mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-01 02:53:14 +00:00
* feat(terraform): add safe backend environment adoption Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer. * ci(deploy): pause dev and staging deployments Prevent application releases from racing Terraform adoption while retaining production deployment and validation. * ci(deploy): require manual environment dispatch * fix: update `required_version` from `>=1.7.0` to `>=1.9.0` The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+. CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding * chore(deps): add `terraform` to renovate dependency coverage * ci(deploy): drop unprovisioned prod dispatch path
48 lines
1.9 KiB
Markdown
48 lines
1.9 KiB
Markdown
# Terraform deployment infrastructure
|
|
|
|
Terraform adopts the environment-owned Sea Haven backend infrastructure while
|
|
keeping shared and Elastic Beanstalk-generated resources outside state.
|
|
|
|
## Roots
|
|
|
|
- `live/dev/` imports the existing dev environment-owned resources.
|
|
- `live/staging/` imports the existing staging environment-owned resources.
|
|
- `live/tf-poc/` manages the retained import-rehearsal environment after its
|
|
completed transfer from CloudFormation.
|
|
|
|
Shared RDS, application, VPC, subnet, service-role, shared-certificate, and
|
|
Elastic Beanstalk-generated inventory remains data-only or provider-managed.
|
|
Secret metadata is managed, but secret values are never authored in Terraform
|
|
configuration. Elastic Beanstalk receives secret values through
|
|
`environmentsecrets` ARN/key references.
|
|
|
|
## HCP credentials
|
|
|
|
Org-baseline CloudFormation owns the HCP Terraform plan/apply roles and their
|
|
manager tags. The retired `shoc-backend-bootstrap` workspace and backend
|
|
bootstrap root were removed after the four dev/staging roles transferred
|
|
without replacement.
|
|
|
|
## Environment adoption
|
|
|
|
Follow [`live/README.md`](live/README.md). For each dev/staging adoption, the
|
|
first plan must import the environment-owned resources with zero create,
|
|
update, delete, or replacement actions. The second reviewed phase may update
|
|
only explicitly allowlisted ownership metadata and the narrowed dev deploy S3
|
|
policy.
|
|
|
|
The GitHub Environment secret `AWS_DEPLOY_ROLE_ARN` retains the existing role
|
|
ARN throughout adoption.
|
|
|
|
## Local validation
|
|
|
|
```bash
|
|
terraform -chdir=terraform fmt -check -recursive
|
|
terraform -chdir=terraform/live/dev init -backend=false
|
|
terraform -chdir=terraform/live/dev validate
|
|
terraform -chdir=terraform/live/staging init -backend=false
|
|
terraform -chdir=terraform/live/staging validate
|
|
terraform -chdir=terraform/live/tf-poc init -backend=false
|
|
terraform -chdir=terraform/live/tf-poc validate
|
|
python scripts/test-terraform-import-plan-check.py
|
|
```
|