shoc-backend/terraform/live/tf-poc/variables.tf
Adam Moussa 24f08d3cb1
feat(terraform): adopt live deployment roles safely (#94)
* feat(terraform): add safe backend environment adoption

Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer.

* ci(deploy): pause dev and staging deployments

Prevent application releases from racing Terraform adoption while retaining production deployment and validation.

* ci(deploy): require manual environment dispatch

* fix: update `required_version` from `>=1.7.0` to `>=1.9.0`

The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+.

CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding

* chore(deps): add `terraform` to renovate dependency coverage

* ci(deploy): drop unprovisioned prod dispatch path
2026-08-31 11:51:18 -04:00

30 lines
833 B
HCL

variable "poc_environment_id" {
type = string
description = "Exact e-* ID of the retained POC environment."
validation {
condition = can(regex("^e-[a-z0-9]+$", var.poc_environment_id))
error_message = "poc_environment_id must be an Elastic Beanstalk e-* ID."
}
}
variable "poc_hosted_zone_id" {
type = string
description = "Exact Route 53 ID of the retained child zone."
validation {
condition = can(regex("^Z[A-Z0-9]+$", var.poc_hosted_zone_id))
error_message = "poc_hosted_zone_id must be a Route 53 hosted-zone ID."
}
}
variable "poc_certificate_arn" {
type = string
description = "Exact ARN of the retained ACM certificate."
}
variable "poc_app_config_secret_arn" {
type = string
description = "Exact ARN of the retained POC app-config secret."
}