From 23c4024cea12dd52de774f2151f6503ab82a58bb Mon Sep 17 00:00:00 2001 From: Colin Saliceti <8416694+saliceti@users.noreply.github.com> Date: Thu, 24 Sep 2026 15:09:39 +0100 Subject: [PATCH] Fix front door domain logic for non apex domains https://github.com/NHSDigital/dtos-devops-templates/pull/319 fixed the log for apex domains, but broke non-apex domains. It incorrectly generated the _dnsauth record with the DNS zone suffix, like _dnsauth.pr-2177.review.run-breast-screening.nhs.uk Fix the domain so it is simply like: _dnsauth.pr-2177.review --- infrastructure/modules/cdn-frontdoor-endpoint/dns.tf | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/infrastructure/modules/cdn-frontdoor-endpoint/dns.tf b/infrastructure/modules/cdn-frontdoor-endpoint/dns.tf index 1d3fdf38..39432ff3 100644 --- a/infrastructure/modules/cdn-frontdoor-endpoint/dns.tf +++ b/infrastructure/modules/cdn-frontdoor-endpoint/dns.tf @@ -31,8 +31,13 @@ resource "azurerm_dns_txt_record" "challenge" { for_each = { for k, v in var.custom_domains : k => v if v.tls.certificate_type == "ManagedCertificate" } # If the host name is the same as the zone name, then it's the apex domain - # Apex domain requires _dnsauth. Subdomains require _dnsauth.. - name = each.value.host_name == each.value.dns_zone_name ? "_dnsauth" : "_dnsauth.${each.value.host_name}" + # Apex domain requires _dnsauth. Subdomains require _dnsauth. + # The subdomain is the host name without the zone name suffix + name = ( + each.value.host_name == each.value.dns_zone_name ? + "_dnsauth" : + "_dnsauth.${replace(each.value.host_name, ".${each.value.dns_zone_name}", "")}" + ) zone_name = each.value.dns_zone_name resource_group_name = each.value.dns_zone_rg_name ttl = 60