# saif-web-service

This module deploys a frontend web application to Azure App Service.

## ℹ️ Authentication Note

This module deploys static web applications that do not handle authentication directly. Authentication for frontend applications is managed by:

- **Corporate users (internal)**: Authenticated via **Entra ID** at the API gateway or backend level
- **External users**: Authenticated via **Okta** at the API gateway or backend level

The `Tenant` variable in this module refers to the **Azure infrastructure tenant** (Corporate/External subscriptions) for resource naming and deployment targeting, not the authentication provider.

<!-- BEGIN_TF_DOCS -->
## Providers

No providers.

## Inputs

| Name | Description | Type | Default | Required |
|------|-------------|------|---------|:--------:|
| <a name="input_application_name"></a> [application\_name](#input\_application\_name) | The name of the application | `string` | n/a | yes |
| <a name="input_application_settings"></a> [application\_settings](#input\_application\_settings) | Settings for your application | `map(string)` | `{}` | no |
| <a name="input_create_staging_slot"></a> [create\_staging\_slot](#input\_create\_staging\_slot) | Whether to create a staging slot for the web app | `bool` | `false` | no |
| <a name="input_custom_subdomain"></a> [custom\_subdomain](#input\_custom\_subdomain) | Custom subdomain to attach this app to (e.g., 'myapp' for myapp.saif.com). The custom subdomain must be created in azure.terraform first. Empty string disables custom domain routing. | `string` | `""` | no |
| <a name="input_deployed_by"></a> [deployed\_by](#input\_deployed\_by) | Identifier for the deployment mechanism (e.g. Terraform, GitHub Actions) | `string` | `"Terraform"` | no |
| <a name="input_enable_health_check"></a> [enable\_health\_check](#input\_enable\_health\_check) | Whether to enable the App Service health check. Defaults to true. Set to false to opt out. | `bool` | `true` | no |
| <a name="input_environment"></a> [environment](#input\_environment) | The environment in which the resources are deployed | `string` | n/a | yes |
| <a name="input_environment_short_name"></a> [environment\_short\_name](#input\_environment\_short\_name) | The short name of the environment | `string` | `null` | no |
| <a name="input_has_backend_api"></a> [has\_backend\_api](#input\_has\_backend\_api) | Whether the application has a backend API. When true, APP\_BACKEND\_URL is included in app settings and the API namer module is created. | `bool` | `true` | no |
| <a name="input_health_check_path"></a> [health\_check\_path](#input\_health\_check\_path) | App Service health check path. Defaults to '/{application\_name}' for subpath-routed apps, or '/' when is\_root\_path = true. Override if the app exposes a different probe endpoint. | `string` | `null` | no |
| <a name="input_is_external_app"></a> [is\_external\_app](#input\_is\_external\_app) | Is this an external application | `bool` | `false` | no |
| <a name="input_is_production"></a> [is\_production](#input\_is\_production) | Is this a production environment | `bool` | n/a | yes |
| <a name="input_is_root_path"></a> [is\_root\_path](#input\_is\_root\_path) | When custom\_subdomain is set, determines the path: true for root (myapp.saif.com), false for subpath matching application name (myapp.saif.com/appname). When false, the subpath is automatically set to /application\_name. | `bool` | `false` | no |
| <a name="input_minimum_tls_version"></a> [minimum\_tls\_version](#input\_minimum\_tls\_version) | Minimum TLS version for the web app. Defaults to 1.2 (Forge standard). | `string` | `"1.2"` | no |
| <a name="input_owner"></a> [owner](#input\_owner) | The name of the team that owns the resources | `string` | n/a | yes |
| <a name="input_project_id"></a> [project\_id](#input\_project\_id) | The id of the project. This will be used to name the resources. | `string` | n/a | yes |
| <a name="input_resource_location"></a> [resource\_location](#input\_resource\_location) | The location the resources will be deployed to. | `string` | `"westus2"` | no |
| <a name="input_tags"></a> [tags](#input\_tags) | A map of tags to be applied to resources in the module | `map(string)` | n/a | yes |
| <a name="input_tenant"></a> [tenant](#input\_tenant) | Deprecated — the Azure infra tenant is fixed to local.azure\_tenant ("Corporate"). Retained for backward compatibility with callers (e.g. the HCP Terraform Okta variable set injecting tenant = "ext") but ignored by this module. | `string` | `"Corporate"` | no |

## Outputs

No outputs.

## Resources
    
<!-- END_TF_DOCS -->

---

[View source on GitHub](https://github.com/saif-corp/forge/blob/main/src/terraform/saif-web-service/README.md)
