shoc-backend/terraform/live/modules/environment-owned/variables.tf
Alexandre Brandizzi 6ceb274bfb
Some checks failed
Validate and deploy / Validate deployable source bundle (push) Has been cancelled
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Has been cancelled
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Has been cancelled
feat: add API Sentry tracing (SH-298) (#105)
* feat: add API Sentry tracing

* feat: activate Sentry deployment environments

* fix: allow Sentry-free design-time tooling

* fix: trace background jobs in Sentry

* feat(observability): identify and scrub Sentry transactions

* fix(observability): finish abandoned transactions
2026-09-04 14:11:32 -03:00

257 lines
5.8 KiB
HCL

variable "aws_account_id" {
type = string
}
variable "aws_region" {
type = string
}
variable "environment" {
type = string
validation {
condition = contains(["dev", "staging"], var.environment)
error_message = "environment must be dev or staging."
}
}
variable "adoption_complete" {
type = bool
description = "False preserves existing ownership metadata. True changes only documented metadata and the dev deploy S3 policy."
default = false
}
variable "manage_eb_settings" {
type = bool
description = "False omits managed Elastic Beanstalk settings during the import-only phase."
default = true
}
variable "eb_application_name" {
type = string
}
variable "eb_environment_name" {
type = string
}
variable "eb_environment_id" {
type = string
description = "Existing Elastic Beanstalk environment ID."
}
variable "platform_arn" {
type = string
}
variable "vpc_id" {
type = string
}
variable "instance_subnet_ids" {
type = list(string)
}
variable "load_balancer_subnet_ids" {
type = list(string)
}
variable "instance_security_group_id" {
type = string
default = null
description = "Pinned existing instance SG setting. Null lets Elastic Beanstalk retain its provider-managed generated SG."
}
variable "eb_service_role_name" {
type = string
}
variable "shared_certificate_arn" {
type = string
description = "Existing shared certificate for dev/staging"
}
variable "sentry_dsn" {
type = string
description = "Sentry DSN for error and transaction monitoring. The DSN is public ingestion configuration, not a secret: it is safe to expose and is delivered as a plain Elastic Beanstalk environment setting instead of Secrets Manager."
}
variable "runtime_role_name" {
type = string
}
variable "runtime_app_config_policy_name" {
type = string
}
variable "runtime_webhook_policy_name" {
type = string
default = null
}
variable "runtime_dynamo_policy_name" {
type = string
default = null
}
variable "permissions_boundary_arn" {
type = string
}
variable "github_deploy_permissions_boundary_arn" {
type = string
description = "Exact org-baseline permissions boundary ARN for the environment GitHub deploy role."
validation {
condition = can(regex(
"^arn:aws:iam::${var.aws_account_id}:policy/shoc-backend-${var.environment}-deploy-boundary$",
var.github_deploy_permissions_boundary_arn,
))
error_message = "github_deploy_permissions_boundary_arn must be the exact environment deploy boundary ARN."
}
}
variable "app_config_secret_name" {
type = string
}
variable "app_config_json_keys" {
type = set(string)
description = "Exact JSON keys exposed through Elastic Beanstalk environmentsecrets."
}
variable "app_config_policy_sid" {
type = string
default = null
}
variable "webhook_secret_arn" {
type = string
default = null
}
variable "work_order_webhook_enabled" {
type = bool
default = true
}
variable "webhook_read_policy_sid" {
type = string
default = null
}
variable "webhook_decrypt_policy_sid" {
type = string
default = null
}
variable "dynamo_reader_role_arn" {
type = string
default = null
description = "Dev-only cross-account role. Null for staging."
}
variable "dynamo_policy_sid" {
type = string
default = null
}
check "dynamo_policy_pair" {
assert {
condition = (var.runtime_dynamo_policy_name == null) == (var.dynamo_reader_role_arn == null)
error_message = "runtime_dynamo_policy_name and dynamo_reader_role_arn must both be set or both be null."
}
}
check "webhook_policy_pair" {
assert {
condition = (
var.work_order_webhook_enabled &&
var.runtime_webhook_policy_name != null &&
var.webhook_secret_arn != null
) || (
!var.work_order_webhook_enabled &&
var.runtime_webhook_policy_name == null &&
var.webhook_secret_arn == null
)
error_message = "Enabled webhooks require a runtime policy and secret ARN; disabled webhooks require both to be null."
}
}
variable "github_repo" {
type = string
}
variable "github_environment" {
type = string
}
variable "github_deploy_role_name" {
type = string
}
variable "github_deploy_policy_name" {
type = string
}
variable "legacy_dev_s3_policy" {
type = bool
description = "Retain the proven GitHub Elastic Beanstalk release policy until application CD is migrated separately."
default = false
}
variable "release_version_label" {
type = string
default = null
nullable = true
description = "Immutable Elastic Beanstalk application version. Null VCS plans leave the live version unchanged."
validation {
condition = (
var.release_version_label == null ||
can(regex("^[0-9a-f]{40}-[0-9]+-[0-9]+$", var.release_version_label))
)
error_message = "release_version_label must be <full-sha>-<run-id>-<attempt>."
}
}
variable "hosted_zone_id" {
type = string
}
variable "api_domain" {
type = string
}
variable "api_record_type" {
type = string
validation {
condition = contains(["A", "CNAME"], var.api_record_type)
error_message = "api_record_type must be A or CNAME."
}
}
variable "api_alias_target" {
type = object({
name = string
zone_id = string
})
description = "Exact existing Route 53 alias target preserved during import. Null resolves the target from Elastic Beanstalk."
default = null
}
variable "metadata_before_adoption" {
description = "Exact current metadata preserved while adoption_complete is false."
type = object({
runtime_role_description = string
runtime_role_tags = map(string)
instance_profile_tags = map(string)
app_config_description = string
app_config_tags = map(string)
deploy_role_description = string
deploy_role_tags = map(string)
environment_tags = map(string)
})
}