| alb_dns_name |
DNS name of the public ALB (for Route53 alias target) |
string |
n/a |
yes |
| alb_https_listener_arn |
ARN of the public ALB HTTPS listener |
string |
n/a |
yes |
| alb_security_group_id |
Security group ID of the public ALB |
string |
n/a |
yes |
| alb_zone_id |
Canonical hosted zone ID of the public ALB (for Route53 alias) |
string |
n/a |
yes |
| base_tags |
Base tags to apply to all resources |
map(string) |
{} |
no |
| certificate_arn |
ARN of the ACM certificate for the hostname |
string |
n/a |
yes |
| cluster_name |
ECS cluster name to deploy the service into |
string |
n/a |
yes |
| container_port |
Port the container listens on |
number |
3000 |
no |
| create_oidc_provider |
Whether to create the GitHub Actions OIDC provider. True for stage (creates it); false for prod (an account-wide provider already exists and is referenced via data source). |
bool |
true |
no |
| deployment_maximum_percent |
ECS rolling-deploy maximum percent. Default 200. Pair with minimum_healthy_percent=0 and set to 100 for stop-before-start on capacity-constrained instances. |
number |
200 |
no |
| deployment_minimum_healthy_percent |
ECS rolling-deploy minimum healthy percent. Default 100 (zero-downtime start-before-stop). Set to 0 where the cluster instance can't fit a second task alongside co-tenants (e.g. prod core shares a t3.small with atrax-api), allowing stop-before-start. |
number |
100 |
no |
| desired_count |
Desired number of ECS tasks |
number |
1 |
no |
| ecs_security_group_id |
Security group ID of ECS tasks (ingress rule for ALB will be added to it) |
string |
n/a |
yes |
| environment |
Environment name |
string |
n/a |
yes |
| github_oidc_ref |
GitHub ref condition for the deploy role's trust policy sub claim. Stage deploys from a branch ('ref:refs/heads/main'); prod deploys from Release tags ('ref:refs/tags/*'). |
string |
"ref:refs/heads/main" |
no |
| github_repo |
GitHub repository (org/repo) allowed to deploy via OIDC |
string |
"cookiehub-com/core-api" |
no |
| hostname |
Public-facing hostname (e.g. 'core-api.stage.cookiehub.net' or 'api.cookiehub.com') |
string |
n/a |
yes |
| name_prefix |
Prefix for resource names |
string |
n/a |
yes |
| rds_security_group_id |
Security group ID of the MariaDB RDS instance (ingress rule for ECS will be added). Empty string skips the ingress rule — used in prod, where the core DB is the legacy non-Terraform MariaDB wired separately. |
string |
"" |
no |
| region |
AWS region |
string |
n/a |
yes |
| task_cpu |
CPU units for the ECS task |
number |
512 |
no |
| task_memory |
Memory in MB for the ECS task |
number |
512 |
no |
| vault_api_url |
Base URL of the vault-api service for consent analytics (e.g. 'https://vault-api.internal.stage.cookiehub.net'). Empty disables the integration — vault-backed endpoints return 503. |
string |
"" |
no |
| vpc_id |
VPC ID (used for the ALB target group) |
string |
n/a |
yes |
| zone_id |
Route53 hosted zone ID |
string |
n/a |
yes |