Skip to content

chore(infra): parameterize the AWS account id and fix stale docs - #375

Merged
nourshoreibah merged 8 commits into
mainfrom
chore/parameterize-aws-account
Aug 25, 2026
Merged

nourshoreibah merged 8 commits into
mainfrom
chore/parameterize-aws-account

Conversation

@nourshoreibah

Copy link
Copy Markdown
Collaborator

Why

The AWS account id was hardcoded into six workflow role ARNs, so pointing CI at a different account meant editing six files with no single source of truth. This makes that a one-value change, and clears out documentation that actively misleads anyone setting the project up.

What changed

Account id is now a Terraform-managed Actions variable. var.aws_account_id (infrastructure/github/variables.tf) → github_actions_variable.aws_account_id → ${{ vars.AWS_ACCOUNT_ID }}, interpolated by every role ARN in frontend-deploy, lambda-deploy (×2), preview-env, terraform-apply, and terraform-plan. Default is the current account, so this is a no-op until the variable is changed.

The state bucket in the five backend.tf files stays literal — Terraform backend blocks cannot interpolate variables. That's a language limitation, not an oversight.

Pinned the infisical provider to 0.17.0 in both roots. It was unconstrained and .terraform.lock.hcl is gitignored, so every fresh init resolves it fresh — aws/ had drifted to 0.17.0 and github/ to 0.15.39. Worth a look at the plan output to confirm github/ is happy on the newer version.

Docs:

  • README.md was upstream terraform-docs boilerplate. Replaced with a real one (stack, quick start, first-admin bootstrap, doc index, deploy model).
  • infrastructure/README.md documented a module.aws/module.github root composition that doesn't exist. It's never regenerated by terraform-docs either, since that dir holds no .tf files. Replaced with a module index.
  • example.env was 0 bytes and referenced by nothing — removed. Added apps/frontend/.env.example instead, since NEXT_PUBLIC_API_BASE_URL had no template anywhere and silently falls back to localhost. Needed a .gitignore exception.
  • infrastructure/AGENTS.md: said three root modules (five), postgres 17.6 (17.9), and described an RDS in test/ whose main.tf is empty. Also notes the account-bootstrap exception to "don't apply by hand".

Cleanups: dropped the /github Infisical data source in aws/secrets.tf (declared, never referenced in that module) and corrected the oidc.tf comment claiming branch_rds has no explicit identifier — it does, main.tf:6.

Verification

  • terraform fmt -recursive -check clean
  • terraform validate passes in aws/ and github/ (pre-existing has_downloads deprecation warnings only)
  • grep -rn 489881683177 returns only the variable default

The plan comment on this PR is the real check — it should show the new github_actions_variable as the only resource change, and no diff in aws/.

⚠️ On merge, vars.AWS_ACCOUNT_ID must exist before any workflow runs, or every role ARN resolves to arn:aws:iam:::role/.... Applying infrastructure/github creates it; the terraform-apply job on this merge does that in the same run, but it's worth watching.

🤖 Generated with Claude Code

nourshoreibah and others added 6 commits August 24, 2026 22:23
The account id was hardcoded into six workflow role ARNs, so pointing CI at a
different AWS account meant editing six files with no single source of truth.

Publish it as a Terraform-managed Actions variable instead: `var.aws_account_id`
-> `vars.AWS_ACCOUNT_ID`, interpolated by every role ARN. Changing accounts is now
one default plus an apply. The state bucket stays literal in the five backend.tf
files because Terraform backend blocks cannot interpolate variables.

Also pins the infisical provider. It was unconstrained in both roots and
.terraform.lock.hcl is gitignored, so a fresh init resolves it fresh -- aws had
drifted to 0.17.0 and github to 0.15.39. Both now pinned to 0.17.0.

Docs were actively misleading:
- root README.md was upstream terraform-docs boilerplate, not about this project
- infrastructure/README.md documented a module.aws/module.github root composition
  that does not exist, and is never regenerated since that dir holds no .tf files
- example.env was 0 bytes and referenced by nothing; removed in favour of a real
  apps/frontend/.env.example, which needed a gitignore exception since
  NEXT_PUBLIC_API_BASE_URL was undocumented in template form
- infrastructure/AGENTS.md said three root modules (five), postgres 17.6 (17.9),
  and described an RDS in test/ whose main.tf is empty

Drops the dead /github Infisical data source in aws/ (declared, never referenced)
and corrects the oidc.tf comment claiming branch_rds has no explicit identifier.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
  - Auto-formatted .tf files with terraform fmt
  - Updated README.md with terraform-docs

  Co-authored-by: nourshoreibah <nourshoreibah@users.noreply.github.com>
Chicken-and-egg in the previous commit: every workflow role ARN interpolates
vars.AWS_ACCOUNT_ID, so if the variable does not exist the ARN resolves to
arn:aws:iam:::role/... and no job can assume a role. CI therefore cannot apply
infrastructure/github, which is the thing that would have created the variable.

The variable has to be set by hand once, before CI runs. Given that, Terraform
must adopt it rather than create it -- a create against an existing variable is
a 409.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The terraform-docs release tarball ships its own README.md and LICENSE. Unpacking
it in the checkout root overwrote the repo's README.md, and the auto-commit step
in the same job then committed the result -- which is why the root README has been
upstream terraform-docs boilerplate.

Extract only the binary, into RUNNER_TEMP.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Reverted by the auto-format job before the tarball-extraction fix landed in this
branch. Restoring the intended content.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
  - Auto-formatted .tf files with terraform fmt
  - Updated README.md with terraform-docs

  Co-authored-by: nourshoreibah <nourshoreibah@users.noreply.github.com>
nourshoreibah and others added 2 commits August 24, 2026 22:39
The job ran with `if: always()` and never looked at what it needed -- it echoed a
message and exited 0 regardless. Since terraform-plan-summary is the only
terraform context in branch protection, a PR whose plan errored still showed a
green required check and could merge.

Check the results of terraform-fmt-docs and terraform-plan explicitly. skipped
still counts as success, so PRs that touch no terraform are unaffected.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
S3_BUCKET_NAME is read nowhere -- docker-compose passes REPORTS_BUCKET_NAME, so
anyone following this template left the reports service with an empty bucket name
and no obvious reason why.

Also drops the placeholder values that looked like real settings (`key`,
`secret`, `region or us-east-2`) and notes where the credentials come from.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

Terraform Plan 📖 infrastructure/github

Terraform Initialization ⚙️success

Terraform Validation 🤖success

Terraform Plan 📖success

Show Plan
data.infisical_secrets.slack_folder: Reading...
data.infisical_secrets.infisical_folder: Reading...
data.infisical_secrets.github_folder: Reading...
data.infisical_secrets.cognito_folder: Reading...
data.infisical_secrets.infisical_folder: Read complete after 0s
data.infisical_secrets.github_folder: Read complete after 0s
data.infisical_secrets.slack_folder: Read complete after 0s
data.infisical_secrets.cognito_folder: Read complete after 0s
github_repository.branch: Refreshing state... [id=branch]
github_actions_variable.aws_account_id: Preparing import... [id=branch:AWS_ACCOUNT_ID]
github_actions_secret.gh_pat: Refreshing state... [id=branch:GH_PAT]
github_repository_environment.preview: Refreshing state... [id=branch:preview]
github_branch_default.main: Refreshing state... [id=branch]
github_repository_environment.production_db: Refreshing state... [id=branch:production-db]
github_actions_secret.infisical_client_secret: Refreshing state... [id=branch:INFISICAL_CLIENT_SECRET]
github_actions_secret.cognito_user_pool_id: Refreshing state... [id=branch:COGNITO_USER_POOL_ID]
github_actions_secret.cognito_client_id: Refreshing state... [id=branch:COGNITO_CLIENT_ID]
github_actions_secret.slack_bot_token: Refreshing state... [id=branch:SLACK_BOT_TOKEN]
github_branch_protection.main: Refreshing state... [id=BPR_kwDOPjZxzc4D-9hQ]
github_branch_protection.bot_state: Refreshing state... [id=BPR_kwDOPjZxzc4EU_R9]
github_actions_secret.infisical_client_id: Refreshing state... [id=branch:INFISICAL_CLIENT_ID]
github_branch.bot_state: Refreshing state... [id=branch:bot-state]
github_actions_variable.aws_account_id: Refreshing state... [id=branch:AWS_ACCOUNT_ID]
github_repository_file.bot_config_json: Refreshing state... [id=branch:config.json:bot-state]
github_repository_file.bot_state_json: Refreshing state... [id=branch:state.json:bot-state]

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  ~ update in-place

Terraform will perform the following actions:

  # github_actions_variable.aws_account_id will be imported
    resource "github_actions_variable" "aws_account_id" {
        created_at    = "2026-08-25 03:09:56 +0000 UTC"
        id            = "branch:AWS_ACCOUNT_ID"
        repository    = "branch"
        repository_id = 1043755469
        updated_at    = "2026-08-25 03:09:56 +0000 UTC"
        value         = "489881683177"
        variable_name = "AWS_ACCOUNT_ID"
    }

  # github_repository.branch will be updated in-place
  ~ resource "github_repository" "branch" {
      ~ description                             = "BRANCH's monorepo for frontend, backend, infra" -> "Branch GitHub Admin"
      ~ has_downloads                           = false -> true
        id                                      = "branch"
        name                                    = "branch"
        # (39 unchanged attributes hidden)

        # (1 unchanged block hidden)
    }

Plan: 1 to import, 0 to add, 1 to change, 0 to destroy.

Warning: Argument is deprecated

  with github_repository.branch,
  on main.tf line 6, in resource "github_repository" "branch":
   6:   has_downloads   = true

This attribute is no longer in use, but it hasn't been removed yet. It will
be removed in a future version. See
https://github.com/orgs/community/discussions/102145#discussioncomment-8351756

(and 7 more similar warnings elsewhere)

─────────────────────────────────────────────────────────────────────────────

Saved the plan to: tfplan

To perform exactly these actions, run the following command to apply:
    terraform apply "tfplan"

Pushed by: @nourshoreibah, Action: pull_request

@nourshoreibah nourshoreibah added the no-review The PR review bot won't run label Aug 25, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Terraform Plan 📖 infrastructure/aws

Terraform Initialization ⚙️success

Terraform Validation 🤖success

Terraform Plan 📖success

Show Plan
data.archive_file.lambda_placeholder: Reading...
data.archive_file.lambda_placeholder: Read complete after 0s [id=96878a51e358033297a32b882fd5223cc95fb8a7]
data.infisical_secrets.rds_folder: Reading...
data.infisical_secrets.sentry_folder: Reading...
data.infisical_secrets.grafana_folder: Reading...
data.infisical_secrets.sentry_folder: Read complete after 0s
data.infisical_secrets.grafana_folder: Read complete after 0s
aws_cloudfront_origin_access_control.frontend: Refreshing state... [id=E2T090T8V5CDLN]
aws_cloudfront_function.rewrite_index: Refreshing state... [id=branch-frontend-rewrite-index]
data.infisical_secrets.rds_folder: Read complete after 0s
data.aws_vpc.default: Reading...
aws_api_gateway_rest_api.branch_api: Refreshing state... [id=2apxzxb0r8]
aws_iam_openid_connect_provider.github: Refreshing state... [id=arn:aws:iam::489881683177:oidc-provider/token.actions.githubusercontent.com]
data.aws_caller_identity.current: Reading...
aws_iam_role.lambda_role: Refreshing state... [id=branch-lambda-role]
aws_s3_bucket.reports_bucket: Refreshing state... [id=c4c-branch-generated-reports20251030194253425700000001]
aws_cognito_user_pool.branch_user_pool: Refreshing state... [id=us-east-2_CxTueqe6g]
data.aws_caller_identity.current: Read complete after 0s [id=489881683177]
aws_s3_bucket.lambda_deployments: Refreshing state... [id=branch-lambda-deployments-489881683177]
aws_s3_bucket.frontend: Refreshing state... [id=branch-frontend-489881683177]
data.aws_iam_policy_document.ci_preview_assume: Reading...
data.aws_iam_policy_document.ci_preview_assume: Read complete after 0s [id=282080688]
data.aws_iam_policy_document.ci_migrate_assume: Reading...
data.aws_iam_policy_document.ci_plan_assume: Reading...
data.aws_iam_policy_document.ci_migrate_assume: Read complete after 0s [id=3474878989]
data.aws_iam_policy_document.ci_plan_assume: Read complete after 0s [id=3057813384]
data.aws_iam_policy_document.ci_apply_assume: Reading...
aws_iam_role.ci_preview: Refreshing state... [id=branch-ci-preview]
data.aws_iam_policy_document.ci_apply_assume: Read complete after 0s [id=813913]
aws_iam_role.ci_migrate: Refreshing state... [id=branch-ci-migrate]
aws_iam_role.ci_plan: Refreshing state... [id=branch-ci-plan]
aws_iam_role.ci_apply: Refreshing state... [id=branch-ci-apply]
aws_iam_role_policy_attachment.lambda_basic: Refreshing state... [id=branch-lambda-role/arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole]
aws_iam_role_policy.ci_preview: Refreshing state... [id=branch-ci-preview:preview-env]
aws_api_gateway_resource.lambda_resources["expenditures"]: Refreshing state... [id=6sdj3w]
aws_api_gateway_resource.lambda_resources["auth"]: Refreshing state... [id=u8unad]
aws_api_gateway_resource.lambda_resources["reports"]: Refreshing state... [id=wsnfk2]
aws_api_gateway_resource.lambda_resources["donors"]: Refreshing state... [id=hybur2]
aws_api_gateway_resource.lambda_resources["projects"]: Refreshing state... [id=chhy2i]
aws_api_gateway_resource.lambda_resources["users"]: Refreshing state... [id=0dkbds]
aws_api_gateway_gateway_response.cors["DEFAULT_4XX"]: Refreshing state... [id=aggr-2apxzxb0r8-DEFAULT_4XX]
aws_api_gateway_gateway_response.cors["DEFAULT_5XX"]: Refreshing state... [id=aggr-2apxzxb0r8-DEFAULT_5XX]
aws_iam_role_policy_attachment.ci_apply_admin: Refreshing state... [id=branch-ci-apply/arn:aws:iam::aws:policy/AdministratorAccess]
aws_iam_role_policy_attachment.ci_plan_readonly: Refreshing state... [id=branch-ci-plan/arn:aws:iam::aws:policy/ReadOnlyAccess]
aws_iam_role_policy.ci_plan_state_lock: Refreshing state... [id=branch-ci-plan:tfstate-lock]
aws_iam_role_policy.lambda_cognito_admin: Refreshing state... [id=branch-lambda-role:branch-lambda-cognito-admin]
aws_cognito_user_pool_client.branch_client: Refreshing state... [id=570i6ocj0882qu0ditm4vrr60f]
aws_api_gateway_resource.lambda_proxy["reports"]: Refreshing state... [id=elsvn3]
aws_api_gateway_resource.lambda_proxy["auth"]: Refreshing state... [id=srhf9j]
aws_api_gateway_resource.lambda_proxy["donors"]: Refreshing state... [id=xkazax]
aws_api_gateway_resource.lambda_proxy["expenditures"]: Refreshing state... [id=14khv0]
aws_api_gateway_resource.lambda_proxy["projects"]: Refreshing state... [id=kmwcxq]
aws_api_gateway_resource.lambda_proxy["users"]: Refreshing state... [id=4sjlu3]
aws_s3_bucket_server_side_encryption_configuration.lambda_deployments: Refreshing state... [id=branch-lambda-deployments-489881683177]
aws_api_gateway_method.lambda_methods["users-PATCH"]: Refreshing state... [id=agm-2apxzxb0r8-0dkbds-PATCH]
aws_api_gateway_method.lambda_methods["expenditures-GET"]: Refreshing state... [id=agm-2apxzxb0r8-6sdj3w-GET]
aws_api_gateway_method.lambda_methods["auth-POST"]: Refreshing state... [id=agm-2apxzxb0r8-u8unad-POST]
aws_api_gateway_method.lambda_methods["auth-OPTIONS"]: Refreshing state... [id=agm-2apxzxb0r8-u8unad-OPTIONS]
aws_api_gateway_method.lambda_methods["auth-GET"]: Refreshing state... [id=agm-2apxzxb0r8-u8unad-GET]
aws_api_gateway_method.lambda_methods["users-GET"]: Refreshing state... [id=agm-2apxzxb0r8-0dkbds-GET]
aws_api_gateway_method.lambda_methods["donors-POST"]: Refreshing state... [id=agm-2apxzxb0r8-hybur2-POST]
aws_api_gateway_method.lambda_methods["reports-OPTIONS"]: Refreshing state... [id=agm-2apxzxb0r8-wsnfk2-OPTIONS]
aws_api_gateway_method.lambda_methods["users-POST"]: Refreshing state... [id=agm-2apxzxb0r8-0dkbds-POST]
aws_api_gateway_method.lambda_methods["projects-OPTIONS"]: Refreshing state... [id=agm-2apxzxb0r8-chhy2i-OPTIONS]
aws_api_gateway_method.lambda_methods["donors-OPTIONS"]: Refreshing state... [id=agm-2apxzxb0r8-hybur2-OPTIONS]
aws_api_gateway_method.lambda_methods["projects-POST"]: Refreshing state... [id=agm-2apxzxb0r8-chhy2i-POST]
aws_api_gateway_method.lambda_methods["expenditures-PATCH"]: Refreshing state... [id=agm-2apxzxb0r8-6sdj3w-PATCH]
aws_api_gateway_method.lambda_methods["expenditures-OPTIONS"]: Refreshing state... [id=agm-2apxzxb0r8-6sdj3w-OPTIONS]
aws_api_gateway_method.lambda_methods["users-OPTIONS"]: Refreshing state... [id=agm-2apxzxb0r8-0dkbds-OPTIONS]
aws_api_gateway_method.lambda_methods["expenditures-POST"]: Refreshing state... [id=agm-2apxzxb0r8-6sdj3w-POST]
aws_api_gateway_method.lambda_methods["reports-GET"]: Refreshing state... [id=agm-2apxzxb0r8-wsnfk2-GET]
aws_api_gateway_method.lambda_methods["projects-GET"]: Refreshing state... [id=agm-2apxzxb0r8-chhy2i-GET]
data.aws_vpc.default: Read complete after 1s [id=vpc-0a9ccfb59c8918ce9]
aws_api_gateway_method.lambda_methods["donors-GET"]: Refreshing state... [id=agm-2apxzxb0r8-hybur2-GET]
aws_api_gateway_method.lambda_methods["users-DELETE"]: Refreshing state... [id=agm-2apxzxb0r8-0dkbds-DELETE]
aws_s3_object.lambda_placeholder["users"]: Refreshing state... [id=branch-lambda-deployments-489881683177/users/initial.zip]
aws_s3_object.lambda_placeholder["donors"]: Refreshing state... [id=branch-lambda-deployments-489881683177/donors/initial.zip]
aws_s3_object.lambda_placeholder["expenditures"]: Refreshing state... [id=branch-lambda-deployments-489881683177/expenditures/initial.zip]
aws_s3_object.lambda_placeholder["auth"]: Refreshing state... [id=branch-lambda-deployments-489881683177/auth/initial.zip]
aws_s3_object.lambda_placeholder["projects"]: Refreshing state... [id=branch-lambda-deployments-489881683177/projects/initial.zip]
aws_s3_object.lambda_placeholder["reports"]: Refreshing state... [id=branch-lambda-deployments-489881683177/reports/initial.zip]
aws_s3_bucket_versioning.lambda_deployments: Refreshing state... [id=branch-lambda-deployments-489881683177]
aws_s3_bucket_public_access_block.reports_bucket_public_access: Refreshing state... [id=c4c-branch-generated-reports20251030194253425700000001]
aws_iam_role_policy.lambda_s3_objects: Refreshing state... [id=branch-lambda-role:branch-lambda-s3-objects]
aws_api_gateway_method.lambda_proxy_any["users"]: Refreshing state... [id=agm-2apxzxb0r8-4sjlu3-ANY]
aws_api_gateway_method.lambda_proxy_any["auth"]: Refreshing state... [id=agm-2apxzxb0r8-srhf9j-ANY]
aws_api_gateway_method.lambda_proxy_any["donors"]: Refreshing state... [id=agm-2apxzxb0r8-xkazax-ANY]
aws_api_gateway_method.lambda_proxy_any["expenditures"]: Refreshing state... [id=agm-2apxzxb0r8-14khv0-ANY]
aws_api_gateway_method.lambda_proxy_any["projects"]: Refreshing state... [id=agm-2apxzxb0r8-kmwcxq-ANY]
aws_api_gateway_method.lambda_proxy_any["reports"]: Refreshing state... [id=agm-2apxzxb0r8-elsvn3-ANY]
aws_api_gateway_method.cors_proxy_options["users"]: Refreshing state... [id=agm-2apxzxb0r8-4sjlu3-OPTIONS]
aws_api_gateway_method.cors_proxy_options["donors"]: Refreshing state... [id=agm-2apxzxb0r8-xkazax-OPTIONS]
aws_api_gateway_method.cors_proxy_options["expenditures"]: Refreshing state... [id=agm-2apxzxb0r8-14khv0-OPTIONS]
aws_api_gateway_method.cors_proxy_options["reports"]: Refreshing state... [id=agm-2apxzxb0r8-elsvn3-OPTIONS]
aws_api_gateway_method.cors_proxy_options["auth"]: Refreshing state... [id=agm-2apxzxb0r8-srhf9j-OPTIONS]
aws_api_gateway_method.cors_proxy_options["projects"]: Refreshing state... [id=agm-2apxzxb0r8-kmwcxq-OPTIONS]
aws_s3_bucket_public_access_block.frontend: Refreshing state... [id=branch-frontend-489881683177]
aws_security_group.rds: Refreshing state... [id=sg-0c8a1ff1676a14edb]
aws_cloudfront_distribution.frontend: Refreshing state... [id=E37FDHRYNZNF4R]
aws_api_gateway_method_response.cors["users-proxy"]: Refreshing state... [id=agmr-2apxzxb0r8-4sjlu3-OPTIONS-200]
aws_api_gateway_method_response.cors["expenditures-proxy"]: Refreshing state... [id=agmr-2apxzxb0r8-14khv0-OPTIONS-200]
aws_api_gateway_method_response.cors["donors-proxy"]: Refreshing state... [id=agmr-2apxzxb0r8-xkazax-OPTIONS-200]
aws_api_gateway_method_response.cors["projects"]: Refreshing state... [id=agmr-2apxzxb0r8-chhy2i-OPTIONS-200]
aws_api_gateway_method_response.cors["auth-proxy"]: Refreshing state... [id=agmr-2apxzxb0r8-srhf9j-OPTIONS-200]
aws_api_gateway_method_response.cors["auth"]: Refreshing state... [id=agmr-2apxzxb0r8-u8unad-OPTIONS-200]
aws_api_gateway_method_response.cors["donors"]: Refreshing state... [id=agmr-2apxzxb0r8-hybur2-OPTIONS-200]
aws_api_gateway_method_response.cors["reports-proxy"]: Refreshing state... [id=agmr-2apxzxb0r8-elsvn3-OPTIONS-200]
aws_api_gateway_method_response.cors["projects-proxy"]: Refreshing state... [id=agmr-2apxzxb0r8-kmwcxq-OPTIONS-200]
aws_api_gateway_method_response.cors["expenditures"]: Refreshing state... [id=agmr-2apxzxb0r8-6sdj3w-OPTIONS-200]
aws_api_gateway_method_response.cors["users"]: Refreshing state... [id=agmr-2apxzxb0r8-0dkbds-OPTIONS-200]
aws_api_gateway_method_response.cors["reports"]: Refreshing state... [id=agmr-2apxzxb0r8-wsnfk2-OPTIONS-200]
aws_api_gateway_integration.cors["users"]: Refreshing state... [id=agi-2apxzxb0r8-0dkbds-OPTIONS]
aws_api_gateway_integration.cors["donors-proxy"]: Refreshing state... [id=agi-2apxzxb0r8-xkazax-OPTIONS]
aws_api_gateway_integration.cors["donors"]: Refreshing state... [id=agi-2apxzxb0r8-hybur2-OPTIONS]
aws_api_gateway_integration.cors["expenditures"]: Refreshing state... [id=agi-2apxzxb0r8-6sdj3w-OPTIONS]
aws_api_gateway_integration.cors["projects-proxy"]: Refreshing state... [id=agi-2apxzxb0r8-kmwcxq-OPTIONS]
aws_api_gateway_integration.cors["auth"]: Refreshing state... [id=agi-2apxzxb0r8-u8unad-OPTIONS]
aws_api_gateway_integration.cors["reports"]: Refreshing state... [id=agi-2apxzxb0r8-wsnfk2-OPTIONS]
aws_api_gateway_integration.cors["expenditures-proxy"]: Refreshing state... [id=agi-2apxzxb0r8-14khv0-OPTIONS]
aws_api_gateway_integration.cors["reports-proxy"]: Refreshing state... [id=agi-2apxzxb0r8-elsvn3-OPTIONS]
aws_api_gateway_integration.cors["auth-proxy"]: Refreshing state... [id=agi-2apxzxb0r8-srhf9j-OPTIONS]
aws_api_gateway_integration.cors["projects"]: Refreshing state... [id=agi-2apxzxb0r8-chhy2i-OPTIONS]
aws_api_gateway_integration.cors["users-proxy"]: Refreshing state... [id=agi-2apxzxb0r8-4sjlu3-OPTIONS]
aws_vpc_security_group_ingress_rule.rds_postgres: Refreshing state... [id=sgr-0594341dc6234d55c]
aws_db_instance.branch_rds: Refreshing state... [id=db-AMMYFTORW6XJGRELV7WQZCNHQI]
aws_vpc_security_group_egress_rule.rds_all: Refreshing state... [id=sgr-099fe0d98d4b3f3b5]
data.aws_iam_policy_document.frontend_bucket: Reading...
data.aws_iam_policy_document.frontend_bucket: Read complete after 0s [id=1471335443]
aws_s3_bucket_policy.frontend: Refreshing state... [id=branch-frontend-489881683177]
aws_api_gateway_integration_response.cors["expenditures-proxy"]: Refreshing state... [id=agir-2apxzxb0r8-14khv0-OPTIONS-200]
aws_api_gateway_integration_response.cors["projects-proxy"]: Refreshing state... [id=agir-2apxzxb0r8-kmwcxq-OPTIONS-200]
aws_api_gateway_integration_response.cors["users-proxy"]: Refreshing state... [id=agir-2apxzxb0r8-4sjlu3-OPTIONS-200]
aws_api_gateway_integration_response.cors["auth"]: Refreshing state... [id=agir-2apxzxb0r8-u8unad-OPTIONS-200]
aws_api_gateway_integration_response.cors["projects"]: Refreshing state... [id=agir-2apxzxb0r8-chhy2i-OPTIONS-200]
aws_api_gateway_integration_response.cors["auth-proxy"]: Refreshing state... [id=agir-2apxzxb0r8-srhf9j-OPTIONS-200]
aws_api_gateway_integration_response.cors["donors"]: Refreshing state... [id=agir-2apxzxb0r8-hybur2-OPTIONS-200]
aws_api_gateway_integration_response.cors["expenditures"]: Refreshing state... [id=agir-2apxzxb0r8-6sdj3w-OPTIONS-200]
aws_api_gateway_integration_response.cors["reports"]: Refreshing state... [id=agir-2apxzxb0r8-wsnfk2-OPTIONS-200]
aws_api_gateway_integration_response.cors["reports-proxy"]: Refreshing state... [id=agir-2apxzxb0r8-elsvn3-OPTIONS-200]
aws_api_gateway_integration_response.cors["users"]: Refreshing state... [id=agir-2apxzxb0r8-0dkbds-OPTIONS-200]
aws_api_gateway_integration_response.cors["donors-proxy"]: Refreshing state... [id=agir-2apxzxb0r8-xkazax-OPTIONS-200]
aws_lambda_function.functions["expenditures"]: Refreshing state... [id=branch-expenditures]
aws_lambda_function.functions["auth"]: Refreshing state... [id=branch-auth]
aws_lambda_function.functions["projects"]: Refreshing state... [id=branch-projects]
aws_lambda_function.functions["users"]: Refreshing state... [id=branch-users]
aws_lambda_function.functions["donors"]: Refreshing state... [id=branch-donors]
aws_lambda_function.functions["reports"]: Refreshing state... [id=branch-reports]
aws_iam_role_policy.ci_migrate: Refreshing state... [id=branch-ci-migrate:db-migrate]
aws_lambda_permission.api_gateway_permissions["auth"]: Refreshing state... [id=AllowAPIGatewayInvoke]
aws_lambda_permission.api_gateway_permissions["donors"]: Refreshing state... [id=AllowAPIGatewayInvoke]
aws_api_gateway_integration.lambda_integrations["users-PATCH"]: Refreshing state... [id=agi-2apxzxb0r8-0dkbds-PATCH]
aws_lambda_permission.api_gateway_permissions["projects"]: Refreshing state... [id=AllowAPIGatewayInvoke]
aws_api_gateway_integration.lambda_integrations["auth-POST"]: Refreshing state... [id=agi-2apxzxb0r8-u8unad-POST]
aws_lambda_permission.api_gateway_permissions["reports"]: Refreshing state... [id=AllowAPIGatewayInvoke]
aws_lambda_permission.api_gateway_permissions["expenditures"]: Refreshing state... [id=AllowAPIGatewayInvoke]
aws_lambda_permission.api_gateway_permissions["users"]: Refreshing state... [id=AllowAPIGatewayInvoke]
aws_api_gateway_integration.lambda_integrations["expenditures-POST"]: Refreshing state... [id=agi-2apxzxb0r8-6sdj3w-POST]
aws_api_gateway_integration.lambda_integrations["users-POST"]: Refreshing state... [id=agi-2apxzxb0r8-0dkbds-POST]
aws_api_gateway_integration.lambda_integrations["donors-GET"]: Refreshing state... [id=agi-2apxzxb0r8-hybur2-GET]
aws_api_gateway_integration.lambda_integrations["users-DELETE"]: Refreshing state... [id=agi-2apxzxb0r8-0dkbds-DELETE]
aws_api_gateway_integration.lambda_integrations["projects-GET"]: Refreshing state... [id=agi-2apxzxb0r8-chhy2i-GET]
aws_api_gateway_integration.lambda_integrations["expenditures-PATCH"]: Refreshing state... [id=agi-2apxzxb0r8-6sdj3w-PATCH]
aws_api_gateway_integration.lambda_integrations["reports-GET"]: Refreshing state... [id=agi-2apxzxb0r8-wsnfk2-GET]
aws_api_gateway_integration.lambda_integrations["expenditures-GET"]: Refreshing state... [id=agi-2apxzxb0r8-6sdj3w-GET]
aws_api_gateway_integration.lambda_integrations["auth-GET"]: Refreshing state... [id=agi-2apxzxb0r8-u8unad-GET]
aws_api_gateway_integration.lambda_integrations["donors-POST"]: Refreshing state... [id=agi-2apxzxb0r8-hybur2-POST]
aws_api_gateway_integration.lambda_integrations["users-GET"]: Refreshing state... [id=agi-2apxzxb0r8-0dkbds-GET]
aws_api_gateway_integration.lambda_integrations["projects-POST"]: Refreshing state... [id=agi-2apxzxb0r8-chhy2i-POST]
aws_api_gateway_integration.lambda_proxy_integrations["reports"]: Refreshing state... [id=agi-2apxzxb0r8-elsvn3-ANY]
aws_api_gateway_integration.lambda_proxy_integrations["users"]: Refreshing state... [id=agi-2apxzxb0r8-4sjlu3-ANY]
aws_api_gateway_integration.lambda_proxy_integrations["auth"]: Refreshing state... [id=agi-2apxzxb0r8-srhf9j-ANY]
aws_api_gateway_integration.lambda_proxy_integrations["donors"]: Refreshing state... [id=agi-2apxzxb0r8-xkazax-ANY]
aws_api_gateway_integration.lambda_proxy_integrations["expenditures"]: Refreshing state... [id=agi-2apxzxb0r8-14khv0-ANY]
aws_api_gateway_integration.lambda_proxy_integrations["projects"]: Refreshing state... [id=agi-2apxzxb0r8-kmwcxq-ANY]
aws_api_gateway_deployment.branch_deployment: Refreshing state... [id=tf9rqv]
aws_api_gateway_stage.branch_stage: Refreshing state... [id=ags-2apxzxb0r8-prod]

No changes. Your infrastructure matches the configuration.

Terraform has compared your real infrastructure against your configuration
and found no differences, so no changes are needed.

Pushed by: @nourshoreibah, Action: pull_request

@nourshoreibah
nourshoreibah marked this pull request as ready for review August 25, 2026 03:10
@nourshoreibah
nourshoreibah merged commit 4c40b48 into main Aug 25, 2026
27 of 30 checks passed
@nourshoreibah
nourshoreibah deleted the chore/parameterize-aws-account branch August 25, 2026 03:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-review The PR review bot won't run

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant