shoc-frontend-new/terraform/live/modules/environment-owned/variables.tf
Adam Moussa c96a259365
Some checks failed
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
refactor(cd): ship SPA content from GitHub on main (#220)
* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD

Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.

* ci: run Frontend checks and Terraform CI on PRs to main and dev

Match backend 148 so a PR targeting origin/dev still gets the required
checks. Push remains main only.

* refactor(terraform): keep live/dev and live/staging as HCP roots

Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.

* style: prettier terraform-validate.mjs

* fix(terraform): pin githubdeploy assume-role policy in import checker

Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
2026-09-18 14:30:20 -04:00

135 lines
3.3 KiB
HCL

variable "environment" {
type = string
description = "Environment name."
validation {
condition = contains(["dev", "staging"], var.environment)
error_message = "environment must be dev or staging."
}
}
variable "adoption_complete" {
type = bool
description = "Switches ownership tags and drops the auto-delete helper grant from the bucket policy."
default = false
}
variable "aws_account_id" {
type = string
description = "AWS account containing the resources."
}
variable "aws_region" {
type = string
description = "AWS region used by the environment."
}
variable "github_repo" {
type = string
description = "owner/name used in OIDC job_workflow_ref."
}
variable "bucket_name" {
type = string
description = "Existing private S3 origin bucket."
}
variable "distribution_id" {
type = string
description = "Existing CloudFront distribution ID."
}
variable "origin_access_control_name" {
type = string
description = "Exact existing CloudFront OAC name."
}
variable "origin_access_control_description" {
type = string
description = "Exact existing CloudFront OAC description."
}
variable "origin_id" {
type = string
description = "Exact origin ID in the existing distribution."
}
variable "function_name" {
type = string
description = "Existing CloudFront Function name."
}
variable "domain_name" {
type = string
description = "Site hostname."
}
variable "hosted_zone_id" {
type = string
description = "Inventory-verified hosted zone ID."
}
variable "certificate_arn" {
type = string
description = "Inventory-verified ACM certificate ARN."
}
variable "cache_policy_id" {
type = string
description = "Inventory-verified AWS managed cache policy ID."
}
variable "github_oidc_provider_arn" {
type = string
description = "Inventory-verified GitHub OIDC provider ARN."
}
variable "deploy_role_name" {
type = string
description = "Existing GitHub deployment role name."
}
variable "deploy_inline_policy_name" {
type = string
description = "Existing generated inline policy name."
}
variable "deploy_permissions_boundary_arn" {
type = string
description = "Exact permissions boundary attached before import."
}
variable "cloudformation_stack_name" {
type = string
description = "Legacy CloudFormation stack used by the pre-adoption policy."
}
variable "bucket_auto_delete_helper_role_arn" {
type = string
description = "Exact legacy S3 auto-delete helper role ARN."
}
variable "pre_adoption_tags" {
type = map(string)
description = "Exact tags present while CloudFormation still owns the resources."
}
variable "pre_adoption_bucket_tags" {
type = map(string)
description = "Exact pre-adoption S3 tags, including the CDK auto-delete marker."
}
variable "ownership_tags" {
type = map(string)
description = "Tags applied by the controlled ownership transfer."
}
variable "pre_adoption_deploy_role_tags" {
type = map(string)
description = "Exact pre-adoption deploy-role tags, including its HCP manager tag."
}
variable "post_adoption_deploy_role_tags" {
type = map(string)
description = "Exact post-adoption deploy-role tags, preserving its HCP manager tag."
}