shoc-frontend-new/terraform/README.md
Adam Moussa 2a106d4e9e
ci(cd): convert SPA hosting to handbook HCP and GitHub content CD
Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.
2026-09-17 15:55:25 -04:00

3.3 KiB

Frontend Terraform (SPA CD)

One terraform/ root for dev and staging in AWS account 396287094661. HCP Terraform owns the bucket, CloudFront, DNS, and the GitHub deploy role. GitHub Actions owns content: .github/workflows/deploy-web.yaml syncs dist/ to the bucket root and invalidates /*.

Creating, formatting, initializing with -backend=false, and validating these files does not authorize an AWS, HCP Terraform, GitHub, or deployment mutation. Live cutover waits for an explicit greenlight.

Fixed targets

dev staging
Site dev.seahaven.com staging.seahaven.com
Bucket seahaven-shoc-frontend-dev seahaven-shoc-frontend-staging
Distribution E2CWLM1AFB964P E2JDVEZ6EGD49J
Deploy role githubdeploy-shoc-frontend-new-dev githubdeploy-shoc-frontend-new-staging
HCP workspace shoc-frontend-new-dev shoc-frontend-new-staging
Workspace environment dev staging

There is no prod CloudFront in this round. Do not create shoc-frontend-new-prod.

Ownership

module.environment_owned keeps the same addresses as the adopted HCP shoc-frontend-new-dev state. The SPA origin path is empty. The release pointer is forgotten (removed { destroy = false }), not destroyed.

Deploy parameters live under /shoc-frontend-new/<env>/deploy/{bucket,distribution-id}. githubdeploy may List/Get/Put/Delete the bucket root, CreateInvalidation, and GetParameter on those two names. OIDC trust is environment:<env> plus job_workflow_ref for .github/workflows/deploy-web.yaml at refs/heads/main and refs/tags/v*.

adoption_complete is pinned per stack in locals.tf. It is not a workspace variable.

Local checks (no apply)

terraform -chdir=terraform fmt -check -recursive
terraform -chdir=terraform init -backend=false -lockfile=readonly
TF_VAR_environment=dev terraform -chdir=terraform validate
python3 scripts/test-terraform-import-plan-check.py
python3 scripts/test_check_app_terraform_isolation.py
bash scripts/test-verify-cloudfront-release.sh

PRs cannot mix terraform/ with deployable application files. Workflow, docs, and gate-script changes may travel with either side. G13 is python3 scripts/check_app_terraform_isolation.py against the PR base.

npm run test:terraform and npm run verify wrap the same gates. They never create an HCP run or touch AWS.

Cutover (greenlight only)

  1. Point both HCP workspaces at working directory terraform/ with tag app:shoc-frontend-new. Dev VCS branch main. Staging tag regex ^v[0-9]+\.[0-9]+\.[0-9]+-staging$.
  2. Set workspace variable environment to dev or staging.
  3. Auto-apply off. Apply the origin-path move for dev before any --delete root sync.
  4. Create GitHub Environment dev (staging already exists). Set DEPLOY_ROLE_ARN on each.
  5. Enable deploy-web.yaml. Then retire deploy.yml, TF_API_TOKEN, and TERRAFORM_CONTENT_CD_ENABLED.