Skip to content

saif-web-service

This module deploys a frontend web application to Azure App Service.

ℹ️ Authentication Note

This module deploys static web applications that do not handle authentication directly. Authentication for frontend applications is managed by:

  • Corporate users (internal): Authenticated via Entra ID at the API gateway or backend level
  • External users: Authenticated via Okta at the API gateway or backend level

The Tenant variable in this module refers to the Azure infrastructure tenant (Corporate/External subscriptions) for resource naming and deployment targeting, not the authentication provider.

Providers

No providers.

Inputs

Name Description Type Default Required
application_name The name of the application string n/a yes
application_settings Settings for your application map(string) {} no
create_staging_slot Whether to create a staging slot for the web app bool false no
custom_subdomain Custom subdomain to attach this app to (e.g., 'myapp' for myapp.saif.com). The custom subdomain must be created in azure.terraform first. Empty string disables custom domain routing. string "" no
deployed_by Identifier for the deployment mechanism (e.g. Terraform, GitHub Actions) string "Terraform" no
enable_health_check Whether to enable the App Service health check. Defaults to true. Set to false to opt out. bool true no
environment The environment in which the resources are deployed string n/a yes
environment_short_name The short name of the environment string null no
has_backend_api Whether the application has a backend API. When true, APP_BACKEND_URL is included in app settings and the API namer module is created. bool true no
health_check_path App Service health check path. Defaults to '/{application_name}' for subpath-routed apps, or '/' when is_root_path = true. Override if the app exposes a different probe endpoint. string null no
is_external_app Is this an external application bool false no
is_production Is this a production environment bool n/a yes
is_root_path When custom_subdomain is set, determines the path: true for root (myapp.saif.com), false for subpath matching application name (myapp.saif.com/appname). When false, the subpath is automatically set to /application_name. bool false no
minimum_tls_version Minimum TLS version for the web app. Defaults to 1.2 (Forge standard). string "1.2" no
owner The name of the team that owns the resources string n/a yes
project_id The id of the project. This will be used to name the resources. string n/a yes
resource_location The location the resources will be deployed to. string "westus2" no
tags A map of tags to be applied to resources in the module map(string) n/a yes
tenant Deprecated — the Azure infra tenant is fixed to local.azure_tenant ("Corporate"). Retained for backward compatibility with callers (e.g. the HCP Terraform Okta variable set injecting tenant = "ext") but ignored by this module. string "Corporate" no

Outputs

No outputs.

Resources


View source on GitHub