shoc-frontend-new/infra/cdk/bin/app.ts

102 lines
4 KiB
JavaScript

#!/usr/bin/env node
import { App, Stack, Tags } from "aws-cdk-lib";
import { FrontendStack } from "../lib/frontend-stack";
import { TfPocCertificateStack, TfPocZoneStack } from "../lib/tf-poc-shared-stack";
const app = new App();
const tfPoc = String(app.node.tryGetContext("tfPoc") ?? "false").toLowerCase() === "true";
if (tfPoc) {
const pocEnv = { account: "396287094661", region: "us-east-1" };
const tfPocPhase = String(app.node.tryGetContext("tfPocPhase") ?? "").toLowerCase();
if (!["zone", "environment"].includes(tfPocPhase)) {
throw new Error("tfPocPhase must be set explicitly to 'zone' or 'environment'.");
}
const createEnvironment = tfPocPhase === "environment";
const zoneStack = new TfPocZoneStack(app, "shoc-frontend-tf-poc-shared", {
env: pocEnv,
terminationProtection: true,
});
const stacks: Stack[] = [zoneStack];
if (createEnvironment) {
const certificateStack = new TfPocCertificateStack(app, "shoc-frontend-tf-poc-certificate", {
env: pocEnv,
terminationProtection: true,
hostedZone: zoneStack.hostedZone,
});
const environmentStack = new FrontendStack(app, "shoc-frontend-tf-poc", {
envName: "tf-poc",
githubRepo: "Sea-Haven-Industries/shoc-frontend-new",
deployBranch: "tf-poc",
githubEnvironment: "tf-poc",
terminationProtection: true,
domainNames: [zoneStack.hostedZoneName],
certificateArn: certificateStack.certificateArn,
hostedZoneId: zoneStack.hostedZoneId,
hostedZoneName: zoneStack.hostedZoneName,
retainForTerraformAdoption: true,
env: pocEnv,
});
certificateStack.addDependency(zoneStack);
environmentStack.addDependency(certificateStack);
stacks.push(certificateStack, environmentStack);
}
for (const stack of stacks) {
Tags.of(stack).add("Project", "shoc-frontend");
Tags.of(stack).add("Environment", "tf-poc");
Tags.of(stack).add("ManagedBy", "cdk");
}
} else {
// Defaults match the dev setup; override via `-c key=value` on the CLI.
const envName = app.node.tryGetContext("envName") ?? "dev";
const githubRepo =
app.node.tryGetContext("githubRepo") ?? "Sea-Haven-Industries/shoc-frontend-new";
const deployBranch = app.node.tryGetContext("deployBranch") ?? "dev";
// When set (e.g. "staging"), the deploy role trusts the exact GitHub
// environment OIDC subject instead of a deploy-branch ref. Empty = dev-style
// branch-ref trust.
const githubEnvironment = app.node.tryGetContext("githubEnvironment") ?? "";
// Custom domain. Comma-separated, e.g. -c domainNames=dev.seahaven.com
// The ACM cert MUST be in us-east-1 in the SAME account this stack deploys to.
const domainNames = (app.node.tryGetContext("domainNames") ?? "")
.split(",")
.map((d: string) => d.trim())
.filter((d: string) => d.length > 0);
const certificateArn = app.node.tryGetContext("certificateArn") ?? "";
// Route 53 hosted zone (this account) for the custom-domain alias record.
const hostedZoneId = app.node.tryGetContext("hostedZoneId") ?? "";
const hostedZoneName = app.node.tryGetContext("hostedZoneName") ?? "";
const retainForTerraformAdoption =
String(app.node.tryGetContext("retainForTerraformAdoption") ?? "false").toLowerCase() ===
"true";
// Staging and beyond protect their stacks from accidental deletion; dev
// stays teardown-friendly (its artifacts are reproducible). CDK applies this
// at deploy time — it is not part of the synthesized template.
const terminationProtection = envName !== "dev";
const stack = new FrontendStack(app, `shoc-frontend-${envName}`, {
envName,
githubRepo,
deployBranch,
githubEnvironment,
terminationProtection,
domainNames,
certificateArn,
hostedZoneId,
hostedZoneName,
retainForTerraformAdoption,
env: {
account: process.env.CDK_DEFAULT_ACCOUNT,
region: process.env.CDK_DEFAULT_REGION ?? "us-east-1",
},
});
Tags.of(stack).add("Project", "shoc-frontend");
Tags.of(stack).add("Environment", envName);
Tags.of(stack).add("ManagedBy", "cdk");
}