mirror of
https://github.com/Sea-Haven-Industries/shoc-frontend-new.git
synced 2026-09-30 12:43:13 +00:00
Port the reviewed dev root and environment-owned/inventory modules from
111eb556 with the 13 pinned dev identifiers. adoption_complete is pinned
to false in code; the root has no variables so a workspace variable
cannot change what applies. The tf-poc root, staging root, and tf-poc
map entries are dropped; staging constants stay only for the checker's
cross-environment negative tests.
65 lines
1.7 KiB
HCL
65 lines
1.7 KiB
HCL
data "aws_caller_identity" "current" {
|
|
lifecycle {
|
|
postcondition {
|
|
condition = self.account_id == var.aws_account_id
|
|
error_message = "Refusing to inspect resources outside the expected AWS account."
|
|
}
|
|
}
|
|
}
|
|
|
|
data "aws_region" "current" {
|
|
lifecycle {
|
|
postcondition {
|
|
condition = self.region == var.aws_region
|
|
error_message = "Refusing to inspect resources outside the expected AWS region."
|
|
}
|
|
}
|
|
}
|
|
|
|
data "aws_route53_zone" "site" {
|
|
name = "${trimsuffix(var.hosted_zone_name, ".")}."
|
|
private_zone = false
|
|
|
|
lifecycle {
|
|
postcondition {
|
|
condition = self.zone_id == var.expected_hosted_zone_id
|
|
error_message = "The resolved Route 53 zone does not match the pinned hosted zone."
|
|
}
|
|
}
|
|
}
|
|
|
|
data "aws_acm_certificate" "shared" {
|
|
domain = var.certificate_domain
|
|
statuses = ["ISSUED"]
|
|
types = ["AMAZON_ISSUED"]
|
|
most_recent = true
|
|
|
|
lifecycle {
|
|
postcondition {
|
|
condition = self.arn == var.expected_certificate_arn
|
|
error_message = "The resolved ACM certificate does not match the pinned certificate."
|
|
}
|
|
}
|
|
}
|
|
|
|
data "aws_iam_openid_connect_provider" "github" {
|
|
url = "https://token.actions.githubusercontent.com"
|
|
|
|
lifecycle {
|
|
postcondition {
|
|
condition = self.arn == var.expected_github_oidc_provider_arn
|
|
error_message = "The GitHub OIDC provider does not match the pinned account provider."
|
|
}
|
|
}
|
|
}
|
|
|
|
data "aws_cloudfront_cache_policy" "managed" {
|
|
name = var.cache_policy_name
|
|
|
|
lifecycle {
|
|
postcondition {
|
|
condition = self.id == var.expected_cache_policy_id
|
|
error_message = "The AWS managed CloudFront cache policy does not match the pinned ID."
|
|
}
|
|
}
|
|
}
|