diff --git a/terraform/cloudfront.tf b/terraform/cloudfront.tf index 2347c2e..5e634b1 100644 --- a/terraform/cloudfront.tf +++ b/terraform/cloudfront.tf @@ -13,7 +13,9 @@ resource "aws_cloudfront_distribution" "form" { comment = "meal-order-manager form hosting" default_root_object = "index.html" price_class = "PriceClass_100" - aliases = [var.domain_name] + # Empty until DNS cutover: AWS rejects a second distribution claiming an + # alias whose DNS still points at another CloudFront distribution (mgmt). + aliases = var.attach_custom_domain ? [var.domain_name] : [] # Shared org CloudFront WAF (audit M-17), resolved from Parameter Store. web_acl_id = data.aws_ssm_parameter.app_web_acl_arn.value @@ -53,9 +55,10 @@ resource "aws_cloudfront_distribution" "form" { } viewer_certificate { - acm_certificate_arn = data.aws_acm_certificate.orders.arn - ssl_support_method = "sni-only" - minimum_protocol_version = "TLSv1.2_2021" + cloudfront_default_certificate = !var.attach_custom_domain + acm_certificate_arn = var.attach_custom_domain ? data.aws_acm_certificate.orders.arn : null + ssl_support_method = var.attach_custom_domain ? "sni-only" : null + minimum_protocol_version = var.attach_custom_domain ? "TLSv1.2_2021" : null } lifecycle { diff --git a/terraform/locals.tf b/terraform/locals.tf index e225699..a8d48c1 100644 --- a/terraform/locals.tf +++ b/terraform/locals.tf @@ -11,7 +11,9 @@ locals { artifacts_bucket_name = "${local.project}-artifacts-${local.account_id}" table_name = "${local.project}-orders" - form_url = "https://${var.domain_name}" + # Pre-DNS: use the CloudFront domain. After cutover (attach_custom_domain), + # use the public custom domain. + form_url = var.attach_custom_domain ? "https://${var.domain_name}" : "https://${aws_cloudfront_distribution.form.domain_name}" ssm_prefix = "/${local.project}" slack_channel_param = "${local.ssm_prefix}/slack-channel-id" diff --git a/terraform/terraform.tfvars.example b/terraform/terraform.tfvars.example index dc82164..be3b5f9 100644 --- a/terraform/terraform.tfvars.example +++ b/terraform/terraform.tfvars.example @@ -5,8 +5,9 @@ aws_region = "us-east-1" # Custom domain for the order form. An ISSUED ACM certificate for this domain -# must already exist in us-east-1 (see acm.tf). -domain_name = "orders.seahaven.com" +# must already exist in us-east-1 (see acm.tf). Attach only at DNS cutover. +domain_name = "orders.seahaven.com" +attach_custom_domain = false # Payroll deduction report recipient and SES-verified sender. payroll_email = "payroll@seahavenind.com" diff --git a/terraform/variables.tf b/terraform/variables.tf index 0cd8e78..34fa72e 100644 --- a/terraform/variables.tf +++ b/terraform/variables.tf @@ -5,11 +5,17 @@ variable "aws_region" { } variable "domain_name" { - description = "Custom domain served by the CloudFront distribution. An ISSUED ACM certificate for this domain must already exist in us-east-1 (see acm.tf)." + description = "Custom domain served by the CloudFront distribution when attach_custom_domain is true. An ISSUED ACM certificate for this domain must already exist in us-east-1 (see acm.tf)." type = string default = "orders.seahaven.com" } +variable "attach_custom_domain" { + description = "When true, attach domain_name as a CloudFront alias with the ACM viewer certificate. Keep false until DNS cutover so the prod distribution can exist while orders.seahaven.com still points at mgmt." + type = bool + default = false +} + variable "payroll_email" { description = "Recipient of the weekly payroll deduction report." type = string