saif-resources / custom-subdomain
Vanity domain routing module. Attaches a webapp or API to a pre-provisioned team custom subdomain endpoint managed by saif-custom-subdomain-service.
Prerequisites
The team must have a custom subdomain provisioned. This module derives the expected Front Door endpoint and custom-domain resource names from context.is_production, context.environment_short_name, and subdomain, then looks those resources up in the shared org Front Door profile.
Usage
module "custom_subdomain" {
source = "app.terraform.io/SAIFCorp/resources/saif//modules/custom-subdomain"
version = "~> 3.5.0"
context = module.environment.context
subdomain = "policies" # team custom subdomain slug
application_name = var.application_name
origin_hostname = module.webapp.web_app_default_hostname
origin_resource_id = module.webapp.web_app_id
resource_group_location = module.resource_group.location
is_root_path = true # route "/" → webapp; false = route "/{application_name}/*"
}
Name
Description
Required
context
Platform context from environment module
yes
subdomain
Team custom subdomain slug used to derive the Front Door endpoint/domain
yes
application_name
Short app name (used in FD resource naming)
yes
origin_hostname
Origin hostname (web app or API default hostname)
yes
origin_resource_id
Origin resource ID (for Private Link)
yes
resource_group_location
Azure region of the origin resource
yes
is_root_path
Route at / when true, /{application_name}/ when false (default: false)
no
Outputs
Name
Description
origin_group_id
Origin group resource ID on team's FD profile
origin_ids
Origin resource IDs
route_id
Front Door route resource ID
What it creates
Front Door origin group on the team's FD profile (from saif-custom-subdomain-service)
Front Door route on the team's custom subdomain endpoint
Custom domain association between the route and custom domain
Notes
Private Link approval : After the first plan/apply, approve the Private Link request from the web app's networking blade in the Azure portal.
Root vs sub-path : is_root_path = true sends all traffic at / to the app. false routes only /{application_name}/*.
Context dependency : the module uses context.is_production, context.environment_short_name, context.org_services.fd_profile_id, context.org_services.resource_group_name, and context.org_services.fd_add_origin_header_rule_set_id to derive and resolve the Front Door resources. If the team custom subdomain is not provisioned yet, the plan fails with a targeted lookup error.
Providers
Name
Description
Type
Default
Required
application_name
Short name for the application (used in FD resource naming)
string
n/a
yes
context
Platform context from the environment module
any
n/a
yes
is_root_path
When true, route handles '/' (root). When false, route handles '/{application_name}/*'.
bool
false
no
origin_hostname
The hostname of the origin resource (e.g. web app or API default hostname)
string
n/a
yes
origin_name
Override the Front Door origin resource name. Defaults to '{application_name}-custom-origin'. Set to match the legacy name when migrating an existing deployment to avoid destroying and recreating the origin.
string
null
no
origin_resource_id
The resource ID of the origin (used for Private Link approval)
string
n/a
yes
resource_group_location
Azure region of the origin resource (used for Private Link location)
string
n/a
yes
subdomain
Key of the custom subdomain to use (must match the team custom subdomain slug provisioned in Front Door)
string
n/a
yes
target_type
Private Link target type for the origin. Use 'sites' for App Service or 'web' for static website storage.
string
"sites"
no
Outputs
Name
Description
origin_group_id
The origin group resource ID on the team's Front Door profile
origin_ids
The origin resource IDs in the origin group
route_id
The Front Door route resource ID
Resources
resource.azurerm_cdn_frontdoor_custom_domain_association.custom_domain (/terraform-docs/modules/custom-subdomain/main.tf#122)
data source.azapi_resource_list.frontdoor_custom_domains (/terraform-docs/modules/custom-subdomain/main.tf#52)
data source.azapi_resource_list.frontdoor_endpoints (/terraform-docs/modules/custom-subdomain/main.tf#46)
data source.azurerm_cdn_frontdoor_custom_domain.subdomain (/terraform-docs/modules/custom-subdomain/main.tf#66)
data source.azurerm_cdn_frontdoor_endpoint.subdomain (/terraform-docs/modules/custom-subdomain/main.tf#58)
data source.azurerm_client_config.guard (/terraform-docs/modules/custom-subdomain/main.tf#37)
View source on GitHub