Skip to content

saif-resources / custom-subdomain

Vanity domain routing module. Attaches a webapp or API to a pre-provisioned team custom subdomain endpoint managed by saif-custom-subdomain-service.

Prerequisites

The team must have a custom subdomain provisioned. This module derives the expected Front Door endpoint and custom-domain resource names from context.is_production, context.environment_short_name, and subdomain, then looks those resources up in the shared org Front Door profile.

Usage

module "custom_subdomain" {
  source  = "app.terraform.io/SAIFCorp/resources/saif//modules/custom-subdomain"
  version = "~> 3.5.0"

  context   = module.environment.context
  subdomain = "policies" # team custom subdomain slug

  application_name        = var.application_name
  origin_hostname         = module.webapp.web_app_default_hostname
  origin_resource_id      = module.webapp.web_app_id
  resource_group_location = module.resource_group.location

  is_root_path = true  # route "/" → webapp; false = route "/{application_name}/*"
}

Inputs

Name Description Required
context Platform context from environment module yes
subdomain Team custom subdomain slug used to derive the Front Door endpoint/domain yes
application_name Short app name (used in FD resource naming) yes
origin_hostname Origin hostname (web app or API default hostname) yes
origin_resource_id Origin resource ID (for Private Link) yes
resource_group_location Azure region of the origin resource yes
is_root_path Route at / when true, /{application_name}/ when false (default: false) no

Outputs

Name Description
origin_group_id Origin group resource ID on team's FD profile
origin_ids Origin resource IDs
route_id Front Door route resource ID

What it creates

  • Front Door origin group on the team's FD profile (from saif-custom-subdomain-service)
  • Front Door route on the team's custom subdomain endpoint
  • Custom domain association between the route and custom domain

Notes

  • Private Link approval: After the first plan/apply, approve the Private Link request from the web app's networking blade in the Azure portal.
  • Root vs sub-path: is_root_path = true sends all traffic at / to the app. false routes only /{application_name}/*.
  • Context dependency: the module uses context.is_production, context.environment_short_name, context.org_services.fd_profile_id, context.org_services.resource_group_name, and context.org_services.fd_add_origin_header_rule_set_id to derive and resolve the Front Door resources. If the team custom subdomain is not provisioned yet, the plan fails with a targeted lookup error.

Providers

Name Version
azapi >= 2.0, < 3.0
azurerm >= 4.0, < 5.0

Inputs

Name Description Type Default Required
application_name Short name for the application (used in FD resource naming) string n/a yes
context Platform context from the environment module any n/a yes
is_root_path When true, route handles '/' (root). When false, route handles '/{application_name}/*'. bool false no
origin_hostname The hostname of the origin resource (e.g. web app or API default hostname) string n/a yes
origin_name Override the Front Door origin resource name. Defaults to '{application_name}-custom-origin'. Set to match the legacy name when migrating an existing deployment to avoid destroying and recreating the origin. string null no
origin_resource_id The resource ID of the origin (used for Private Link approval) string n/a yes
resource_group_location Azure region of the origin resource (used for Private Link location) string n/a yes
subdomain Key of the custom subdomain to use (must match the team custom subdomain slug provisioned in Front Door) string n/a yes
target_type Private Link target type for the origin. Use 'sites' for App Service or 'web' for static website storage. string "sites" no

Outputs

Name Description
origin_group_id The origin group resource ID on the team's Front Door profile
origin_ids The origin resource IDs in the origin group
route_id The Front Door route resource ID

Resources

  • resource.azurerm_cdn_frontdoor_custom_domain_association.custom_domain (/terraform-docs/modules/custom-subdomain/main.tf#122)
  • data source.azapi_resource_list.frontdoor_custom_domains (/terraform-docs/modules/custom-subdomain/main.tf#52)
  • data source.azapi_resource_list.frontdoor_endpoints (/terraform-docs/modules/custom-subdomain/main.tf#46)
  • data source.azurerm_cdn_frontdoor_custom_domain.subdomain (/terraform-docs/modules/custom-subdomain/main.tf#66)
  • data source.azurerm_cdn_frontdoor_endpoint.subdomain (/terraform-docs/modules/custom-subdomain/main.tf#58)
  • data source.azurerm_client_config.guard (/terraform-docs/modules/custom-subdomain/main.tf#37)

View source on GitHub