Certificate Manager (ACM)
AWS Certificate Manager (ACM) issues the TLS certificates that let your application serve HTTPS. ACM proves you own a domain by checking a DNS record, and it renews the certificate on its own as long as that record stays in place.
The Byks module creates and validates certificates for you when you use ecs_services or cloudfront_distributions, and the ALB module does the same through acm_config. You only need a certificate of your own for resources you set up outside those modules, for example an extra listener certificate on a shared ALB, or a CloudFront distribution you manage yourself.
Terraform configuration
Create a standalone certificate with the terraform-aws-acm-route53 module. Each instance of the module creates one certificate for one primary domain and any alternate domains. It also writes the DNS validation records to Route53 and waits until ACM has issued the certificate. Use the certificate_arn output wherever you need the certificate, for example on an ALB listener.
The module needs two AWS providers. Pass the provider for the account and region the certificate belongs in as aws, and the provider for the account that holds the Route53 hosted zones as aws.route53. Most Terraform Infrastruktur-repos already define the aws.route53 provider in route53_provider.tf.
module "service_certificate" {
source = "git@github.com:BYM-IKT/terraform-aws-acm-route53.git?ref=v3"
primary_domain = {
dns_record = "kattehotell-api.test.bymoslo.net"
route53_domain = data.aws_route53_zone.route53_zone.name
}
# options go here
providers = {
aws = aws
aws.route53 = aws.route53
}
}
Certificates for CloudFront
CloudFront only accepts certificates from the us-east-1 region. For a CloudFront certificate, pass a provider configured for us-east-1 as aws, for example aws = aws.us-east-1.
Options
| Option | Type | Default | Description |
|---|---|---|---|
alternate_domains |
map(string) |
{} |
Extra domains to add to the certificate. Each key is a domain name, and each value is the Route53 hosted zone that domain belongs to, for example { "kattehotell.test.bymoslo.net" = "test.bymoslo.net" }. Every hosted zone must exist in the aws.route53 account. |
alarm_topic_arn |
string |
null |
ARN of an SNS topic that gets a CloudWatch alarm when the certificate has less than 30 days left before it expires. ACM normally renews certificates well before that point, so an alarm means renewal has failed. With null, the module creates no alarm. |
primary_domain |
object |
required | The certificate's main domain and the hosted zone it belongs to. See Primary domain object. |
Primary domain object
Used in primary_domain.
| Option | Type | Default | Description |
|---|---|---|---|
dns_record |
string |
required | The domain name the certificate is for, for example kattehotell-api.test.bymoslo.net. |
route53_domain |
string |
required | The Route53 hosted zone that dns_record belongs to, for example test.bymoslo.net. The zone must exist in the aws.route53 account. |
Outputs
| Output | Description |
|---|---|
certificate_arn |
ARN of the issued certificate. Terraform only returns it after validation completes. |
Alternate domains in the first apply
When you set alternate_domains, the first terraform apply can fail with an error saying acm_certificate_domain_validation_options is known only after apply. Apply the inner certificate module first with -target, for example terraform apply -target module.service_certificate.module.acm, then run a full apply.
Resources
-
AWS documentation
Official AWS documentation for ACM