fix(cloudfront): defer custom domain alias until DNS cutover

This commit is contained in:
Adam Moussa 2026-08-10 13:46:04 -04:00
parent 145b0cbac6
commit 5a00cc33fa
No known key found for this signature in database
4 changed files with 20 additions and 8 deletions

View file

@ -13,7 +13,9 @@ resource "aws_cloudfront_distribution" "form" {
comment = "meal-order-manager form hosting" comment = "meal-order-manager form hosting"
default_root_object = "index.html" default_root_object = "index.html"
price_class = "PriceClass_100" price_class = "PriceClass_100"
aliases = [var.domain_name] # Empty until DNS cutover: AWS rejects a second distribution claiming an
# alias whose DNS still points at another CloudFront distribution (mgmt).
aliases = var.attach_custom_domain ? [var.domain_name] : []
# Shared org CloudFront WAF (audit M-17), resolved from Parameter Store. # Shared org CloudFront WAF (audit M-17), resolved from Parameter Store.
web_acl_id = data.aws_ssm_parameter.app_web_acl_arn.value web_acl_id = data.aws_ssm_parameter.app_web_acl_arn.value
@ -53,9 +55,10 @@ resource "aws_cloudfront_distribution" "form" {
} }
viewer_certificate { viewer_certificate {
acm_certificate_arn = data.aws_acm_certificate.orders.arn cloudfront_default_certificate = !var.attach_custom_domain
ssl_support_method = "sni-only" acm_certificate_arn = var.attach_custom_domain ? data.aws_acm_certificate.orders.arn : null
minimum_protocol_version = "TLSv1.2_2021" ssl_support_method = var.attach_custom_domain ? "sni-only" : null
minimum_protocol_version = var.attach_custom_domain ? "TLSv1.2_2021" : null
} }
lifecycle { lifecycle {

View file

@ -11,7 +11,9 @@ locals {
artifacts_bucket_name = "${local.project}-artifacts-${local.account_id}" artifacts_bucket_name = "${local.project}-artifacts-${local.account_id}"
table_name = "${local.project}-orders" table_name = "${local.project}-orders"
form_url = "https://${var.domain_name}" # Pre-DNS: use the CloudFront domain. After cutover (attach_custom_domain),
# use the public custom domain.
form_url = var.attach_custom_domain ? "https://${var.domain_name}" : "https://${aws_cloudfront_distribution.form.domain_name}"
ssm_prefix = "/${local.project}" ssm_prefix = "/${local.project}"
slack_channel_param = "${local.ssm_prefix}/slack-channel-id" slack_channel_param = "${local.ssm_prefix}/slack-channel-id"

View file

@ -5,8 +5,9 @@
aws_region = "us-east-1" aws_region = "us-east-1"
# Custom domain for the order form. An ISSUED ACM certificate for this domain # Custom domain for the order form. An ISSUED ACM certificate for this domain
# must already exist in us-east-1 (see acm.tf). # must already exist in us-east-1 (see acm.tf). Attach only at DNS cutover.
domain_name = "orders.seahaven.com" domain_name = "orders.seahaven.com"
attach_custom_domain = false
# Payroll deduction report recipient and SES-verified sender. # Payroll deduction report recipient and SES-verified sender.
payroll_email = "payroll@seahavenind.com" payroll_email = "payroll@seahavenind.com"

View file

@ -5,11 +5,17 @@ variable "aws_region" {
} }
variable "domain_name" { variable "domain_name" {
description = "Custom domain served by the CloudFront distribution. An ISSUED ACM certificate for this domain must already exist in us-east-1 (see acm.tf)." description = "Custom domain served by the CloudFront distribution when attach_custom_domain is true. An ISSUED ACM certificate for this domain must already exist in us-east-1 (see acm.tf)."
type = string type = string
default = "orders.seahaven.com" default = "orders.seahaven.com"
} }
variable "attach_custom_domain" {
description = "When true, attach domain_name as a CloudFront alias with the ACM viewer certificate. Keep false until DNS cutover so the prod distribution can exist while orders.seahaven.com still points at mgmt."
type = bool
default = false
}
variable "payroll_email" { variable "payroll_email" {
description = "Recipient of the weekly payroll deduction report." description = "Recipient of the weekly payroll deduction report."
type = string type = string