mirror of
https://github.com/Sea-Haven-Industries/shoc-frontend-new.git
synced 2026-10-07 12:49:00 +00:00
152 lines
5.8 KiB
HCL
152 lines
5.8 KiB
HCL
variable "adoption_complete" {
|
|
type = bool
|
|
description = "Enable only after import, no-op verification, and ownership transfer approval."
|
|
default = false
|
|
}
|
|
|
|
variable "distribution_id" {
|
|
type = string
|
|
description = "CloudFront distribution ID emitted by the tf-poc creator."
|
|
}
|
|
|
|
variable "origin_access_control_id" {
|
|
type = string
|
|
description = "CloudFront OAC ID emitted by the tf-poc creator."
|
|
}
|
|
|
|
variable "origin_access_control_name" {
|
|
type = string
|
|
description = "Exact CloudFront OAC name emitted by the tf-poc creator."
|
|
}
|
|
|
|
variable "origin_id" {
|
|
type = string
|
|
description = "Exact distribution origin ID emitted by the tf-poc creator."
|
|
}
|
|
|
|
variable "function_name" {
|
|
type = string
|
|
description = "CloudFront Function name emitted by the tf-poc creator."
|
|
}
|
|
|
|
variable "hosted_zone_id" {
|
|
type = string
|
|
description = "Dedicated frontend tf-poc hosted zone ID emitted by the creator."
|
|
}
|
|
|
|
variable "certificate_arn" {
|
|
type = string
|
|
description = "Dedicated frontend tf-poc ACM certificate ARN emitted by the creator."
|
|
}
|
|
|
|
variable "deploy_inline_policy_name" {
|
|
type = string
|
|
description = "Generated inline policy name emitted by the tf-poc creator."
|
|
}
|
|
|
|
variable "bucket_auto_delete_helper_role_arn" {
|
|
type = string
|
|
description = "S3 auto-delete helper role ARN emitted by the tf-poc creator."
|
|
}
|
|
|
|
locals {
|
|
environment = "tf-poc"
|
|
workspace_name = "shoc-frontend-new-tf-poc"
|
|
aws_account_id = "396287094661"
|
|
aws_region = "us-east-1"
|
|
bucket_name = "seahaven-shoc-frontend-tf-poc"
|
|
domain_name = "frontend-tf-poc.seahaven.com"
|
|
api_url = "https://api.tf-poc.seahaven.com/api"
|
|
github_oidc_arn = "arn:aws:iam::396287094661:oidc-provider/token.actions.githubusercontent.com"
|
|
deploy_role_name = "githubdeploy-shoc-frontend-new-tf-poc"
|
|
stack_name = "shoc-frontend-tf-poc"
|
|
cache_policy_id = "658327ea-f89d-4fab-a63d-7e88639e58f6"
|
|
permissions_boundary_arn = (
|
|
"arn:aws:iam::396287094661:policy/shoc-frontend-new-tf-poc-deploy-boundary"
|
|
)
|
|
generated_values = {
|
|
distribution_id = var.distribution_id
|
|
origin_access_control_id = var.origin_access_control_id
|
|
origin_access_control_name = var.origin_access_control_name
|
|
origin_id = var.origin_id
|
|
function_name = var.function_name
|
|
hosted_zone_id = var.hosted_zone_id
|
|
certificate_arn = var.certificate_arn
|
|
deploy_inline_policy_name = var.deploy_inline_policy_name
|
|
bucket_auto_delete_helper_role_arn = var.bucket_auto_delete_helper_role_arn
|
|
}
|
|
legacy_tags = {
|
|
Environment = "tf-poc"
|
|
ManagedBy = "cdk"
|
|
Project = "shoc-frontend"
|
|
}
|
|
legacy_bucket_tags = merge(local.legacy_tags, {
|
|
"aws-cdk:auto-delete-objects" = "true"
|
|
})
|
|
terraform_tags = {
|
|
Environment = "tf-poc"
|
|
ManagedBy = "terraform"
|
|
Ownership = "terraform"
|
|
Project = "shoc-frontend"
|
|
}
|
|
manager_tag = {
|
|
HcpTerraformWorkspace = local.workspace_name
|
|
}
|
|
}
|
|
|
|
check "creator_outputs_populated" {
|
|
assert {
|
|
condition = alltrue([
|
|
for value in values(local.generated_values) :
|
|
length(trimspace(value)) > 0 && !startswith(value, "REPLACE_WITH_")
|
|
])
|
|
error_message = "Populate every tf-poc generated value from creator outputs before planning."
|
|
}
|
|
}
|
|
|
|
module "inventory" {
|
|
source = "../modules/environment-inventory"
|
|
|
|
aws_account_id = local.aws_account_id
|
|
aws_region = local.aws_region
|
|
hosted_zone_name = local.domain_name
|
|
expected_hosted_zone_id = var.hosted_zone_id
|
|
certificate_domain = local.domain_name
|
|
expected_certificate_arn = var.certificate_arn
|
|
expected_github_oidc_provider_arn = local.github_oidc_arn
|
|
expected_cache_policy_id = local.cache_policy_id
|
|
}
|
|
|
|
module "environment_owned" {
|
|
source = "../modules/environment-owned"
|
|
|
|
environment = local.environment
|
|
adoption_complete = var.adoption_complete
|
|
aws_account_id = local.aws_account_id
|
|
aws_region = local.aws_region
|
|
bucket_name = local.bucket_name
|
|
distribution_id = var.distribution_id
|
|
origin_access_control_name = var.origin_access_control_name
|
|
origin_access_control_description = ""
|
|
origin_id = var.origin_id
|
|
function_name = var.function_name
|
|
domain_name = local.domain_name
|
|
hosted_zone_id = var.hosted_zone_id
|
|
certificate_arn = var.certificate_arn
|
|
cache_policy_id = local.cache_policy_id
|
|
github_oidc_provider_arn = local.github_oidc_arn
|
|
github_subject = "repo:Sea-Haven-Industries/shoc-frontend-new:environment:tf-poc"
|
|
pre_adoption_github_subject_operator = "StringEquals"
|
|
post_adoption_github_subject_operator = "StringEquals"
|
|
deploy_branch = "tf-poc"
|
|
deploy_role_name = local.deploy_role_name
|
|
deploy_inline_policy_name = var.deploy_inline_policy_name
|
|
deploy_permissions_boundary_arn = local.permissions_boundary_arn
|
|
cloudformation_stack_name = local.stack_name
|
|
bucket_auto_delete_helper_role_arn = var.bucket_auto_delete_helper_role_arn
|
|
pre_adoption_tags = local.legacy_tags
|
|
pre_adoption_bucket_tags = local.legacy_bucket_tags
|
|
ownership_tags = local.terraform_tags
|
|
pre_adoption_deploy_role_tags = merge(local.legacy_tags, local.manager_tag)
|
|
post_adoption_deploy_role_tags = merge(local.terraform_tags, local.manager_tag)
|
|
}
|