mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 10:43:13 +00:00
Add import-only dev and staging state with least-privilege HCP authentication and plan safety guards.
69 lines
1.9 KiB
HCL
69 lines
1.9 KiB
HCL
data "aws_iam_policy_document" "eb_ec2_assume" {
|
|
statement {
|
|
effect = "Allow"
|
|
actions = ["sts:AssumeRole"]
|
|
|
|
principals {
|
|
type = "Service"
|
|
identifiers = ["ec2.amazonaws.com"]
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role" "eb_ec2" {
|
|
name = var.eb_ec2_role_name
|
|
path = local.content_role_path
|
|
description = "Elastic Beanstalk instance role for ${var.eb_environment_name}"
|
|
assume_role_policy = data.aws_iam_policy_document.eb_ec2_assume.json
|
|
max_session_duration = 3600
|
|
permissions_boundary = var.execution_boundary_arn
|
|
|
|
lifecycle {
|
|
ignore_changes = [permissions_boundary]
|
|
}
|
|
|
|
depends_on = [terraform_data.account_guard]
|
|
}
|
|
|
|
resource "aws_iam_role_policy_attachment" "eb_web_tier" {
|
|
role = aws_iam_role.eb_ec2.name
|
|
policy_arn = "arn:aws:iam::aws:policy/AWSElasticBeanstalkWebTier"
|
|
}
|
|
|
|
resource "aws_iam_role_policy_attachment" "eb_worker_tier" {
|
|
role = aws_iam_role.eb_ec2.name
|
|
policy_arn = "arn:aws:iam::aws:policy/AWSElasticBeanstalkWorkerTier"
|
|
}
|
|
|
|
resource "aws_iam_role_policy_attachment" "eb_ssm" {
|
|
role = aws_iam_role.eb_ec2.name
|
|
policy_arn = "arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore"
|
|
}
|
|
|
|
data "aws_iam_policy_document" "eb_ec2_secrets" {
|
|
statement {
|
|
sid = "PocSecrets"
|
|
effect = "Allow"
|
|
actions = [
|
|
"secretsmanager:GetSecretValue",
|
|
"secretsmanager:DescribeSecret",
|
|
]
|
|
resources = [
|
|
aws_secretsmanager_secret.jwt.arn,
|
|
aws_secretsmanager_secret.webhook.arn,
|
|
aws_db_instance.poc.master_user_secret[0].secret_arn,
|
|
]
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role_policy" "eb_ec2_secrets" {
|
|
name = "shoc-backend-tf-poc-secrets"
|
|
role = aws_iam_role.eb_ec2.id
|
|
policy = data.aws_iam_policy_document.eb_ec2_secrets.json
|
|
}
|
|
|
|
resource "aws_iam_instance_profile" "eb_ec2" {
|
|
name = var.eb_ec2_role_name
|
|
path = local.content_role_path
|
|
role = aws_iam_role.eb_ec2.name
|
|
}
|