Repository navigation
Expand file tree
/
Copy pathvariables.tf
More file actions
102 lines (88 loc) · 3.29 KB
/
Copy pathvariables.tf
File metadata and controls
102 lines (88 loc) · 3.29 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
variable "github" {
description = <<-EOT
The GitHub configuration used for configuring the OIDC provider.
`owner_id` and `repo_id` are the numeric GitHub IDs used by the subject
claim. Read them from the `github_organization` and `github_repository` data
sources rather than pasting them in, so that they cannot drift from `owner`
and `repo`.
EOT
type = object({
owner = string
owner_id = string
repo = string
repo_id = string
trunk_branch = string
})
validation {
condition = length(var.github.owner) > 0 && length(var.github.repo) > 0 && length(var.github.trunk_branch) > 0
error_message = "github.owner, github.repo and github.trunk_branch must all be non-empty."
}
# A wildcard here would still produce a working trust policy, but one that
# matches far more than the intended repository, so reject anything but digits.
validation {
condition = alltrue([
for id in [var.github.owner_id, var.github.repo_id] : can(regex("^[1-9][0-9]*$", id))
])
error_message = "github.owner_id and github.repo_id must each be a numeric GitHub ID."
}
}
variable "tfstate_config" {
description = "The Terraform state backend configuration, to which the provider will provide access."
type = object({
bucket_name = string
state_files = list(string)
})
validation {
condition = length(var.tfstate_config.bucket_name) >= 3 && length(var.tfstate_config.bucket_name) <= 63
error_message = "tfstate_config.bucket_name must be a valid S3 bucket name (3-63 characters)."
}
validation {
condition = length(var.tfstate_config.state_files) > 0
error_message = "tfstate_config.state_files must contain at least one state file path."
}
}
variable "name_prefix" {
description = "The name prefix used for the resources created by this module."
type = string
validation {
# "gha-<name_prefix>-admin" must stay within the 64-character IAM role name limit.
condition = can(regex("^[a-zA-Z0-9-]+$", var.name_prefix)) && length(var.name_prefix) <= 54
error_message = "name_prefix must contain only alphanumeric characters and hyphens, and be at most 54 characters."
}
}
variable "read_policy_document" {
description = "The IAM policy document for the reader role assumed from non-trunk branch workflows."
type = object({
Version = string
Statement = list(object({
Effect = string
Action = list(string)
Resource = string
}))
})
}
variable "admin_policy_document" {
description = "The IAM policy document for the admin role assumed from trunk branch workflows."
type = object({
Version = string
Statement = list(object({
Effect = string
Action = list(string)
Resource = string
}))
})
}
variable "max_session_duration" {
description = "The maximum session duration (in seconds) for the admin and reader roles."
type = number
default = 3600
validation {
condition = var.max_session_duration >= 3600 && var.max_session_duration <= 43200
error_message = "max_session_duration must be between 3600 and 43200 seconds (AWS IAM limits)."
}
}
variable "tags" {
description = "A map of tags to apply to all resources created by this module."
type = map(string)
default = {}
}