mirror of
https://github.com/Sea-Haven-Industries/seahaven-door-unlock-api.git
synced 2026-09-30 05:53:12 +00:00
fix(terraform): defer api domain until dns cutover (#83)
API Gateway custom domain names are unique per region across accounts, so prod cannot create doorunlock.seahaven.com while mgmt still holds it.
This commit is contained in:
parent
cdd810001d
commit
61f13bddfe
4 changed files with 16 additions and 6 deletions
|
|
@ -22,7 +22,7 @@ Phones keep `https://doorunlock.seahaven.com`. Cutover is a Route 53 A-record fl
|
|||
- **BLF sync Lambda** — daily 09:00 UTC EventBridge job that writes 3CX department BLFs
|
||||
- **SSM Parameter Store** — Elements API key, auth token, and door ID (created out of band; Terraform never reads SecureString values)
|
||||
- **Secrets Manager** — 3CX XAPI credentials (`afterhours-shift-manager/3cx-*`), referenced by ARN only
|
||||
- **Custom Domain** — `doorunlock.seahaven.com` via an out-of-band ACM certificate in prod plus an API Gateway domain mapping. Route 53 stays in mgmt.
|
||||
- **Custom Domain** — `doorunlock.seahaven.com` via an out-of-band ACM certificate in prod. The API Gateway domain mapping is attached at DNS cutover (`attach_custom_domain`). Route 53 stays in mgmt. Until then, proof uses the execute-api URL.
|
||||
- **CloudWatch alarms** — one error alarm per Lambda (unlock, lockdown, authorizer, poller, blf-sync); each fires on `Errors > 0` and notifies the prod `site-alerts` SNS topic (ALARM state only)
|
||||
|
||||
## Infrastructure (HCP Terraform)
|
||||
|
|
|
|||
|
|
@ -115,6 +115,8 @@ resource "aws_lambda_permission" "authorizer" {
|
|||
}
|
||||
|
||||
resource "aws_apigatewayv2_domain_name" "this" {
|
||||
count = var.attach_custom_domain ? 1 : 0
|
||||
|
||||
domain_name = var.domain_name
|
||||
|
||||
domain_name_configuration {
|
||||
|
|
@ -125,7 +127,9 @@ resource "aws_apigatewayv2_domain_name" "this" {
|
|||
}
|
||||
|
||||
resource "aws_apigatewayv2_api_mapping" "this" {
|
||||
count = var.attach_custom_domain ? 1 : 0
|
||||
|
||||
api_id = aws_apigatewayv2_api.this.id
|
||||
domain_name = aws_apigatewayv2_domain_name.this.id
|
||||
domain_name = aws_apigatewayv2_domain_name.this[0].id
|
||||
stage = aws_apigatewayv2_stage.default.id
|
||||
}
|
||||
|
|
|
|||
|
|
@ -4,13 +4,13 @@ output "api_endpoint" {
|
|||
}
|
||||
|
||||
output "custom_domain_target" {
|
||||
description = "API Gateway regional domain name. DNS A alias target for doorunlock.seahaven.com at cutover."
|
||||
value = aws_apigatewayv2_domain_name.this.domain_name_configuration[0].target_domain_name
|
||||
description = "API Gateway regional domain name. DNS A alias target for doorunlock.seahaven.com at cutover. Null until attach_custom_domain is true."
|
||||
value = var.attach_custom_domain ? aws_apigatewayv2_domain_name.this[0].domain_name_configuration[0].target_domain_name : null
|
||||
}
|
||||
|
||||
output "custom_domain_hosted_zone_id" {
|
||||
description = "API Gateway regional hosted zone id for the Route53 alias."
|
||||
value = aws_apigatewayv2_domain_name.this.domain_name_configuration[0].hosted_zone_id
|
||||
description = "API Gateway regional hosted zone id for the Route53 alias. Null until attach_custom_domain is true."
|
||||
value = var.attach_custom_domain ? aws_apigatewayv2_domain_name.this[0].domain_name_configuration[0].hosted_zone_id : null
|
||||
}
|
||||
|
||||
output "artifacts_bucket_name" {
|
||||
|
|
|
|||
|
|
@ -15,3 +15,9 @@ variable "enable_schedules" {
|
|||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "attach_custom_domain" {
|
||||
description = "When true, create the API Gateway custom domain and mapping. Keep false until mgmt releases doorunlock.seahaven.com at DNS cutover; the hostname is unique per region across accounts."
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue