mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 06:33:12 +00:00
fix(cloudfront): defer custom domain alias until DNS cutover
This commit is contained in:
parent
145b0cbac6
commit
5a00cc33fa
4 changed files with 20 additions and 8 deletions
|
|
@ -13,7 +13,9 @@ resource "aws_cloudfront_distribution" "form" {
|
|||
comment = "meal-order-manager form hosting"
|
||||
default_root_object = "index.html"
|
||||
price_class = "PriceClass_100"
|
||||
aliases = [var.domain_name]
|
||||
# Empty until DNS cutover: AWS rejects a second distribution claiming an
|
||||
# alias whose DNS still points at another CloudFront distribution (mgmt).
|
||||
aliases = var.attach_custom_domain ? [var.domain_name] : []
|
||||
|
||||
# Shared org CloudFront WAF (audit M-17), resolved from Parameter Store.
|
||||
web_acl_id = data.aws_ssm_parameter.app_web_acl_arn.value
|
||||
|
|
@ -53,9 +55,10 @@ resource "aws_cloudfront_distribution" "form" {
|
|||
}
|
||||
|
||||
viewer_certificate {
|
||||
acm_certificate_arn = data.aws_acm_certificate.orders.arn
|
||||
ssl_support_method = "sni-only"
|
||||
minimum_protocol_version = "TLSv1.2_2021"
|
||||
cloudfront_default_certificate = !var.attach_custom_domain
|
||||
acm_certificate_arn = var.attach_custom_domain ? data.aws_acm_certificate.orders.arn : null
|
||||
ssl_support_method = var.attach_custom_domain ? "sni-only" : null
|
||||
minimum_protocol_version = var.attach_custom_domain ? "TLSv1.2_2021" : null
|
||||
}
|
||||
|
||||
lifecycle {
|
||||
|
|
|
|||
|
|
@ -11,7 +11,9 @@ locals {
|
|||
artifacts_bucket_name = "${local.project}-artifacts-${local.account_id}"
|
||||
|
||||
table_name = "${local.project}-orders"
|
||||
form_url = "https://${var.domain_name}"
|
||||
# Pre-DNS: use the CloudFront domain. After cutover (attach_custom_domain),
|
||||
# use the public custom domain.
|
||||
form_url = var.attach_custom_domain ? "https://${var.domain_name}" : "https://${aws_cloudfront_distribution.form.domain_name}"
|
||||
|
||||
ssm_prefix = "/${local.project}"
|
||||
slack_channel_param = "${local.ssm_prefix}/slack-channel-id"
|
||||
|
|
|
|||
|
|
@ -5,8 +5,9 @@
|
|||
aws_region = "us-east-1"
|
||||
|
||||
# Custom domain for the order form. An ISSUED ACM certificate for this domain
|
||||
# must already exist in us-east-1 (see acm.tf).
|
||||
domain_name = "orders.seahaven.com"
|
||||
# must already exist in us-east-1 (see acm.tf). Attach only at DNS cutover.
|
||||
domain_name = "orders.seahaven.com"
|
||||
attach_custom_domain = false
|
||||
|
||||
# Payroll deduction report recipient and SES-verified sender.
|
||||
payroll_email = "payroll@seahavenind.com"
|
||||
|
|
|
|||
|
|
@ -5,11 +5,17 @@ variable "aws_region" {
|
|||
}
|
||||
|
||||
variable "domain_name" {
|
||||
description = "Custom domain served by the CloudFront distribution. An ISSUED ACM certificate for this domain must already exist in us-east-1 (see acm.tf)."
|
||||
description = "Custom domain served by the CloudFront distribution when attach_custom_domain is true. An ISSUED ACM certificate for this domain must already exist in us-east-1 (see acm.tf)."
|
||||
type = string
|
||||
default = "orders.seahaven.com"
|
||||
}
|
||||
|
||||
variable "attach_custom_domain" {
|
||||
description = "When true, attach domain_name as a CloudFront alias with the ACM viewer certificate. Keep false until DNS cutover so the prod distribution can exist while orders.seahaven.com still points at mgmt."
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "payroll_email" {
|
||||
description = "Recipient of the weekly payroll deduction report."
|
||||
type = string
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue