mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 03:43:11 +00:00
Some checks failed
* feat: add API Sentry tracing * feat: activate Sentry deployment environments * fix: allow Sentry-free design-time tooling * fix: trace background jobs in Sentry * feat(observability): identify and scrub Sentry transactions * fix(observability): finish abandoned transactions
257 lines
5.8 KiB
HCL
257 lines
5.8 KiB
HCL
variable "aws_account_id" {
|
|
type = string
|
|
}
|
|
|
|
variable "aws_region" {
|
|
type = string
|
|
}
|
|
|
|
variable "environment" {
|
|
type = string
|
|
|
|
validation {
|
|
condition = contains(["dev", "staging"], var.environment)
|
|
error_message = "environment must be dev or staging."
|
|
}
|
|
}
|
|
|
|
variable "adoption_complete" {
|
|
type = bool
|
|
description = "False preserves existing ownership metadata. True changes only documented metadata and the dev deploy S3 policy."
|
|
default = false
|
|
}
|
|
|
|
variable "manage_eb_settings" {
|
|
type = bool
|
|
description = "False omits managed Elastic Beanstalk settings during the import-only phase."
|
|
default = true
|
|
}
|
|
|
|
variable "eb_application_name" {
|
|
type = string
|
|
}
|
|
|
|
variable "eb_environment_name" {
|
|
type = string
|
|
}
|
|
|
|
variable "eb_environment_id" {
|
|
type = string
|
|
description = "Existing Elastic Beanstalk environment ID."
|
|
}
|
|
|
|
variable "platform_arn" {
|
|
type = string
|
|
}
|
|
|
|
variable "vpc_id" {
|
|
type = string
|
|
}
|
|
|
|
variable "instance_subnet_ids" {
|
|
type = list(string)
|
|
}
|
|
|
|
variable "load_balancer_subnet_ids" {
|
|
type = list(string)
|
|
}
|
|
|
|
variable "instance_security_group_id" {
|
|
type = string
|
|
default = null
|
|
description = "Pinned existing instance SG setting. Null lets Elastic Beanstalk retain its provider-managed generated SG."
|
|
}
|
|
|
|
variable "eb_service_role_name" {
|
|
type = string
|
|
}
|
|
|
|
variable "shared_certificate_arn" {
|
|
type = string
|
|
description = "Existing shared certificate for dev/staging"
|
|
}
|
|
|
|
variable "sentry_dsn" {
|
|
type = string
|
|
description = "Sentry DSN for error and transaction monitoring. The DSN is public ingestion configuration, not a secret: it is safe to expose and is delivered as a plain Elastic Beanstalk environment setting instead of Secrets Manager."
|
|
}
|
|
|
|
variable "runtime_role_name" {
|
|
type = string
|
|
}
|
|
|
|
variable "runtime_app_config_policy_name" {
|
|
type = string
|
|
}
|
|
|
|
variable "runtime_webhook_policy_name" {
|
|
type = string
|
|
default = null
|
|
}
|
|
|
|
variable "runtime_dynamo_policy_name" {
|
|
type = string
|
|
default = null
|
|
}
|
|
|
|
variable "permissions_boundary_arn" {
|
|
type = string
|
|
}
|
|
|
|
variable "github_deploy_permissions_boundary_arn" {
|
|
type = string
|
|
description = "Exact org-baseline permissions boundary ARN for the environment GitHub deploy role."
|
|
|
|
validation {
|
|
condition = can(regex(
|
|
"^arn:aws:iam::${var.aws_account_id}:policy/shoc-backend-${var.environment}-deploy-boundary$",
|
|
var.github_deploy_permissions_boundary_arn,
|
|
))
|
|
error_message = "github_deploy_permissions_boundary_arn must be the exact environment deploy boundary ARN."
|
|
}
|
|
}
|
|
|
|
variable "app_config_secret_name" {
|
|
type = string
|
|
}
|
|
|
|
variable "app_config_json_keys" {
|
|
type = set(string)
|
|
description = "Exact JSON keys exposed through Elastic Beanstalk environmentsecrets."
|
|
}
|
|
|
|
variable "app_config_policy_sid" {
|
|
type = string
|
|
default = null
|
|
}
|
|
|
|
variable "webhook_secret_arn" {
|
|
type = string
|
|
default = null
|
|
}
|
|
|
|
variable "work_order_webhook_enabled" {
|
|
type = bool
|
|
default = true
|
|
}
|
|
|
|
variable "webhook_read_policy_sid" {
|
|
type = string
|
|
default = null
|
|
}
|
|
|
|
variable "webhook_decrypt_policy_sid" {
|
|
type = string
|
|
default = null
|
|
}
|
|
|
|
variable "dynamo_reader_role_arn" {
|
|
type = string
|
|
default = null
|
|
description = "Dev-only cross-account role. Null for staging."
|
|
}
|
|
|
|
variable "dynamo_policy_sid" {
|
|
type = string
|
|
default = null
|
|
}
|
|
|
|
check "dynamo_policy_pair" {
|
|
assert {
|
|
condition = (var.runtime_dynamo_policy_name == null) == (var.dynamo_reader_role_arn == null)
|
|
error_message = "runtime_dynamo_policy_name and dynamo_reader_role_arn must both be set or both be null."
|
|
}
|
|
}
|
|
|
|
check "webhook_policy_pair" {
|
|
assert {
|
|
condition = (
|
|
var.work_order_webhook_enabled &&
|
|
var.runtime_webhook_policy_name != null &&
|
|
var.webhook_secret_arn != null
|
|
) || (
|
|
!var.work_order_webhook_enabled &&
|
|
var.runtime_webhook_policy_name == null &&
|
|
var.webhook_secret_arn == null
|
|
)
|
|
error_message = "Enabled webhooks require a runtime policy and secret ARN; disabled webhooks require both to be null."
|
|
}
|
|
}
|
|
|
|
variable "github_repo" {
|
|
type = string
|
|
}
|
|
|
|
variable "github_environment" {
|
|
type = string
|
|
}
|
|
|
|
variable "github_deploy_role_name" {
|
|
type = string
|
|
}
|
|
|
|
variable "github_deploy_policy_name" {
|
|
type = string
|
|
}
|
|
|
|
variable "legacy_dev_s3_policy" {
|
|
type = bool
|
|
description = "Retain the proven GitHub Elastic Beanstalk release policy until application CD is migrated separately."
|
|
default = false
|
|
}
|
|
|
|
variable "release_version_label" {
|
|
type = string
|
|
default = null
|
|
nullable = true
|
|
|
|
description = "Immutable Elastic Beanstalk application version. Null VCS plans leave the live version unchanged."
|
|
|
|
validation {
|
|
condition = (
|
|
var.release_version_label == null ||
|
|
can(regex("^[0-9a-f]{40}-[0-9]+-[0-9]+$", var.release_version_label))
|
|
)
|
|
error_message = "release_version_label must be <full-sha>-<run-id>-<attempt>."
|
|
}
|
|
}
|
|
|
|
variable "hosted_zone_id" {
|
|
type = string
|
|
}
|
|
|
|
variable "api_domain" {
|
|
type = string
|
|
}
|
|
|
|
variable "api_record_type" {
|
|
type = string
|
|
|
|
validation {
|
|
condition = contains(["A", "CNAME"], var.api_record_type)
|
|
error_message = "api_record_type must be A or CNAME."
|
|
}
|
|
}
|
|
|
|
variable "api_alias_target" {
|
|
type = object({
|
|
name = string
|
|
zone_id = string
|
|
})
|
|
description = "Exact existing Route 53 alias target preserved during import. Null resolves the target from Elastic Beanstalk."
|
|
default = null
|
|
}
|
|
|
|
variable "metadata_before_adoption" {
|
|
description = "Exact current metadata preserved while adoption_complete is false."
|
|
type = object({
|
|
runtime_role_description = string
|
|
runtime_role_tags = map(string)
|
|
instance_profile_tags = map(string)
|
|
app_config_description = string
|
|
app_config_tags = map(string)
|
|
deploy_role_description = string
|
|
deploy_role_tags = map(string)
|
|
environment_tags = map(string)
|
|
})
|
|
}
|