shoc-backend/terraform/locals.tf
Adam Moussa 25c2e84e8f feat(terraform): adopt live deployment roles safely
Add import-only dev and staging state with least-privilege HCP authentication and plan safety guards.
2026-08-28 19:12:34 -04:00

48 lines
1.4 KiB
HCL

data "aws_caller_identity" "current" {}
data "aws_iam_openid_connect_provider" "github" {
url = "https://token.actions.githubusercontent.com"
}
data "aws_iam_role" "eb_service" {
name = var.eb_service_role_name
}
data "aws_elastic_beanstalk_solution_stack" "dotnet" {
most_recent = true
name_regex = "^64bit Amazon Linux 2023 .* running .NET 8$"
}
data "aws_elastic_beanstalk_hosted_zone" "current" {}
locals {
account_id = data.aws_caller_identity.current.account_id
content_role_path = "/tf-managed/"
webhook_secret_name = "shoc-backend-tf-poc/webhook-hmac"
jwt_secret_name = "shoc-backend-tf-poc/jwt"
}
resource "terraform_data" "account_guard" {
lifecycle {
precondition {
condition = local.account_id == var.aws_account_id
error_message = "Refuse to apply outside seahaven-external-dev (${var.aws_account_id}). Caller is ${local.account_id}."
}
precondition {
condition = can(regex("^vpc-", var.vpc_id))
error_message = "Set vpc_id from live Elastic Beanstalk discovery before apply."
}
precondition {
condition = length(var.private_subnet_ids) >= 2
error_message = "Set at least two private_subnet_ids before apply."
}
precondition {
condition = length(var.public_subnet_ids) >= 2
error_message = "Set at least two public_subnet_ids before apply."
}
}
}