Merge pull request #133 from Sea-Haven-Industries/fix/cloudfront-aliases-pre-dns

fix(cloudfront): defer custom domain alias until DNS cutover (PLAT-98)
This commit is contained in:
Adam Moussa 2026-08-10 14:05:39 -04:00 • committed by GitHub
commit 9f047bf259
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
4 changed files with 20 additions and 8 deletions

View file

@ -13,7 +13,9 @@ resource "aws_cloudfront_distribution" "form" {
comment = "meal-order-manager form hosting"
default_root_object = "index.html"
price_class = "PriceClass_100"
aliases = [var.domain_name]
# Empty until DNS cutover: AWS rejects a second distribution claiming an
# alias whose DNS still points at another CloudFront distribution (mgmt).
aliases = var.attach_custom_domain ? [var.domain_name] : []
# Shared org CloudFront WAF (audit M-17), resolved from Parameter Store.
web_acl_id = data.aws_ssm_parameter.app_web_acl_arn.value
@ -53,9 +55,10 @@ resource "aws_cloudfront_distribution" "form" {
}
viewer_certificate {
acm_certificate_arn = data.aws_acm_certificate.orders.arn
ssl_support_method = "sni-only"
minimum_protocol_version = "TLSv1.2_2021"
cloudfront_default_certificate = !var.attach_custom_domain
acm_certificate_arn = var.attach_custom_domain ? data.aws_acm_certificate.orders.arn : null
ssl_support_method = var.attach_custom_domain ? "sni-only" : null
minimum_protocol_version = var.attach_custom_domain ? "TLSv1.2_2021" : null
}
lifecycle {

View file

@ -11,7 +11,9 @@ locals {
artifacts_bucket_name = "${local.project}-artifacts-${local.account_id}"
table_name = "${local.project}-orders"
form_url = "https://${var.domain_name}"
# Pre-DNS: use the CloudFront domain. After cutover (attach_custom_domain),
# use the public custom domain.
form_url = var.attach_custom_domain ? "https://${var.domain_name}" : "https://${aws_cloudfront_distribution.form.domain_name}"
ssm_prefix = "/${local.project}"
slack_channel_param = "${local.ssm_prefix}/slack-channel-id"

View file

@ -5,8 +5,9 @@
aws_region = "us-east-1"
# Custom domain for the order form. An ISSUED ACM certificate for this domain
# must already exist in us-east-1 (see acm.tf).
# must already exist in us-east-1 (see acm.tf). Attach only at DNS cutover.
domain_name = "orders.seahaven.com"
attach_custom_domain = false
# Payroll deduction report recipient and SES-verified sender.
payroll_email = "payroll@seahavenind.com"

View file

@ -5,11 +5,17 @@ variable "aws_region" {
}
variable "domain_name" {
description = "Custom domain served by the CloudFront distribution. An ISSUED ACM certificate for this domain must already exist in us-east-1 (see acm.tf)."
description = "Custom domain served by the CloudFront distribution when attach_custom_domain is true. An ISSUED ACM certificate for this domain must already exist in us-east-1 (see acm.tf)."
type = string
default = "orders.seahaven.com"
}
variable "attach_custom_domain" {
description = "When true, attach domain_name as a CloudFront alias with the ACM viewer certificate. Keep false until DNS cutover so the prod distribution can exist while orders.seahaven.com still points at mgmt."
type = bool
default = false
}
variable "payroll_email" {
description = "Recipient of the weekly payroll deduction report."
type = string