瀏覽代碼

Merge pull request #207 from mdr-engineering/feature/ftd_MSOCI-1590_DNSSEC

Enables DNSSEC for xdr.accenturefederalcyber.com
Frederick Damstra 4 年之前
父節點
當前提交
89e9f98a74
共有 1 個文件被更改,包括 2 次插入7 次删除
  1. 2 7
      base/dns/public_dns/dnssec.tf

+ 2 - 7
base/dns/public_dns/dnssec.tf

@@ -1,6 +1,5 @@
 locals {
-  domains_to_secure = toset([ "accenturefederalcyber.net", "xdrtest.accenturefederalcyber.net", "accenturefederalcyber.com", "xdrtest.accenturefederalcyber.com" ]) # for testing
-  #domains_to_secure = var.hosted_public_dns_zones
+  domains_to_secure = toset(var.hosted_public_dns_zones)
 }
 
 resource "aws_kms_key" "dnssec" {
@@ -117,11 +116,7 @@ resource "aws_route53_hosted_zone_dnssec" "dnssec" {
 }
 
 resource "aws_route53_record" "ds" {
-  #for_each = local.domains_with_parents
-  for_each = { 
-    "xdrtest.accenturefederalcyber.net" = "accenturefederalcyber.net",
-    "xdrtest.accenturefederalcyber.com" = "accenturefederalcyber.com",
-  }
+  for_each = local.domains_with_parents
 
   allow_overwrite = true
   name            = each.key