chore(infra): point Terraform state at the client account bucket - #389
Merged
Merged
Conversation
State must live in the client's AWS account: the CI roles created there cannot reach c4c-neu-terraform-state-files in C4C's account. Renames the bucket in all 14 references — the five backend.tf files, the seven .tflock/bucket ARNs inside the oidc.tf jsonencode policies, and both AGENTS.md files. State starts fresh; nothing is migrated. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The client account is on the AWS free tier plan, which rejects a 7-day retention outright: FreeTierRestrictionError: The specified backup retention period exceeds the maximum available to free tier customers. 1 keeps point-in-time recovery as the backstop for CI-applied migrations rather than disabling it. Raise it back to 7 once the account plan is upgraded. backup_window stays unset — AWS cross-validates it against the unmanaged maintenance window, so it is pinned both or neither. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sets var.aws_account_id to the new account, which publishes vars.AWS_ACCOUNT_ID and repoints all six workflows' OIDC role ARNs in one apply. README is terraform-docs generated and tracks the default. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The import added in #384 adopts /aws/lambda/branch-* log groups on the assumption Lambda already created them. That holds in C4C's account, not in the client's, where the functions have never run: Error: Cannot import non-existent remote object It fails plan as well as apply, so terraform-plan cannot go green while it is present. Without it Terraform just creates the groups at 30d retention, which is the same end state. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Terraform Plan 📖
|
Contributor
Terraform Plan 📖
|
Contributor
Terraform Plan 📖
|
Contributor
Terraform Plan 📖
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Step 3 of the AWS account handoff. The state bucket
branch-tf-statenow exists in the client's account; this points every Terraform root and every state-related IAM policy at it.c4c-neu-terraform-state-fileslives in C4C's account, so the CI roles thatinfrastructure/awscreates in the client's account cannot reach it. The backend must move with the account.What changed
14 references, in 8 files:
backend.tf—aws,github,preview,preview-shared,test. Backend blocks can't interpolate variables, so these are literal edits by necessity.infrastructure/aws/oidc.tf— four.tflockobject ARNs in the plan role'stfstate-lockpolicy, plus the bucket ARN and two prefixes in the preview role. All insidejsonencodeblocks, which is why they don't read as backend config.AGENTS.md— root andinfrastructure/.No DynamoDB table is involved: since #386 the backends use
use_lockfile = true, so the lock is a<key>.tflockobject beside the state.State starts fresh. Nothing is migrated — the old state describes resources in C4C's account that are slated for teardown, and it is kept only so that teardown can run from a pre-merge checkout.
Sequencing — read before merging
Opened as a draft on purpose. The plan role holds
ReadOnlyAccessplus a narrow policy naming those exact.tflockobjects, so this PR cannot pass its ownterraform-planuntil the roles exist in the new account. That is expected, not a regression. Required order:infrastructure/awslocally with theC4CAdminkey, from this branch — that creates the roles already pointing atbranch-tf-state.var.aws_account_idto the new account, and applyinfrastructure/githubsovars.AWS_ACCOUNT_IDrepoints the workflows.Merging out of order means merging a PR whose own plan failed, which
terraform-plan-summarycorrectly blocks.Verification
grep -rn c4c-neu-terraform-state-files .returns nothing.terraform fmt -check -recursive infrastructure/passes.terraform initagainst the new bucket, since these credentials are for a different account.🤖 Generated with Claude Code