mirror of
https://github.com/Sea-Haven-Industries/seahaven-door-unlock-api.git
synced 2026-10-02 22:43:28 +00:00
fix(terraform): defer api domain until dns cutover
API Gateway custom domain names are unique per region across accounts, so prod cannot create doorunlock.seahaven.com while mgmt still holds it.
This commit is contained in:
parent
cdd810001d
commit
9281925760
4 changed files with 16 additions and 6 deletions
|
|
@ -22,7 +22,7 @@ Phones keep `https://doorunlock.seahaven.com`. Cutover is a Route 53 A-record fl
|
|||
- **BLF sync Lambda** — daily 09:00 UTC EventBridge job that writes 3CX department BLFs
|
||||
- **SSM Parameter Store** — Elements API key, auth token, and door ID (created out of band; Terraform never reads SecureString values)
|
||||
- **Secrets Manager** — 3CX XAPI credentials (`afterhours-shift-manager/3cx-*`), referenced by ARN only
|
||||
- **Custom Domain** — `doorunlock.seahaven.com` via an out-of-band ACM certificate in prod plus an API Gateway domain mapping. Route 53 stays in mgmt.
|
||||
- **Custom Domain** — `doorunlock.seahaven.com` via an out-of-band ACM certificate in prod. The API Gateway domain mapping is attached at DNS cutover (`attach_custom_domain`). Route 53 stays in mgmt. Until then, proof uses the execute-api URL.
|
||||
- **CloudWatch alarms** — one error alarm per Lambda (unlock, lockdown, authorizer, poller, blf-sync); each fires on `Errors > 0` and notifies the prod `site-alerts` SNS topic (ALARM state only)
|
||||
|
||||
## Infrastructure (HCP Terraform)
|
||||
|
|
|
|||
|
|
@ -115,6 +115,8 @@ resource "aws_lambda_permission" "authorizer" {
|
|||
}
|
||||
|
||||
resource "aws_apigatewayv2_domain_name" "this" {
|
||||
count = var.attach_custom_domain ? 1 : 0
|
||||
|
||||
domain_name = var.domain_name
|
||||
|
||||
domain_name_configuration {
|
||||
|
|
@ -125,7 +127,9 @@ resource "aws_apigatewayv2_domain_name" "this" {
|
|||
}
|
||||
|
||||
resource "aws_apigatewayv2_api_mapping" "this" {
|
||||
count = var.attach_custom_domain ? 1 : 0
|
||||
|
||||
api_id = aws_apigatewayv2_api.this.id
|
||||
domain_name = aws_apigatewayv2_domain_name.this.id
|
||||
domain_name = aws_apigatewayv2_domain_name.this[0].id
|
||||
stage = aws_apigatewayv2_stage.default.id
|
||||
}
|
||||
|
|
|
|||
|
|
@ -4,13 +4,13 @@ output "api_endpoint" {
|
|||
}
|
||||
|
||||
output "custom_domain_target" {
|
||||
description = "API Gateway regional domain name. DNS A alias target for doorunlock.seahaven.com at cutover."
|
||||
value = aws_apigatewayv2_domain_name.this.domain_name_configuration[0].target_domain_name
|
||||
description = "API Gateway regional domain name. DNS A alias target for doorunlock.seahaven.com at cutover. Null until attach_custom_domain is true."
|
||||
value = var.attach_custom_domain ? aws_apigatewayv2_domain_name.this[0].domain_name_configuration[0].target_domain_name : null
|
||||
}
|
||||
|
||||
output "custom_domain_hosted_zone_id" {
|
||||
description = "API Gateway regional hosted zone id for the Route53 alias."
|
||||
value = aws_apigatewayv2_domain_name.this.domain_name_configuration[0].hosted_zone_id
|
||||
description = "API Gateway regional hosted zone id for the Route53 alias. Null until attach_custom_domain is true."
|
||||
value = var.attach_custom_domain ? aws_apigatewayv2_domain_name.this[0].domain_name_configuration[0].hosted_zone_id : null
|
||||
}
|
||||
|
||||
output "artifacts_bucket_name" {
|
||||
|
|
|
|||
|
|
@ -15,3 +15,9 @@ variable "enable_schedules" {
|
|||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "attach_custom_domain" {
|
||||
description = "When true, create the API Gateway custom domain and mapping. Keep false until mgmt releases doorunlock.seahaven.com at DNS cutover; the hostname is unique per region across accounts."
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue