shoc-backend/terraform/live/modules/environment-inventory/main.tf
Adam Moussa 24f08d3cb1
feat(terraform): adopt live deployment roles safely (#94)
* feat(terraform): add safe backend environment adoption

Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer.

* ci(deploy): pause dev and staging deployments

Prevent application releases from racing Terraform adoption while retaining production deployment and validation.

* ci(deploy): require manual environment dispatch

* fix: update `required_version` from `>=1.7.0` to `>=1.9.0`

The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+.

CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding

* chore(deps): add `terraform` to renovate dependency coverage

* ci(deploy): drop unprovisioned prod dispatch path
2026-08-31 11:51:18 -04:00

33 lines
942 B
HCL

data "aws_caller_identity" "current" {}
data "aws_db_instance" "shared" {
db_instance_identifier = var.rds_identifier
}
data "aws_acm_certificate" "shared" {
domain = var.certificate_domain
statuses = ["ISSUED"]
most_recent = true
}
data "aws_route53_zone" "api" {
name = var.hosted_zone_name
private_zone = false
}
check "identity" {
assert {
condition = data.aws_caller_identity.current.account_id == var.aws_account_id
error_message = "Refusing to inspect resources outside the expected AWS account."
}
assert {
condition = data.aws_acm_certificate.shared.arn == var.expected_certificate_arn
error_message = "The resolved ACM certificate does not match the pinned live certificate."
}
assert {
condition = data.aws_route53_zone.api.zone_id == var.expected_hosted_zone_id
error_message = "The resolved Route 53 zone does not match the pinned live zone."
}
}