shoc-backend/terraform/live/modules/environment-owned/variables.tf
Adam Moussa 77c3016c9d
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
feat(deploy): move dev application CD through Terraform (#102)
* feat(deploy): move dev application CD through Terraform

GitHub creates the immutable Elastic Beanstalk version; HCP Terraform is the only UpdateEnvironment caller via a guarded version_label run.

* fix: add permissions block for dependency-review workflow

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* fix(terraform): stop pinning the generated dev instance SG

---------

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-09-03 14:12:06 +00:00

252 lines
5.7 KiB
HCL

variable "aws_account_id" {
type = string
}
variable "aws_region" {
type = string
}
variable "environment" {
type = string
validation {
condition = contains(["dev", "staging", "tf-poc"], var.environment)
error_message = "environment must be dev, staging, or tf-poc."
}
}
variable "adoption_complete" {
type = bool
description = "False preserves existing ownership metadata. True changes only documented metadata and the dev deploy S3 policy."
default = false
}
variable "manage_eb_settings" {
type = bool
description = "False omits managed Elastic Beanstalk settings during the import-only phase."
default = true
}
variable "eb_application_name" {
type = string
}
variable "eb_environment_name" {
type = string
}
variable "eb_environment_id" {
type = string
description = "Existing environment ID. Empty only before the CDK POC has been provisioned."
}
variable "platform_arn" {
type = string
}
variable "vpc_id" {
type = string
}
variable "instance_subnet_ids" {
type = list(string)
}
variable "load_balancer_subnet_ids" {
type = list(string)
}
variable "instance_security_group_id" {
type = string
default = null
description = "Pinned existing instance SG setting. Null lets Elastic Beanstalk retain its provider-managed generated SG."
}
variable "eb_service_role_name" {
type = string
}
variable "shared_certificate_arn" {
type = string
description = "Existing shared certificate for dev/staging, or the POC certificate ARN."
}
variable "runtime_role_name" {
type = string
}
variable "runtime_app_config_policy_name" {
type = string
}
variable "runtime_webhook_policy_name" {
type = string
default = null
}
variable "runtime_dynamo_policy_name" {
type = string
default = null
}
variable "permissions_boundary_arn" {
type = string
}
variable "github_deploy_permissions_boundary_arn" {
type = string
description = "Exact org-baseline permissions boundary ARN for the environment GitHub deploy role."
validation {
condition = can(regex(
"^arn:aws:iam::${var.aws_account_id}:policy/shoc-backend-${var.environment}-deploy-boundary$",
var.github_deploy_permissions_boundary_arn,
))
error_message = "github_deploy_permissions_boundary_arn must be the exact environment deploy boundary ARN."
}
}
variable "app_config_secret_name" {
type = string
}
variable "app_config_json_keys" {
type = set(string)
description = "Exact JSON keys exposed through Elastic Beanstalk environmentsecrets."
}
variable "app_config_policy_sid" {
type = string
default = null
}
variable "webhook_secret_arn" {
type = string
default = null
}
variable "work_order_webhook_enabled" {
type = bool
default = true
}
variable "webhook_read_policy_sid" {
type = string
default = null
}
variable "webhook_decrypt_policy_sid" {
type = string
default = null
}
variable "dynamo_reader_role_arn" {
type = string
default = null
description = "Dev-only cross-account role. Null for staging and tf-poc."
}
variable "dynamo_policy_sid" {
type = string
default = null
}
check "dynamo_policy_pair" {
assert {
condition = (var.runtime_dynamo_policy_name == null) == (var.dynamo_reader_role_arn == null)
error_message = "runtime_dynamo_policy_name and dynamo_reader_role_arn must both be set or both be null."
}
}
check "webhook_policy_pair" {
assert {
condition = (
var.work_order_webhook_enabled &&
var.runtime_webhook_policy_name != null &&
var.webhook_secret_arn != null
) || (
!var.work_order_webhook_enabled &&
var.runtime_webhook_policy_name == null &&
var.webhook_secret_arn == null
)
error_message = "Enabled webhooks require a runtime policy and secret ARN; disabled webhooks require both to be null."
}
}
variable "github_repo" {
type = string
}
variable "github_environment" {
type = string
}
variable "github_deploy_role_name" {
type = string
}
variable "github_deploy_policy_name" {
type = string
}
variable "legacy_dev_s3_policy" {
type = bool
description = "Retain the proven GitHub Elastic Beanstalk release policy until application CD is migrated separately."
default = false
}
variable "release_version_label" {
type = string
default = null
nullable = true
description = "Immutable Elastic Beanstalk application version. Null VCS plans leave the live version unchanged."
validation {
condition = (
var.release_version_label == null ||
can(regex("^[0-9a-f]{40}-[0-9]+-[0-9]+$", var.release_version_label))
)
error_message = "release_version_label must be <full-sha>-<run-id>-<attempt>."
}
}
variable "hosted_zone_id" {
type = string
}
variable "api_domain" {
type = string
}
variable "api_record_type" {
type = string
validation {
condition = contains(["A", "CNAME"], var.api_record_type)
error_message = "api_record_type must be A or CNAME."
}
}
variable "api_alias_target" {
type = object({
name = string
zone_id = string
})
description = "Exact existing Route 53 alias target preserved during import. Null resolves the target from Elastic Beanstalk."
default = null
}
variable "metadata_before_adoption" {
description = "Exact current metadata preserved while adoption_complete is false."
type = object({
runtime_role_description = string
runtime_role_tags = map(string)
instance_profile_tags = map(string)
app_config_description = string
app_config_tags = map(string)
deploy_role_description = string
deploy_role_tags = map(string)
environment_tags = map(string)
})
}