Skip to content

Certificate Manager (ACM)

AWS Certificate Manager (ACM) issues the TLS certificates that let your application serve HTTPS. ACM proves you own a domain by checking a DNS record, and it renews the certificate on its own as long as that record stays in place.

The Byks module creates and validates certificates for you when you use ecs_services or cloudfront_distributions, and the ALB module does the same through acm_config. You only need a certificate of your own for resources you set up outside those modules, for example an extra listener certificate on a shared ALB, or a CloudFront distribution you manage yourself.

Terraform configuration

Create a standalone certificate with the terraform-aws-acm-route53 module. Each instance of the module creates one certificate for one primary domain and any alternate domains. It also writes the DNS validation records to Route53 and waits until ACM has issued the certificate. Use the certificate_arn output wherever you need the certificate, for example on an ALB listener.

The module needs two AWS providers. Pass the provider for the account and region the certificate belongs in as aws, and the provider for the account that holds the Route53 hosted zones as aws.route53. Most Terraform Infrastruktur-repos already define the aws.route53 provider in route53_provider.tf.

acm.tf
module "service_certificate" {
  source = "git@github.com:BYM-IKT/terraform-aws-acm-route53.git?ref=v3"
  primary_domain = {
    dns_record     = "kattehotell-api.test.bymoslo.net"
    route53_domain = data.aws_route53_zone.route53_zone.name
  }
  # options go here

  providers = {
    aws         = aws
    aws.route53 = aws.route53
  }
}

Certificates for CloudFront

CloudFront only accepts certificates from the us-east-1 region. For a CloudFront certificate, pass a provider configured for us-east-1 as aws, for example aws = aws.us-east-1.

Options

Option Type Default Description
alternate_domains map(string) {} Extra domains to add to the certificate. Each key is a domain name, and each value is the Route53 hosted zone that domain belongs to, for example { "kattehotell.test.bymoslo.net" = "test.bymoslo.net" }. Every hosted zone must exist in the aws.route53 account.
alarm_topic_arn string null ARN of an SNS topic that gets a CloudWatch alarm when the certificate has less than 30 days left before it expires. ACM normally renews certificates well before that point, so an alarm means renewal has failed. With null, the module creates no alarm.
primary_domain object required The certificate's main domain and the hosted zone it belongs to. See Primary domain object.

Primary domain object

Used in primary_domain.

Option Type Default Description
dns_record string required The domain name the certificate is for, for example kattehotell-api.test.bymoslo.net.
route53_domain string required The Route53 hosted zone that dns_record belongs to, for example test.bymoslo.net. The zone must exist in the aws.route53 account.

Outputs

Output Description
certificate_arn ARN of the issued certificate. Terraform only returns it after validation completes.

Alternate domains in the first apply

When you set alternate_domains, the first terraform apply can fail with an error saying acm_certificate_domain_validation_options is known only after apply. Apply the inner certificate module first with -target, for example terraform apply -target module.service_certificate.module.acm, then run a full apply.

Resources