Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 6 additions & 4 deletions terraform/environments/aws/github-dev.tfvars
Original file line number Diff line number Diff line change
Expand Up @@ -25,11 +25,13 @@ lambda_log_retention_days = 7
# Function URL auth_type is derived from enable_cdn (local in compute.tf):
# enable_cdn = false -> NONE (direct browser hits, app-layer auth)
# enable_cdn = true -> AWS_IAM (CloudFront OAC signs every request)
# Current deployed dev origin (Lambda Function URL) + local Webpack dev server.
# After applying with enable_cdn = true, replace this list with:
# - the CloudFront domain from `terraform output cloudfront_domain_name`
# (e.g. "https://d1234abcd.cloudfront.net"), or the custom domain name
# set in TF_VAR_frontend_domain_names if one is configured.
# - keep http://localhost:3000 for local dev server.
# Wildcard is rejected by the module (allow_credentials=true + * = any-origin CSRF).
# Update the Lambda Function URL entry when the dev environment is redeployed.
lambda_allowed_origins = [
"https://33pz7pombdqwu3bdlxp4lqxyra0bsriy.lambda-url.us-east-1.on.aws",
"http://localhost:3000",
]

Expand Down Expand Up @@ -71,7 +73,7 @@ secret_recovery_window_days = 7
# Frontend / CDN
# ==============================================

enable_cdn = false
enable_cdn = true
frontend_price_class = "PriceClass_100"
create_subdomain_zone = false

Expand Down
13 changes: 8 additions & 5 deletions terraform/environments/aws/github-prod.tfvars
Original file line number Diff line number Diff line change
Expand Up @@ -25,10 +25,13 @@ lambda_log_retention_days = 30
# Function URL auth_type is derived from enable_cdn (local in compute.tf):
# enable_cdn = false -> NONE (direct browser hits, app-layer auth)
# enable_cdn = true -> AWS_IAM (CloudFront OAC signs every request)
# TODO(env-not-deployed): prod environment is not yet provisioned. Update this
# to the actual prod origin (e.g. the customer-facing dashboard domain) when
# the env exists. .invalid placeholder ensures any accidental apply fails fast
# on hostname resolution.
# Prod is not yet provisioned. Before the first terraform apply:
# 1. Replace the .invalid placeholder with the actual prod CloudFront domain
# (from `terraform output cloudfront_domain_name` after apply), or the
# customer-facing custom domain set in TF_VAR_frontend_domain_names.
# 2. Set TF_VAR_frontend_domain_names to the customer-facing domain (e.g.
# "app.cudly.io") so the CloudFront distribution aliases are correct.
# The .invalid TLD ensures any accidental apply fails fast on hostname resolution.
lambda_allowed_origins = ["https://prod-not-yet-deployed.invalid"]

# Fargate Configuration (when compute_platform = "fargate")
Expand Down Expand Up @@ -70,7 +73,7 @@ secret_recovery_window_days = 30
# Frontend / CDN
# ==============================================

enable_cdn = false
enable_cdn = true
frontend_price_class = "PriceClass_200"
create_subdomain_zone = false

Expand Down
11 changes: 7 additions & 4 deletions terraform/environments/aws/github-staging.tfvars
Original file line number Diff line number Diff line change
Expand Up @@ -25,9 +25,12 @@ lambda_log_retention_days = 14
# Function URL auth_type is derived from enable_cdn (local in compute.tf):
# enable_cdn = false -> NONE (direct browser hits, app-layer auth)
# enable_cdn = true -> AWS_IAM (CloudFront OAC signs every request)
# TODO(env-not-deployed): staging environment is not yet provisioned. Update this
# to the actual staging origin when the env exists. Until then the .invalid TLD
# ensures any accidental terraform apply fails fast on hostname resolution.
# Staging is not yet provisioned. Before the first terraform apply:
# 1. Replace the .invalid placeholder with the actual staging CloudFront
# domain (from `terraform output cloudfront_domain_name` after apply),
# or the custom domain set in TF_VAR_frontend_domain_names.
# 2. Keep http://localhost:3000 for local dev server access.
# The .invalid TLD ensures any accidental apply fails fast on hostname resolution.
lambda_allowed_origins = ["https://staging-not-yet-deployed.invalid"]

# Fargate Configuration (when compute_platform = "fargate")
Expand Down Expand Up @@ -69,7 +72,7 @@ secret_recovery_window_days = 14
# Frontend / CDN
# ==============================================

enable_cdn = false
enable_cdn = true
frontend_price_class = "PriceClass_100"
create_subdomain_zone = false

Expand Down
Loading