mirror of
https://github.com/Sea-Haven-Industries/shoc-frontend-new.git
synced 2026-09-30 09:13:11 +00:00
Some checks failed
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD Give HCP the bucket and CloudFront with an empty origin path. GitHub owns bucket-root sync and invalidation so merge-to-main and a human staging tag can deploy without creating HCP runs. G13 fails PRs that mix terraform/ with deployable application files. * ci: run Frontend checks and Terraform CI on PRs to main and dev Match backend 148 so a PR targeting origin/dev still gets the required checks. Push remains main only. * refactor(terraform): keep live/dev and live/staging as HCP roots Leave the adopted working directories in place so this CD PR does not retarget two live HCP workspaces. Flattening stays a later change. * style: prettier terraform-validate.mjs * fix(terraform): pin githubdeploy assume-role policy in import checker Reject controlled role updates whose trust document is not the rendered GitHub OIDC policy, matching the bucket-policy pin.
95 lines
4 KiB
HCL
95 lines
4 KiB
HCL
locals {
|
|
# Controlled ownership transfer. Pinned in code, never a workspace variable.
|
|
adoption_complete = true
|
|
|
|
environment = "dev"
|
|
workspace_name = "shoc-frontend-new-dev"
|
|
github_repo = "Sea-Haven-Industries/shoc-frontend-new"
|
|
aws_account_id = "396287094661"
|
|
aws_region = "us-east-1"
|
|
bucket_name = "seahaven-shoc-frontend-dev"
|
|
distribution_id = "E2CWLM1AFB964P"
|
|
oac_id = "E30VSIK87N8H64"
|
|
oac_name = "shocfrontenddevDistributionOrigin1S3OriginAccessControlDFC82620"
|
|
origin_id = "shocfrontenddevDistributionOrigin10CCD0EE1"
|
|
function_name = "us-east-1shocfrontenddevSpaRewrite58674DB8"
|
|
domain_name = "dev.seahaven.com"
|
|
hosted_zone_id = "Z07671212N75U4YLPWZR8"
|
|
certificate_arn = (
|
|
"arn:aws:acm:us-east-1:396287094661:certificate/2b78e74f-7b65-4b82-a413-7a498b102f00"
|
|
)
|
|
github_oidc_arn = (
|
|
"arn:aws:iam::396287094661:oidc-provider/token.actions.githubusercontent.com"
|
|
)
|
|
deploy_role_name = "githubdeploy-shoc-frontend-new-dev"
|
|
inline_policy = "GithubDeployRoleDefaultPolicyE8F540D1"
|
|
stack_name = "shoc-frontend-dev"
|
|
cache_policy_id = "658327ea-f89d-4fab-a63d-7e88639e58f6"
|
|
permissions_boundary_arn = (
|
|
"arn:aws:iam::396287094661:policy/shoc-frontend-new-dev-deploy-boundary"
|
|
)
|
|
bucket_auto_delete_helper_role_arn = (
|
|
"arn:aws:iam::396287094661:role/shoc-frontend-dev-CustomS3AutoDeleteObjectsCustomRe-dmSDIY8EH7KV"
|
|
)
|
|
legacy_tags = {
|
|
Environment = "dev"
|
|
ManagedBy = "cdk"
|
|
Project = "shoc-frontend"
|
|
}
|
|
legacy_bucket_tags = merge(local.legacy_tags, {
|
|
"aws-cdk:auto-delete-objects" = "true"
|
|
})
|
|
terraform_tags = {
|
|
Environment = "dev"
|
|
ManagedBy = "terraform"
|
|
Ownership = "terraform"
|
|
Project = "shoc-frontend"
|
|
}
|
|
manager_tag = {
|
|
HcpTerraformWorkspace = local.workspace_name
|
|
}
|
|
}
|
|
|
|
module "inventory" {
|
|
source = "../modules/environment-inventory"
|
|
|
|
aws_account_id = local.aws_account_id
|
|
aws_region = local.aws_region
|
|
hosted_zone_name = local.domain_name
|
|
expected_hosted_zone_id = local.hosted_zone_id
|
|
certificate_domain = "*.seahaven.com"
|
|
expected_certificate_arn = local.certificate_arn
|
|
expected_github_oidc_provider_arn = local.github_oidc_arn
|
|
expected_cache_policy_id = local.cache_policy_id
|
|
}
|
|
|
|
module "environment_owned" {
|
|
source = "../modules/environment-owned"
|
|
|
|
environment = local.environment
|
|
adoption_complete = local.adoption_complete
|
|
aws_account_id = local.aws_account_id
|
|
aws_region = local.aws_region
|
|
github_repo = local.github_repo
|
|
bucket_name = local.bucket_name
|
|
distribution_id = local.distribution_id
|
|
origin_access_control_name = local.oac_name
|
|
origin_access_control_description = ""
|
|
origin_id = local.origin_id
|
|
function_name = local.function_name
|
|
domain_name = local.domain_name
|
|
hosted_zone_id = local.hosted_zone_id
|
|
certificate_arn = local.certificate_arn
|
|
cache_policy_id = local.cache_policy_id
|
|
github_oidc_provider_arn = local.github_oidc_arn
|
|
deploy_role_name = local.deploy_role_name
|
|
deploy_inline_policy_name = local.inline_policy
|
|
deploy_permissions_boundary_arn = local.permissions_boundary_arn
|
|
cloudformation_stack_name = local.stack_name
|
|
bucket_auto_delete_helper_role_arn = local.bucket_auto_delete_helper_role_arn
|
|
pre_adoption_tags = local.legacy_tags
|
|
pre_adoption_bucket_tags = local.legacy_bucket_tags
|
|
ownership_tags = local.terraform_tags
|
|
pre_adoption_deploy_role_tags = merge(local.legacy_tags, local.manager_tag)
|
|
post_adoption_deploy_role_tags = merge(local.terraform_tags, local.manager_tag)
|
|
}
|