Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add digitransit subscription key #95

Merged
merged 6 commits into from
Jun 15, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 14 additions & 13 deletions main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -139,19 +139,20 @@ resource "azurerm_key_vault_secret" "mongo_db_connection_string" {
}

module "web" {
source = "./modules/web"
resource_group_location = local.resource_group_location
resource_group_name = module.common.resource_group_name
app_service_plan_id = module.common.tikweb_app_plan_id
acme_account_key = module.common.acme_account_key
root_zone_name = module.dns_prod.root_zone_name
dns_resource_group_name = module.dns_prod.resource_group_name
subdomain = "@"
mongo_connection_string = module.mongodb.db_connection_string
google_oauth_client_id = module.keyvault.google_oauth_client_id
google_oauth_client_secret = module.keyvault.google_oauth_client_secret
public_ilmo_url = "https://${module.ilmo.fqdn}"
public_legacy_url = "https://tietokilta.fi"
source = "./modules/web"
resource_group_location = local.resource_group_location
resource_group_name = module.common.resource_group_name
app_service_plan_id = module.common.tikweb_app_plan_id
acme_account_key = module.common.acme_account_key
root_zone_name = module.dns_prod.root_zone_name
dns_resource_group_name = module.dns_prod.resource_group_name
subdomain = "@"
mongo_connection_string = module.mongodb.db_connection_string
google_oauth_client_id = module.keyvault.google_oauth_client_id
google_oauth_client_secret = module.keyvault.google_oauth_client_secret
public_ilmo_url = "https://${module.ilmo.fqdn}"
public_legacy_url = "https://tietokilta.fi"
digitransit_subscription_key = module.keyvault.digitransit_subscription_key
}
resource "azurerm_key_vault_secret" "cms_password" {
name = "cms-password"
Expand Down
6 changes: 6 additions & 0 deletions modules/keyvault/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,12 @@ resource "azurerm_key_vault_access_policy" "admin" {

}

data "azurerm_key_vault_secret" "digitransit_subscription_key" {
name = "digitransit-subscription-key"
key_vault_id = azurerm_key_vault.keyvault.id
depends_on = [azurerm_key_vault_access_policy.admin, azurerm_key_vault_access_policy.CI]
}

data "azurerm_key_vault_secret" "ilmo_auth_jwt_secret" {
name = "ilmo-auth-jwt-secret"
key_vault_id = azurerm_key_vault.keyvault.id
Expand Down
5 changes: 5 additions & 0 deletions modules/keyvault/output.tf
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,11 @@ output "keyvault_id" {
value = azurerm_key_vault.keyvault.id
}

output "digitransit_subscription_key" {
value = data.azurerm_key_vault_secret.digitransit_subscription_key.value
sensitive = true
}

output "ilmo_auth_jwt_secret" {
value = data.azurerm_key_vault_secret.ilmo_auth_jwt_secret.value
sensitive = true
Expand Down
15 changes: 8 additions & 7 deletions modules/web/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -59,13 +59,14 @@ resource "azurerm_linux_web_app" "web" {
}
https_only = true
app_settings = {
NODE_ENVIRONMENT = "production"
PUBLIC_ILMOMASIINA_URL = var.public_ilmo_url
WEBSITES_PORT = 3000
PORT = 3000
NEXT_REVALIDATION_KEY = random_password.revalidation_key.result
PUBLIC_SERVER_URL = "https://${azurerm_linux_web_app.cms.default_hostname}"
PUBLIC_LEGACY_URL = var.public_legacy_url
NODE_ENVIRONMENT = "production"
PUBLIC_ILMOMASIINA_URL = var.public_ilmo_url
WEBSITES_PORT = 3000
PORT = 3000
NEXT_REVALIDATION_KEY = random_password.revalidation_key.result
PUBLIC_SERVER_URL = "https://${azurerm_linux_web_app.cms.default_hostname}"
PUBLIC_LEGACY_URL = var.public_legacy_url
DIGITRANSIT_SUBSCRIPTION_KEY = var.digitransit_subscription_key
}
}
resource "random_password" "payload_secret" {
Expand Down
5 changes: 5 additions & 0 deletions modules/web/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -49,3 +49,8 @@ variable "public_ilmo_url" {
variable "public_legacy_url" {
type = string
}

variable "digitransit_subscription_key" {
type = string
sensitive = true
}
Loading