meal-order-manager/terraform/acm.tf

21 lines
1,018 B
Terraform
Raw Normal View History

# ACM certificate for the order form's custom domain.
#
# The certificate is an out-of-band bootstrap dependency and is deliberately NOT
# created here. It was requested in the prod account ahead of this configuration
# (arn:aws:acm:us-east-1:011934824531:certificate/4edac16c-0e19-4307-a34a-f6da257ccda3)
# and validated by DNS. Declaring an aws_acm_certificate resource as well would
# request a second certificate for the same domain on the first apply, so this
# configuration only reads the issued one.
#
# Bootstrap order, if the domain is ever rebuilt from nothing:
# 1. aws acm request-certificate --domain-name orders.seahaven.com \
# --validation-method DNS --region us-east-1
# 2. Publish the CNAME validation record and wait for status ISSUED.
# 3. Run terraform apply. Until step 2 completes, this data source finds no
# ISSUED certificate and the plan fails closed.
data "aws_acm_certificate" "orders" {
domain = var.domain_name
statuses = ["ISSUED"]
most_recent = true
}