saif-resources / webapp
Compute-only module for a Linux web app hosted on the team's App Service Plan, VNet-integrated,
with a container image pulled from shared ACR via managed identity.
Front Door routing is composed by the service layer (e.g. saif-web-service).
Usage
module "webapp" {
source = "app.terraform.io/SAIFCorp/resources/saif//modules/webapp"
version = "~> 3.7.0"
context = module.environment.context
identity = module.identity.identity
resource_group_name = module.resource_group.resource_group_name
resource_group_location = module.resource_group.location
app_settings = merge (
module.identity.app_settings ,
{
"SomeApp__Setting" = "value"
}
)
}
Providers
Name
Description
Type
Default
Required
app_settings
Application settings merged from all modules + caller-specific values
map(string)
{}
no
auth_settings
Azure AD authentication configuration for the web app. When set, enables auth_settings_v2 with the given allowed identities. Used to restrict access to APIM managed identity.
object({ client_id = string tenant_auth_endpoint = string allowed_identities = list(string) })
null
no
container_config
Container configuration for the web app. Defaults to ACR pull via UAMI.
object({ use_managed_identity = optional(bool, true) managed_identity_client_id = optional(string, "") })
null
no
context
Platform context from the environment module
any
n/a
yes
create_staging_slot
Whether to create a staging deployment slot
bool
false
no
enable_health_check
Whether to enable the App Service health check. Defaults to true. Set to false to opt out.
bool
true
no
enable_observability
Whether to enable OTEL observability settings
bool
true
no
health_check_path
Health check path for the App Service site_config. Used by the App Service health eviction policy.
string
"/health"
no
identity
Identity bundle from the identity module (uami_id, uami_client_id, app_client_id, sp_principal_id, etc.)
any
n/a
yes
name
Override the web app resource name. Defaults to the namer-generated name. Set to match the legacy name when migrating an existing deployment to avoid a forced replacement.
string
null
no
observability_config
Observability configuration for service name and resource attributes. Defaults to project_id and environment.
object({ service_name = string resource_attributes = optional(string, "") })
null
no
private_endpoint_enabled
Whether to create a private endpoint for the web app. Disable for workspaces that were deployed before private endpoints were introduced.
bool
true
no
resource_group_location
The Azure region for resources
string
n/a
yes
resource_group_name
The resource group name for the web app
string
n/a
yes
site_config
Additional site configuration overrides
map(any)
{ "vnet_route_all_enabled": true }
no
staging_app_settings_overrides
App settings overrides for the staging slot. Merged on top of the main app_settings.
map(string)
{}
no
Outputs
Name
Description
web_app_default_hostname
The web app default hostname (deprecated — use webapp.default_hostname)
web_app_id
The web app resource ID (deprecated — use webapp.id)
web_app_name
The web app name (deprecated — use webapp.name)
webapp
Web app resource attributes
Resources
resource.azurerm_linux_web_app_slot.staging (/terraform-docs/modules/webapp/webapp.tf#85)
View source on GitHub