Skip to content

Undo the fs abbreviation in civic-tech-jobs - #236

Merged
ale210 merged 1 commit into
mainfrom
227-undo-fs-abbreviation
Sep 13, 2026
Merged

ale210 merged 1 commit into
mainfrom
227-undo-fs-abbreviation

Conversation

@ale210

@ale210 ale210 commented Sep 13, 2026 •

Copy link
Copy Markdown
Member

Closes #227.

Spells the civic-tech-jobs stage container's application type out as fullstack again, reversing 1f13c57. The fs abbreviation existed only to fit the target group's 32-character limit, which the container module now handles itself (#231), so the service, log group, security group and IAM names can match the ECR repository and Postgres roles.

This apply has downtime. An ECS service name forces replacement, so stage.civictechjobs.org goes down while the service is destroyed and recreated.

What the plan should show, and nothing else:

  • ECS service, task definition, log group, security group, IAM role and task policy replaced, all renamed civic-tech-jobs-fs-stage → civic-tech-jobs-fullstack-stage
  • target group civic-tech-jobs-fs-stage-145 → ctj-fs-stage-145 as +/- (create before destroy) — the full name would be 35 characters, so the ladder drops to rung 2; listener rule 200 updated in place
  • no change to module.civic_tech_jobs_stage_database — it already uses fullstack, so its roles, passwords and SSM parameters must not appear. If they do, stop.

Also updates the container module's header comment (and README) to say civic-tech-jobs now falls to rung 2 alongside civic-tech-index.

The CivicTechJobs deploy workflow names the old service and is fixed in hackforla/CivicTechJobs#755. That only takes effect when their develop is next released to main, so their next release needs to be coordinated with this apply, or its redeploy step will target a service that does not exist.

@github-actions

github-actions Bot commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

Terraform plan in terraform
With backend config files: terraform/prod.backend.tfvars

Plan: 10 to add, 1 to change, 10 to destroy.
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
!~  update in-place
-/+ destroy and then create replacement
+/- create replacement and then destroy

Terraform will perform the following actions:

  # module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_cloudwatch_log_group.this must be replaced
-/+ resource "aws_cloudwatch_log_group" "this" {
!~      arn                         = "arn:aws:logs:us-west-2:035866691871:log-group:/ecs/civic-tech-jobs-fs-stage" -> (known after apply)
!~      deletion_protection_enabled = false -> (known after apply)
!~      id                          = "*****************************" -> (known after apply)
!~      log_group_class             = "STANDARD" -> (known after apply)
!~      name                        = "/ecs/civic-tech-jobs-fs-stage" -> "/ecs/civic-tech-jobs-fullstack-stage" # forces replacement
+       name_prefix                 = (known after apply)
        tags                        = {
            "project" = "civic-tech-jobs"
        }
#        (5 unchanged attributes hidden)
    }

  # module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_ecs_service.fargate[0] must be replaced
-/+ resource "aws_ecs_service" "fargate" {
!~      arn                                = "arn:aws:ecs:us-west-2:035866691871:service/incubator-prod/civic-tech-jobs-fs-stage" -> (known after apply)
!~      availability_zone_rebalancing      = "ENABLED" -> (known after apply)
-       health_check_grace_period_seconds  = 0 -> null
!~      iam_role                           = "/aws-service-role/ecs.amazonaws.com/AWSServiceRoleForECS" -> (known after apply)
!~      id                                 = "**********************************************************************************" -> (known after apply)
!~      name                               = "civic-tech-jobs-fs-stage" -> "civic-tech-jobs-fullstack-stage" # forces replacement
+       platform_version                   = (known after apply)
        tags                               = {
            "project" = "civic-tech-jobs"
        }
!~      task_definition                    = "arn:aws:ecs:us-west-2:035866691871:task-definition/civic-tech-jobs-fs-stage:9" -> (known after apply)
!~      triggers                           = {} -> (known after apply)
#        (12 unchanged attributes hidden)

-       deployment_circuit_breaker {
-           enable   = false -> null
-           rollback = false -> null
        }

!~      deployment_configuration (known after apply)
-       deployment_configuration {
-           bake_time_in_minutes = "0" -> null
-           strategy             = "ROLLING" -> null
        }

-       deployment_controller {
-           type = "ECS" -> null
        }

-       load_balancer {
-           container_name   = "civic-tech-jobs-fs-stage" -> null
-           container_port   = 8000 -> null
-           target_group_arn = "arn:aws:elasticloadbalancing:us-west-2:035866691871:targetgroup/civic-tech-jobs-fs-stage-145/56a29f2b04cb1961" -> null
#            (1 unchanged attribute hidden)
        }
+       load_balancer {
+           container_name   = "civic-tech-jobs-fullstack-stage"
+           container_port   = 8000
+           target_group_arn = (known after apply)
#            (1 unchanged attribute hidden)
        }

!~      network_configuration {
!~          security_groups  = [
-               "sg-0d384beaea3ec08be",
            ] -> (known after apply)
#            (2 unchanged attributes hidden)
        }

#        (2 unchanged blocks hidden)
    }

  # module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_ecs_task_definition.task must be replaced
-/+ resource "aws_ecs_task_definition" "task" {
!~      arn                      = "arn:aws:ecs:us-west-2:035866691871:task-definition/civic-tech-jobs-fs-stage:9" -> (known after apply)
!~      arn_without_revision     = "arn:aws:ecs:us-west-2:035866691871:task-definition/civic-tech-jobs-fs-stage" -> (known after apply)
!~      container_definitions    = (sensitive value) # forces replacement
!~      enable_fault_injection   = false -> (known after apply)
!~      family                   = "civic-tech-jobs-fs-stage" -> "civic-tech-jobs-fullstack-stage" # forces replacement
!~      id                       = "************************" -> (known after apply)
!~      revision                 = 9 -> (known after apply)
        tags                     = {
            "project" = "civic-tech-jobs"
        }
!~      task_role_arn            = "arn:aws:iam::035866691871:role/ecs-container-civic-tech-jobs-fs-stage" -> (known after apply) # forces replacement
#        (11 unchanged attributes hidden)
    }

  # module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_iam_policy.container_policy must be replaced
-/+ resource "aws_iam_policy" "container_policy" {
!~      arn              = "arn:aws:iam::035866691871:policy/civic-tech-jobs-fs-stage-task-policy" -> (known after apply)
!~      attachment_count = 1 -> (known after apply)
!~      id               = "*********************************************************************" -> (known after apply)
!~      name             = "civic-tech-jobs-fs-stage-task-policy" -> "civic-tech-jobs-fullstack-stage-task-policy" # forces replacement
+       name_prefix      = (known after apply)
!~      policy_id        = "*********************" -> (known after apply)
-       tags             = {} -> null
#        (4 unchanged attributes hidden)
    }

  # module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_iam_role.instance must be replaced
-/+ resource "aws_iam_role" "instance" {
!~      arn                   = "arn:aws:iam::035866691871:role/ecs-container-civic-tech-jobs-fs-stage" -> (known after apply)
!~      create_date           = "2025-03-13T06:34:58Z" -> (known after apply)
!~      id                    = "**************************************" -> (known after apply)
!~      managed_policy_arns   = [
-           "arn:aws:iam::035866691871:policy/civic-tech-jobs-fs-stage-task-policy",
        ] -> (known after apply)
!~      name                  = "ecs-container-civic-tech-jobs-fs-stage" -> "ecs-container-civic-tech-jobs-fullstack-stage" # forces replacement
+       name_prefix           = (known after apply)
        tags                  = {
            "tag-key" = "*********"
        }
!~      unique_id             = "*********************" -> (known after apply)
#        (7 unchanged attributes hidden)

!~      inline_policy (known after apply)
    }

  # module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_iam_role_policy_attachment.task_policy must be replaced
-/+ resource "aws_iam_role_policy_attachment" "task_policy" {
!~      id         = "*****************************************************************" -> (known after apply)
!~      policy_arn = "arn:aws:iam::035866691871:policy/civic-tech-jobs-fs-stage-task-policy" -> (known after apply) # forces replacement
!~      role       = "ecs-container-civic-tech-jobs-fs-stage" -> "ecs-container-civic-tech-jobs-fullstack-stage" # forces replacement
    }

  # module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_lb_listener_rule.static will be updated in-place
!~  resource "aws_lb_listener_rule" "static" {
        id           = "arn:aws:elasticloadbalancing:us-west-2:035866691871:listener-rule/app/incubator-prod-lb/7451adf77133ef36/390a225766a4daf3/8b944647d0d45e1e"
        tags         = {}
#        (5 unchanged attributes hidden)

!~      action {
!~          target_group_arn = "arn:aws:elasticloadbalancing:us-west-2:035866691871:targetgroup/civic-tech-jobs-fs-stage-145/56a29f2b04cb1961" -> (known after apply)
#            (2 unchanged attributes hidden)
        }

#        (2 unchanged blocks hidden)
    }

  # module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_lb_target_group.this must be replaced
+/- resource "aws_lb_target_group" "this" {
!~      arn                                = "arn:aws:elasticloadbalancing:us-west-2:035866691871:targetgroup/civic-tech-jobs-fs-stage-145/56a29f2b04cb1961" -> (known after apply)
!~      arn_suffix                         = "targetgroup/civic-tech-jobs-fs-stage-145/56a29f2b04cb1961" -> (known after apply)
+       connection_termination             = (known after apply)
!~      id                                 = "*************************************************************************************************************" -> (known after apply)
!~      ip_address_type                    = "ipv4" -> (known after apply)
!~      load_balancer_arns                 = [
-           "arn:aws:elasticloadbalancing:us-west-2:035866691871:loadbalancer/app/incubator-prod-lb/7451adf77133ef36",
        ] -> (known after apply)
!~      load_balancing_algorithm_type      = "round_robin" -> (known after apply)
!~      load_balancing_anomaly_mitigation  = "off" -> (known after apply)
!~      load_balancing_cross_zone_enabled  = "use_load_balancer_configuration" -> (known after apply)
!~      name                               = "civic-tech-jobs-fs-stage-145" -> "ctj-fs-stage-145" # forces replacement
+       name_prefix                        = (known after apply)
+       preserve_client_ip                 = (known after apply)
!~      protocol_version                   = "HTTP1" -> (known after apply)
-       tags                               = {} -> null
-       target_control_port                = 0 -> null
#        (10 unchanged attributes hidden)

!~      health_check {
!~          timeout             = 5 -> (known after apply)
#            (8 unchanged attributes hidden)
        }

!~      stickiness (known after apply)
-       stickiness {
-           cookie_duration = 86400 -> null
-           enabled         = false -> null
-           type            = "lb_cookie" -> null
#            (1 unchanged attribute hidden)
        }

!~      target_failover (known after apply)
-       target_failover {}

!~      target_group_health (known after apply)
-       target_group_health {
-           dns_failover {
-               minimum_healthy_targets_count      = "1" -> null
-               minimum_healthy_targets_percentage = "off" -> null
            }
-           unhealthy_state_routing {
-               minimum_healthy_targets_count      = 1 -> null
-               minimum_healthy_targets_percentage = "off" -> null
            }
        }

!~      target_health_state {
+           enable_unhealthy_connection_termination = false
+           unhealthy_draining_interval             = 0
        }
    }

  # module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_security_group.container must be replaced
+/- resource "aws_security_group" "container" {
!~      arn                    = "arn:aws:ec2:us-west-2:035866691871:security-group/sg-0d384beaea3ec08be" -> (known after apply)
!~      description            = "Container civic-tech-jobs-fs-stage" -> "Container civic-tech-jobs-fullstack-stage" # forces replacement
!~      egress                 = [
-           {
-               cidr_blocks      = [
-                   "0.0.0.0/0",
                ]
-               from_port        = 0
-               ipv6_cidr_blocks = []
-               prefix_list_ids  = []
-               protocol         = "-1"
-               security_groups  = []
-               self             = false
-               to_port          = 0
#                (1 unchanged attribute hidden)
            },
        ] -> (known after apply)
!~      id                     = "********************" -> (known after apply)
!~      ingress                = [
-           {
-               cidr_blocks      = [
-                   "10.10.0.0/16",
                ]
-               from_port        = 8000
-               ipv6_cidr_blocks = []
-               prefix_list_ids  = []
-               protocol         = "tcp"
-               security_groups  = []
-               self             = false
-               to_port          = 8000
#                (1 unchanged attribute hidden)
            },
        ] -> (known after apply)
!~      name                   = "ecs-container-civic-tech-jobs-fs-stage" -> "ecs-container-civic-tech-jobs-fullstack-stage" # forces replacement
+       name_prefix            = (known after apply)
!~      owner_id               = "************" -> (known after apply)
!~      tags                   = {
!~          "Name" = "ecs-container-civic-tech-jobs-fs-stage" -> "ecs-container-civic-tech-jobs-fullstack-stage"
        }
!~      tags_all               = {
!~          "Name"       = "ecs-container-civic-tech-jobs-fs-stage" -> "ecs-container-civic-tech-jobs-fullstack-stage"
#            (1 unchanged element hidden)
        }
#        (3 unchanged attributes hidden)
    }

  # module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_vpc_security_group_egress_rule.allow_all_traffic must be replaced
+/- resource "aws_vpc_security_group_egress_rule" "allow_all_traffic" {
!~      arn                    = "arn:aws:ec2:us-west-2:035866691871:security-group-rule/sgr-00d0ac63ba7740037" -> (known after apply)
!~      id                     = "*********************" -> (known after apply)
!~      security_group_id      = "********************" -> (known after apply) # forces replacement
!~      security_group_rule_id = "*********************" -> (known after apply)
#        (4 unchanged attributes hidden)
    }

  # module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_vpc_security_group_ingress_rule.container_ingress_port must be replaced
+/- resource "aws_vpc_security_group_ingress_rule" "container_ingress_port" {
!~      arn                    = "arn:aws:ec2:us-west-2:035866691871:security-group-rule/sgr-0397513833cd8b8af" -> (known after apply)
!~      id                     = "*********************" -> (known after apply)
!~      security_group_id      = "********************" -> (known after apply) # forces replacement
!~      security_group_rule_id = "*********************" -> (known after apply)
#        (6 unchanged attributes hidden)
    }

Plan: 10 to add, 1 to change, 10 to destroy.

✅ Plan applied in Terraform apply (OIDC) #88

@ale210
ale210 merged commit 80c053a into main Sep 13, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Undo the fs abbreviation in civic-tech-jobs

1 participant