Skip to content

saif-resources / webapp

Compute-only module for a Linux web app hosted on the team's App Service Plan, VNet-integrated, with a container image pulled from shared ACR via managed identity. Front Door routing is composed by the service layer (e.g. saif-web-service).

Usage

module "webapp" {
  source  = "app.terraform.io/SAIFCorp/resources/saif//modules/webapp"
  version = "~> 3.7.0"

  context  = module.environment.context
  identity = module.identity.identity

  resource_group_name     = module.resource_group.resource_group_name
  resource_group_location = module.resource_group.location

  app_settings = merge(
    module.identity.app_settings,
    {
      "SomeApp__Setting" = "value"
    }
  )
}

Providers

Name Version
azurerm >= 4.0, < 5.0

Inputs

Name Description Type Default Required
app_settings Application settings merged from all modules + caller-specific values map(string) {} no
auth_settings Azure AD authentication configuration for the web app. When set, enables auth_settings_v2 with the given allowed identities. Used to restrict access to APIM managed identity.
object({
client_id = string
tenant_auth_endpoint = string
allowed_identities = list(string)
})
null no
container_config Container configuration for the web app. Defaults to ACR pull via UAMI.
object({
use_managed_identity = optional(bool, true)
managed_identity_client_id = optional(string, "")
})
null no
context Platform context from the environment module any n/a yes
create_staging_slot Whether to create a staging deployment slot bool false no
enable_health_check Whether to enable the App Service health check. Defaults to true. Set to false to opt out. bool true no
enable_observability Whether to enable OTEL observability settings bool true no
health_check_path Health check path for the App Service site_config. Used by the App Service health eviction policy. string "/health" no
identity Identity bundle from the identity module (uami_id, uami_client_id, app_client_id, sp_principal_id, etc.) any n/a yes
name Override the web app resource name. Defaults to the namer-generated name. Set to match the legacy name when migrating an existing deployment to avoid a forced replacement. string null no
observability_config Observability configuration for service name and resource attributes. Defaults to project_id and environment.
object({
service_name = string
resource_attributes = optional(string, "")
})
null no
private_endpoint_enabled Whether to create a private endpoint for the web app. Disable for workspaces that were deployed before private endpoints were introduced. bool true no
resource_group_location The Azure region for resources string n/a yes
resource_group_name The resource group name for the web app string n/a yes
site_config Additional site configuration overrides map(any)
{
"vnet_route_all_enabled": true
}
no
staging_app_settings_overrides App settings overrides for the staging slot. Merged on top of the main app_settings. map(string) {} no

Outputs

Name Description
web_app_default_hostname The web app default hostname (deprecated — use webapp.default_hostname)
web_app_id The web app resource ID (deprecated — use webapp.id)
web_app_name The web app name (deprecated — use webapp.name)
webapp Web app resource attributes

Resources

  • resource.azurerm_linux_web_app_slot.staging (/terraform-docs/modules/webapp/webapp.tf#85)

View source on GitHub