* fix(iam): let staging githubdeploy GetObject the release zip * fix(iam): allow staging githubdeploy to cache EB processed extensions * fix(iam): allow staging githubdeploy GetObjectAcl for EB updates * fix(iam): grant staging githubdeploy named S3 reads on EB resources prefix * fix(iam): allow staging githubdeploy to delete EB version cache objects * fix(iam): scope staging githubdeploy S3 object access to the EB bucket * fix(iam): allow staging githubdeploy PutObjectVersionAcl on EB artifacts * fix(iam): allow staging githubdeploy GetBucketPolicy on the EB bucket * fix(iam): scope staging githubdeploy S3 objects to SHOC and staging EB prefixes |
||
|---|---|---|
| .. | ||
| live | ||
| README.md | ||
Terraform deployment infrastructure
Terraform adopts the environment-owned Sea Haven backend infrastructure while keeping shared and Elastic Beanstalk-generated resources outside state.
Roots
live/dev/imports the existing dev environment-owned resources.live/staging/imports the existing staging environment-owned resources.
Shared RDS, application, VPC, subnet, service-role, shared-certificate, and
Elastic Beanstalk-generated inventory remains data-only or provider-managed.
Secret metadata is managed, but secret values are never authored in Terraform
configuration. Elastic Beanstalk receives secret values through
environmentsecrets ARN/key references.
The Sentry DSN is public ingestion configuration, not a secret: each root passes
it through the required sentry_dsn module variable as the plain
SENTRY_DSN environment setting. SENTRY_ENVIRONMENT is development for the
dev root and the root environment name otherwise. Production has no Terraform
root yet; production Sentry wiring will reuse the same variable when one is
added.
HCP credentials
Org-baseline CloudFormation owns the HCP Terraform plan/apply roles and their
manager tags. The retired shoc-backend-bootstrap workspace and backend
bootstrap root were removed after the four dev/staging roles transferred
without replacement.
Environment adoption
Follow live/README.md. For each dev/staging adoption, the
first plan must import the environment-owned resources with zero create,
update, delete, or replacement actions. The second reviewed phase may update
only explicitly allowlisted ownership metadata and the narrowed dev deploy S3
policy.
The GitHub Environment variable DEPLOY_ROLE_ARN is the OIDC role used
by application CD after cutover. Adoption may still have the older
AWS_DEPLOY_ROLE_ARN secret until that cutover.
Local validation
terraform fmt -check -recursive terraform
terraform -chdir=terraform/live/dev init -backend=false
terraform -chdir=terraform/live/dev validate
terraform -chdir=terraform/live/staging init -backend=false
terraform -chdir=terraform/live/staging validate
python scripts/test-terraform-import-plan-check.py
python3 scripts/test_next_release_tag.py
python3 scripts/test_require_commit_checks.py
python3 scripts/test_check_app_terraform_isolation.py