mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 18:53:12 +00:00
Add import-only dev and staging state with least-privilege HCP authentication and plan safety guards.
88 lines
2.7 KiB
HCL
88 lines
2.7 KiB
HCL
variable "aws_region" {
|
|
type = string
|
|
description = "AWS region for IAM (global) and any regional data sources"
|
|
default = "us-east-1"
|
|
}
|
|
|
|
variable "aws_account_id" {
|
|
type = string
|
|
description = "seahaven-external-dev. Apply refuses any other account."
|
|
default = "396287094661"
|
|
|
|
validation {
|
|
condition = var.aws_account_id == "396287094661"
|
|
error_message = "This bootstrap is only for seahaven-external-dev (396287094661)."
|
|
}
|
|
}
|
|
|
|
variable "hcp_organization" {
|
|
type = string
|
|
description = "HCP Terraform organization name in OIDC trust subs"
|
|
default = "seahaven"
|
|
}
|
|
|
|
variable "hcp_project" {
|
|
type = string
|
|
description = "HCP Terraform project name in OIDC trust subs"
|
|
default = "seahaven-external-dev"
|
|
}
|
|
|
|
variable "hcp_workload_workspace" {
|
|
type = string
|
|
description = "Workload workspace the plan/apply roles trust (not this bootstrap workspace)"
|
|
default = "shoc-backend-tf-poc"
|
|
}
|
|
|
|
variable "create_tfc_oidc_provider" {
|
|
type = bool
|
|
description = "Create the account-global app.terraform.io OIDC provider. Default false: import the provider the frontend POC already created. Set true only if that data source fails."
|
|
default = false
|
|
}
|
|
|
|
variable "github_deploy_role_name" {
|
|
type = string
|
|
description = "GitHub OIDC deploy role name (path /tf-managed/ is fixed in IAM ARNs)"
|
|
default = "githubdeploy-shoc-backend-tf-poc"
|
|
}
|
|
|
|
variable "eb_ec2_role_name" {
|
|
type = string
|
|
description = "Elastic Beanstalk instance role name (path /tf-managed/)"
|
|
default = "shoc-backend-tf-poc-ec2"
|
|
}
|
|
|
|
variable "eb_application_name" {
|
|
type = string
|
|
description = "POC Elastic Beanstalk application the apply role may manage"
|
|
default = "shoc-backend-tf-poc"
|
|
}
|
|
|
|
variable "eb_environment_name" {
|
|
type = string
|
|
description = "POC Elastic Beanstalk environment the apply role may manage"
|
|
default = "shoc-backend-tf-poc"
|
|
}
|
|
|
|
variable "rds_identifier" {
|
|
type = string
|
|
description = "POC RDS instance identifier the apply role may manage"
|
|
default = "shoc-backend-tf-poc"
|
|
}
|
|
|
|
variable "hosted_zone_id" {
|
|
type = string
|
|
description = "dev.seahaven.com zone; apply may change records here (tf-poc + ACM validation only in workload TF)"
|
|
default = "Z07671212N75U4YLPWZR8"
|
|
}
|
|
|
|
variable "execution_boundary_arn" {
|
|
type = string
|
|
description = "SCP-required permissions boundary for CreateRole in this account"
|
|
default = "arn:aws:iam::396287094661:policy/external-dev-execution-boundary"
|
|
}
|
|
|
|
variable "eb_service_role_name" {
|
|
type = string
|
|
description = "Existing Elastic Beanstalk service role to PassRole (not created by this stack)"
|
|
default = "shoc-eb-service-role"
|
|
}
|