Files
shared-memory/terraform/outputs.tf
shadowdaoandClaude Opus 4.7 d1d4c60f2d fix: address Phase-5 code review (4 findings)
Reviewer flagged two security-relevant items and two operational bugs
on the external-DB + Terraform module merge.

1. Terraform: `enable_execute_command = true` was hardcoded on the app
   and embedder services. Production attack surface (anyone with
   `ecs:ExecuteCommand` on the service gets a container shell) AND
   non-functional today since the task roles have no `ssmmessages:*`
   permission. Added a new `enable_execute_command` boolean input
   variable defaulting to `false`; when flipped on, the SSM messages
   policy is conditionally attached to both task roles so the feature
   actually works. README's variable description tells operators to
   flip on for incidents, off afterward.

2. Terraform: `secret_arns` output was not marked `sensitive`. The ARNs
   themselves aren't secrets, but the embedded secret names print to
   `terraform apply` stdout and CI logs. Marked sensitive on both the
   module output and the example output. Operators wanting the values
   can still `terraform output -json secret_arns`.

3. Terraform: embedder task definition was missing `HOST=0.0.0.0` and
   `PORT=8080`. Fargate awsvpc tasks each get their own ENI; default
   Node HTTP servers bind 127.0.0.1, which would make every
   app→embedder Service Connect call time out. Added both vars to
   `embedder_environment`. Also added `NEXT_TELEMETRY_DISABLED=1` to
   `app_environment` per the spec's hardening checklist.

4. Compose: docker-compose.external-db.yml uses the `!override` YAML
   tag, which requires Docker Compose >= 2.24.0. Silently ignored on
   older Compose, causing the `db` dependency to survive the merge and
   startup to fail. Documented the minimum version in the override
   file's header AND in the main README prerequisites with a deep
   link to the External Postgres section.

terraform fmt + validate (module + examples/basic) both clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-18 09:48:04 -07:00

91 lines
3.1 KiB
Terraform

# -----------------------------------------------------------------------------
# Outputs.
#
# Designed to give the operator everything they need to:
# * point DNS at the ALB
# * run the migrator one-shot
# * extend the RDS security group with task ingress
# * tail logs
# -----------------------------------------------------------------------------
output "alb_dns_name" {
description = "ALB DNS name. Create a Route53 alias record pointing var.domain_name at this."
value = aws_lb.this.dns_name
}
output "alb_zone_id" {
description = "ALB hosted zone ID, used as `alias.zone_id` on aws_route53_record."
value = aws_lb.this.zone_id
}
output "ecs_cluster_arn" {
description = "ECS cluster ARN."
value = aws_ecs_cluster.this.arn
}
output "ecs_cluster_name" {
description = "ECS cluster name. Pass to `aws ecs run-task --cluster`."
value = aws_ecs_cluster.this.name
}
output "app_service_name" {
description = "App ECS service name."
value = aws_ecs_service.app.name
}
output "embedder_service_name" {
description = "Embedder ECS service name."
value = aws_ecs_service.embedder.name
}
output "migrator_task_definition_arn" {
description = "Migrator task definition ARN. Use with `aws ecs run-task --task-definition`."
value = aws_ecs_task_definition.migrator.arn
}
output "migrator_task_definition_family" {
description = "Migrator task definition family — accepts the latest revision automatically when passed to `aws ecs run-task`."
value = aws_ecs_task_definition.migrator.family
}
output "app_log_group_name" {
description = "CloudWatch log group for the app service."
value = aws_cloudwatch_log_group.app.name
}
output "embedder_log_group_name" {
description = "CloudWatch log group for the embedder service."
value = aws_cloudwatch_log_group.embedder.name
}
output "migrator_log_group_name" {
description = "CloudWatch log group for the migrator one-shot task."
value = aws_cloudwatch_log_group.migrator.name
}
output "app_security_group_id" {
description = "Security group attached to app tasks. Add this as a source on your RDS SG inbound rule for port 5432."
value = aws_security_group.app.id
}
output "embedder_security_group_id" {
description = "Security group attached to embedder tasks. Embedder doesn't hit RDS today, but expose for symmetry."
value = aws_security_group.embedder.id
}
output "migrator_security_group_id" {
description = "Security group attached to the migrator one-shot. Must be allowed inbound on your RDS SG (5432) — this is what runs SQL migrations."
value = aws_security_group.migrator.id
}
output "private_subnet_ids_for_run_task" {
description = "Echo of var.private_subnet_ids so `aws ecs run-task --network-configuration` can be assembled without re-typing them."
value = var.private_subnet_ids
}
output "secret_arns" {
description = "Map of env-var name to Secrets Manager ARN. For visibility only — do not re-feed back into the module. Marked sensitive so the secret names don't print in `terraform apply` stdout or CI logs."
value = local.secret_arns
sensitive = true
}