variable "region" { description = "AWS region. Bedrock + AgentCore have the widest quotas in us-east-1 / us-west-2." type = string default = "us-east-1" } variable "project" { description = "Name prefix for all resources." type = string default = "hncb-deid-demo" } variable "bedrock_model_id" { description = "Bedrock model the agent reasons with." type = string default = "anthropic.claude-3-5-sonnet-20241022-v2:0" } # Fusion is a shared SaaS instance (NOT deployed here). Only the Presidio detector # is self-hosted. TODO: set after scripts/deploy.sh builds + pushes the image. variable "presidio_image_uri" { description = "ECR URI for the Presidio detector image built from ./presidio." type = string default = "REPLACE_ME_PRESIDIO_IMAGE_URI" } # Where the /tokenize Lambda reaches the Presidio detector. After deploy this is # the Presidio Fargate task's public endpoint (http://:5001). Kept a # variable so a laptop rehearsal can point at a local/ngrok detector. variable "presidio_url" { description = "Base URL of the Presidio detector /analyze service." type = string default = "http://localhost:5001" } # Shared secret Fusion SaaS presents to the public endpoints (bearer / x-api-key). # NEVER commit a real value -- pass via TF_VAR_tokenize_api_key or a .tfvars file # that is gitignored. Empty default leaves the endpoint open (dev only). variable "tokenize_api_key" { description = "Shared secret required on /tokenize (and /restore) requests." type = string default = "" sensitive = true } # AgentCore Runtime ARN (created out-of-band by `agentcore launch`, see T5). The # demo orchestrator (T6) invokes it. Empty -> orchestrator skips the agent step. variable "agent_runtime_arn" { description = "Bedrock AgentCore Runtime ARN the demo orchestrator invokes." type = string default = "" }