mirror of
https://github.com/Sea-Haven-Industries/shoc-frontend-new.git
synced 2026-10-01 22:07:53 +00:00
* feat(terraform): ship dev content CD through Terraform (SH-300) GitHub uploads immutable release prefixes; Terraform owns live publish. Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set. * fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)
194 lines
5.2 KiB
HCL
194 lines
5.2 KiB
HCL
variable "environment" {
|
|
type = string
|
|
description = "Environment name."
|
|
|
|
validation {
|
|
condition = contains(["dev", "staging"], var.environment)
|
|
error_message = "environment must be dev or staging."
|
|
}
|
|
}
|
|
|
|
variable "adoption_complete" {
|
|
type = bool
|
|
description = "Switches ownership tags and drops the auto-delete helper grant from the bucket policy."
|
|
default = false
|
|
}
|
|
|
|
variable "release_version_label" {
|
|
type = string
|
|
default = null
|
|
nullable = true
|
|
|
|
description = "Immutable content release label. Null VCS plans read the live pointer from S3."
|
|
|
|
validation {
|
|
condition = (
|
|
var.release_version_label == null ||
|
|
var.release_version_label == "" ||
|
|
can(regex("^[0-9a-f]{40}-[0-9]+-[0-9]+$", var.release_version_label))
|
|
)
|
|
error_message = "release_version_label must be empty or <full-sha>-<run-id>-<attempt>."
|
|
}
|
|
}
|
|
|
|
variable "previous_release_version_label" {
|
|
type = string
|
|
default = null
|
|
nullable = true
|
|
|
|
description = "Previous content release label used as the origin-group failover. Null VCS plans read the live pointer from S3."
|
|
|
|
validation {
|
|
condition = (
|
|
var.previous_release_version_label == null ||
|
|
var.previous_release_version_label == "" ||
|
|
can(regex("^[0-9a-f]{40}-[0-9]+-[0-9]+$", var.previous_release_version_label))
|
|
)
|
|
error_message = "previous_release_version_label must be empty or <full-sha>-<run-id>-<attempt>."
|
|
}
|
|
}
|
|
|
|
variable "aws_account_id" {
|
|
type = string
|
|
description = "AWS account containing the resources."
|
|
}
|
|
|
|
variable "aws_region" {
|
|
type = string
|
|
description = "AWS region used by the environment."
|
|
}
|
|
|
|
variable "bucket_name" {
|
|
type = string
|
|
description = "Existing private S3 origin bucket."
|
|
}
|
|
|
|
variable "distribution_id" {
|
|
type = string
|
|
description = "Existing CloudFront distribution ID."
|
|
}
|
|
|
|
variable "origin_access_control_name" {
|
|
type = string
|
|
description = "Exact existing CloudFront OAC name."
|
|
}
|
|
|
|
variable "origin_access_control_description" {
|
|
type = string
|
|
description = "Exact existing CloudFront OAC description."
|
|
}
|
|
|
|
variable "origin_id" {
|
|
type = string
|
|
description = "Exact origin ID in the existing distribution."
|
|
}
|
|
|
|
variable "function_name" {
|
|
type = string
|
|
description = "Existing CloudFront Function name."
|
|
}
|
|
|
|
variable "domain_name" {
|
|
type = string
|
|
description = "Site hostname."
|
|
}
|
|
|
|
variable "hosted_zone_id" {
|
|
type = string
|
|
description = "Inventory-verified hosted zone ID."
|
|
}
|
|
|
|
variable "certificate_arn" {
|
|
type = string
|
|
description = "Inventory-verified ACM certificate ARN."
|
|
}
|
|
|
|
variable "cache_policy_id" {
|
|
type = string
|
|
description = "Inventory-verified AWS managed cache policy ID."
|
|
}
|
|
|
|
variable "github_oidc_provider_arn" {
|
|
type = string
|
|
description = "Inventory-verified GitHub OIDC provider ARN."
|
|
}
|
|
|
|
variable "github_subject" {
|
|
type = string
|
|
description = "Exact GitHub OIDC subject in the existing role."
|
|
}
|
|
|
|
variable "pre_adoption_github_subject_operator" {
|
|
type = string
|
|
description = "Condition operator used by the role before adoption."
|
|
|
|
validation {
|
|
condition = contains(["StringEquals", "StringLike"], var.pre_adoption_github_subject_operator)
|
|
error_message = "pre_adoption_github_subject_operator must be StringEquals or StringLike."
|
|
}
|
|
}
|
|
|
|
variable "post_adoption_github_subject_operator" {
|
|
type = string
|
|
description = "Condition operator used by the role after adoption."
|
|
|
|
validation {
|
|
condition = contains(["StringEquals", "StringLike"], var.post_adoption_github_subject_operator)
|
|
error_message = "post_adoption_github_subject_operator must be StringEquals or StringLike."
|
|
}
|
|
}
|
|
|
|
variable "deploy_branch" {
|
|
type = string
|
|
description = "Branch or environment named in the existing role description."
|
|
}
|
|
|
|
variable "deploy_role_name" {
|
|
type = string
|
|
description = "Existing GitHub deployment role name."
|
|
}
|
|
|
|
variable "deploy_inline_policy_name" {
|
|
type = string
|
|
description = "Existing generated inline policy name."
|
|
}
|
|
|
|
variable "deploy_permissions_boundary_arn" {
|
|
type = string
|
|
description = "Exact permissions boundary attached before import."
|
|
}
|
|
|
|
variable "cloudformation_stack_name" {
|
|
type = string
|
|
description = "Legacy CloudFormation stack used by the pre-adoption policy."
|
|
}
|
|
|
|
variable "bucket_auto_delete_helper_role_arn" {
|
|
type = string
|
|
description = "Exact legacy S3 auto-delete helper role ARN."
|
|
}
|
|
|
|
variable "pre_adoption_tags" {
|
|
type = map(string)
|
|
description = "Exact tags present while CloudFormation still owns the resources."
|
|
}
|
|
|
|
variable "pre_adoption_bucket_tags" {
|
|
type = map(string)
|
|
description = "Exact pre-adoption S3 tags, including the CDK auto-delete marker."
|
|
}
|
|
|
|
variable "ownership_tags" {
|
|
type = map(string)
|
|
description = "Tags applied by the controlled ownership transfer."
|
|
}
|
|
|
|
variable "pre_adoption_deploy_role_tags" {
|
|
type = map(string)
|
|
description = "Exact pre-adoption deploy-role tags, including its HCP manager tag."
|
|
}
|
|
|
|
variable "post_adoption_deploy_role_tags" {
|
|
type = map(string)
|
|
description = "Exact post-adoption deploy-role tags, preserving its HCP manager tag."
|
|
}
|