fix(terraform): defer api domain until dns cutover

API Gateway custom domain names are unique per region across accounts, so prod cannot create doorunlock.seahaven.com while mgmt still holds it.
This commit is contained in:
Adam Moussa 2026-08-27 18:55:30 -04:00
parent cdd810001d
commit 9281925760
No known key found for this signature in database
4 changed files with 16 additions and 6 deletions

View file

@ -22,7 +22,7 @@ Phones keep `https://doorunlock.seahaven.com`. Cutover is a Route 53 A-record fl
- **BLF sync Lambda** — daily 09:00 UTC EventBridge job that writes 3CX department BLFs
- **SSM Parameter Store** — Elements API key, auth token, and door ID (created out of band; Terraform never reads SecureString values)
- **Secrets Manager** — 3CX XAPI credentials (`afterhours-shift-manager/3cx-*`), referenced by ARN only
- **Custom Domain** — `doorunlock.seahaven.com` via an out-of-band ACM certificate in prod plus an API Gateway domain mapping. Route 53 stays in mgmt.
- **Custom Domain** — `doorunlock.seahaven.com` via an out-of-band ACM certificate in prod. The API Gateway domain mapping is attached at DNS cutover (`attach_custom_domain`). Route 53 stays in mgmt. Until then, proof uses the execute-api URL.
- **CloudWatch alarms** — one error alarm per Lambda (unlock, lockdown, authorizer, poller, blf-sync); each fires on `Errors > 0` and notifies the prod `site-alerts` SNS topic (ALARM state only)
## Infrastructure (HCP Terraform)

View file

@ -115,6 +115,8 @@ resource "aws_lambda_permission" "authorizer" {
}
resource "aws_apigatewayv2_domain_name" "this" {
count = var.attach_custom_domain ? 1 : 0
domain_name = var.domain_name
domain_name_configuration {
@ -125,7 +127,9 @@ resource "aws_apigatewayv2_domain_name" "this" {
}
resource "aws_apigatewayv2_api_mapping" "this" {
count = var.attach_custom_domain ? 1 : 0
api_id = aws_apigatewayv2_api.this.id
domain_name = aws_apigatewayv2_domain_name.this.id
domain_name = aws_apigatewayv2_domain_name.this[0].id
stage = aws_apigatewayv2_stage.default.id
}

View file

@ -4,13 +4,13 @@ output "api_endpoint" {
}
output "custom_domain_target" {
description = "API Gateway regional domain name. DNS A alias target for doorunlock.seahaven.com at cutover."
value = aws_apigatewayv2_domain_name.this.domain_name_configuration[0].target_domain_name
description = "API Gateway regional domain name. DNS A alias target for doorunlock.seahaven.com at cutover. Null until attach_custom_domain is true."
value = var.attach_custom_domain ? aws_apigatewayv2_domain_name.this[0].domain_name_configuration[0].target_domain_name : null
}
output "custom_domain_hosted_zone_id" {
description = "API Gateway regional hosted zone id for the Route53 alias."
value = aws_apigatewayv2_domain_name.this.domain_name_configuration[0].hosted_zone_id
description = "API Gateway regional hosted zone id for the Route53 alias. Null until attach_custom_domain is true."
value = var.attach_custom_domain ? aws_apigatewayv2_domain_name.this[0].domain_name_configuration[0].hosted_zone_id : null
}
output "artifacts_bucket_name" {

View file

@ -15,3 +15,9 @@ variable "enable_schedules" {
type = bool
default = false
}
variable "attach_custom_domain" {
description = "When true, create the API Gateway custom domain and mapping. Keep false until mgmt releases doorunlock.seahaven.com at DNS cutover; the hostname is unique per region across accounts."
type = bool
default = false
}