shoc-backend/terraform/variables.tf
Adam Moussa 25c2e84e8f feat(terraform): adopt live deployment roles safely
Add import-only dev and staging state with least-privilege HCP authentication and plan safety guards.
2026-08-28 19:12:34 -04:00

195 lines
5.9 KiB
HCL

variable "aws_region" {
type = string
description = "AWS region for the API, RDS, ACM, and Elastic Beanstalk."
default = "us-east-1"
}
variable "aws_account_id" {
type = string
description = "seahaven-external-dev. Apply refuses any other account."
default = "396287094661"
validation {
condition = var.aws_account_id == "396287094661"
error_message = "This stack is only for seahaven-external-dev (396287094661)."
}
}
variable "environment" {
type = string
description = "Logical environment. POC apply is tf-poc only. dev/staging/prod are accepted so promotion does not rewrite the module."
default = "tf-poc"
validation {
condition = contains(["tf-poc", "dev", "staging", "prod"], var.environment)
error_message = "environment must be tf-poc, dev, staging, or prod."
}
}
variable "domain_name" {
type = string
description = "Public API hostname."
default = "tf-poc.api.dev.seahaven.com"
validation {
condition = var.environment != "tf-poc" || var.domain_name == "tf-poc.api.dev.seahaven.com"
error_message = "tf-poc hostname must be tf-poc.api.dev.seahaven.com."
}
validation {
condition = var.environment != "dev" || var.domain_name == "api.dev.seahaven.com"
error_message = "dev hostname must be api.dev.seahaven.com."
}
validation {
condition = var.domain_name != "api.tf-poc.dev.seahaven.com"
error_message = "Refuse api.tf-poc.dev.seahaven.com; use tf-poc.api.dev.seahaven.com."
}
}
variable "hosted_zone_id" {
type = string
description = "Route 53 zone for the hostname + ACM DNS validation."
default = "Z07671212N75U4YLPWZR8"
}
variable "hosted_zone_name" {
type = string
description = "Zone name; used only for documentation and FQDN checks."
default = "dev.seahaven.com"
}
variable "github_repo" {
type = string
description = "GitHub owner/name for the deploy OIDC trust"
default = "Sea-Haven-Industries/shoc-backend"
}
variable "github_environment" {
type = string
description = "GitHub Actions environment name used in the OIDC sub"
default = "tf-poc"
}
variable "github_deploy_role_name" {
type = string
description = "IAM role name at path /tf-managed/"
default = "githubdeploy-shoc-backend-tf-poc"
}
variable "eb_application_name" {
type = string
description = "Elastic Beanstalk application name. POC uses a separate app from live shoc-backend."
default = "shoc-backend-tf-poc"
validation {
condition = var.environment != "tf-poc" || var.eb_application_name == "shoc-backend-tf-poc"
error_message = "tf-poc Elastic Beanstalk application must be shoc-backend-tf-poc."
}
validation {
condition = var.environment != "dev" || var.eb_application_name == "shoc-backend"
error_message = "dev Elastic Beanstalk application must be shoc-backend."
}
}
variable "eb_environment_name" {
type = string
description = "Elastic Beanstalk environment name."
default = "shoc-backend-tf-poc"
validation {
condition = var.environment != "tf-poc" || var.eb_environment_name == "shoc-backend-tf-poc"
error_message = "tf-poc Elastic Beanstalk environment must be shoc-backend-tf-poc."
}
validation {
condition = var.environment != "dev" || var.eb_environment_name == "shoc-backend-dev"
error_message = "dev Elastic Beanstalk environment must be shoc-backend-dev."
}
}
variable "eb_ec2_role_name" {
type = string
description = "Instance role / instance-profile name at path /tf-managed/"
default = "shoc-backend-tf-poc-ec2"
}
variable "eb_service_role_name" {
type = string
description = "Existing Elastic Beanstalk service role (data-sourced, not created)"
default = "shoc-eb-service-role"
}
variable "eb_instance_type" {
type = string
description = "EC2 instance type for the POC environment"
default = "t3.small"
}
variable "vpc_id" {
type = string
description = "Existing VPC that hosts live Elastic Beanstalk. Required at apply; discover before first apply."
default = ""
}
variable "private_subnet_ids" {
type = list(string)
description = "Private subnets for RDS and EB instances (at least two AZs)."
default = []
}
variable "public_subnet_ids" {
type = list(string)
description = "Public subnets for the EB application load balancer (at least two AZs)."
default = []
}
variable "associate_public_ip" {
type = bool
description = "Associate a public IP on EB instances. Live shoc-backend-dev uses true on public subnets."
default = true
}
variable "rds_identifier" {
type = string
description = "RDS instance identifier"
default = "shoc-backend-tf-poc"
}
variable "rds_instance_class" {
type = string
description = "RDS SQL Server Express instance class"
default = "db.t3.small"
}
variable "rds_allocated_storage" {
type = number
description = "RDS allocated storage in GiB. SQL Server minimum is 20. Express database size remains 10 GiB."
default = 20
}
variable "rds_master_username" {
type = string
description = "RDS master username. Cannot be sa/admin/root."
default = "shoc_admin"
}
variable "database_name" {
type = string
description = "SQL Server catalog the API uses. Create this database once after RDS is available (RDS Express does not accept db_name)."
default = "shoc_tf_poc"
}
variable "sendgrid_api_key" {
type = string
description = "SendGrid API key. Set as a sensitive HCP workspace variable before smoke that sends mail. Empty is allowed for first apply."
default = ""
sensitive = true
}
variable "execution_boundary_arn" {
type = string
description = "SCP-required permissions boundary on CreateRole"
default = "arn:aws:iam::396287094661:policy/external-dev-execution-boundary"
}