From 3abc6cee23997cfed87047ec0faca8c2a82afa5f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=EC=98=A4=EC=A4=80=EC=84=9D=28Junseok=20Oh=29DevOps?= <52226147+Atom-oh@users.noreply.github.com> Date: Thu, 3 Sep 2026 15:50:04 +0000 Subject: [PATCH] fix(terraform): repo-root relative paths for the samples layout depth MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The imported tf files kept origin's ../../.. (terraform/v2/foundation is 3 levels deep); the samples layout is terraform/foundation (2 levels), so every file()/source reference escaping to agent/, scripts/, web/ walked past the repo root — plan failed with 'Invalid function argument' on a fresh checkout (15 references across 7 files). --- terraform/foundation/ai.tf | 8 ++++---- terraform/foundation/eks.tf | 4 ++-- terraform/foundation/incidents.tf | 6 +++--- terraform/foundation/remediation.tf | 4 ++-- terraform/foundation/secret-rotation.tf | 2 +- terraform/foundation/steampipe.tf | 4 ++-- terraform/foundation/workers.tf | 2 +- 7 files changed, 15 insertions(+), 15 deletions(-) diff --git a/terraform/foundation/ai.tf b/terraform/foundation/ai.tf index b4283649f..aa885d51d 100644 --- a/terraform/foundation/ai.tf +++ b/terraform/foundation/ai.tf @@ -809,11 +809,11 @@ data "archive_file" "agent" { type = "zip" output_path = "${path.module}/.build/agent-${each.key}.zip" source { - content = file("${path.module}/../../../agent/lambda/${each.value.file}") + content = file("${path.module}/../../agent/lambda/${each.value.file}") filename = each.value.file } source { - content = file("${path.module}/../../../agent/lambda/cross_account.py") + content = file("${path.module}/../../agent/lambda/cross_account.py") filename = "cross_account.py" } # The datasource-family connectors (clickhouse/prometheus/loki/tempo/mimir) import the shared @@ -823,7 +823,7 @@ data "archive_file" "agent" { dynamic "source" { for_each = contains(["clickhouse_mcp.py", "prometheus_mcp.py", "loki_mcp.py", "tempo_mcp.py", "mimir_mcp.py", "jaeger_mcp.py", "dynatrace_mcp.py", "datadog_mcp.py"], each.value.file) ? [1] : [] content { - content = file("${path.module}/../../../agent/lambda/datasource_http.py") + content = file("${path.module}/../../agent/lambda/datasource_http.py") filename = "datasource_http.py" } } @@ -834,7 +834,7 @@ data "archive_file" "agent" { dynamic "source" { for_each = contains(["clickhouse_mcp.py", "aws_rds_mcp.py"], each.value.file) ? [1] : [] content { - content = file("${path.module}/../../../agent/lambda/sql_readonly_guard.py") + content = file("${path.module}/../../agent/lambda/sql_readonly_guard.py") filename = "sql_readonly_guard.py" } } diff --git a/terraform/foundation/eks.tf b/terraform/foundation/eks.tf index 02c56ceed..3be46da88 100644 --- a/terraform/foundation/eks.tf +++ b/terraform/foundation/eks.tf @@ -76,13 +76,13 @@ data "archive_file" "eks_auto_register" { type = "zip" output_path = "${path.module}/.build/eks_auto_register.zip" source { - content = file("${path.root}/../../../scripts/v2/eks/auto_register.py") + content = file("${path.root}/../../scripts/v2/eks/auto_register.py") filename = "auto_register.py" } source { # Regional RDS CA trust bundle — the Lambda REQUIRES verified TLS to Aurora # (PR #36 review: this write-path must not run CERT_NONE). - content = file("${path.root}/../../../scripts/v2/eks/rds-ca-bundle.pem") + content = file("${path.root}/../../scripts/v2/eks/rds-ca-bundle.pem") filename = "rds-ca-bundle.pem" } } diff --git a/terraform/foundation/incidents.tf b/terraform/foundation/incidents.tf index 694b6c459..d7e4e5cd9 100644 --- a/terraform/foundation/incidents.tf +++ b/terraform/foundation/incidents.tf @@ -23,9 +23,9 @@ locals { il = var.incident_lifecycle_enabled ? 1 : 0 rwb = var.rca_writeback_enabled ? 1 : 0 # ADR-034 write-back gate (see writeback.tf) - inc_src = "${path.module}/../../../scripts/v2/incident" - workers_src_il = "${path.module}/../../../scripts/v2/workers" # reuse db.py + status_updater ARN - rem_src_il = "${path.module}/../../../scripts/v2/remediation" # ADR-034: writeback.py imports remediation_executor (+ action_catalog) — the 029/036 single-write surface + inc_src = "${path.module}/../../scripts/v2/incident" + workers_src_il = "${path.module}/../../scripts/v2/workers" # reuse db.py + status_updater ARN + rem_src_il = "${path.module}/../../scripts/v2/remediation" # ADR-034: writeback.py imports remediation_executor (+ action_catalog) — the 029/036 single-write surface inc_acct = data.aws_caller_identity.current.account_id # The AgentCore runtime ARN SSM param — created by ai.tf when agentcore_enabled, written by # provision.py after apply. Referenced by NAME (string), NOT the gated resource, so the incident diff --git a/terraform/foundation/remediation.tf b/terraform/foundation/remediation.tf index 9e3f2aad2..bfd41982d 100644 --- a/terraform/foundation/remediation.tf +++ b/terraform/foundation/remediation.tf @@ -18,8 +18,8 @@ locals { # the IAM split). Both default false ⇒ re_or_iw=0 ⇒ unchanged. iw = var.integrations_write_enabled ? 1 : 0 re_or_iw = (var.remediation_enabled || var.integrations_write_enabled) ? 1 : 0 - rem_src = "${path.module}/../../../scripts/v2/remediation" - workers_src_re = "${path.module}/../../../scripts/v2/workers" # reuse db.py/status_updater + rem_src = "${path.module}/../../scripts/v2/remediation" + workers_src_re = "${path.module}/../../scripts/v2/workers" # reuse db.py/status_updater rem_acct = data.aws_caller_identity.current.account_id worker_cname_re = local.worker_cname # reuse the worker container name (workers.tf) } diff --git a/terraform/foundation/secret-rotation.tf b/terraform/foundation/secret-rotation.tf index 5e615d968..a036208c3 100644 --- a/terraform/foundation/secret-rotation.tf +++ b/terraform/foundation/secret-rotation.tf @@ -32,7 +32,7 @@ data "archive_file" "secret_rotation_redeploy" { type = "zip" output_path = "${path.module}/.build/secret_rotation_redeploy.zip" source { - content = file("${path.root}/../../../scripts/v2/secret-rotation/redeploy.py") + content = file("${path.root}/../../scripts/v2/secret-rotation/redeploy.py") filename = "redeploy.py" } } diff --git a/terraform/foundation/steampipe.tf b/terraform/foundation/steampipe.tf index a395a5c91..21fc060cb 100644 --- a/terraform/foundation/steampipe.tf +++ b/terraform/foundation/steampipe.tf @@ -258,7 +258,7 @@ resource "aws_cloudwatch_metric_alarm" "steampipe_down" { # ---- sync Lambda (VPC, pg8000 layer; queries Steampipe + writes Aurora) ---- resource "terraform_data" "inv_pg8000_build" { count = local.sp - triggers_replace = filemd5("${path.module}/../../../scripts/v2/steampipe/requirements.txt") + triggers_replace = filemd5("${path.module}/../../scripts/v2/steampipe/requirements.txt") provisioner "local-exec" { command = <<-EOT set -e @@ -288,7 +288,7 @@ data "archive_file" "inv_sync_src" { type = "zip" output_path = "${path.module}/.build/inv_sync.zip" source { - content = file("${path.module}/../../../scripts/v2/steampipe/sync_lambda.py") + content = file("${path.module}/../../scripts/v2/steampipe/sync_lambda.py") filename = "sync_lambda.py" } } diff --git a/terraform/foundation/workers.tf b/terraform/foundation/workers.tf index 41423df67..1f1a61442 100644 --- a/terraform/foundation/workers.tf +++ b/terraform/foundation/workers.tf @@ -10,7 +10,7 @@ locals { we = var.workers_enabled ? 1 : 0 - workers_src = "${path.module}/../../../scripts/v2/workers" + workers_src = "${path.module}/../../scripts/v2/workers" worker_cname = "worker" # MUST equal the ContainerOverrides Name in sfn.asl.json acct = data.aws_caller_identity.current.account_id # ai-cost aggregator gate — reuses the worker role/pg8000 layer/VPC, so it REQUIRES workers_enabled.