From bd57b4e55806440f413f48c5d99980f98a68790c Mon Sep 17 00:00:00 2001 From: Alex English Date: Wed, 9 Sep 2026 21:25:42 -0700 Subject: [PATCH] Tag log groups, Cognito pools and the website bucket with project Fills the empty tags block on the ECS log group, which covers all ten /ecs/* groups, and adds the project tag to both Home Unite Us Cognito pools and the civictechindex.org bucket. The bucket's value is written literally rather than taken from local.project_name, which holds "civic-tech-index" in that directory where the standard's value is "civictechindex". --- terraform/modules/container/main.tf | 1 + terraform/projects/civic-tech-index/s3.tf | 8 ++++++++ terraform/projects/home-unite-us/cognito-prod.tf | 4 ++++ terraform/projects/home-unite-us/cognito-qa.tf | 4 ++++ 4 files changed, 17 insertions(+) diff --git a/terraform/modules/container/main.tf b/terraform/modules/container/main.tf index 5c008a5..aaab51b 100644 --- a/terraform/modules/container/main.tf +++ b/terraform/modules/container/main.tf @@ -185,6 +185,7 @@ resource "aws_cloudwatch_log_group" "this" { name = "/ecs/${local.envappname}" tags = { + project = var.project_name } } diff --git a/terraform/projects/civic-tech-index/s3.tf b/terraform/projects/civic-tech-index/s3.tf index b2d5909..51997f5 100644 --- a/terraform/projects/civic-tech-index/s3.tf +++ b/terraform/projects/civic-tech-index/s3.tf @@ -10,6 +10,14 @@ resource "aws_s3_bucket" "website" { bucket = "civictechindex.org" + + # "civictechindex" is the project value from the tag standard, and it is written + # literally here for the same reason ecr.tf writes it literally: local.project_name + # in this directory is "civic-tech-index", which is not the standard's value. The + # two spellings are reconciled separately -- do not switch this to local.project_name. + tags = { + project = "civictechindex" + } } resource "aws_s3_bucket_website_configuration" "website" { diff --git a/terraform/projects/home-unite-us/cognito-prod.tf b/terraform/projects/home-unite-us/cognito-prod.tf index 3929bb3..f8b8a03 100644 --- a/terraform/projects/home-unite-us/cognito-prod.tf +++ b/terraform/projects/home-unite-us/cognito-prod.tf @@ -138,6 +138,10 @@ resource "aws_cognito_user_pool" "homeuniteus_prod" { default_email_option = "CONFIRM_WITH_CODE" } + tags = { + project = local.project_name + } + // Destroying this pool destroys the production user accounts, which cannot be // recovered by recreating it. deletion_protection above is the AWS-side guard; // this is the Terraform-side one. diff --git a/terraform/projects/home-unite-us/cognito-qa.tf b/terraform/projects/home-unite-us/cognito-qa.tf index 1fda020..7ed83ff 100644 --- a/terraform/projects/home-unite-us/cognito-qa.tf +++ b/terraform/projects/home-unite-us/cognito-qa.tf @@ -190,6 +190,10 @@ resource "aws_cognito_user_pool" "homeuniteus" { verification_message_template { default_email_option = "CONFIRM_WITH_CODE" } + + tags = { + project = local.project_name + } } locals {