variable "aws_account_id" { type = string } variable "aws_region" { type = string } variable "environment" { type = string validation { condition = contains(["dev", "staging"], var.environment) error_message = "environment must be dev or staging." } } variable "adoption_complete" { type = bool description = "False preserves existing ownership metadata. True changes only documented metadata and the dev deploy S3 policy." default = false } variable "manage_eb_settings" { type = bool description = "False omits managed Elastic Beanstalk settings during the import-only phase." default = true } variable "eb_application_name" { type = string } variable "eb_environment_name" { type = string } variable "eb_environment_id" { type = string description = "Existing Elastic Beanstalk environment ID." } variable "platform_arn" { type = string } variable "vpc_id" { type = string } variable "instance_subnet_ids" { type = list(string) } variable "load_balancer_subnet_ids" { type = list(string) } variable "instance_security_group_id" { type = string default = null description = "Pinned existing instance SG setting. Null lets Elastic Beanstalk retain its provider-managed generated SG." } variable "eb_service_role_name" { type = string } variable "shared_certificate_arn" { type = string description = "Existing shared certificate for dev/staging" } variable "sentry_dsn" { type = string description = "Sentry DSN for error and transaction monitoring. The DSN is public ingestion configuration, not a secret: it is safe to expose and is delivered as a plain Elastic Beanstalk environment setting instead of Secrets Manager." } variable "runtime_role_name" { type = string } variable "runtime_app_config_policy_name" { type = string } variable "runtime_webhook_policy_name" { type = string default = null } variable "runtime_dynamo_policy_name" { type = string default = null } variable "permissions_boundary_arn" { type = string } variable "github_deploy_permissions_boundary_arn" { type = string description = "Exact org-baseline permissions boundary ARN for the environment GitHub deploy role." validation { condition = can(regex( "^arn:aws:iam::${var.aws_account_id}:policy/shoc-backend-${var.environment}-deploy-boundary$", var.github_deploy_permissions_boundary_arn, )) error_message = "github_deploy_permissions_boundary_arn must be the exact environment deploy boundary ARN." } } variable "app_config_secret_name" { type = string } variable "app_config_json_keys" { type = set(string) description = "Exact JSON keys exposed through Elastic Beanstalk environmentsecrets." } variable "app_config_policy_sid" { type = string default = null } variable "webhook_secret_arn" { type = string default = null } variable "work_order_webhook_enabled" { type = bool default = true } variable "webhook_read_policy_sid" { type = string default = null } variable "webhook_decrypt_policy_sid" { type = string default = null } variable "dynamo_reader_role_arn" { type = string default = null description = "Dev-only cross-account role. Null for staging." } variable "dynamo_policy_sid" { type = string default = null } check "dynamo_policy_pair" { assert { condition = (var.runtime_dynamo_policy_name == null) == (var.dynamo_reader_role_arn == null) error_message = "runtime_dynamo_policy_name and dynamo_reader_role_arn must both be set or both be null." } } check "webhook_policy_pair" { assert { condition = ( var.work_order_webhook_enabled && var.runtime_webhook_policy_name != null && var.webhook_secret_arn != null ) || ( !var.work_order_webhook_enabled && var.runtime_webhook_policy_name == null && var.webhook_secret_arn == null ) error_message = "Enabled webhooks require a runtime policy and secret ARN; disabled webhooks require both to be null." } } variable "github_repo" { type = string } variable "github_environment" { type = string } variable "github_deploy_role_name" { type = string } variable "github_deploy_policy_name" { type = string } variable "legacy_dev_s3_policy" { type = bool description = "Retain the proven GitHub Elastic Beanstalk release policy until application CD is migrated separately." default = false } variable "smoke_url" { type = string description = "HTTPS origin used by post-deploy smoke checks. Written to SSM for GitHub Actions." } variable "hosted_zone_id" { type = string } variable "api_domain" { type = string } variable "api_record_type" { type = string validation { condition = contains(["A", "CNAME"], var.api_record_type) error_message = "api_record_type must be A or CNAME." } } variable "api_alias_target" { type = object({ name = string zone_id = string }) description = "Exact existing Route 53 alias target preserved during import. Null resolves the target from Elastic Beanstalk." default = null } variable "api_cname_target" { type = string description = "Exact existing Route 53 CNAME target preserved during import. Null resolves the target from Elastic Beanstalk." default = null } variable "metadata_before_adoption" { description = "Exact current metadata preserved while adoption_complete is false." type = object({ runtime_role_description = string runtime_role_tags = map(string) instance_profile_tags = map(string) app_config_description = string app_config_tags = map(string) deploy_role_description = string deploy_role_tags = map(string) environment_tags = map(string) }) }