mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-02 12:03:21 +00:00
Add import-only dev and staging state with least-privilege HCP authentication and plan safety guards.
59 lines
1.4 KiB
HCL
59 lines
1.4 KiB
HCL
data "aws_caller_identity" "current" {}
|
|
|
|
data "aws_vpc" "selected" {
|
|
id = var.vpc_id
|
|
}
|
|
|
|
data "aws_subnet" "selected" {
|
|
for_each = var.subnet_ids
|
|
id = each.value
|
|
}
|
|
|
|
data "aws_db_instance" "shared" {
|
|
db_instance_identifier = var.rds_identifier
|
|
}
|
|
|
|
data "aws_iam_role" "eb_service" {
|
|
name = var.eb_service_role_name
|
|
}
|
|
|
|
data "aws_iam_role" "runtime" {
|
|
name = var.runtime_role_name
|
|
}
|
|
|
|
data "aws_iam_instance_profile" "runtime" {
|
|
name = var.instance_profile_name
|
|
}
|
|
|
|
data "aws_security_group" "environment" {
|
|
for_each = var.security_group_ids
|
|
id = each.value
|
|
}
|
|
|
|
data "aws_acm_certificate" "shared" {
|
|
domain = var.certificate_domain
|
|
statuses = ["ISSUED"]
|
|
most_recent = true
|
|
}
|
|
|
|
data "aws_route53_zone" "api" {
|
|
name = var.hosted_zone_name
|
|
private_zone = false
|
|
}
|
|
|
|
check "identity" {
|
|
assert {
|
|
condition = data.aws_caller_identity.current.account_id == var.aws_account_id
|
|
error_message = "Refusing to inspect resources outside the expected AWS account."
|
|
}
|
|
|
|
assert {
|
|
condition = data.aws_acm_certificate.shared.arn == var.expected_certificate_arn
|
|
error_message = "The resolved ACM certificate does not match the pinned live certificate."
|
|
}
|
|
|
|
assert {
|
|
condition = data.aws_route53_zone.api.zone_id == var.expected_hosted_zone_id
|
|
error_message = "The resolved Route 53 zone does not match the pinned live zone."
|
|
}
|
|
}
|