Skip to content

feat(infra): let Terraform adopt the zone Route 53 Domains creates - #390

Merged
nourshoreibah merged 4 commits into
mainfrom
feat/route53-registered-zone
Aug 30, 2026
Merged

nourshoreibah merged 4 commits into
mainfrom
feat/route53-registered-zone

Conversation

@nourshoreibah

Copy link
Copy Markdown
Collaborator

Follow-up to #388. We're keeping everything in AWS, which means registering
branchaccounting.com through Route 53 Domains — and that breaks an
assumption dns.tf was making.

The problem

Registering a domain in Route 53 Domains automatically creates a hosted zone
for it and points the domain's nameservers at that zone. dns.tf unconditionally
created its own:

resource "aws_route53_zone" "app" {
  count = local.create_dns ? 1 : 0
  name  = var.app_domain
}

So buying the domain inside AWS would leave two hosted zones for one name,
each with a different set of nameservers. Terraform would happily write the ACM
validation records, the SES DKIM CNAMEs, SPF and DMARC into its zone, while the
registrar kept pointing the world at the other one.

The failure mode is nasty because nothing looks wrong: the plan is clean, every
record shows as created, the SES console says "pending verification" forever, and
public lookups return NXDOMAIN. You would be debugging DKIM propagation while the
actual problem is that the records are in a zone nobody queries.

The fix

var.use_existing_hosted_zone selects where the zone comes from:

value behaviour when
false (default) creates aws_route53_zone.app domain registered elsewhere, NS set by hand at the registrar
true reads it via data.aws_route53_zone.app domain registered through Route 53 Domains

Both feed two new locals — local.zone_id and local.zone_name_servers — and
every record in dns.tf and email.tf now goes through local.zone_id instead
of reaching for aws_route53_zone.app[0] directly. The
app_domain_nameservers output reads local.zone_name_servers, so it keeps
working in both modes (and is simply informational in the Route 53 case, since
the registrar already points at the right zone).

Adopting rather than importing is deliberate. There is no Terraform resource
that registers a domain, so the registration and its zone get created outside
this module no matter what. A data source states that honestly; an import block
would claim the module owns a zone it did not create and would put zone deletion
on the table during a destroy.

Also corrected

The app_domain variable's comment and description both described "a subdomain
delegated to Route 53 from the registrar" and used accounting.branchinitiative.com
as the example. Neither matches the plan any more — branchaccounting.com is an
apex, registered in AWS. Updated to match.

Verification

  • terraform fmt -check -recursive clean, terraform validate passes

  • Gating checked with terraform console across all three states — the two zone
    flags are mutually exclusive and never both true:

    app_domain use_existing_hosted_zone create_zone lookup_zone
    "" — false false
    set false true false
    set true false true
  • Derived values resolve correctly for the real domain: no-reply@branchaccounting.com,
    mail.branchaccounting.com, api.branchaccounting.com, and both DMARC forms
    (v=DMARC1; p=none; and with rua=mailto:…)

  • Applies as a no-op today — app_domain is still ""

🤖 Generated with Claude Code

Registering a domain through Route 53 Domains creates a hosted zone for it
automatically and points the domain's nameservers at that zone. `dns.tf`
unconditionally created its own `aws_route53_zone.app`, so buying the domain
inside AWS -- the plan for branchaccounting.com -- would leave two zones for one
name with different nameservers. Records would be written to the Terraform zone
while resolution followed the registrar's, and every lookup would return
NXDOMAIN with nothing in the plan output looking wrong.

`var.use_existing_hosted_zone` picks the source: false keeps the current
behaviour of creating the zone, true reads the existing one through
`data.aws_route53_zone.app`. Both paths feed `local.zone_id`, which every record
in dns.tf and email.tf now uses instead of reaching for the resource, and
`local.zone_name_servers` behind the `app_domain_nameservers` output.

Adopting rather than importing keeps the zone owned by whoever created it: there
is no Terraform resource that registers a domain, so the registration and its
zone are created outside this module either way, and a data source says that
without pretending the module owns them.

Also corrects the `app_domain` example and description. Both described a
subdomain delegated from an external registrar, which is no longer the intended
shape.

Locals verified with `terraform console` across all three states:

  app_domain = ""                          -> create/lookup both false
  app_domain set                           -> create true, lookup false
  app_domain set + use_existing_hosted_zone -> create false, lookup true

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
github-actions Bot added a commit that referenced this pull request Aug 30, 2026
github-actions Bot and others added 2 commits August 30, 2026 17:59
  - Auto-formatted .tf files with terraform fmt
  - Updated README.md with terraform-docs

  Co-authored-by: nourshoreibah <nourshoreibah@users.noreply.github.com>
@nourshoreibah nourshoreibah added the no-review The PR review bot won't run label Aug 30, 2026
github-actions Bot added a commit that referenced this pull request Aug 30, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Terraform Plan 📖 infrastructure/aws

Terraform Initialization ⚙️success

Terraform Validation 🤖success

Terraform Plan 📖success

Show Plan
data.archive_file.lambda_placeholder: Reading...
data.archive_file.lambda_placeholder: Read complete after 0s [id=96878a51e358033297a32b882fd5223cc95fb8a7]
data.aws_vpc.default: Reading...
aws_cloudfront_origin_access_control.frontend: Refreshing state... [id=E1ZI46GY0YEFAD]
aws_cloudfront_function.rewrite_index: Refreshing state... [id=branch-frontend-rewrite-index]
data.aws_caller_identity.current: Reading...
aws_iam_openid_connect_provider.github: Refreshing state... [id=arn:aws:iam::404813129370:oidc-provider/token.actions.githubusercontent.com]
aws_s3_bucket.reports_bucket: Refreshing state... [id=c4c-branch-generated-reports20260830181426405600000001]
aws_iam_role.lambda_role: Refreshing state... [id=branch-lambda-role]
aws_api_gateway_rest_api.branch_api: Refreshing state... [id=btt3bl5139]
aws_cloudwatch_log_group.lambda["reports"]: Refreshing state... [id=/aws/lambda/branch-reports]
aws_cloudwatch_log_group.lambda["users"]: Refreshing state... [id=/aws/lambda/branch-users]
data.aws_caller_identity.current: Read complete after 0s [id=404813129370]
aws_cloudwatch_log_group.lambda["auth"]: Refreshing state... [id=/aws/lambda/branch-auth]
aws_cloudwatch_log_group.lambda["donors"]: Refreshing state... [id=/aws/lambda/branch-donors]
aws_cloudwatch_log_group.lambda["expenditures"]: Refreshing state... [id=/aws/lambda/branch-expenditures]
aws_cloudwatch_log_group.lambda["projects"]: Refreshing state... [id=/aws/lambda/branch-projects]
data.aws_region.current: Reading...
data.aws_region.current: Read complete after 0s [id=us-east-2]
data.infisical_secrets.rds_folder: Reading...
data.infisical_secrets.grafana_folder: Reading...
data.infisical_secrets.sentry_folder: Reading...
data.infisical_secrets.grafana_folder: Read complete after 0s
aws_s3_bucket.lambda_deployments: Refreshing state... [id=branch-lambda-deployments-404813129370]
aws_s3_bucket.frontend: Refreshing state... [id=branch-frontend-404813129370]
data.infisical_secrets.rds_folder: Read complete after 0s
data.aws_iam_policy_document.ci_preview_assume: Reading...
data.aws_iam_policy_document.ci_plan_assume: Reading...
data.aws_iam_policy_document.ci_preview_assume: Read complete after 0s [id=245163413]
data.aws_iam_policy_document.ci_plan_assume: Read complete after 0s [id=1050147292]
data.aws_iam_policy_document.ci_migrate_assume: Reading...
data.aws_iam_policy_document.ci_apply_assume: Reading...
data.aws_iam_policy_document.ci_apply_assume: Read complete after 0s [id=3235391464]
data.aws_iam_policy_document.ci_migrate_assume: Read complete after 0s [id=3606114350]
aws_api_gateway_gateway_response.cors["DEFAULT_4XX"]: Refreshing state... [id=aggr-btt3bl5139-DEFAULT_4XX]
aws_api_gateway_gateway_response.cors["DEFAULT_5XX"]: Refreshing state... [id=aggr-btt3bl5139-DEFAULT_5XX]
aws_api_gateway_resource.lambda_resources["auth"]: Refreshing state... [id=j2bjjp]
data.infisical_secrets.sentry_folder: Read complete after 0s
aws_api_gateway_resource.lambda_resources["donors"]: Refreshing state... [id=ooaugc]
aws_api_gateway_resource.lambda_resources["expenditures"]: Refreshing state... [id=x3f6cx]
aws_api_gateway_resource.lambda_resources["reports"]: Refreshing state... [id=fbius2]
aws_api_gateway_resource.lambda_resources["projects"]: Refreshing state... [id=5rlpdk]
aws_api_gateway_resource.lambda_resources["users"]: Refreshing state... [id=r6frgh]
aws_iam_role.ci_plan: Refreshing state... [id=branch-ci-plan]
aws_iam_role.ci_preview: Refreshing state... [id=branch-ci-preview]
aws_iam_role.ci_apply: Refreshing state... [id=branch-ci-apply]
aws_iam_role.ci_migrate: Refreshing state... [id=branch-ci-migrate]
aws_iam_role_policy_attachment.lambda_basic: Refreshing state... [id=branch-lambda-role/arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole]
data.aws_vpc.default: Read complete after 1s [id=vpc-0d3819d8bbb63db8c]
aws_iam_role_policy.lambda_ses_send: Refreshing state... [id=branch-lambda-role:branch-lambda-ses-send]
aws_api_gateway_resource.lambda_proxy["projects"]: Refreshing state... [id=zofyad]
aws_api_gateway_resource.lambda_proxy["reports"]: Refreshing state... [id=qpfkcg]
aws_api_gateway_resource.lambda_proxy["users"]: Refreshing state... [id=0s4etn]
aws_api_gateway_resource.lambda_proxy["auth"]: Refreshing state... [id=7tjm3k]
aws_api_gateway_resource.lambda_proxy["expenditures"]: Refreshing state... [id=2haqg7]
aws_api_gateway_resource.lambda_proxy["donors"]: Refreshing state... [id=37l1nw]
aws_api_gateway_method.lambda_methods["donors-POST"]: Refreshing state... [id=agm-btt3bl5139-ooaugc-POST]
aws_api_gateway_method.lambda_methods["users-OPTIONS"]: Refreshing state... [id=agm-btt3bl5139-r6frgh-OPTIONS]
aws_api_gateway_method.lambda_methods["users-PATCH"]: Refreshing state... [id=agm-btt3bl5139-r6frgh-PATCH]
aws_api_gateway_method.lambda_methods["reports-OPTIONS"]: Refreshing state... [id=agm-btt3bl5139-fbius2-OPTIONS]
aws_api_gateway_method.lambda_methods["expenditures-GET"]: Refreshing state... [id=agm-btt3bl5139-x3f6cx-GET]
aws_api_gateway_method.lambda_methods["auth-OPTIONS"]: Refreshing state... [id=agm-btt3bl5139-j2bjjp-OPTIONS]
aws_api_gateway_method.lambda_methods["projects-POST"]: Refreshing state... [id=agm-btt3bl5139-5rlpdk-POST]
aws_api_gateway_method.lambda_methods["projects-GET"]: Refreshing state... [id=agm-btt3bl5139-5rlpdk-GET]
aws_api_gateway_method.lambda_methods["expenditures-POST"]: Refreshing state... [id=agm-btt3bl5139-x3f6cx-POST]
aws_api_gateway_method.lambda_methods["projects-OPTIONS"]: Refreshing state... [id=agm-btt3bl5139-5rlpdk-OPTIONS]
aws_api_gateway_method.lambda_methods["expenditures-PATCH"]: Refreshing state... [id=agm-btt3bl5139-x3f6cx-PATCH]
aws_api_gateway_method.lambda_methods["expenditures-OPTIONS"]: Refreshing state... [id=agm-btt3bl5139-x3f6cx-OPTIONS]
aws_api_gateway_method.lambda_methods["donors-OPTIONS"]: Refreshing state... [id=agm-btt3bl5139-ooaugc-OPTIONS]
aws_api_gateway_method.lambda_methods["donors-GET"]: Refreshing state... [id=agm-btt3bl5139-ooaugc-GET]
aws_api_gateway_method.lambda_methods["auth-GET"]: Refreshing state... [id=agm-btt3bl5139-j2bjjp-GET]
aws_api_gateway_method.lambda_methods["users-POST"]: Refreshing state... [id=agm-btt3bl5139-r6frgh-POST]
aws_api_gateway_method.lambda_methods["reports-GET"]: Refreshing state... [id=agm-btt3bl5139-fbius2-GET]
aws_api_gateway_method.lambda_methods["auth-POST"]: Refreshing state... [id=agm-btt3bl5139-j2bjjp-POST]
aws_api_gateway_method.lambda_methods["users-GET"]: Refreshing state... [id=agm-btt3bl5139-r6frgh-GET]
aws_api_gateway_method.lambda_methods["users-DELETE"]: Refreshing state... [id=agm-btt3bl5139-r6frgh-DELETE]
aws_security_group.rds: Refreshing state... [id=sg-0fcbb6d585a94c4b9]
aws_iam_role_policy_attachment.ci_apply_admin: Refreshing state... [id=branch-ci-apply/arn:aws:iam::aws:policy/AdministratorAccess]
aws_iam_role_policy.lambda_s3_objects: Refreshing state... [id=branch-lambda-role:branch-lambda-s3-objects]
aws_s3_bucket_public_access_block.reports_bucket_public_access: Refreshing state... [id=c4c-branch-generated-reports20260830181426405600000001]
aws_iam_role_policy.ci_plan_state_lock: Refreshing state... [id=branch-ci-plan:tfstate-lock]
aws_iam_role_policy_attachment.ci_plan_readonly: Refreshing state... [id=branch-ci-plan/arn:aws:iam::aws:policy/ReadOnlyAccess]
aws_iam_role_policy.ci_preview: Refreshing state... [id=branch-ci-preview:preview-env]
aws_api_gateway_method.lambda_proxy_any["expenditures"]: Refreshing state... [id=agm-btt3bl5139-2haqg7-ANY]
aws_api_gateway_method.lambda_proxy_any["reports"]: Refreshing state... [id=agm-btt3bl5139-qpfkcg-ANY]
aws_api_gateway_method.lambda_proxy_any["users"]: Refreshing state... [id=agm-btt3bl5139-0s4etn-ANY]
aws_api_gateway_method.lambda_proxy_any["auth"]: Refreshing state... [id=agm-btt3bl5139-7tjm3k-ANY]
aws_api_gateway_method.lambda_proxy_any["donors"]: Refreshing state... [id=agm-btt3bl5139-37l1nw-ANY]
aws_api_gateway_method.lambda_proxy_any["projects"]: Refreshing state... [id=agm-btt3bl5139-zofyad-ANY]
aws_api_gateway_method.cors_proxy_options["auth"]: Refreshing state... [id=agm-btt3bl5139-7tjm3k-OPTIONS]
aws_api_gateway_method.cors_proxy_options["donors"]: Refreshing state... [id=agm-btt3bl5139-37l1nw-OPTIONS]
aws_api_gateway_method.cors_proxy_options["expenditures"]: Refreshing state... [id=agm-btt3bl5139-2haqg7-OPTIONS]
aws_api_gateway_method.cors_proxy_options["projects"]: Refreshing state... [id=agm-btt3bl5139-zofyad-OPTIONS]
aws_api_gateway_method.cors_proxy_options["users"]: Refreshing state... [id=agm-btt3bl5139-0s4etn-OPTIONS]
aws_api_gateway_method.cors_proxy_options["reports"]: Refreshing state... [id=agm-btt3bl5139-qpfkcg-OPTIONS]
aws_vpc_security_group_ingress_rule.rds_postgres: Refreshing state... [id=sgr-04300761c6a4d1014]
aws_db_instance.branch_rds: Refreshing state... [id=db-RQUC7A6QEZXSCYCKNMBKSKTS3Y]
aws_vpc_security_group_egress_rule.rds_all: Refreshing state... [id=sgr-0937cfcf0113fcbe8]
aws_s3_bucket_public_access_block.frontend: Refreshing state... [id=branch-frontend-404813129370]
aws_cloudfront_distribution.frontend: Refreshing state... [id=EOTKQTE3WUELO]
aws_api_gateway_method_response.cors["auth-proxy"]: Refreshing state... [id=agmr-btt3bl5139-7tjm3k-OPTIONS-200]
aws_api_gateway_method_response.cors["projects"]: Refreshing state... [id=agmr-btt3bl5139-5rlpdk-OPTIONS-200]
aws_api_gateway_method_response.cors["users"]: Refreshing state... [id=agmr-btt3bl5139-r6frgh-OPTIONS-200]
aws_api_gateway_method_response.cors["auth"]: Refreshing state... [id=agmr-btt3bl5139-j2bjjp-OPTIONS-200]
aws_api_gateway_method_response.cors["reports"]: Refreshing state... [id=agmr-btt3bl5139-fbius2-OPTIONS-200]
aws_api_gateway_method_response.cors["donors"]: Refreshing state... [id=agmr-btt3bl5139-ooaugc-OPTIONS-200]
aws_api_gateway_method_response.cors["expenditures-proxy"]: Refreshing state... [id=agmr-btt3bl5139-2haqg7-OPTIONS-200]
aws_api_gateway_method_response.cors["donors-proxy"]: Refreshing state... [id=agmr-btt3bl5139-37l1nw-OPTIONS-200]
aws_api_gateway_method_response.cors["projects-proxy"]: Refreshing state... [id=agmr-btt3bl5139-zofyad-OPTIONS-200]
aws_api_gateway_method_response.cors["expenditures"]: Refreshing state... [id=agmr-btt3bl5139-x3f6cx-OPTIONS-200]
aws_api_gateway_method_response.cors["users-proxy"]: Refreshing state... [id=agmr-btt3bl5139-0s4etn-OPTIONS-200]
aws_api_gateway_method_response.cors["reports-proxy"]: Refreshing state... [id=agmr-btt3bl5139-qpfkcg-OPTIONS-200]
aws_api_gateway_integration.cors["projects"]: Refreshing state... [id=agi-btt3bl5139-5rlpdk-OPTIONS]
aws_api_gateway_integration.cors["auth-proxy"]: Refreshing state... [id=agi-btt3bl5139-7tjm3k-OPTIONS]
aws_api_gateway_integration.cors["donors"]: Refreshing state... [id=agi-btt3bl5139-ooaugc-OPTIONS]
aws_api_gateway_integration.cors["reports"]: Refreshing state... [id=agi-btt3bl5139-fbius2-OPTIONS]
aws_api_gateway_integration.cors["expenditures-proxy"]: Refreshing state... [id=agi-btt3bl5139-2haqg7-OPTIONS]
aws_api_gateway_integration.cors["expenditures"]: Refreshing state... [id=agi-btt3bl5139-x3f6cx-OPTIONS]
aws_api_gateway_integration.cors["users"]: Refreshing state... [id=agi-btt3bl5139-r6frgh-OPTIONS]
aws_api_gateway_integration.cors["donors-proxy"]: Refreshing state... [id=agi-btt3bl5139-37l1nw-OPTIONS]
aws_api_gateway_integration.cors["projects-proxy"]: Refreshing state... [id=agi-btt3bl5139-zofyad-OPTIONS]
aws_api_gateway_integration.cors["users-proxy"]: Refreshing state... [id=agi-btt3bl5139-0s4etn-OPTIONS]
aws_api_gateway_integration.cors["reports-proxy"]: Refreshing state... [id=agi-btt3bl5139-qpfkcg-OPTIONS]
aws_api_gateway_integration.cors["auth"]: Refreshing state... [id=agi-btt3bl5139-j2bjjp-OPTIONS]
aws_s3_bucket_versioning.lambda_deployments: Refreshing state... [id=branch-lambda-deployments-404813129370]
aws_s3_bucket_server_side_encryption_configuration.lambda_deployments: Refreshing state... [id=branch-lambda-deployments-404813129370]
aws_s3_object.lambda_placeholder["donors"]: Refreshing state... [id=branch-lambda-deployments-404813129370/donors/initial.zip]
aws_s3_object.lambda_placeholder["reports"]: Refreshing state... [id=branch-lambda-deployments-404813129370/reports/initial.zip]
aws_s3_object.lambda_placeholder["users"]: Refreshing state... [id=branch-lambda-deployments-404813129370/users/initial.zip]
aws_s3_object.lambda_placeholder["auth"]: Refreshing state... [id=branch-lambda-deployments-404813129370/auth/initial.zip]
aws_s3_object.lambda_placeholder["expenditures"]: Refreshing state... [id=branch-lambda-deployments-404813129370/expenditures/initial.zip]
aws_s3_object.lambda_placeholder["projects"]: Refreshing state... [id=branch-lambda-deployments-404813129370/projects/initial.zip]
data.aws_iam_policy_document.frontend_bucket: Reading...
data.aws_iam_policy_document.frontend_bucket: Read complete after 0s [id=1913669945]
aws_s3_bucket_policy.frontend: Refreshing state... [id=branch-frontend-404813129370]
aws_cognito_user_pool.branch_user_pool: Refreshing state... [id=us-east-2_ES8vlp7b4]
aws_iam_role_policy.lambda_cognito_admin: Refreshing state... [id=branch-lambda-role:branch-lambda-cognito-admin]
aws_cognito_user_pool_client.branch_client: Refreshing state... [id=26r3n4d9ttjp6fvhdg1erd2eli]
aws_lambda_function.functions["expenditures"]: Refreshing state... [id=branch-expenditures]
aws_lambda_function.functions["users"]: Refreshing state... [id=branch-users]
aws_lambda_function.functions["auth"]: Refreshing state... [id=branch-auth]
aws_lambda_function.functions["projects"]: Refreshing state... [id=branch-projects]
aws_lambda_function.functions["donors"]: Refreshing state... [id=branch-donors]
aws_lambda_function.functions["reports"]: Refreshing state... [id=branch-reports]
aws_iam_role_policy.ci_migrate: Refreshing state... [id=branch-ci-migrate:db-migrate]
aws_api_gateway_integration.lambda_proxy_integrations["users"]: Refreshing state... [id=agi-btt3bl5139-0s4etn-ANY]
aws_api_gateway_integration.lambda_proxy_integrations["auth"]: Refreshing state... [id=agi-btt3bl5139-7tjm3k-ANY]
aws_api_gateway_integration.lambda_proxy_integrations["donors"]: Refreshing state... [id=agi-btt3bl5139-37l1nw-ANY]
aws_api_gateway_integration.lambda_proxy_integrations["expenditures"]: Refreshing state... [id=agi-btt3bl5139-2haqg7-ANY]
aws_api_gateway_integration.lambda_proxy_integrations["projects"]: Refreshing state... [id=agi-btt3bl5139-zofyad-ANY]
aws_api_gateway_integration.lambda_proxy_integrations["reports"]: Refreshing state... [id=agi-btt3bl5139-qpfkcg-ANY]
aws_lambda_permission.api_gateway_permissions["auth"]: Refreshing state... [id=AllowAPIGatewayInvoke]
aws_lambda_permission.api_gateway_permissions["projects"]: Refreshing state... [id=AllowAPIGatewayInvoke]
aws_lambda_permission.api_gateway_permissions["donors"]: Refreshing state... [id=AllowAPIGatewayInvoke]
aws_lambda_permission.api_gateway_permissions["users"]: Refreshing state... [id=AllowAPIGatewayInvoke]
aws_lambda_permission.api_gateway_permissions["expenditures"]: Refreshing state... [id=AllowAPIGatewayInvoke]
aws_lambda_permission.api_gateway_permissions["reports"]: Refreshing state... [id=AllowAPIGatewayInvoke]
aws_api_gateway_integration.lambda_integrations["donors-GET"]: Refreshing state... [id=agi-btt3bl5139-ooaugc-GET]
aws_api_gateway_integration.lambda_integrations["expenditures-GET"]: Refreshing state... [id=agi-btt3bl5139-x3f6cx-GET]
aws_api_gateway_integration.lambda_integrations["users-PATCH"]: Refreshing state... [id=agi-btt3bl5139-r6frgh-PATCH]
aws_api_gateway_integration.lambda_integrations["users-POST"]: Refreshing state... [id=agi-btt3bl5139-r6frgh-POST]
aws_api_gateway_integration.lambda_integrations["donors-POST"]: Refreshing state... [id=agi-btt3bl5139-ooaugc-POST]
aws_api_gateway_integration.lambda_integrations["users-GET"]: Refreshing state... [id=agi-btt3bl5139-r6frgh-GET]
aws_api_gateway_integration.lambda_integrations["auth-GET"]: Refreshing state... [id=agi-btt3bl5139-j2bjjp-GET]
aws_api_gateway_integration.lambda_integrations["projects-POST"]: Refreshing state... [id=agi-btt3bl5139-5rlpdk-POST]
aws_api_gateway_integration.lambda_integrations["expenditures-POST"]: Refreshing state... [id=agi-btt3bl5139-x3f6cx-POST]
aws_api_gateway_integration.lambda_integrations["expenditures-PATCH"]: Refreshing state... [id=agi-btt3bl5139-x3f6cx-PATCH]
aws_api_gateway_integration.lambda_integrations["users-DELETE"]: Refreshing state... [id=agi-btt3bl5139-r6frgh-DELETE]
aws_api_gateway_integration.lambda_integrations["projects-GET"]: Refreshing state... [id=agi-btt3bl5139-5rlpdk-GET]
aws_api_gateway_integration.lambda_integrations["reports-GET"]: Refreshing state... [id=agi-btt3bl5139-fbius2-GET]
aws_api_gateway_integration.lambda_integrations["auth-POST"]: Refreshing state... [id=agi-btt3bl5139-j2bjjp-POST]
aws_api_gateway_integration_response.cors["reports-proxy"]: Refreshing state... [id=agir-btt3bl5139-qpfkcg-OPTIONS-200]
aws_api_gateway_integration_response.cors["donors"]: Refreshing state... [id=agir-btt3bl5139-ooaugc-OPTIONS-200]
aws_api_gateway_integration_response.cors["reports"]: Refreshing state... [id=agir-btt3bl5139-fbius2-OPTIONS-200]
aws_api_gateway_integration_response.cors["projects"]: Refreshing state... [id=agir-btt3bl5139-5rlpdk-OPTIONS-200]
aws_api_gateway_integration_response.cors["expenditures-proxy"]: Refreshing state... [id=agir-btt3bl5139-2haqg7-OPTIONS-200]
aws_api_gateway_integration_response.cors["projects-proxy"]: Refreshing state... [id=agir-btt3bl5139-zofyad-OPTIONS-200]
aws_api_gateway_integration_response.cors["donors-proxy"]: Refreshing state... [id=agir-btt3bl5139-37l1nw-OPTIONS-200]
aws_api_gateway_integration_response.cors["users-proxy"]: Refreshing state... [id=agir-btt3bl5139-0s4etn-OPTIONS-200]
aws_api_gateway_integration_response.cors["auth"]: Refreshing state... [id=agir-btt3bl5139-j2bjjp-OPTIONS-200]
aws_api_gateway_integration_response.cors["users"]: Refreshing state... [id=agir-btt3bl5139-r6frgh-OPTIONS-200]
aws_api_gateway_integration_response.cors["auth-proxy"]: Refreshing state... [id=agir-btt3bl5139-7tjm3k-OPTIONS-200]
aws_api_gateway_integration_response.cors["expenditures"]: Refreshing state... [id=agir-btt3bl5139-x3f6cx-OPTIONS-200]
aws_api_gateway_deployment.branch_deployment: Refreshing state... [id=f4ddhq]
aws_api_gateway_stage.branch_stage: Refreshing state... [id=ags-btt3bl5139-prod]

No changes. Your infrastructure matches the configuration.

Terraform has compared your real infrastructure against your configuration
and found no differences, so no changes are needed.

Pushed by: @nourshoreibah, Action: pull_request

@nourshoreibah
nourshoreibah merged commit 469ac99 into main Aug 30, 2026
15 checks passed
@nourshoreibah
nourshoreibah deleted the feat/route53-registered-zone branch August 30, 2026 19:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-review The PR review bot won't run

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant