| access_logs |
Enable access logs for S3 buckets, requires log_bucket variable to be set |
bool |
false |
no |
| additional_dynamodb_tags |
Tags added to DynamoDB tables, merged with default tags |
map(string) |
{} |
no |
| additional_lambda_tags |
Tags added to Lambda functions, merged with default tags |
map(string) |
{} |
no |
| additional_s3_tags |
Tags added to S3 buckets, merged with default tags |
map(string) |
{} |
no |
| aws_principals |
List of ARNs for AWS principals allowed to assume DynamoDB reader role or execute the tls_cert lambda |
list(string) |
[] |
no |
| blocked_encryption_types |
Server side encryption types to block on S3 buckets, currently AWS supports SSE-C only. Set to [] to allow all encryption types |
list(string) |
[ "SSE-C" ] |
no |
| bucket_key_enabled |
Whether or not to use Amazon S3 Bucket Keys for SSE-KMS |
bool |
false |
no |
| bucket_prefix |
First part of s3 bucket name to ensure uniqueness, if left blank a random suffix will be used instead |
string |
"" |
no |
| cert_info_files |
List of file names to be uploaded to internal S3 bucket for processing |
list(string) |
[] |
no |
| cloudfront_geo_restricted_locations |
List of countries to block from CloudFront Distribution |
list(string) |
[ "CN", "IR", "KP", "RU" ] |
no |
| cloudfront_minimum_protocol_version |
CloudFront minimum TLS protocol version |
string |
"TLSv1.2_2021" |
no |
| cloudfront_web_acl_id |
WAF attachment for the public CRL CloudFront distribution, expects the WAF ARN |
string |
null |
no |
| csr_files |
List of CSR file names to be uploaded to internal S3 bucket for processing |
list(string) |
[] |
no |
| custom_extension_allowlist |
List of X.509 extension OIDs callers may include via the 'extensions' field when requesting a TLS certificate. Empty by default, which disables the feature. Extensions the CA emits itself (basicConstraints, keyUsage, subjectAltName, extendedKeyUsage, etc.) are always rejected regardless of this list. |
list(string) |
[] |
no |
| custom_sns_topic_display_name |
Customised SNS topic display name, leave empty to use standard naming convention |
string |
"" |
no |
| custom_sns_topic_name |
Customised SNS topic name, leave empty to use standard naming convention |
string |
"" |
no |
| default_aws_kms_key_for_s3 |
Use default AWS KMS key instead of customer managed key for S3 bucket encryption. Applicable only if "sse_algorithm" is "aws:kms" |
bool |
false |
no |
| dynamodb_deletion_protection |
Enable deletion protection for the DynamoDB table |
bool |
false |
no |
| env |
Environment name, e.g. dev |
string |
"dev" |
no |
| existing_slack_secret_name |
Name of an existing AWS Secrets Manager secret containing the Slack OAuth token, owned by another CA deployment in the same AWS account and region. Secrets Manager secrets are regional and are looked up in the provider region, so a deployment in another region needs its own secret, or a replica of this one. When set, this deployment uses the existing secret and doesn't create its own, so the token only needs to be uploaded once per region |
string |
"" |
no |
| expiry_reminders |
List of days before certificate expiry to send reminder notifications, set to empty list to disable expiry reminders |
list(number) |
[ 30, 15, 7, 1 ] |
no |
| external_s3_bucket_name |
Name of an existing external S3 bucket for CRL and CA certificate publication, owned by another CA deployment in the same AWS account. When set, this deployment publishes its (project-prefixed) CRL and certificate files to the shared bucket and does not create its own external S3 bucket, CloudFront distribution, TLS certificate or DNS record |
string |
"" |
no |
| filter_pattern |
Filter pattern for CloudWatch logs subscription filter |
string |
"" |
no |
| hosted_zone_domain |
Hosted zone domain, e.g. dev.ca.example.com |
string |
"" |
no |
| hosted_zone_id |
Hosted zone ID for public zone, e.g. Z0123456XXXXXXXXXXX |
string |
"" |
no |
| issuing_ca_info |
Issuing CA certificate information |
object({ commonName = string country = optional(string) state = optional(string) lifetime = optional(number) locality = optional(string) organization = optional(string) organizationalUnit = optional(string) emailAddress = optional(string) pathLengthConstraint = optional(number) }) |
{ "commonName": "Serverless Issuing CA", "country": "GB", "emailAddress": null, "lifetime": 3650, "locality": "London", "organization": "Serverless", "organizationalUnit": "IT", "pathLengthConstraint": null, "state": "London" } |
no |
| issuing_ca_key_spec |
Issuing CA key specification |
string |
"ECC_NIST_P256" |
no |
| issuing_crl_days |
Number of days before Issuing CA CRL expires, in addition to seconds. Must be greater than or equal to Step Function interval |
number |
1 |
no |
| issuing_crl_seconds |
Number of seconds before Issuing CA CRL expires, in addition to days. Used for overlap in case of clock skew |
number |
600 |
no |
| kms_arn_resource |
KMS key ARN used for general resource encryption, different from key used for CA key protection |
string |
"" |
no |
| kms_key_alias |
KMS key alias for bucket encryption with key rotation disabled, if left at default, TLS key gen KMS key will be used |
string |
"" |
no |
| log_bucket |
Name of log bucket, if access_logs variable set to true |
string |
"" |
no |
| logging_account_id |
AWS Account ID of central logging account for CloudWatch subscription filters |
string |
"" |
no |
| max_cert_lifetime |
Maximum end entity certificate lifetime in days |
number |
365 |
no |
| memory_size |
Standard memory allocation for Lambda functions |
number |
128 |
no |
| prod_envs |
List of production environment names, for these names the environment name suffix is not required in resource names |
list(string) |
[ "prd", "prod" ] |
no |
| project |
abbreviation for the project, forms first part of resource names |
string |
"serverless" |
no |
| public_crl |
Whether to make the CRL and CA certificates publicly available |
bool |
false |
no |
| root_ca_info |
Root CA certificate information |
object({ commonName = string country = optional(string) state = optional(string) lifetime = optional(number) locality = optional(string) organization = optional(string) organizationalUnit = optional(string) emailAddress = optional(string) pathLengthConstraint = optional(number) }) |
{ "commonName": "Serverless Root CA", "country": "GB", "emailAddress": null, "lifetime": 7300, "locality": "London", "organization": "Serverless", "organizationalUnit": "IT", "pathLengthConstraint": null, "state": "London" } |
no |
| root_ca_key_spec |
Root CA key specification |
string |
"ECC_NIST_P384" |
no |
| root_crl_days |
Number of days before Root CA CRL expires, in addition to seconds. Must be greater than or equal to Step Function interval |
number |
1 |
no |
| root_crl_seconds |
Number of seconds before Root CA CRL expires, in addition to days. Used for overlap in case of clock skew |
number |
600 |
no |
| runtime |
Lambda language runtime. Defaults to the python-version in repo and can be overridden. |
string |
"" |
no |
| s3_aws_principals |
List of AWS Principals to allow access to external S3 bucket |
list(string) |
[] |
no |
| schedule_expression |
Step function schedule in cron format, must be daily or more frequent for expiry reminders to work correctly, interval should be same as issuing_crl_days |
string |
"cron(15 8 * * ? *)" |
no |
| secret_recovery_window_in_days |
Number of days that AWS Secrets Manager waits before deleting a secret |
number |
7 |
no |
| slack_bad_emoji |
Slack emoji for bad events |
string |
":octagonal_sign:" |
no |
| slack_channels |
List of Slack Channels |
list(string) |
[] |
no |
| slack_good_emoji |
Slack emoji for good events |
string |
":white_check_mark:" |
no |
| slack_token |
Slack App OAuth token |
string |
"" |
no |
| slack_username |
Slack username appearing in the from field in the Slack message |
string |
"Serverless CA" |
no |
| slack_warning_emoji |
Slack emoji for warning events |
string |
":warning:" |
no |
| sns_email_subscriptions |
List of email addresses to subscribe to SNS topic |
list(string) |
[] |
no |
| sns_lambda_subscriptions |
A map of lambda names to arns to subscribe to SNS topic |
map(string) |
{} |
no |
| sns_policy |
A string containing the SNS policy, if used |
string |
"" |
no |
| sns_policy_template |
Name of SNS policy template file, if used |
string |
"default" |
no |
| sns_sqs_subscriptions |
A map of SQS names to arns to subscribe to the SNS topic |
map(string) |
{} |
no |
| sse_algorithm |
Server side encryption algorithm for internal S3 bucket object upload |
string |
"" |
no |
| subscription_filter_destination |
CloudWatch log subscription filter destination, last section of ARN |
string |
"" |
no |
| tags |
see also additional_s3_tags, additional_dynamodb_tags, additional_lambda_tags |
map(string) |
{} |
no |
| timeout |
Amount of time Lambda Function has to run in seconds |
number |
180 |
no |
| workload_account_id |
Workload account ID allowed to subscribe to SNS topic if cross-account policy used |
string |
"" |
no |
| xray_enabled |
Whether to enable active tracing with AWS X-Ray |
bool |
true |
no |