shoc-frontend-new/scripts/terraform_import_plan_resources.py
Adam Moussa c96a259365
Some checks failed
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
refactor(cd): ship SPA content from GitHub on main (#220)
* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD

Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.

* ci: run Frontend checks and Terraform CI on PRs to main and dev

Match backend 148 so a PR targeting origin/dev still gets the required
checks. Push remains main only.

* refactor(terraform): keep live/dev and live/staging as HCP roots

Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.

* style: prettier terraform-validate.mjs

* fix(terraform): pin githubdeploy assume-role policy in import checker

Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
2026-09-18 14:30:20 -04:00

150 lines
6 KiB
Python
Executable file

"""Canonical frontend Terraform ownership and import-ID maps.
Dev is already in HCP state. Staging constants authorize the first import of
the live CDK stack onto terraform/live/staging.
"""
COMMON_RESOURCES = {
"module.environment_owned.aws_s3_bucket.site": "aws_s3_bucket",
"module.environment_owned.aws_s3_bucket_public_access_block.site": (
"aws_s3_bucket_public_access_block"
),
"module.environment_owned.aws_s3_bucket_ownership_controls.site": (
"aws_s3_bucket_ownership_controls"
),
"module.environment_owned.aws_s3_bucket_server_side_encryption_configuration.site": (
"aws_s3_bucket_server_side_encryption_configuration"
),
"module.environment_owned.aws_s3_bucket_versioning.site": "aws_s3_bucket_versioning",
"module.environment_owned.aws_s3_bucket_policy.site": "aws_s3_bucket_policy",
"module.environment_owned.aws_cloudfront_distribution.site": (
"aws_cloudfront_distribution"
),
"module.environment_owned.aws_cloudfront_origin_access_control.site": (
"aws_cloudfront_origin_access_control"
),
"module.environment_owned.aws_cloudfront_function.spa_rewrite": (
"aws_cloudfront_function"
),
"module.environment_owned.aws_route53_record.site_a": "aws_route53_record",
"module.environment_owned.aws_route53_record.site_aaaa": "aws_route53_record",
"module.environment_owned.aws_iam_role.github_deploy": "aws_iam_role",
"module.environment_owned.aws_iam_role_policy.github_deploy": "aws_iam_role_policy",
"module.environment_owned.aws_ssm_parameter.deploy_bucket": "aws_ssm_parameter",
"module.environment_owned.aws_ssm_parameter.deploy_distribution_id": (
"aws_ssm_parameter"
),
}
REQUIRED_RESOURCES = {
environment: dict(COMMON_RESOURCES)
for environment in ("dev", "staging")
}
CONTROLLED_UPDATE_ADDRESSES = frozenset(
{
"module.environment_owned.aws_s3_bucket.site",
"module.environment_owned.aws_s3_bucket_policy.site",
"module.environment_owned.aws_cloudfront_distribution.site",
"module.environment_owned.aws_cloudfront_function.spa_rewrite",
"module.environment_owned.aws_iam_role.github_deploy",
"module.environment_owned.aws_iam_role_policy.github_deploy",
}
)
ALLOWED_CREATE_ADDRESSES = frozenset(
{
"module.environment_owned.aws_ssm_parameter.deploy_bucket",
"module.environment_owned.aws_ssm_parameter.deploy_distribution_id",
}
)
GITHUB_REPO = "Sea-Haven-Industries/shoc-frontend-new"
GITHUB_OIDC_PROVIDER_ARN = (
"arn:aws:iam::396287094661:oidc-provider/token.actions.githubusercontent.com"
)
ENVIRONMENT_CONFIG = {
"dev": {
"bucket_name": "seahaven-shoc-frontend-dev",
"bucket_auto_delete_helper_role_arn": (
"arn:aws:iam::396287094661:role/"
"shoc-frontend-dev-CustomS3AutoDeleteObjectsCustomRe-dmSDIY8EH7KV"
),
"cloudformation_stack_name": "shoc-frontend-dev",
"distribution_id": "E2CWLM1AFB964P",
"workspace_name": "shoc-frontend-new-dev",
},
"staging": {
"bucket_name": "seahaven-shoc-frontend-staging",
"bucket_auto_delete_helper_role_arn": (
"arn:aws:iam::396287094661:role/"
"shoc-frontend-staging-CustomS3AutoDeleteObjectsCust-QbMDqZbl7YQ3"
),
"cloudformation_stack_name": "shoc-frontend-staging",
"distribution_id": "E2JDVEZ6EGD49J",
"workspace_name": "shoc-frontend-new-staging",
},
}
def _bucket_imports(bucket_name: str) -> dict[str, str]:
return {
address: bucket_name
for address in COMMON_RESOURCES
if address.startswith("module.environment_owned.aws_s3_bucket")
}
REQUIRED_IMPORT_IDS: dict[str, dict[str, str | None]] = {
"dev": {
**_bucket_imports("seahaven-shoc-frontend-dev"),
"module.environment_owned.aws_cloudfront_distribution.site": "E2CWLM1AFB964P",
"module.environment_owned.aws_cloudfront_origin_access_control.site": (
"E30VSIK87N8H64"
),
"module.environment_owned.aws_cloudfront_function.spa_rewrite": (
"us-east-1shocfrontenddevSpaRewrite58674DB8"
),
"module.environment_owned.aws_route53_record.site_a": (
"Z07671212N75U4YLPWZR8_dev.seahaven.com_A"
),
"module.environment_owned.aws_route53_record.site_aaaa": (
"Z07671212N75U4YLPWZR8_dev.seahaven.com_AAAA"
),
"module.environment_owned.aws_iam_role.github_deploy": (
"githubdeploy-shoc-frontend-new-dev"
),
"module.environment_owned.aws_iam_role_policy.github_deploy": (
"githubdeploy-shoc-frontend-new-dev:"
"GithubDeployRoleDefaultPolicyE8F540D1"
),
"module.environment_owned.aws_ssm_parameter.deploy_bucket": None,
"module.environment_owned.aws_ssm_parameter.deploy_distribution_id": None,
},
"staging": {
**_bucket_imports("seahaven-shoc-frontend-staging"),
"module.environment_owned.aws_cloudfront_distribution.site": "E2JDVEZ6EGD49J",
"module.environment_owned.aws_cloudfront_origin_access_control.site": (
"E1PF5R6QQNBZAI"
),
"module.environment_owned.aws_cloudfront_function.spa_rewrite": (
"us-east-1shocfrontendstagingSpaRewriteE9C0CBDA"
),
"module.environment_owned.aws_route53_record.site_a": (
"Z02602739VQWBWCAGXP4_staging.seahaven.com_A"
),
"module.environment_owned.aws_route53_record.site_aaaa": (
"Z02602739VQWBWCAGXP4_staging.seahaven.com_AAAA"
),
"module.environment_owned.aws_iam_role.github_deploy": (
"githubdeploy-shoc-frontend-new-staging"
),
"module.environment_owned.aws_iam_role_policy.github_deploy": (
"githubdeploy-shoc-frontend-new-staging:"
"GithubDeployRoleDefaultPolicyE8F540D1"
),
"module.environment_owned.aws_ssm_parameter.deploy_bucket": None,
"module.environment_owned.aws_ssm_parameter.deploy_distribution_id": None,
},
}