shoc-backend/terraform
Adam Moussa 24f08d3cb1
feat(terraform): adopt live deployment roles safely (#94)
* feat(terraform): add safe backend environment adoption

Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer.

* ci(deploy): pause dev and staging deployments

Prevent application releases from racing Terraform adoption while retaining production deployment and validation.

* ci(deploy): require manual environment dispatch

* fix: update `required_version` from `>=1.7.0` to `>=1.9.0`

The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+.

CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding

* chore(deps): add `terraform` to renovate dependency coverage

* ci(deploy): drop unprovisioned prod dispatch path
2026-08-31 11:51:18 -04:00
..
live feat(terraform): adopt live deployment roles safely (#94) 2026-08-31 11:51:18 -04:00
README.md feat(terraform): adopt live deployment roles safely (#94) 2026-08-31 11:51:18 -04:00

Terraform deployment infrastructure

Terraform adopts the environment-owned Sea Haven backend infrastructure while keeping shared and Elastic Beanstalk-generated resources outside state.

Roots

  • live/dev/ imports the existing dev environment-owned resources.
  • live/staging/ imports the existing staging environment-owned resources.
  • live/tf-poc/ manages the retained import-rehearsal environment after its completed transfer from CloudFormation.

Shared RDS, application, VPC, subnet, service-role, shared-certificate, and Elastic Beanstalk-generated inventory remains data-only or provider-managed. Secret metadata is managed, but secret values are never authored in Terraform configuration. Elastic Beanstalk receives secret values through environmentsecrets ARN/key references.

HCP credentials

Org-baseline CloudFormation owns the HCP Terraform plan/apply roles and their manager tags. The retired shoc-backend-bootstrap workspace and backend bootstrap root were removed after the four dev/staging roles transferred without replacement.

Environment adoption

Follow live/README.md. For each dev/staging adoption, the first plan must import the environment-owned resources with zero create, update, delete, or replacement actions. The second reviewed phase may update only explicitly allowlisted ownership metadata and the narrowed dev deploy S3 policy.

The GitHub Environment secret AWS_DEPLOY_ROLE_ARN retains the existing role ARN throughout adoption.

Local validation

terraform -chdir=terraform fmt -check -recursive
terraform -chdir=terraform/live/dev init -backend=false
terraform -chdir=terraform/live/dev validate
terraform -chdir=terraform/live/staging init -backend=false
terraform -chdir=terraform/live/staging validate
terraform -chdir=terraform/live/tf-poc init -backend=false
terraform -chdir=terraform/live/tf-poc validate
python scripts/test-terraform-import-plan-check.py