GitHub creates the immutable Elastic Beanstalk version; HCP Terraform is the only UpdateEnvironment caller via a guarded version_label run. |
||
|---|---|---|
| .. | ||
| live | ||
| README.md | ||
Terraform deployment infrastructure
Terraform adopts the environment-owned Sea Haven backend infrastructure while keeping shared and Elastic Beanstalk-generated resources outside state.
Roots
live/dev/imports the existing dev environment-owned resources.live/staging/imports the existing staging environment-owned resources.live/tf-poc/manages the retained import-rehearsal environment after its completed transfer from CloudFormation.
Shared RDS, application, VPC, subnet, service-role, shared-certificate, and
Elastic Beanstalk-generated inventory remains data-only or provider-managed.
Secret metadata is managed, but secret values are never authored in Terraform
configuration. Elastic Beanstalk receives secret values through
environmentsecrets ARN/key references.
HCP credentials
Org-baseline CloudFormation owns the HCP Terraform plan/apply roles and their
manager tags. The retired shoc-backend-bootstrap workspace and backend
bootstrap root were removed after the four dev/staging roles transferred
without replacement.
Environment adoption
Follow live/README.md. For each dev/staging adoption, the
first plan must import the environment-owned resources with zero create,
update, delete, or replacement actions. The second reviewed phase may update
only explicitly allowlisted ownership metadata and the narrowed dev deploy S3
policy.
The GitHub Environment secret AWS_DEPLOY_ROLE_ARN retains the existing role
ARN throughout adoption.
Local validation
terraform -chdir=terraform fmt -check -recursive
terraform -chdir=terraform/live/dev init -backend=false
terraform -chdir=terraform/live/dev validate
terraform -chdir=terraform/live/staging init -backend=false
terraform -chdir=terraform/live/staging validate
terraform -chdir=terraform/live/tf-poc init -backend=false
terraform -chdir=terraform/live/tf-poc validate
python scripts/test-terraform-import-plan-check.py
python scripts/test-terraform-release-plan-check.py