shared` RDS instance, VPC, subnets, EB service role, shared
|
`shoc-sqlserver-shared` RDS instance, VPC, subnets, EB service role, shared
|
||||||
certificate, shared RDS security group, and EB-generated SG/ALB/ASG/CloudFormation
|
certificate, shared RDS security group, and EB-generated SG/ALB/ASG/CloudFormation
|
||||||
resources must never enter an environment state. The `shoc_tf_poc` SQL catalog
|
resources must never enter an environment state.
|
||||||
is out of band.
|
|
||||||
|
|
||||||
Secret values are not Terraform resources, variables, outputs, or managed EB
|
Secret values are not Terraform resources, variables, outputs, or managed EB
|
||||||
settings. Terraform manages the app-config secret shell and maps approved JSON
|
settings. Terraform manages the app-config secret shell and maps approved JSON
|
||||||
|
|
@ -78,9 +73,7 @@ Terraform does not perform this pre-import mutation.
|
||||||
## Two-phase adoption
|
## Two-phase adoption
|
||||||
|
|
||||||
Each dev/staging root pins `adoption_complete=false` in reviewed code until its
|
Each dev/staging root pins `adoption_complete=false` in reviewed code until its
|
||||||
initial import is proven. It is not an HCP workspace variable. The retained
|
initial import is proven. It is not an HCP workspace variable.
|
||||||
tf-poc rehearsal has completed both phases and therefore pins
|
|
||||||
`adoption_complete=true`.
|
|
||||||
|
|
||||||
1. Create the HCP workspace and configure dynamic credentials.
|
1. Create the HCP workspace and configure dynamic credentials.
|
||||||
2. Run the declarative imports.
|
2. Run the declarative imports.
|
||||||
|
|
@ -169,19 +162,6 @@ This change is the allowed exception that mixes deployable application CD with
|
||||||
the Terraform variable that application CD needs. Later PRs must not mix
|
the Terraform variable that application CD needs. Later PRs must not mix
|
||||||
deployable application changes with Terraform or CDK changes.
|
deployable application changes with Terraform or CDK changes.
|
||||||
|
|
||||||
## POC retained identifiers
|
|
||||||
|
|
||||||
The tf-poc HCP workspace stores the exact retained environment ID, app-config
|
|
||||||
secret ARN, child-zone ID, and certificate ARN declared in
|
|
||||||
`tf-poc/variables.tf`. The declarative import blocks consumed those identifiers
|
|
||||||
during the completed transfer. Do not guess or replace them, and do not put
|
|
||||||
credentials or secret values in HCP variables.
|
|
||||||
|
|
||||||
ACM DNS validation remains part of the Terraform-owned certificate resource;
|
|
||||||
its generated validation record is not a separate ownership target. The public
|
|
||||||
delegation of `tf-poc.seahaven.com` from `seahaven.com` remains outside this
|
|
||||||
Terraform state.
|
|
||||||
|
|
||||||
## Pinned live identities
|
## Pinned live identities
|
||||||
|
|
||||||
- Dev: workspace `shoc-backend-dev`; EB environment `shoc-backend-dev`
|
- Dev: workspace `shoc-backend-dev`; EB environment `shoc-backend-dev`
|
||||||
|
|
@ -198,5 +178,3 @@ identifiers make accidental cross-environment reuse fail review and planning.
|
||||||
- Auto-apply remains off.
|
- Auto-apply remains off.
|
||||||
- Org baseline owns final HCP plan/apply permissions and manager tags.
|
- Org baseline owns final HCP plan/apply permissions and manager tags.
|
||||||
- Every imported Terraform resource has `prevent_destroy`.
|
- Every imported Terraform resource has `prevent_destroy`.
|
||||||
- The tf-poc CloudFormation creator path was removed after its no-op import,
|
|
||||||
controlled update, and retained-resource ownership transfer completed.
|
|
||||||
|
|
|
||||||
|
|
@ -196,7 +196,6 @@ resource "aws_iam_role" "github_deploy" {
|
||||||
|
|
||||||
data "aws_iam_policy_document" "deploy" {
|
data "aws_iam_policy_document" "deploy" {
|
||||||
statement {
|
statement {
|
||||||
sid = var.environment == "tf-poc" ? "DescribeDeploymentResources" : null
|
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
actions = [
|
actions = [
|
||||||
"autoscaling:Describe*",
|
"autoscaling:Describe*",
|
||||||
|
|
@ -210,7 +209,6 @@ data "aws_iam_policy_document" "deploy" {
|
||||||
}
|
}
|
||||||
|
|
||||||
statement {
|
statement {
|
||||||
sid = var.environment == "tf-poc" ? "CreateApplicationVersion" : null
|
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
actions = ["elasticbeanstalk:CreateApplicationVersion"]
|
actions = ["elasticbeanstalk:CreateApplicationVersion"]
|
||||||
resources = [
|
resources = [
|
||||||
|
|
@ -220,45 +218,38 @@ data "aws_iam_policy_document" "deploy" {
|
||||||
}
|
}
|
||||||
|
|
||||||
statement {
|
statement {
|
||||||
sid = var.environment == "tf-poc" ? "UpdatePocEnvironment" : null
|
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
actions = ["elasticbeanstalk:UpdateEnvironment"]
|
actions = ["elasticbeanstalk:UpdateEnvironment"]
|
||||||
resources = [local.environment_arn]
|
resources = [local.environment_arn]
|
||||||
}
|
}
|
||||||
|
|
||||||
dynamic "statement" {
|
statement {
|
||||||
for_each = var.environment != "tf-poc" ? [1] : []
|
effect = "Allow"
|
||||||
content {
|
actions = [
|
||||||
effect = "Allow"
|
"cloudformation:CancelUpdateStack",
|
||||||
actions = [
|
"cloudformation:DescribeStackEvents",
|
||||||
"cloudformation:CancelUpdateStack",
|
"cloudformation:DescribeStackResource",
|
||||||
"cloudformation:DescribeStackEvents",
|
"cloudformation:DescribeStackResources",
|
||||||
"cloudformation:DescribeStackResource",
|
"cloudformation:DescribeStacks",
|
||||||
"cloudformation:DescribeStackResources",
|
"cloudformation:GetTemplate",
|
||||||
"cloudformation:DescribeStacks",
|
"cloudformation:ListStackResources",
|
||||||
"cloudformation:GetTemplate",
|
"cloudformation:UpdateStack",
|
||||||
"cloudformation:ListStackResources",
|
]
|
||||||
"cloudformation:UpdateStack",
|
resources = [
|
||||||
]
|
"arn:aws:cloudformation:${var.aws_region}:${var.aws_account_id}:stack/${local.environment_stack_name}/*",
|
||||||
resources = [
|
]
|
||||||
"arn:aws:cloudformation:${var.aws_region}:${var.aws_account_id}:stack/${local.environment_stack_name}/*",
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
dynamic "statement" {
|
statement {
|
||||||
for_each = var.environment != "tf-poc" ? [1] : []
|
effect = "Allow"
|
||||||
content {
|
actions = [
|
||||||
effect = "Allow"
|
"autoscaling:PutNotificationConfiguration",
|
||||||
actions = [
|
"autoscaling:ResumeProcesses",
|
||||||
"autoscaling:PutNotificationConfiguration",
|
"autoscaling:SuspendProcesses",
|
||||||
"autoscaling:ResumeProcesses",
|
]
|
||||||
"autoscaling:SuspendProcesses",
|
resources = [
|
||||||
]
|
"arn:aws:autoscaling:${var.aws_region}:${var.aws_account_id}:autoScalingGroup:*:autoScalingGroupName/${local.environment_stack_name}-*",
|
||||||
resources = [
|
]
|
||||||
"arn:aws:autoscaling:${var.aws_region}:${var.aws_account_id}:autoScalingGroup:*:autoScalingGroupName/${local.environment_stack_name}-*",
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
dynamic "statement" {
|
dynamic "statement" {
|
||||||
|
|
@ -288,7 +279,6 @@ data "aws_iam_policy_document" "deploy" {
|
||||||
dynamic "statement" {
|
dynamic "statement" {
|
||||||
for_each = local.use_legacy_s3_policy ? [] : [1]
|
for_each = local.use_legacy_s3_policy ? [] : [1]
|
||||||
content {
|
content {
|
||||||
sid = var.environment == "tf-poc" ? "UploadApplicationVersion" : null
|
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
actions = ["s3:PutObject"]
|
actions = ["s3:PutObject"]
|
||||||
resources = ["arn:aws:s3:::${local.eb_bucket_name}/${var.eb_application_name}/*"]
|
resources = ["arn:aws:s3:::${local.eb_bucket_name}/${var.eb_application_name}/*"]
|
||||||
|
|
@ -298,25 +288,11 @@ data "aws_iam_policy_document" "deploy" {
|
||||||
dynamic "statement" {
|
dynamic "statement" {
|
||||||
for_each = local.use_legacy_s3_policy ? [] : [1]
|
for_each = local.use_legacy_s3_policy ? [] : [1]
|
||||||
content {
|
content {
|
||||||
sid = var.environment == "tf-poc" ? "UseBeanstalkBucket" : null
|
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
actions = ["s3:GetBucketLocation", "s3:ListBucket"]
|
actions = ["s3:GetBucketLocation", "s3:ListBucket"]
|
||||||
resources = ["arn:aws:s3:::${local.eb_bucket_name}"]
|
resources = ["arn:aws:s3:::${local.eb_bucket_name}"]
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
dynamic "statement" {
|
|
||||||
for_each = var.environment == "tf-poc" ? [1] : []
|
|
||||||
content {
|
|
||||||
sid = "DenyLiveEnvironments"
|
|
||||||
effect = "Deny"
|
|
||||||
actions = ["elasticbeanstalk:*"]
|
|
||||||
resources = [
|
|
||||||
"arn:aws:elasticbeanstalk:${var.aws_region}:${var.aws_account_id}:environment/${var.eb_application_name}/shoc-backend-dev",
|
|
||||||
"arn:aws:elasticbeanstalk:${var.aws_region}:${var.aws_account_id}:environment/${var.eb_application_name}/shoc-backend-staging",
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
resource "aws_iam_role_policy" "github_deploy" {
|
resource "aws_iam_role_policy" "github_deploy" {
|
||||||
|
|
|
||||||
|
|
@ -10,8 +10,8 @@ variable "environment" {
|
||||||
type = string
|
type = string
|
||||||
|
|
||||||
validation {
|
validation {
|
||||||
condition = contains(["dev", "staging", "tf-poc"], var.environment)
|
condition = contains(["dev", "staging"], var.environment)
|
||||||
error_message = "environment must be dev, staging, or tf-poc."
|
error_message = "environment must be dev or staging."
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -37,7 +37,7 @@ variable "eb_environment_name" {
|
||||||
|
|
||||||
variable "eb_environment_id" {
|
variable "eb_environment_id" {
|
||||||
type = string
|
type = string
|
||||||
description = "Existing environment ID. Empty only before the CDK POC has been provisioned."
|
description = "Existing Elastic Beanstalk environment ID."
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "platform_arn" {
|
variable "platform_arn" {
|
||||||
|
|
@ -143,7 +143,7 @@ variable "webhook_decrypt_policy_sid" {
|
||||||
variable "dynamo_reader_role_arn" {
|
variable "dynamo_reader_role_arn" {
|
||||||
type = string
|
type = string
|
||||||
default = null
|
default = null
|
||||||
description = "Dev-only cross-account role. Null for staging and tf-poc."
|
description = "Dev-only cross-account role. Null for staging."
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "dynamo_policy_sid" {
|
variable "dynamo_policy_sid" {
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue