# saif-resources / webapp

Compute-only module for a Linux web app hosted on the team's App Service Plan, VNet-integrated,
with a container image pulled from shared ACR via managed identity.
Front Door routing is composed by the service layer (e.g. `saif-web-service`).

## Usage

```hcl
module "webapp" {
  source  = "app.terraform.io/SAIFCorp/resources/saif//modules/webapp"
  version = "~> 3.7.0"

  context  = module.environment.context
  identity = module.identity.identity

  resource_group_name     = module.resource_group.resource_group_name
  resource_group_location = module.resource_group.location

  app_settings = merge(
    module.identity.app_settings,
    {
      "SomeApp__Setting" = "value"
    }
  )
}
```

<!-- BEGIN_TF_DOCS -->
## Providers

| Name | Version |
|------|---------|
| <a name="provider_azurerm"></a> [azurerm](#provider\_azurerm) | >= 4.0, < 5.0 |

## Inputs

| Name | Description | Type | Default | Required |
|------|-------------|------|---------|:--------:|
| <a name="input_app_settings"></a> [app\_settings](#input\_app\_settings) | Application settings merged from all modules + caller-specific values | `map(string)` | `{}` | no |
| <a name="input_auth_settings"></a> [auth\_settings](#input\_auth\_settings) | Azure AD authentication configuration for the web app. When set, enables auth\_settings\_v2 with the given allowed identities. Used to restrict access to APIM managed identity. | <pre>object({<br/>    client_id            = string<br/>    tenant_auth_endpoint = string<br/>    allowed_identities   = list(string)<br/>  })</pre> | `null` | no |
| <a name="input_container_config"></a> [container\_config](#input\_container\_config) | Container configuration for the web app. Defaults to ACR pull via UAMI. | <pre>object({<br/>    use_managed_identity       = optional(bool, true)<br/>    managed_identity_client_id = optional(string, "")<br/>  })</pre> | `null` | no |
| <a name="input_context"></a> [context](#input\_context) | Platform context from the environment module | `any` | n/a | yes |
| <a name="input_create_staging_slot"></a> [create\_staging\_slot](#input\_create\_staging\_slot) | Whether to create a staging deployment slot | `bool` | `false` | no |
| <a name="input_enable_health_check"></a> [enable\_health\_check](#input\_enable\_health\_check) | Whether to enable the App Service health check. Defaults to true. Set to false to opt out. | `bool` | `true` | no |
| <a name="input_enable_observability"></a> [enable\_observability](#input\_enable\_observability) | Whether to enable OTEL observability settings | `bool` | `true` | no |
| <a name="input_health_check_path"></a> [health\_check\_path](#input\_health\_check\_path) | Health check path for the App Service site\_config. Used by the App Service health eviction policy. | `string` | `"/health"` | no |
| <a name="input_identity"></a> [identity](#input\_identity) | Identity bundle from the identity module (uami\_id, uami\_client\_id, app\_client\_id, sp\_principal\_id, etc.) | `any` | n/a | yes |
| <a name="input_name"></a> [name](#input\_name) | Override the web app resource name. Defaults to the namer-generated name. Set to match the legacy name when migrating an existing deployment to avoid a forced replacement. | `string` | `null` | no |
| <a name="input_observability_config"></a> [observability\_config](#input\_observability\_config) | Observability configuration for service name and resource attributes. Defaults to project\_id and environment. | <pre>object({<br/>    service_name        = string<br/>    resource_attributes = optional(string, "")<br/>  })</pre> | `null` | no |
| <a name="input_private_endpoint_enabled"></a> [private\_endpoint\_enabled](#input\_private\_endpoint\_enabled) | Whether to create a private endpoint for the web app. Disable for workspaces that were deployed before private endpoints were introduced. | `bool` | `true` | no |
| <a name="input_resource_group_location"></a> [resource\_group\_location](#input\_resource\_group\_location) | The Azure region for resources | `string` | n/a | yes |
| <a name="input_resource_group_name"></a> [resource\_group\_name](#input\_resource\_group\_name) | The resource group name for the web app | `string` | n/a | yes |
| <a name="input_site_config"></a> [site\_config](#input\_site\_config) | Additional site configuration overrides | `map(any)` | <pre>{<br/>  "vnet_route_all_enabled": true<br/>}</pre> | no |
| <a name="input_staging_app_settings_overrides"></a> [staging\_app\_settings\_overrides](#input\_staging\_app\_settings\_overrides) | App settings overrides for the staging slot. Merged on top of the main app\_settings. | `map(string)` | `{}` | no |

## Outputs

| Name | Description |
|------|-------------|
| <a name="output_web_app_default_hostname"></a> [web\_app\_default\_hostname](#output\_web\_app\_default\_hostname) | The web app default hostname (deprecated — use webapp.default\_hostname) |
| <a name="output_web_app_id"></a> [web\_app\_id](#output\_web\_app\_id) | The web app resource ID (deprecated — use webapp.id) |
| <a name="output_web_app_name"></a> [web\_app\_name](#output\_web\_app\_name) | The web app name (deprecated — use webapp.name) |
| <a name="output_webapp"></a> [webapp](#output\_webapp) | Web app resource attributes |

## Resources


- resource.azurerm_linux_web_app_slot.staging (/terraform-docs/modules/webapp/webapp.tf#85)    
<!-- END_TF_DOCS -->

---

[View source on GitHub](https://github.com/saif-corp/forge/blob/main/src/terraform/saif-resources/modules/webapp/README.md)
