shoc-backend/terraform/live/tf-poc/main.tf
Adam Moussa 24f08d3cb1
feat(terraform): adopt live deployment roles safely (#94)
* feat(terraform): add safe backend environment adoption

Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer.

* ci(deploy): pause dev and staging deployments

Prevent application releases from racing Terraform adoption while retaining production deployment and validation.

* ci(deploy): require manual environment dispatch

* fix: update `required_version` from `>=1.7.0` to `>=1.9.0`

The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+.

CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding

* chore(deps): add `terraform` to renovate dependency coverage

* ci(deploy): drop unprovisioned prod dispatch path
2026-08-31 11:51:18 -04:00

115 lines
4 KiB
HCL

data "aws_caller_identity" "current" {}
data "aws_vpc" "shared" {
id = "vpc-0d16336143f3da25e"
}
data "aws_db_instance" "shared" {
db_instance_identifier = "shoc-sqlserver-shared"
}
data "aws_iam_role" "eb_service" {
name = "shoc-eb-service-role"
}
check "account" {
assert {
condition = data.aws_caller_identity.current.account_id == "396287094661"
error_message = "Refusing to inspect or adopt the POC outside account 396287094661."
}
}
resource "aws_route53_zone" "poc" {
name = "tf-poc.seahaven.com"
comment = "Terraform import rehearsal child zone. Parent NS delegation is a separate approved operation."
force_destroy = false
tags = {
env = "tf-poc"
project = "shoc"
}
lifecycle {
prevent_destroy = true
}
}
resource "aws_acm_certificate" "poc" {
domain_name = "*.tf-poc.seahaven.com"
validation_method = "DNS"
tags = {
Name = "shoc-backend-terraform-import-poc/Certificate"
env = "tf-poc"
project = "shoc"
}
lifecycle {
prevent_destroy = true
}
}
module "environment" {
source = "../modules/environment-owned"
aws_account_id = "396287094661"
aws_region = "us-east-1"
environment = "tf-poc"
adoption_complete = true
eb_application_name = "shoc-backend"
eb_environment_name = "shoc-backend-tf-poc"
eb_environment_id = var.poc_environment_id
platform_arn = "arn:aws:elasticbeanstalk:us-east-1::platform/.NET 8 running on 64bit Amazon Linux 2023/3.11.3"
vpc_id = data.aws_vpc.shared.id
instance_subnet_ids = ["subnet-02946ccd6735742e9", "subnet-0bedaa6e0c750be4f", "subnet-09eaf2bfa468d206f"]
load_balancer_subnet_ids = ["subnet-09eaf2bfa468d206f", "subnet-02946ccd6735742e9", "subnet-0bedaa6e0c750be4f"]
instance_security_group_id = null
eb_service_role_name = data.aws_iam_role.eb_service.name
shared_certificate_arn = aws_acm_certificate.poc.arn
runtime_role_name = "shoc-backend-tf-poc"
runtime_app_config_policy_name = "shoc-tf-poc-secrets-read"
runtime_webhook_policy_name = null
permissions_boundary_arn = "arn:aws:iam::396287094661:policy/shoc-backend-tf-poc-runtime-boundary"
github_deploy_permissions_boundary_arn = "arn:aws:iam::396287094661:policy/shoc-backend-tf-poc-deploy-boundary"
app_config_secret_name = "shoc/tf-poc/app-config"
app_config_json_keys = [
"ConnectionStrings__DefaultConnection",
"JWT__Secret",
"JWT__ValidAudience",
"JWT__ValidIssuer",
"SendGrid__ApiKey",
]
webhook_secret_arn = null
work_order_webhook_enabled = false
github_repo = "Sea-Haven-Industries/shoc-backend"
github_environment = "tf-poc"
github_deploy_role_name = "githubdeploy-shoc-backend-tf-poc"
github_deploy_policy_name = "githubdeploy-shoc-backend-tf-poc-eb"
legacy_dev_s3_policy = false
hosted_zone_id = aws_route53_zone.poc.zone_id
api_domain = "api.tf-poc.seahaven.com"
api_record_type = "CNAME"
metadata_before_adoption = {
runtime_role_description = "SHOC backend tf-poc compute role (EB instance profile)"
runtime_role_tags = {
env = "tf-poc"
project = "shoc"
}
instance_profile_tags = {}
app_config_description = "SHOC tf-poc application config (conn string, JWT, SendGrid)"
app_config_tags = {
env = "tf-poc"
project = "shoc"
}
deploy_role_description = "GitHub OIDC deploy role for shoc-backend-tf-poc."
deploy_role_tags = {
HcpTerraformWorkspace = "shoc-backend-tf-poc"
env = "tf-poc"
project = "shoc"
}
environment_tags = {
env = "tf-poc"
project = "shoc"
}
}
}