mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 08:23:12 +00:00
* feat(terraform): add safe backend environment adoption Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer. * ci(deploy): pause dev and staging deployments Prevent application releases from racing Terraform adoption while retaining production deployment and validation. * ci(deploy): require manual environment dispatch * fix: update `required_version` from `>=1.7.0` to `>=1.9.0` The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+. CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding * chore(deps): add `terraform` to renovate dependency coverage * ci(deploy): drop unprovisioned prod dispatch path
115 lines
4 KiB
HCL
115 lines
4 KiB
HCL
data "aws_caller_identity" "current" {}
|
|
|
|
data "aws_vpc" "shared" {
|
|
id = "vpc-0d16336143f3da25e"
|
|
}
|
|
|
|
data "aws_db_instance" "shared" {
|
|
db_instance_identifier = "shoc-sqlserver-shared"
|
|
}
|
|
|
|
data "aws_iam_role" "eb_service" {
|
|
name = "shoc-eb-service-role"
|
|
}
|
|
|
|
check "account" {
|
|
assert {
|
|
condition = data.aws_caller_identity.current.account_id == "396287094661"
|
|
error_message = "Refusing to inspect or adopt the POC outside account 396287094661."
|
|
}
|
|
}
|
|
|
|
resource "aws_route53_zone" "poc" {
|
|
name = "tf-poc.seahaven.com"
|
|
comment = "Terraform import rehearsal child zone. Parent NS delegation is a separate approved operation."
|
|
force_destroy = false
|
|
|
|
tags = {
|
|
env = "tf-poc"
|
|
project = "shoc"
|
|
}
|
|
|
|
lifecycle {
|
|
prevent_destroy = true
|
|
}
|
|
}
|
|
|
|
resource "aws_acm_certificate" "poc" {
|
|
domain_name = "*.tf-poc.seahaven.com"
|
|
validation_method = "DNS"
|
|
|
|
tags = {
|
|
Name = "shoc-backend-terraform-import-poc/Certificate"
|
|
env = "tf-poc"
|
|
project = "shoc"
|
|
}
|
|
|
|
lifecycle {
|
|
prevent_destroy = true
|
|
}
|
|
}
|
|
|
|
module "environment" {
|
|
source = "../modules/environment-owned"
|
|
|
|
aws_account_id = "396287094661"
|
|
aws_region = "us-east-1"
|
|
environment = "tf-poc"
|
|
adoption_complete = true
|
|
eb_application_name = "shoc-backend"
|
|
eb_environment_name = "shoc-backend-tf-poc"
|
|
eb_environment_id = var.poc_environment_id
|
|
platform_arn = "arn:aws:elasticbeanstalk:us-east-1::platform/.NET 8 running on 64bit Amazon Linux 2023/3.11.3"
|
|
vpc_id = data.aws_vpc.shared.id
|
|
instance_subnet_ids = ["subnet-02946ccd6735742e9", "subnet-0bedaa6e0c750be4f", "subnet-09eaf2bfa468d206f"]
|
|
load_balancer_subnet_ids = ["subnet-09eaf2bfa468d206f", "subnet-02946ccd6735742e9", "subnet-0bedaa6e0c750be4f"]
|
|
instance_security_group_id = null
|
|
eb_service_role_name = data.aws_iam_role.eb_service.name
|
|
shared_certificate_arn = aws_acm_certificate.poc.arn
|
|
runtime_role_name = "shoc-backend-tf-poc"
|
|
runtime_app_config_policy_name = "shoc-tf-poc-secrets-read"
|
|
runtime_webhook_policy_name = null
|
|
permissions_boundary_arn = "arn:aws:iam::396287094661:policy/shoc-backend-tf-poc-runtime-boundary"
|
|
github_deploy_permissions_boundary_arn = "arn:aws:iam::396287094661:policy/shoc-backend-tf-poc-deploy-boundary"
|
|
app_config_secret_name = "shoc/tf-poc/app-config"
|
|
app_config_json_keys = [
|
|
"ConnectionStrings__DefaultConnection",
|
|
"JWT__Secret",
|
|
"JWT__ValidAudience",
|
|
"JWT__ValidIssuer",
|
|
"SendGrid__ApiKey",
|
|
]
|
|
webhook_secret_arn = null
|
|
work_order_webhook_enabled = false
|
|
github_repo = "Sea-Haven-Industries/shoc-backend"
|
|
github_environment = "tf-poc"
|
|
github_deploy_role_name = "githubdeploy-shoc-backend-tf-poc"
|
|
github_deploy_policy_name = "githubdeploy-shoc-backend-tf-poc-eb"
|
|
legacy_dev_s3_policy = false
|
|
hosted_zone_id = aws_route53_zone.poc.zone_id
|
|
api_domain = "api.tf-poc.seahaven.com"
|
|
api_record_type = "CNAME"
|
|
metadata_before_adoption = {
|
|
runtime_role_description = "SHOC backend tf-poc compute role (EB instance profile)"
|
|
runtime_role_tags = {
|
|
env = "tf-poc"
|
|
project = "shoc"
|
|
}
|
|
instance_profile_tags = {}
|
|
app_config_description = "SHOC tf-poc application config (conn string, JWT, SendGrid)"
|
|
app_config_tags = {
|
|
env = "tf-poc"
|
|
project = "shoc"
|
|
}
|
|
deploy_role_description = "GitHub OIDC deploy role for shoc-backend-tf-poc."
|
|
deploy_role_tags = {
|
|
HcpTerraformWorkspace = "shoc-backend-tf-poc"
|
|
env = "tf-poc"
|
|
project = "shoc"
|
|
}
|
|
environment_tags = {
|
|
env = "tf-poc"
|
|
project = "shoc"
|
|
}
|
|
}
|
|
}
|