cloud-gov/cg-provision

Create internal domain load balancer for CUPS

Opened this issue · 0 comments

Create an internal ELB for a FQDN internal domain for CUPS services on the platform to limit traffic going out and back in through the front door and costing cycles

Notes

  • Customer CUPS require FQDN and if the CUPS app is internal to cloud.gov it has to leave our NATS gateway and come back through the front door of Shield/WAF and using cycles
  • An internal domain elb would allow that traffic to stay inside the VPC and educing cost and overhead on the main front ELB.

Acceptance Criteria

  • Create internal elb
  • Make it a module with a boolean on/off switch to enable by environment
  • Create DNS records and wildcard for elb
  • Create Let's Encrypt flow to manage new domain wildcard cert
  • Enable shared internal domain to CF