Skip to content

Configuration & domains

The rule: no domain, account ID, region, or resource name appears in application code. The placeholder domain frond.cntnus.app will be replaced by the real brand domain — that change is pure configuration, no code changes.

Layers of configuration

LayerFileConsumers
Environmentsinfra/config/environments.jsonCDK (infrastructure)
Accountsinfra/config/accounts.jsonCDK (deploy targets)
Runtime configconfig.json injected into each site’s S3 bucket at deploythe canvas app, marketing links
Schema + loaderpackages/configall frontends
Lambda env varsset by infra/lib/stacks/api-stack.tsservices/api
CI/CD context-c githubConnectionArn, -c githubRepo at pipeline deployinfra/bin/pipeline.ts

environments.json

{
"prod": {
"account": "prod",
"productName": "Frond",
"zoneDomain": "frond.cntnus.app",
"appDomain": "app.frond.cntnus.app",
"wwwDomain": "frond.cntnus.app",
"wwwAliases": ["www.frond.cntnus.app"],
"docsDomain": "docs.frond.cntnus.app",
"apiDomain": "api.frond.cntnus.app",
"authDomain": "auth.frond.cntnus.app",
"authDisabled": false,
"features": { "publishing": true, "collaboration": false }
}
}

Runtime config.json

Rendered per environment by the CDK and uploaded next to the app bundle:

{
"version": 1,
"environment": "dev",
"productName": "Frond",
"auth": { "region": "us-east-1", "userPoolId": "…", "userPoolClientId": "…",
"issuer": "https://auth.dev.frond.cntnus.app",
"redirectUri": "https://dev.frond.cntnus.app/callback",
"scopes": ["openid", "email", "profile"] },
"api": { "baseUrl": "https://api.dev.frond.cntnus.app" },
"storage": { "region": "us-east-1", "bucket": "…" },
"links": { "app": "https://dev.frond.cntnus.app", "www": "…", "docs": "…", "api": "…" },
"features": { "publishing": true, "collaboration": false }
}

The app loads it at startup (window.__FROND_CONFIG__ takes precedence, for embedding). The same file drives the marketing site’s links — so one build artifact deploys to all three environments; only the injected JSON differs.

Rebranding / domain change checklist

  1. Update infra/config/environments.json (new domains).
  2. Redeploy each environment (CDK recreates certificates and DNS records in the env’s hosted zone; NS delegation for the new zone is a one-time manual step in the parent zone — see Deployment).
  3. Re-point the Cognito hosted-UI callback URLs (CDK regenerates them from appDomain).
  4. That’s it — no application code changes.

Secret management

There are deliberately no secrets in the repo. The only sensitive deploy-time inputs are the GitHub CodeStar connection ARN (passed via CDK context / env var) and optional alert email addresses (CDK context). If secrets are ever needed, they go to Secrets Manager / SSM Parameter Store and are read by the Lambda via IAM, never via environment values checked in.