mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-02 03:53:24 +00:00
Add import-only dev and staging state with least-privilege HCP authentication and plan safety guards.
48 lines
1.4 KiB
HCL
48 lines
1.4 KiB
HCL
data "aws_caller_identity" "current" {}
|
|
|
|
data "aws_iam_openid_connect_provider" "github" {
|
|
url = "https://token.actions.githubusercontent.com"
|
|
}
|
|
|
|
data "aws_iam_role" "eb_service" {
|
|
name = var.eb_service_role_name
|
|
}
|
|
|
|
data "aws_elastic_beanstalk_solution_stack" "dotnet" {
|
|
most_recent = true
|
|
name_regex = "^64bit Amazon Linux 2023 .* running .NET 8$"
|
|
}
|
|
|
|
data "aws_elastic_beanstalk_hosted_zone" "current" {}
|
|
|
|
locals {
|
|
account_id = data.aws_caller_identity.current.account_id
|
|
content_role_path = "/tf-managed/"
|
|
|
|
webhook_secret_name = "shoc-backend-tf-poc/webhook-hmac"
|
|
jwt_secret_name = "shoc-backend-tf-poc/jwt"
|
|
}
|
|
|
|
resource "terraform_data" "account_guard" {
|
|
lifecycle {
|
|
precondition {
|
|
condition = local.account_id == var.aws_account_id
|
|
error_message = "Refuse to apply outside seahaven-external-dev (${var.aws_account_id}). Caller is ${local.account_id}."
|
|
}
|
|
|
|
precondition {
|
|
condition = can(regex("^vpc-", var.vpc_id))
|
|
error_message = "Set vpc_id from live Elastic Beanstalk discovery before apply."
|
|
}
|
|
|
|
precondition {
|
|
condition = length(var.private_subnet_ids) >= 2
|
|
error_message = "Set at least two private_subnet_ids before apply."
|
|
}
|
|
|
|
precondition {
|
|
condition = length(var.public_subnet_ids) >= 2
|
|
error_message = "Set at least two public_subnet_ids before apply."
|
|
}
|
|
}
|
|
}
|