Skip to content

Conversation

@narinder17
Copy link
Contributor

Jira link

https://tools.hmcts.net/jira/browse/DTSPO-29278

Change description

To decomm DNS records sdt.apps-nle.hmcts.net and stdcomm.apps-nle.hmcts.net, related resources.

Note VM's & LB to be actioned on another ticket - https://tools.hmcts.net/jira/browse/DTSPO-29215.

Testing done

Security Vulnerability Assessment

CVE Suppression: Are there any CVEs present in the codebase (either newly introduced or pre-existing) that are being intentionally suppressed or ignored by this commit?

  • Yes
  • No

Checklist

  • commit messages are meaningful and follow good commit message guidelines
  • README and other documentation has been updated / added (if needed)
  • tests have been updated / new tests has been added (if needed)
  • Does this PR introduce a breaking change

@hmcts-platform-operations

Plan Result (278: Ithc - TerraformPlanApply)

No changes. Your infrastructure matches the configuration.

@hmcts-platform-operations

Plan Result (278: Dev - TerraformPlanApply)

No changes. Your infrastructure matches the configuration.

@hmcts-platform-operations

Plan Result (278: nle - TerraformPlanApply)

⚠️ Resource Deletion will happen

This plan contains resource delete operation. Please check the plan result very carefully!

Plan: 0 to add, 0 to change, 1 to destroy.
  • Delete
    • module.public-dns.azurerm_dns_cname_record.this["sdt"]
Change Result (Click me)
  # module.public-dns.azurerm_dns_cname_record.this["sdt"] will be destroyed
  # (because key ["sdt"] is not in for_each map)
  - resource "azurerm_dns_cname_record" "this" {
      - fqdn                = "sdt.nle.platform.hmcts.net." -> null
      - id                  = "/subscriptions/ed302caf-ec27-4c64-a05e-85731c3ce90e/resourceGroups/reformmgmtrg/providers/Microsoft.Network/dnsZones/nle.platform.hmcts.net/CNAME/sdt" -> null
      - name                = "sdt" -> null
      - record              = "firewall-nonprodi-palo-sdtnle.uksouth.cloudapp.azure.com" -> null
      - resource_group_name = "reformmgmtrg" -> null
      - tags                = {} -> null
      - ttl                 = 300 -> null
      - zone_name           = "nle.platform.hmcts.net" -> null
        # (1 unchanged attribute hidden)
    }

Plan: 0 to add, 0 to change, 1 to destroy.

@hmcts-platform-operations

Plan Result (278: Demo - TerraformPlanApply)

No changes. Your infrastructure matches the configuration.

@hmcts-platform-operations

Plan Result (278: Test - TerraformPlanApply)

No changes. Your infrastructure matches the configuration.

@hmcts-platform-operations

Plan Result (278: Staging - TerraformPlanApply)

Plan: 0 to add, 1 to change, 0 to destroy.
  • Update
    • module.public-dns.azurerm_dns_txt_record.this["_dnsauth.idam-user-dashboard-staging"]
Change Result (Click me)
  # module.public-dns.azurerm_dns_txt_record.this["_dnsauth.idam-user-dashboard-staging"] will be updated in-place
  ~ resource "azurerm_dns_txt_record" "this" {
        id                  = "/subscriptions/ed302caf-ec27-4c64-a05e-85731c3ce90e/resourceGroups/reformmgmtrg/providers/Microsoft.Network/dnsZones/aat.platform.hmcts.net/TXT/_dnsauth.idam-user-dashboard-staging"
        name                = "_dnsauth.idam-user-dashboard-staging"
        tags                = {}
        # (4 unchanged attributes hidden)

      - record {
          - value = "_j2t8p33d04u73yoemk43s1donj8s1ul" -> null
        }
      + record {
          + value = "_rvig1ta23kg7687jnw9jd616nnediza"
        }
    }

Plan: 0 to add, 1 to change, 0 to destroy.

@hmcts-platform-operations

Plan Result (278: Sandbox - TerraformPlanApply)

No changes. Your infrastructure matches the configuration.

@hmcts-platform-operations

Plan Result (278: Prod - TerraformPlanApply)

⚠️ Resource Deletion will happen

This plan contains resource delete operation. Please check the plan result very carefully!

Plan: 0 to add, 3 to change, 6 to destroy.
  • Update
    • module.appeal-infected-blood-compensation-decision.azurerm_dns_txt_record.this["_dnsauth"]
    • module.platform-hmcts.azurerm_dns_txt_record.this["_dnsauth.apply-for-adoption"]
    • module.prod-platform.azurerm_dns_cname_record.this["_AC285A78514B19D657B18C29B98F4C7F.vh-admin-web"]
  • Delete
    • module.apps-nle-hmcts.azurerm_dns_a_record.this["sdt-uks"]
    • module.apps-nle-hmcts.azurerm_dns_a_record.this["sdt-ukw"]
    • module.apps-nle-hmcts.azurerm_dns_a_record.this["sdtcomm-uks"]
    • module.apps-nle-hmcts.azurerm_dns_a_record.this["sdtcomm-ukw"]
    • module.apps-nle-hmcts.azurerm_dns_cname_record.this["sdt"]
    • module.apps-nle-hmcts.azurerm_dns_cname_record.this["sdtcomm"]
Change Result (Click me)
  # module.appeal-infected-blood-compensation-decision.azurerm_dns_txt_record.this["_dnsauth"] will be updated in-place
  ~ resource "azurerm_dns_txt_record" "this" {
        id                  = "/subscriptions/ed302caf-ec27-4c64-a05e-85731c3ce90e/resourceGroups/reformmgmtrg/providers/Microsoft.Network/dnsZones/appeal-infected-blood-compensation-decision.service.gov.uk/TXT/_dnsauth"
        name                = "_dnsauth"
        tags                = {}
        # (4 unchanged attributes hidden)

      - record {
          - value = "_mk450bwt82w2k1g8co34kcmoc075n2t" -> null
        }
      + record {
          + value = "_qgm4dnxog4erse5j0mw7z3d4lia20jx"
        }
    }

  # module.apps-nle-hmcts.azurerm_dns_a_record.this["sdt-uks"] will be destroyed
  # (because key ["sdt-uks"] is not in for_each map)
  - resource "azurerm_dns_a_record" "this" {
      - fqdn                = "sdt-uks.apps-nle.hmcts.net." -> null
      - id                  = "/subscriptions/ed302caf-ec27-4c64-a05e-85731c3ce90e/resourceGroups/reformmgmtrg/providers/Microsoft.Network/dnsZones/apps-nle.hmcts.net/A/sdt-uks" -> null
      - name                = "sdt-uks" -> null
      - records             = [
          - "13.87.70.10",
        ] -> null
      - resource_group_name = "reformmgmtrg" -> null
      - tags                = {} -> null
      - ttl                 = 60 -> null
      - zone_name           = "apps-nle.hmcts.net" -> null
        # (1 unchanged attribute hidden)
    }

  # module.apps-nle-hmcts.azurerm_dns_a_record.this["sdt-ukw"] will be destroyed
  # (because key ["sdt-ukw"] is not in for_each map)
  - resource "azurerm_dns_a_record" "this" {
      - fqdn                = "sdt-ukw.apps-nle.hmcts.net." -> null
      - id                  = "/subscriptions/ed302caf-ec27-4c64-a05e-85731c3ce90e/resourceGroups/reformmgmtrg/providers/Microsoft.Network/dnsZones/apps-nle.hmcts.net/A/sdt-ukw" -> null
      - name                = "sdt-ukw" -> null
      - records             = [
          - "51.141.85.60",
        ] -> null
      - resource_group_name = "reformmgmtrg" -> null
      - tags                = {} -> null
      - ttl                 = 60 -> null
      - zone_name           = "apps-nle.hmcts.net" -> null
        # (1 unchanged attribute hidden)
    }

  # module.apps-nle-hmcts.azurerm_dns_a_record.this["sdtcomm-uks"] will be destroyed
  # (because key ["sdtcomm-uks"] is not in for_each map)
  - resource "azurerm_dns_a_record" "this" {
      - fqdn                = "sdtcomm-uks.apps-nle.hmcts.net." -> null
      - id                  = "/subscriptions/ed302caf-ec27-4c64-a05e-85731c3ce90e/resourceGroups/reformmgmtrg/providers/Microsoft.Network/dnsZones/apps-nle.hmcts.net/A/sdtcomm-uks" -> null
      - name                = "sdtcomm-uks" -> null
      - records             = [
          - "51.142.81.183",
        ] -> null
      - resource_group_name = "reformmgmtrg" -> null
      - tags                = {} -> null
      - ttl                 = 60 -> null
      - zone_name           = "apps-nle.hmcts.net" -> null
        # (1 unchanged attribute hidden)
    }

  # module.apps-nle-hmcts.azurerm_dns_a_record.this["sdtcomm-ukw"] will be destroyed
  # (because key ["sdtcomm-ukw"] is not in for_each map)
  - resource "azurerm_dns_a_record" "this" {
      - fqdn                = "sdtcomm-ukw.apps-nle.hmcts.net." -> null
      - id                  = "/subscriptions/ed302caf-ec27-4c64-a05e-85731c3ce90e/resourceGroups/reformmgmtrg/providers/Microsoft.Network/dnsZones/apps-nle.hmcts.net/A/sdtcomm-ukw" -> null
      - name                = "sdtcomm-ukw" -> null
      - records             = [
          - "51.141.85.61",
        ] -> null
      - resource_group_name = "reformmgmtrg" -> null
      - tags                = {} -> null
      - ttl                 = 60 -> null
      - zone_name           = "apps-nle.hmcts.net" -> null
        # (1 unchanged attribute hidden)
    }

  # module.apps-nle-hmcts.azurerm_dns_cname_record.this["sdt"] will be destroyed
  # (because key ["sdt"] is not in for_each map)
  - resource "azurerm_dns_cname_record" "this" {
      - fqdn                = "sdt.apps-nle.hmcts.net." -> null
      - id                  = "/subscriptions/ed302caf-ec27-4c64-a05e-85731c3ce90e/resourceGroups/reformmgmtrg/providers/Microsoft.Network/dnsZones/apps-nle.hmcts.net/CNAME/sdt" -> null
      - name                = "sdt" -> null
      - record              = "sdt-uks.apps-nle.hmcts.net" -> null
      - resource_group_name = "reformmgmtrg" -> null
      - tags                = {} -> null
      - ttl                 = 300 -> null
      - zone_name           = "apps-nle.hmcts.net" -> null
        # (1 unchanged attribute hidden)
    }

  # module.apps-nle-hmcts.azurerm_dns_cname_record.this["sdtcomm"] will be destroyed
  # (because key ["sdtcomm"] is not in for_each map)
  - resource "azurerm_dns_cname_record" "this" {
      - fqdn                = "sdtcomm.apps-nle.hmcts.net." -> null
      - id                  = "/subscriptions/ed302caf-ec27-4c64-a05e-85731c3ce90e/resourceGroups/reformmgmtrg/providers/Microsoft.Network/dnsZones/apps-nle.hmcts.net/CNAME/sdtcomm" -> null
      - name                = "sdtcomm" -> null
      - record              = "sdtcomm-uks.apps-nle.hmcts.net" -> null
      - resource_group_name = "reformmgmtrg" -> null
      - tags                = {} -> null
      - ttl                 = 300 -> null
      - zone_name           = "apps-nle.hmcts.net" -> null
        # (1 unchanged attribute hidden)
    }

  # module.platform-hmcts.azurerm_dns_txt_record.this["_dnsauth.apply-for-adoption"] will be updated in-place
  ~ resource "azurerm_dns_txt_record" "this" {
        id                  = "/subscriptions/ed302caf-ec27-4c64-a05e-85731c3ce90e/resourceGroups/reformmgmtrg/providers/Microsoft.Network/dnsZones/platform.hmcts.net/TXT/_dnsauth.apply-for-adoption"
        name                = "_dnsauth.apply-for-adoption"
        tags                = {}
        # (4 unchanged attributes hidden)

      - record {
          - value = "_2g92w3xfx5gbzcoxrxvg91ev59p54z5" -> null
        }
      + record {
          + value = "n3zyn06dl4jk9flktv4d018rxhrrjfm7"
        }
    }

  # module.prod-platform.azurerm_dns_cname_record.this["_AC285A78514B19D657B18C29B98F4C7F.vh-admin-web"] will be updated in-place
  ~ resource "azurerm_dns_cname_record" "this" {
        id                  = "/subscriptions/ed302caf-ec27-4c64-a05e-85731c3ce90e/resourceGroups/reformmgmtrg/providers/Microsoft.Network/dnsZones/prod.platform.hmcts.net/CNAME/_ac285a78514b19d657b18c29b98f4c7f.vh-admin-web"
        name                = "_ac285a78514b19d657b18c29b98f4c7f.vh-admin-web"
      ~ record              = "032DDB9A61BB0588601DD6D4C005A812.302202E1FB30DE99CD976C202BDB71AC.fbb25c1fc3c9ad12a80d.sectigo.com." -> "032DDB9A61BB0588601DD6D4C005A812.302202E1FB30DE99CD976C202BDB71AC.d7703fe5d42a59a77748.sectigo.com."
        tags                = {}
        # (5 unchanged attributes hidden)
    }

Plan: 0 to add, 3 to change, 6 to destroy.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment