shoc-backend/terraform/README.md
Alexandre Brandizzi 6ceb274bfb
Some checks failed
Validate and deploy / Validate deployable source bundle (push) Has been cancelled
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Has been cancelled
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Has been cancelled
feat: add API Sentry tracing (SH-298) (#105)
* feat: add API Sentry tracing

* feat: activate Sentry deployment environments

* fix: allow Sentry-free design-time tooling

* fix: trace background jobs in Sentry

* feat(observability): identify and scrub Sentry transactions

* fix(observability): finish abandoned transactions
2026-09-04 14:11:32 -03:00

52 lines
2.1 KiB
Markdown

# Terraform deployment infrastructure
Terraform adopts the environment-owned Sea Haven backend infrastructure while
keeping shared and Elastic Beanstalk-generated resources outside state.
## Roots
- `live/dev/` imports the existing dev environment-owned resources.
- `live/staging/` imports the existing staging environment-owned resources.
Shared RDS, application, VPC, subnet, service-role, shared-certificate, and
Elastic Beanstalk-generated inventory remains data-only or provider-managed.
Secret metadata is managed, but secret values are never authored in Terraform
configuration. Elastic Beanstalk receives secret values through
`environmentsecrets` ARN/key references.
The Sentry DSN is public ingestion configuration, not a secret: each root passes
it through the required `sentry_dsn` module variable as the plain
`SENTRY_DSN` environment setting. `SENTRY_ENVIRONMENT` is `development` for the
dev root and the root environment name otherwise. Production has no Terraform
root yet; production Sentry wiring will reuse the same variable when one is
added.
## HCP credentials
Org-baseline CloudFormation owns the HCP Terraform plan/apply roles and their
manager tags. The retired `shoc-backend-bootstrap` workspace and backend
bootstrap root were removed after the four dev/staging roles transferred
without replacement.
## Environment adoption
Follow [`live/README.md`](live/README.md). For each dev/staging adoption, the
first plan must import the environment-owned resources with zero create,
update, delete, or replacement actions. The second reviewed phase may update
only explicitly allowlisted ownership metadata and the narrowed dev deploy S3
policy.
The GitHub Environment secret `AWS_DEPLOY_ROLE_ARN` retains the existing role
ARN throughout adoption.
## Local validation
```bash
terraform -chdir=terraform fmt -check -recursive
terraform -chdir=terraform/live/dev init -backend=false
terraform -chdir=terraform/live/dev validate
terraform -chdir=terraform/live/staging init -backend=false
terraform -chdir=terraform/live/staging validate
python scripts/test-terraform-import-plan-check.py
python scripts/test-terraform-release-plan-check.py
```