Skip to content

feat(terraform): reusable module for deploying the broker Lambda - #25

Merged
jmgilman merged 2 commits into
masterfrom
session-009/phase-5-terraform-module
Apr 23, 2026
Merged

jmgilman merged 2 commits into
masterfrom
session-009/phase-5-terraform-module

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Summary

  • Adds a first-party Terraform module under terraform/ that provisions the published github-token-broker release as an AWS Lambda, with least-privilege IAM, a managed CloudWatch log group, and an optional AWS_IAM-auth Function URL.
  • Amends reusable-release.yml to upload dist/checksums.txt as a release asset (prerequisite for the module's inline SHA256 verification on download).
  • Extends Dependabot to the terraform ecosystem and adds .github/workflows/terraform.yml (fmt, matrix validate, tflint with AWS ruleset, trivy config scan, terraform-docs sync check) — all actions SHA-pinned, top-level permissions: {}.

Three ways to source the Lambda zip via lambda_artifact:

Field When to use
release_version = "v1.0.0" Default. Module runs gh release download + sha256sum --check on apply.
lambda_zip_path Pre-downloaded zip for air-gapped flows.
lambda_source_s3 When the zip is staged to S3 out-of-band.

Validation enforces exactly one is set.

Examples shipped: basic (smallest viable config), function-url (Function URL + principal-scoped invoker permission), with-ssm-bootstrap (gated SSM parameter creation for first-time setup).

Inline SHA256 verification is defense-in-depth; gh attestation verify remains the canonical supply-chain check, documented prominently in terraform/README.md. checksums.txt will be present on all releases shipping from this PR onwards.

Executes Phase 5 of .journal/PLAN.md.

Test plan

Local validation performed on this branch:

  • tofu fmt -check -recursive — clean
  • tofu init -backend=false && tofu validate — module and all three examples
  • tflint --init && tflint --recursive with AWS ruleset v0.47.0 — no findings
  • trivy config --severity HIGH,CRITICAL . — 0 misconfigurations
  • terraform-docs markdown table --output-check — README in sync

To be verified in CI by the new terraform.yml workflow:

  • fmt / validate / lint / security / docs jobs all pass
  • Moon CI still green (no regressions)
  • CodeQL / Scorecard unaffected

Deferred follow-ups (tracked in PLAN.md open threads):

  • Live AWS sandbox deploy of examples/basic — procedure documented in terraform/README.md; execute when a sandbox account is available.
  • Author a terraform skill grounded in lessons from this phase.

🤖 Generated with Claude Code

jmgilman and others added 2 commits April 23, 2026 12:04
Ships a first-party Terraform module under `terraform/` that provisions
the published `github-token-broker` release as an AWS Lambda, including
least-privilege IAM, a managed CloudWatch log group, and an optional
Function URL (AWS_IAM auth only).

Three ways to source the zip via the `lambda_artifact` input:

- `release_version` — `null_resource` + `local-exec` runs
  `gh release download` on the apply host and verifies the zip against
  `checksums.txt` before Terraform consumes it.
- `lambda_zip_path` — pre-downloaded zip for air-gapped flows.
- `lambda_source_s3` — S3 bucket/key when the zip is staged out-of-band.

Inline SHA256 verification is defense-in-depth; `gh attestation verify`
remains the canonical supply-chain check and is documented prominently
in `terraform/README.md`.

Also amends the release pipeline to upload `dist/checksums.txt` as a
release asset (prerequisite for inline verification), extends dependabot
to the terraform ecosystem, and adds a CI workflow with fmt, matrix
validate, tflint (AWS ruleset), trivy config scan, and terraform-docs
sync check — all SHA-pinned with top-level `permissions: {}`.

Examples: `basic`, `function-url` (with principal-scoped invoker
permission), and `with-ssm-bootstrap` (gated SSM parameter creation for
first-time setup).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The terraform-docs CI action (v1.4.1) bundles terraform-docs v0.20.0;
v0.20.0 emits the version constraint in the Providers table, while
v0.21.0 emits the resolved pinned version. Regenerated locally with
v0.20.0 so the docs sync check passes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@jmgilman
jmgilman merged commit 8409a8a into master Apr 23, 2026
12 checks passed
@jmgilman
jmgilman deleted the session-009/phase-5-terraform-module branch April 23, 2026 19:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant