mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-01 08:43:15 +00:00
Add import-only dev and staging state with least-privilege HCP authentication and plan safety guards.
62 lines
1.7 KiB
HCL
62 lines
1.7 KiB
HCL
variable "aws_account_id" {
|
|
type = string
|
|
description = "AWS account containing the existing deploy role."
|
|
}
|
|
|
|
variable "aws_region" {
|
|
type = string
|
|
description = "AWS region containing the Elastic Beanstalk environment."
|
|
}
|
|
|
|
variable "github_repo" {
|
|
type = string
|
|
description = "GitHub owner/repository allowed by the OIDC trust."
|
|
}
|
|
|
|
variable "environment" {
|
|
type = string
|
|
description = "GitHub Environment and deployment environment."
|
|
|
|
validation {
|
|
condition = contains(["dev", "staging"], var.environment)
|
|
error_message = "environment must be dev or staging."
|
|
}
|
|
}
|
|
|
|
variable "eb_application_name" {
|
|
type = string
|
|
description = "Existing Elastic Beanstalk application name."
|
|
}
|
|
|
|
variable "eb_environment_name" {
|
|
type = string
|
|
description = "Existing Elastic Beanstalk environment name."
|
|
}
|
|
|
|
variable "eb_environment_id" {
|
|
type = string
|
|
description = "Existing Elastic Beanstalk environment ID used in generated resource names."
|
|
}
|
|
|
|
variable "github_deploy_role_name" {
|
|
type = string
|
|
description = "Existing root-path GitHub OIDC deploy role name."
|
|
}
|
|
|
|
variable "policy_name" {
|
|
type = string
|
|
description = "Existing inline policy name created by CDK."
|
|
default = "GithubDeployRoleDefaultPolicyE8F540D1"
|
|
}
|
|
|
|
variable "adoption_complete" {
|
|
type = bool
|
|
description = "False preserves the current role exactly for a no-op import. True records Terraform ownership and applies the targeted S3 policy."
|
|
default = false
|
|
}
|
|
|
|
variable "legacy_dev_s3_policy" {
|
|
type = bool
|
|
description = "Whether the current role has the legacy account-wide Elastic Beanstalk S3 permissions. Used only during the no-op import phase."
|
|
default = false
|
|
}
|