Test adding ssl certificate

This commit is contained in:
Khalim Conn-Kowlessar 2023-07-17 11:24:42 +01:00
parent fab6cf0d39
commit fc3c64a3f9

View file

@ -0,0 +1,43 @@
resource "aws_route53_zone" "my_hosted_zone" {
name = var.domain_name
}
# Request an SSL certificate for the domain
resource "aws_acm_certificate" "my_certificate_request" {
domain_name = var.domain_name
subject_alternative_names = ["*.{var.domain_name}"]
validation_method = "DNS"
tags = {
Name : var.domain_name
}
lifecycle {
create_before_destroy = true
}
}
# Create a DNS record to prove that we own the domain
resource "aws_route53_record" "my_validation_record" {
zone_id = aws_route53_zone.my_hosted_zone.zone_id
name = aws_acm_certificate.my_certificate_request.domain_validation_options.0.resource_record_name
type = aws_acm_certificate.my_certificate_request.domain_validation_options.0.resource_record_type
records = [aws_acm_certificate.my_certificate_request.domain_validation_options.0.resource_record_value]
ttl = var.ttl
}
resource "aws_acm_certificate_validation" "my_certificate_validation" {
certificate_arn = aws_acm_certificate.my_certificate_request.arn
validation_record_fqdns = [aws_route53_record.my_validation_record.fqdn]
}
resource "aws_route53_record" "my_caa_record" {
zone_id = aws_route53_zone.my_hosted_zone.zone_id
name = var.domain_name
type = "CAA"
records = [
"0 issue \"amazon.com\"",
"0 issuewild \"amazon.com\""
]
ttl = var.ttl
}