diff --git a/README.md b/README.md index 3b14703..eb67e1c 100644 --- a/README.md +++ b/README.md @@ -22,7 +22,7 @@ Phones keep `https://doorunlock.seahaven.com`. Cutover is a Route 53 A-record fl - **BLF sync Lambda** — daily 09:00 UTC EventBridge job that writes 3CX department BLFs - **SSM Parameter Store** — Elements API key, auth token, and door ID (created out of band; Terraform never reads SecureString values) - **Secrets Manager** — 3CX XAPI credentials (`afterhours-shift-manager/3cx-*`), referenced by ARN only -- **Custom Domain** — `doorunlock.seahaven.com` via an out-of-band ACM certificate in prod plus an API Gateway domain mapping. Route 53 stays in mgmt. +- **Custom Domain** — `doorunlock.seahaven.com` via an out-of-band ACM certificate in prod. The API Gateway domain mapping is attached at DNS cutover (`attach_custom_domain`). Route 53 stays in mgmt. Until then, proof uses the execute-api URL. - **CloudWatch alarms** — one error alarm per Lambda (unlock, lockdown, authorizer, poller, blf-sync); each fires on `Errors > 0` and notifies the prod `site-alerts` SNS topic (ALARM state only) ## Infrastructure (HCP Terraform) diff --git a/terraform/apigateway.tf b/terraform/apigateway.tf index 07f280a..57c1c48 100644 --- a/terraform/apigateway.tf +++ b/terraform/apigateway.tf @@ -115,6 +115,8 @@ resource "aws_lambda_permission" "authorizer" { } resource "aws_apigatewayv2_domain_name" "this" { + count = var.attach_custom_domain ? 1 : 0 + domain_name = var.domain_name domain_name_configuration { @@ -125,7 +127,9 @@ resource "aws_apigatewayv2_domain_name" "this" { } resource "aws_apigatewayv2_api_mapping" "this" { + count = var.attach_custom_domain ? 1 : 0 + api_id = aws_apigatewayv2_api.this.id - domain_name = aws_apigatewayv2_domain_name.this.id + domain_name = aws_apigatewayv2_domain_name.this[0].id stage = aws_apigatewayv2_stage.default.id } diff --git a/terraform/outputs.tf b/terraform/outputs.tf index 489df4b..a4ce336 100644 --- a/terraform/outputs.tf +++ b/terraform/outputs.tf @@ -4,13 +4,13 @@ output "api_endpoint" { } output "custom_domain_target" { - description = "API Gateway regional domain name. DNS A alias target for doorunlock.seahaven.com at cutover." - value = aws_apigatewayv2_domain_name.this.domain_name_configuration[0].target_domain_name + description = "API Gateway regional domain name. DNS A alias target for doorunlock.seahaven.com at cutover. Null until attach_custom_domain is true." + value = var.attach_custom_domain ? aws_apigatewayv2_domain_name.this[0].domain_name_configuration[0].target_domain_name : null } output "custom_domain_hosted_zone_id" { - description = "API Gateway regional hosted zone id for the Route53 alias." - value = aws_apigatewayv2_domain_name.this.domain_name_configuration[0].hosted_zone_id + description = "API Gateway regional hosted zone id for the Route53 alias. Null until attach_custom_domain is true." + value = var.attach_custom_domain ? aws_apigatewayv2_domain_name.this[0].domain_name_configuration[0].hosted_zone_id : null } output "artifacts_bucket_name" { diff --git a/terraform/variables.tf b/terraform/variables.tf index c6ecd44..17527b1 100644 --- a/terraform/variables.tf +++ b/terraform/variables.tf @@ -15,3 +15,9 @@ variable "enable_schedules" { type = bool default = false } + +variable "attach_custom_domain" { + description = "When true, create the API Gateway custom domain and mapping. Keep false until mgmt releases doorunlock.seahaven.com at DNS cutover; the hostname is unique per region across accounts." + type = bool + default = false +}