# saif-resources / custom-subdomain

Vanity domain routing module. Attaches a webapp or API to a pre-provisioned team custom subdomain endpoint managed by `saif-custom-subdomain-service`.

## Prerequisites

The team must have a custom subdomain provisioned. This module derives the expected Front Door endpoint and custom-domain resource names from `context.is_production`, `context.environment_short_name`, and `subdomain`, then looks those resources up in the shared org Front Door profile.

## Usage

```hcl
module "custom_subdomain" {
  source  = "app.terraform.io/SAIFCorp/resources/saif//modules/custom-subdomain"
  version = "~> 3.5.0"

  context   = module.environment.context
  subdomain = "policies" # team custom subdomain slug

  application_name        = var.application_name
  origin_hostname         = module.webapp.web_app_default_hostname
  origin_resource_id      = module.webapp.web_app_id
  resource_group_location = module.resource_group.location

  is_root_path = true  # route "/" → webapp; false = route "/{application_name}/*"
}
```

## Inputs

| Name                      | Description                                                                  | Required |
| ------------------------- | ---------------------------------------------------------------------------- | -------- |
| `context`                 | Platform context from `environment` module                                   | yes      |
| `subdomain`               | Team custom subdomain slug used to derive the Front Door endpoint/domain     | yes      |
| `application_name`        | Short app name (used in FD resource naming)                                  | yes      |
| `origin_hostname`         | Origin hostname (web app or API default hostname)                            | yes      |
| `origin_resource_id`      | Origin resource ID (for Private Link)                                        | yes      |
| `resource_group_location` | Azure region of the origin resource                                          | yes      |
| `is_root_path`            | Route at `/` when true, `/{application_name}/` when false (default: `false`) | no       |

## Outputs

| Name              | Description                                   |
| ----------------- | --------------------------------------------- |
| `origin_group_id` | Origin group resource ID on team's FD profile |
| `origin_ids`      | Origin resource IDs                           |
| `route_id`        | Front Door route resource ID                  |

## What it creates

- Front Door origin group on the team's FD profile (from `saif-custom-subdomain-service`)
- Front Door route on the team's custom subdomain endpoint
- Custom domain association between the route and custom domain

## Notes

- **Private Link approval**: After the first plan/apply, approve the Private Link request from the web app's networking blade in the Azure portal.
- **Root vs sub-path**: `is_root_path = true` sends all traffic at `/` to the app. `false` routes only `/{application_name}/*`.
- **Context dependency**: the module uses `context.is_production`, `context.environment_short_name`, `context.org_services.fd_profile_id`, `context.org_services.resource_group_name`, and `context.org_services.fd_add_origin_header_rule_set_id` to derive and resolve the Front Door resources. If the team custom subdomain is not provisioned yet, the plan fails with a targeted lookup error.

<!-- BEGIN_TF_DOCS -->
## Providers

| Name | Version |
|------|---------|
| <a name="provider_azapi"></a> [azapi](#provider\_azapi) | >= 2.0, < 3.0 |
| <a name="provider_azurerm"></a> [azurerm](#provider\_azurerm) | >= 4.0, < 5.0 |

## Inputs

| Name | Description | Type | Default | Required |
|------|-------------|------|---------|:--------:|
| <a name="input_application_name"></a> [application\_name](#input\_application\_name) | Short name for the application (used in FD resource naming) | `string` | n/a | yes |
| <a name="input_context"></a> [context](#input\_context) | Platform context from the environment module | `any` | n/a | yes |
| <a name="input_is_root_path"></a> [is\_root\_path](#input\_is\_root\_path) | When true, route handles '/' (root). When false, route handles '/{application\_name}/*'. | `bool` | `false` | no |
| <a name="input_origin_hostname"></a> [origin\_hostname](#input\_origin\_hostname) | The hostname of the origin resource (e.g. web app or API default hostname) | `string` | n/a | yes |
| <a name="input_origin_name"></a> [origin\_name](#input\_origin\_name) | Override the Front Door origin resource name. Defaults to '{application\_name}-custom-origin'. Set to match the legacy name when migrating an existing deployment to avoid destroying and recreating the origin. | `string` | `null` | no |
| <a name="input_origin_resource_id"></a> [origin\_resource\_id](#input\_origin\_resource\_id) | The resource ID of the origin (used for Private Link approval) | `string` | n/a | yes |
| <a name="input_resource_group_location"></a> [resource\_group\_location](#input\_resource\_group\_location) | Azure region of the origin resource (used for Private Link location) | `string` | n/a | yes |
| <a name="input_subdomain"></a> [subdomain](#input\_subdomain) | Key of the custom subdomain to use (must match the team custom subdomain slug provisioned in Front Door) | `string` | n/a | yes |
| <a name="input_target_type"></a> [target\_type](#input\_target\_type) | Private Link target type for the origin. Use 'sites' for App Service or 'web' for static website storage. | `string` | `"sites"` | no |

## Outputs

| Name | Description |
|------|-------------|
| <a name="output_origin_group_id"></a> [origin\_group\_id](#output\_origin\_group\_id) | The origin group resource ID on the team's Front Door profile |
| <a name="output_origin_ids"></a> [origin\_ids](#output\_origin\_ids) | The origin resource IDs in the origin group |
| <a name="output_route_id"></a> [route\_id](#output\_route\_id) | The Front Door route resource ID |

## Resources


- resource.azurerm_cdn_frontdoor_custom_domain_association.custom_domain (/terraform-docs/modules/custom-subdomain/main.tf#122)
- data source.azapi_resource_list.frontdoor_custom_domains (/terraform-docs/modules/custom-subdomain/main.tf#52)
- data source.azapi_resource_list.frontdoor_endpoints (/terraform-docs/modules/custom-subdomain/main.tf#46)
- data source.azurerm_cdn_frontdoor_custom_domain.subdomain (/terraform-docs/modules/custom-subdomain/main.tf#66)
- data source.azurerm_cdn_frontdoor_endpoint.subdomain (/terraform-docs/modules/custom-subdomain/main.tf#58)
- data source.azurerm_client_config.guard (/terraform-docs/modules/custom-subdomain/main.tf#37)    
<!-- END_TF_DOCS -->

---

[View source on GitHub](https://github.com/saif-corp/forge/blob/main/src/terraform/saif-resources/modules/custom-subdomain/README.md)
