shoc-backend/terraform/live/modules/deploy-role/variables.tf
Adam Moussa 25c2e84e8f feat(terraform): adopt live deployment roles safely
Add import-only dev and staging state with least-privilege HCP authentication and plan safety guards.
2026-08-28 19:12:34 -04:00

62 lines
1.7 KiB
HCL

variable "aws_account_id" {
type = string
description = "AWS account containing the existing deploy role."
}
variable "aws_region" {
type = string
description = "AWS region containing the Elastic Beanstalk environment."
}
variable "github_repo" {
type = string
description = "GitHub owner/repository allowed by the OIDC trust."
}
variable "environment" {
type = string
description = "GitHub Environment and deployment environment."
validation {
condition = contains(["dev", "staging"], var.environment)
error_message = "environment must be dev or staging."
}
}
variable "eb_application_name" {
type = string
description = "Existing Elastic Beanstalk application name."
}
variable "eb_environment_name" {
type = string
description = "Existing Elastic Beanstalk environment name."
}
variable "eb_environment_id" {
type = string
description = "Existing Elastic Beanstalk environment ID used in generated resource names."
}
variable "github_deploy_role_name" {
type = string
description = "Existing root-path GitHub OIDC deploy role name."
}
variable "policy_name" {
type = string
description = "Existing inline policy name created by CDK."
default = "GithubDeployRoleDefaultPolicyE8F540D1"
}
variable "adoption_complete" {
type = bool
description = "False preserves the current role exactly for a no-op import. True records Terraform ownership and applies the targeted S3 policy."
default = false
}
variable "legacy_dev_s3_policy" {
type = bool
description = "Whether the current role has the legacy account-wide Elastic Beanstalk S3 permissions. Used only during the no-op import phase."
default = false
}