shoc-frontend-new/terraform
Adam Moussa c96a259365
Some checks failed
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
refactor(cd): ship SPA content from GitHub on main (#220)
* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD

Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.

* ci: run Frontend checks and Terraform CI on PRs to main and dev

Match backend 148 so a PR targeting origin/dev still gets the required
checks. Push remains main only.

* refactor(terraform): keep live/dev and live/staging as HCP roots

Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.

* style: prettier terraform-validate.mjs

* fix(terraform): pin githubdeploy assume-role policy in import checker

Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
2026-09-18 14:30:20 -04:00
..
live refactor(cd): ship SPA content from GitHub on main (#220) 2026-09-18 14:30:20 -04:00
README.md refactor(cd): ship SPA content from GitHub on main (#220) 2026-09-18 14:30:20 -04:00

Frontend Terraform (SPA CD)

terraform/live/dev and terraform/live/staging in AWS account 396287094661. HCP Terraform owns the bucket, CloudFront, DNS, and the GitHub deploy role. GitHub Actions owns content: .github/workflows/deploy-web.yaml syncs dist/ to the bucket root and invalidates /*.

Creating, formatting, initializing with -backend=false, and validating these files does not authorize an AWS, HCP Terraform, GitHub, or deployment mutation. Live cutover waits for an explicit greenlight.

Do not collapse these roots into one terraform/ tree in this PR. Flattening retargets two live HCP working directories and is its own change.

Fixed targets

dev staging
Site dev.seahaven.com staging.seahaven.com
Bucket seahaven-shoc-frontend-dev seahaven-shoc-frontend-staging
Distribution E2CWLM1AFB964P E2JDVEZ6EGD49J
Deploy role githubdeploy-shoc-frontend-new-dev githubdeploy-shoc-frontend-new-staging
HCP workspace shoc-frontend-new-dev shoc-frontend-new-staging
Working dir terraform/live/dev terraform/live/staging

There is no prod CloudFront in this round. Do not create shoc-frontend-new-prod.

Ownership

module.environment_owned keeps the same addresses as the adopted HCP shoc-frontend-new-dev state. The SPA origin path is empty. The release pointer is forgotten (removed { destroy = false }), not destroyed.

Deploy parameters live under /shoc-frontend-new/<env>/deploy/{bucket,distribution-id}. githubdeploy may List/Get/Put/Delete the bucket root, CreateInvalidation, and GetParameter on those two names. OIDC trust is environment:<env> plus job_workflow_ref for .github/workflows/deploy-web.yaml at refs/heads/main and refs/tags/v*.

adoption_complete is pinned in each live root. It is not a workspace variable.

Local checks (no apply)

terraform fmt -check -recursive terraform
terraform -chdir=terraform/live/dev init -backend=false -lockfile=readonly
terraform -chdir=terraform/live/dev validate
terraform -chdir=terraform/live/staging init -backend=false -lockfile=readonly
terraform -chdir=terraform/live/staging validate
python3 scripts/test-terraform-import-plan-check.py
python3 scripts/test_check_app_terraform_isolation.py
bash scripts/test-verify-cloudfront-release.sh

PRs cannot mix terraform/ with deployable application files. Workflow, docs, and gate-script changes may travel with either side. G13 is python3 scripts/check_app_terraform_isolation.py against the PR base.

npm run test:terraform and npm run verify wrap the same gates. They never create an HCP run or touch AWS.

Cutover (greenlight only)

  1. Keep HCP working directories terraform/live/dev and terraform/live/staging. Dev VCS branch main. Staging tag regex ^v[0-9]+\.[0-9]+\.[0-9]+-staging$.
  2. Auto-apply off. Apply the origin-path move for dev before any --delete root sync.
  3. Create GitHub Environment dev (staging already exists). Set DEPLOY_ROLE_ARN on each.
  4. Enable deploy-web.yaml. Then retire deploy.yml, TF_API_TOKEN, and TERRAFORM_CONTENT_CD_ENABLED.