mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 07:13:12 +00:00
chore(terraform): remove tf-poc rehearsal
This commit is contained in:
parent
77c3016c9d
commit
bf83decce3
7 changed files with 0 additions and 272 deletions
26
terraform/live/tf-poc/.terraform.lock.hcl
generated
26
terraform/live/tf-poc/.terraform.lock.hcl
generated
|
|
@ -1,26 +0,0 @@
|
|||
# This file is maintained automatically by "terraform init".
|
||||
# Manual edits may be lost in future updates.
|
||||
|
||||
provider "registry.terraform.io/hashicorp/aws" {
|
||||
version = "6.62.0"
|
||||
constraints = "~> 6.57"
|
||||
hashes = [
|
||||
"h1:OthB9UeoBgmy348EpDjs5GDGk6p6UxAMQD5cXn7u9Ho=",
|
||||
"zh:35a9e4bc6fd622c5a99561b882025f2745f1256bbf1a8da8d6b39319b75ae0b5",
|
||||
"zh:405927d470ff16201e40aa0fa2d0ab1de477360a0926d20719cd029179682ecd",
|
||||
"zh:4ab7866593a90bcf18f066b0092a209b9f42852acd783b504031ae74cb6f7010",
|
||||
"zh:5b477f313fc511648a4eed9f9085d0778414835896256ab14296d2345b7070e3",
|
||||
"zh:87de70bc99751f94262cec2260d972555a98f588aa3a613e417438f88a1182df",
|
||||
"zh:88f02a8ff07f00da4ffb3bee9e8ae25588e3a0a92633c625c1c2a63bac00a844",
|
||||
"zh:8d8596257453357c9f3fccaa7d2f04299e8d35b16f364adb8a2c829143a9c090",
|
||||
"zh:953c8e15fa9c12c081f17d66cf45246d032fa23bee33f264dc82242afdb98bc2",
|
||||
"zh:9a7dd903e5e9b2b0cc1317ad2d2692e0ddf05ae2a5aaee20ec5dd1db456711b7",
|
||||
"zh:9b12af85486a96aedd8d7984b0ff811a4b42e3d88dad1a3fb4c0b580d04fa425",
|
||||
"zh:a859154c75c1088d098a481f1ebb259720c5a2ad87781364abf556a741e5adb7",
|
||||
"zh:b8d1e72ad39d5864118f64dd3273424ab637d34b3ff8dd3dfeb4aef9d458587f",
|
||||
"zh:c3666fcfc7b131f5282d4e7249fa68c3a21665757888aa02bbaf6be1cd036bba",
|
||||
"zh:c6b8ff94b3f49bf85fc087381cfe1b271c5b01cf74cf140d58aa500be7138913",
|
||||
"zh:d8143d790e9dd77b8e2f9168e4a33ad6d064dc4b082a0196636b182105aaed14",
|
||||
"zh:fa41eca042f377eb2741e95b36609c1de5b0cd675cd4e3e30c709497cb94db02",
|
||||
]
|
||||
}
|
||||
|
|
@ -1,54 +0,0 @@
|
|||
import {
|
||||
to = aws_route53_zone.poc
|
||||
id = var.poc_hosted_zone_id
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_acm_certificate.poc
|
||||
id = var.poc_certificate_arn
|
||||
}
|
||||
|
||||
import {
|
||||
to = module.environment.aws_elastic_beanstalk_environment.this
|
||||
id = var.poc_environment_id
|
||||
}
|
||||
|
||||
import {
|
||||
to = module.environment.aws_iam_role.runtime
|
||||
id = "shoc-backend-tf-poc"
|
||||
}
|
||||
|
||||
import {
|
||||
to = module.environment.aws_iam_instance_profile.runtime
|
||||
id = "shoc-backend-tf-poc"
|
||||
}
|
||||
|
||||
import {
|
||||
to = module.environment.aws_iam_role_policy_attachment.web_tier
|
||||
id = "shoc-backend-tf-poc/arn:aws:iam::aws:policy/AWSElasticBeanstalkWebTier"
|
||||
}
|
||||
|
||||
import {
|
||||
to = module.environment.aws_iam_role_policy.runtime_app_config
|
||||
id = "shoc-backend-tf-poc:shoc-tf-poc-secrets-read"
|
||||
}
|
||||
|
||||
import {
|
||||
to = module.environment.aws_iam_role.github_deploy
|
||||
id = "githubdeploy-shoc-backend-tf-poc"
|
||||
}
|
||||
|
||||
import {
|
||||
to = module.environment.aws_iam_role_policy.github_deploy
|
||||
id = "githubdeploy-shoc-backend-tf-poc:githubdeploy-shoc-backend-tf-poc-eb"
|
||||
}
|
||||
|
||||
import {
|
||||
to = module.environment.aws_secretsmanager_secret.app_config
|
||||
id = var.poc_app_config_secret_arn
|
||||
}
|
||||
|
||||
import {
|
||||
to = module.environment.aws_route53_record.api_cname[0]
|
||||
id = "${var.poc_hosted_zone_id}_api.tf-poc.seahaven.com_CNAME"
|
||||
}
|
||||
|
|
@ -1,115 +0,0 @@
|
|||
data "aws_caller_identity" "current" {}
|
||||
|
||||
data "aws_vpc" "shared" {
|
||||
id = "vpc-0d16336143f3da25e"
|
||||
}
|
||||
|
||||
data "aws_db_instance" "shared" {
|
||||
db_instance_identifier = "shoc-sqlserver-shared"
|
||||
}
|
||||
|
||||
data "aws_iam_role" "eb_service" {
|
||||
name = "shoc-eb-service-role"
|
||||
}
|
||||
|
||||
check "account" {
|
||||
assert {
|
||||
condition = data.aws_caller_identity.current.account_id == "396287094661"
|
||||
error_message = "Refusing to inspect or adopt the POC outside account 396287094661."
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_route53_zone" "poc" {
|
||||
name = "tf-poc.seahaven.com"
|
||||
comment = "Terraform import rehearsal child zone. Parent NS delegation is a separate approved operation."
|
||||
force_destroy = false
|
||||
|
||||
tags = {
|
||||
env = "tf-poc"
|
||||
project = "shoc"
|
||||
}
|
||||
|
||||
lifecycle {
|
||||
prevent_destroy = true
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_acm_certificate" "poc" {
|
||||
domain_name = "*.tf-poc.seahaven.com"
|
||||
validation_method = "DNS"
|
||||
|
||||
tags = {
|
||||
Name = "shoc-backend-terraform-import-poc/Certificate"
|
||||
env = "tf-poc"
|
||||
project = "shoc"
|
||||
}
|
||||
|
||||
lifecycle {
|
||||
prevent_destroy = true
|
||||
}
|
||||
}
|
||||
|
||||
module "environment" {
|
||||
source = "../modules/environment-owned"
|
||||
|
||||
aws_account_id = "396287094661"
|
||||
aws_region = "us-east-1"
|
||||
environment = "tf-poc"
|
||||
adoption_complete = true
|
||||
eb_application_name = "shoc-backend"
|
||||
eb_environment_name = "shoc-backend-tf-poc"
|
||||
eb_environment_id = var.poc_environment_id
|
||||
platform_arn = "arn:aws:elasticbeanstalk:us-east-1::platform/.NET 8 running on 64bit Amazon Linux 2023/3.11.3"
|
||||
vpc_id = data.aws_vpc.shared.id
|
||||
instance_subnet_ids = ["subnet-02946ccd6735742e9", "subnet-0bedaa6e0c750be4f", "subnet-09eaf2bfa468d206f"]
|
||||
load_balancer_subnet_ids = ["subnet-09eaf2bfa468d206f", "subnet-02946ccd6735742e9", "subnet-0bedaa6e0c750be4f"]
|
||||
instance_security_group_id = null
|
||||
eb_service_role_name = data.aws_iam_role.eb_service.name
|
||||
shared_certificate_arn = aws_acm_certificate.poc.arn
|
||||
runtime_role_name = "shoc-backend-tf-poc"
|
||||
runtime_app_config_policy_name = "shoc-tf-poc-secrets-read"
|
||||
runtime_webhook_policy_name = null
|
||||
permissions_boundary_arn = "arn:aws:iam::396287094661:policy/shoc-backend-tf-poc-runtime-boundary"
|
||||
github_deploy_permissions_boundary_arn = "arn:aws:iam::396287094661:policy/shoc-backend-tf-poc-deploy-boundary"
|
||||
app_config_secret_name = "shoc/tf-poc/app-config"
|
||||
app_config_json_keys = [
|
||||
"ConnectionStrings__DefaultConnection",
|
||||
"JWT__Secret",
|
||||
"JWT__ValidAudience",
|
||||
"JWT__ValidIssuer",
|
||||
"SendGrid__ApiKey",
|
||||
]
|
||||
webhook_secret_arn = null
|
||||
work_order_webhook_enabled = false
|
||||
github_repo = "Sea-Haven-Industries/shoc-backend"
|
||||
github_environment = "tf-poc"
|
||||
github_deploy_role_name = "githubdeploy-shoc-backend-tf-poc"
|
||||
github_deploy_policy_name = "githubdeploy-shoc-backend-tf-poc-eb"
|
||||
legacy_dev_s3_policy = false
|
||||
hosted_zone_id = aws_route53_zone.poc.zone_id
|
||||
api_domain = "api.tf-poc.seahaven.com"
|
||||
api_record_type = "CNAME"
|
||||
metadata_before_adoption = {
|
||||
runtime_role_description = "SHOC backend tf-poc compute role (EB instance profile)"
|
||||
runtime_role_tags = {
|
||||
env = "tf-poc"
|
||||
project = "shoc"
|
||||
}
|
||||
instance_profile_tags = {}
|
||||
app_config_description = "SHOC tf-poc application config (conn string, JWT, SendGrid)"
|
||||
app_config_tags = {
|
||||
env = "tf-poc"
|
||||
project = "shoc"
|
||||
}
|
||||
deploy_role_description = "GitHub OIDC deploy role for shoc-backend-tf-poc."
|
||||
deploy_role_tags = {
|
||||
HcpTerraformWorkspace = "shoc-backend-tf-poc"
|
||||
env = "tf-poc"
|
||||
project = "shoc"
|
||||
}
|
||||
environment_tags = {
|
||||
env = "tf-poc"
|
||||
project = "shoc"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
@ -1,25 +0,0 @@
|
|||
output "environment_arn" {
|
||||
value = module.environment.environment_arn
|
||||
}
|
||||
|
||||
output "runtime_role_arn" {
|
||||
value = module.environment.runtime_role_arn
|
||||
}
|
||||
|
||||
output "github_deploy_role_arn" {
|
||||
value = module.environment.github_deploy_role_arn
|
||||
}
|
||||
|
||||
output "app_config_secret_arn" {
|
||||
value = module.environment.app_config_secret_arn
|
||||
}
|
||||
|
||||
output "child_zone_name_servers" {
|
||||
description = "For a separate, explicitly approved parent-zone delegation operation."
|
||||
value = aws_route53_zone.poc.name_servers
|
||||
}
|
||||
|
||||
output "shared_rds_arn" {
|
||||
description = "Data-only shared RDS instance. The shoc_tf_poc catalog remains out of band."
|
||||
value = data.aws_db_instance.shared.db_instance_arn
|
||||
}
|
||||
|
|
@ -1,3 +0,0 @@
|
|||
provider "aws" {
|
||||
region = "us-east-1"
|
||||
}
|
||||
|
|
@ -1,30 +0,0 @@
|
|||
variable "poc_environment_id" {
|
||||
type = string
|
||||
description = "Exact e-* ID of the retained POC environment."
|
||||
|
||||
validation {
|
||||
condition = can(regex("^e-[a-z0-9]+$", var.poc_environment_id))
|
||||
error_message = "poc_environment_id must be an Elastic Beanstalk e-* ID."
|
||||
}
|
||||
}
|
||||
|
||||
variable "poc_hosted_zone_id" {
|
||||
type = string
|
||||
description = "Exact Route 53 ID of the retained child zone."
|
||||
|
||||
validation {
|
||||
condition = can(regex("^Z[A-Z0-9]+$", var.poc_hosted_zone_id))
|
||||
error_message = "poc_hosted_zone_id must be a Route 53 hosted-zone ID."
|
||||
}
|
||||
}
|
||||
|
||||
variable "poc_certificate_arn" {
|
||||
type = string
|
||||
description = "Exact ARN of the retained ACM certificate."
|
||||
}
|
||||
|
||||
variable "poc_app_config_secret_arn" {
|
||||
type = string
|
||||
description = "Exact ARN of the retained POC app-config secret."
|
||||
}
|
||||
|
||||
|
|
@ -1,19 +0,0 @@
|
|||
terraform {
|
||||
required_version = ">= 1.9.0"
|
||||
|
||||
required_providers {
|
||||
aws = {
|
||||
source = "hashicorp/aws"
|
||||
version = "~> 6.57"
|
||||
}
|
||||
}
|
||||
|
||||
cloud {
|
||||
organization = "seahaven"
|
||||
|
||||
workspaces {
|
||||
project = "seahaven-external-dev"
|
||||
name = "shoc-backend-tf-poc"
|
||||
}
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Reference in a new issue