Skip to content

Commit f79978f

Browse files
Call S3 bucket from deployment helper
1 parent 871a212 commit f79978f

File tree

7 files changed

+27
-17
lines changed

7 files changed

+27
-17
lines changed

locals.tf

Lines changed: 0 additions & 6 deletions
This file was deleted.

main.tf

Lines changed: 2 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,9 @@ module "deployment_helper" {
2020
}
2121
deployment_regions = local.deployment_regions
2222
lambda_function_name = join("", [var.central_account_resource_name_prefix, "deployment-helper"])
23+
central_account_resource_name_prefix = var.central_account_resource_name_prefix
2324
member_account_deployment_helper_role_arn_patterns = [for i in local.member_account_deployment_helper_role_names : join("", ["arn:", local.partition_id, ":iam::*:role/", i])]
24-
terraform_state_bucket_name = local.terraform_state_bucket_name
25+
terraform_state_bucket_name = var.terraform_state_bucket_name
2526
}
2627

2728
module "deployment" {
@@ -52,10 +53,3 @@ module "deployment" {
5253
member_account_deployment_helper_role_name_template = replace(local.member_account_deployment_helper_role_name_template, "<SERVICE>", each.key)
5354
member_account_resource_name_prefix = var.member_account_resource_name_prefix
5455
}
55-
56-
module "tf_state_bucket" {
57-
source = "./modules/s3"
58-
count = var.terraform_state_bucket_name == "" ? 1 : 0
59-
60-
central_account_resource_name_prefix = var.central_account_resource_name_prefix
61-
}

modules/deployment-helper/iam.tf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ module "lambda_role" {
2424
"s3:GetBucketLocation",
2525
"s3:ListBucket"
2626
]
27-
Resource : "arn:${var.current.partition}:s3:::${var.terraform_state_bucket_name}"
27+
Resource : local.terraform_state_bucket_arn
2828
},
2929
{
3030
Effect : "Allow"
@@ -33,7 +33,7 @@ module "lambda_role" {
3333
"s3:PutObject",
3434
"s3:DeleteObject"
3535
]
36-
Resource : "arn:${var.current.partition}:s3:::${var.terraform_state_bucket_name}/*"
36+
Resource : "${local.terraform_state_bucket_arn}/*"
3737
},
3838
{
3939
Effect : "Allow"
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
locals {
2+
terraform_state_bucket_name = (
3+
var.terraform_state_bucket_name != "" ? var.terraform_state_bucket_name :
4+
module.tf_state_bucket[0].s3_bucket_name
5+
)
6+
7+
terraform_state_bucket_arn = (
8+
var.terraform_state_bucket_name != "" ? "arn:${var.current.partition}:s3:::${var.terraform_state_bucket_name}" :
9+
module.tf_state_bucket[0].s3_bucket_arn
10+
)
11+
}

modules/deployment-helper/regional.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,5 +9,5 @@ module "deployment_helper_regional" {
99
}
1010
lambda_function_name = var.lambda_function_name
1111
lambda_role_arn = module.lambda_role.role.arn
12-
terraform_state_bucket_name = var.terraform_state_bucket_name
12+
terraform_state_bucket_name = local.terraform_state_bucket_name
1313
}

modules/deployment-helper/s3.tf

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
module "tf_state_bucket" {
2+
source = "../s3"
3+
count = var.terraform_state_bucket_name == "" ? 1 : 0
4+
5+
central_account_resource_name_prefix = var.central_account_resource_name_prefix
6+
}

modules/deployment-helper/variables.tf

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,11 @@ variable "lambda_function_name" {
1717
type = string
1818
}
1919

20+
variable "central_account_resource_name_prefix" {
21+
type = string
22+
description = "Prefix to be used for resource names in the central account."
23+
}
24+
2025
variable "member_account_deployment_helper_role_arn_patterns" {
2126
description = "The patterns to use to restrict role assumption to the member account Deployment Helper roles."
2227
type = list(string)

0 commit comments

Comments
 (0)