# saif-resources

Composable Terraform resource modules for Forge service infrastructure.

## Overview

Instead of monolithic modules with feature flags, services are assembled from small, independent resource modules that compose through a shared `context` and `identity` interface.

## Usage

Services compose modules together — `environment` provides `context`, `identity` provides the `identity` bundle, and resource modules accept both:

```hcl
module "environment" {
  source  = "app.terraform.io/SAIFCorp/resources/saif//modules/environment"
  version = "~> 1.0.0"

  environment   = var.environment
  tenant        = var.tenant
  owner         = var.owner
  project_id    = var.project_id
  is_production = var.is_production
}

module "identity" {
  source  = "app.terraform.io/SAIFCorp/resources/saif//modules/identity"
  version = "~> 1.0.0"

  providers = {
    azurerm.shared-services = azurerm.shared-services
  }

  context      = module.environment.context
  name         = var.project_id
  ai_hub_roles = true
}

module "api" {
  source  = "app.terraform.io/SAIFCorp/resources/saif//modules/api"
  version = "~> 1.0.0"

  context  = module.environment.context
  identity = module.identity.identity
  # ... compute + APIM + Front Door configuration
}
```

## Modules

| Module             | Status        | Purpose                                                                 |
| ------------------ | ------------- | ----------------------------------------------------------------------- |
| `environment`      | ✅ Implemented | Shared infra resolution (TFE outputs, networking, naming)               |
| `identity`         | ✅ Implemented | UAMI + App Registration + KV secret lifecycle                           |
| `api`              | ✅ Implemented | Backend API: APIM + WebApp + shared FD route + PE                       |
| `cosmosdb`         | ✅ Implemented | CosmosDB account + containers + RBAC                                    |
| `ai-project`       | ✅ Implemented | AI Foundry project + model deployment                                   |
| `bot`              | ✅ Implemented | Azure Bot Service + OAuth + Teams channel                               |
| `webapp`           | 📋 Planned     | Frontend Web App: WebApp + FD origin group + shared FD route + PE       |
| `storage`          | 📋 Planned     | Blob storage + containers + RBAC                                        |
| `servicebus-queue` | ✅ Implemented | App-scoped Service Bus queue(s) for internal producer/consumer messaging + queue-level RBAC |
| `staticsite`       | 📋 Planned     | Static Site / SPA: Storage static website + dedicated FD endpoint + WAF |
| `custom-subdomain` | 📋 Planned     | Optional FD vanity domain routing for any compute module                |

<!-- BEGIN_TF_DOCS -->
## Providers

No providers.

## Inputs

No inputs.

## Outputs

No outputs.

## Resources
    
<!-- END_TF_DOCS -->

---

[View source on GitHub](https://github.com/saif-corp/forge/blob/main/src/terraform/saif-resources/README.md)
