Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 12 additions & 1 deletion docs/data-sources/cdn_distribution.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,10 +51,11 @@ Read-Only:

- `backend` (Attributes) The configured backend for the distribution (see [below for nested schema](#nestedatt--config--backend))
- `blocked_ips` (List of String) Restricts access to your content by specifying a list of blocked IPv4 addresses. This feature enhances security and privacy by preventing these addresses from accessing your distribution. Note: once a value is set, removing the attribute from your configuration will retain the last known value in state; to clear it explicitly, set it to an empty list.
- `cache_config` (Attributes) Groups the cache options that influence how the CDN builds its cache key. Warning: enabling query-string vary produces one cache entry per unique query-string combination (unbounded when query_string_vary_parameters is empty). Each entry in cache_key_headers multiplies the number of cache variants by the number of distinct values observed for that header. Use these settings sparingly. Note: when the Image Optimizer is enabled, the CDN automatically enables query-string vary for image responses regardless of the query_string_vary_enabled setting. (see [below for nested schema](#nestedatt--config--cache_config))
- `default_cache_duration` (String) Sets the default cache duration for the distribution. The default cache duration is applied when a 'Cache-Control' header is not presented in the origin's response. We use ISO8601 duration format for cache duration (e.g. P1DT2H30M). Note: once a value is set, removing the attribute from your configuration will retain the last known value in state.
- `forward_host_header` (Boolean) Enable this allows the 'Host' header to be passed through to the origin.
- `monthly_limit_bytes` (Number) Sets the monthly limit of bandwidth in bytes that the pullzone is allowed to use. Note: once a value is set, removing the attribute from your configuration will retain the last known value in state.
- `optimizer` (Attributes) Configuration for the Image Optimizer. This is a paid feature that automatically optimizes images to reduce their file size for faster delivery, leading to improved website performance and a better user experience. (see [below for nested schema](#nestedatt--config--optimizer))
- `optimizer` (Attributes) Configuration for the Image Optimizer. This is a paid feature that automatically optimizes images to reduce their file size for faster delivery, leading to improved website performance and a better user experience. Note: when the Image Optimizer is enabled, the CDN automatically enables query-string vary for image responses regardless of the query_string_vary_enabled setting. (see [below for nested schema](#nestedatt--config--optimizer))
- `redirects` (Attributes) A wrapper for a list of redirect rules that allows for redirect settings on a distribution (see [below for nested schema](#nestedatt--config--redirects))
- `regions` (List of String) The configured regions where content will be hosted
- `strip_response_cookies` (Boolean) Enable this to prevent origin-level cookies from being forwarded to the end user.
Expand All @@ -74,6 +75,16 @@ Read-Only:
- `type` (String) The configured backend type. Possible values are: `http`, `bucket`.


<a id="nestedatt--config--cache_config"></a>
### Nested Schema for `config.cache_config`

Read-Only:

- `cache_key_headers` (List of String) HTTP request header names whose values participate in the cache key. Each entry multiplies the number of cache variants by the number of distinct values observed for that header.
- `query_string_vary_enabled` (Boolean) When true, the CDN varies its cache by the request query string. If query_string_vary_parameters is empty, every unique query-string combination produces its own cache entry; if non-empty, only the listed parameters influence the cache key.
- `query_string_vary_parameters` (List of String) Allowlist of query-string parameter names that participate in the cache key when query_string_vary_enabled is true. Ignored while query_string_vary_enabled is false, but still stored so it can be re-activated without losing the list.


<a id="nestedatt--config--optimizer"></a>
### Nested Schema for `config.optimizer`

Expand Down
19 changes: 18 additions & 1 deletion docs/resources/cdn_distribution.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,12 @@ resource "stackit_cdn_distribution" "example_distribution" {
optimizer = {
enabled = true
}

cache_config = {
cache_key_headers = ["Accept-Language"]
query_string_vary_enabled = true
query_string_vary_parameters = ["page", "sort"]
}
}
}

Expand Down Expand Up @@ -156,10 +162,11 @@ Optional:

- `blocked_countries` (List of String) The configured countries where distribution of content is blocked
- `blocked_ips` (List of String) Restricts access to your content by specifying a list of blocked IPv4 addresses. This feature enhances security and privacy by preventing these addresses from accessing your distribution. Note: once a value is set, removing the attribute from your configuration will retain the last known value in state; to clear it explicitly, set it to an empty list.
- `cache_config` (Attributes) Groups the cache options that influence how the CDN builds its cache key. Warning: enabling query-string vary produces one cache entry per unique query-string combination (unbounded when query_string_vary_parameters is empty). Each entry in cache_key_headers multiplies the number of cache variants by the number of distinct values observed for that header. Use these settings sparingly. Note: when the Image Optimizer is enabled, the CDN automatically enables query-string vary for image responses regardless of the query_string_vary_enabled setting. (see [below for nested schema](#nestedatt--config--cache_config))
- `default_cache_duration` (String) Sets the default cache duration for the distribution. The default cache duration is applied when a 'Cache-Control' header is not presented in the origin's response. We use ISO8601 duration format for cache duration (e.g. P1DT2H30M). Note: once a value is set, removing the attribute from your configuration will retain the last known value in state.
- `forward_host_header` (Boolean) Enable this allows the 'Host' header to be passed through to the origin.
- `monthly_limit_bytes` (Number) Sets the monthly limit of bandwidth in bytes that the pullzone is allowed to use. Note: once a value is set, removing the attribute from your configuration will retain the last known value in state.
- `optimizer` (Attributes) Configuration for the Image Optimizer. This is a paid feature that automatically optimizes images to reduce their file size for faster delivery, leading to improved website performance and a better user experience. (see [below for nested schema](#nestedatt--config--optimizer))
- `optimizer` (Attributes) Configuration for the Image Optimizer. This is a paid feature that automatically optimizes images to reduce their file size for faster delivery, leading to improved website performance and a better user experience. Note: when the Image Optimizer is enabled, the CDN automatically enables query-string vary for image responses regardless of the query_string_vary_enabled setting. (see [below for nested schema](#nestedatt--config--optimizer))
- `redirects` (Attributes) A wrapper for a list of redirect rules that allows for redirect settings on a distribution (see [below for nested schema](#nestedatt--config--redirects))
- `strip_response_cookies` (Boolean) Enable this to prevent origin-level cookies from being forwarded to the end user.
- `tls` (Attributes) Configuration for TLS protocol versions. Note: Enabling older TLS versions (1.0, 1.1) is generally discouraged for security reasons. (see [below for nested schema](#nestedatt--config--tls))
Expand Down Expand Up @@ -191,6 +198,16 @@ Required:



<a id="nestedatt--config--cache_config"></a>
### Nested Schema for `config.cache_config`

Optional:

- `cache_key_headers` (List of String) HTTP request header names whose values participate in the cache key. Each entry multiplies the number of cache variants by the number of distinct values observed for that header.
- `query_string_vary_enabled` (Boolean) When true, the CDN varies its cache by the request query string. If query_string_vary_parameters is empty, every unique query-string combination produces its own cache entry; if non-empty, only the listed parameters influence the cache key.
- `query_string_vary_parameters` (List of String) Allowlist of query-string parameter names that participate in the cache key when query_string_vary_enabled is true. Ignored while query_string_vary_enabled is false, but still stored so it can be re-activated without losing the list.


<a id="nestedatt--config--optimizer"></a>
### Nested Schema for `config.optimizer`

Expand Down
6 changes: 6 additions & 0 deletions examples/resources/stackit_cdn_distribution/resource.tf
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,12 @@ resource "stackit_cdn_distribution" "example_distribution" {
optimizer = {
enabled = true
}

cache_config = {
cache_key_headers = ["Accept-Language"]
query_string_vary_enabled = true
query_string_vary_parameters = ["page", "sort"]
}
}
}

Expand Down
28 changes: 28 additions & 0 deletions stackit/internal/services/cdn/cdn_acc_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -136,6 +136,9 @@ var testConfigVarsHttp = config.Variables{
"forward_host_header": config.BoolVariable(true),
"monthly_limit_bytes": config.IntegerVariable(104857600),
"default_cache_duration": config.StringVariable("PT2H"),
"cache_key_headers": config.ListVariable(config.StringVariable("Authorization")),
"query_string_vary_enabled": config.BoolVariable(true),
"query_string_vary_parameters": config.ListVariable(config.StringVariable("utm_source"), config.StringVariable("page")),
"waf": wafConfigVariable(
"ENABLED",
"FREE",
Expand Down Expand Up @@ -167,6 +170,7 @@ func configVarsHttpUpdated() config.Variables {
// Update small features
updatedConfig["strip_response_cookies"] = config.BoolVariable(true)
updatedConfig["forward_host_header"] = config.BoolVariable(false)
updatedConfig["query_string_vary_enabled"] = config.BoolVariable(false)

return updatedConfig
}
Expand Down Expand Up @@ -263,6 +267,14 @@ func TestAccCDNDistributionHttp(t *testing.T) {
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.monthly_limit_bytes", testutil.ConvertConfigVariable(testConfigVarsHttp["monthly_limit_bytes"])),
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.default_cache_duration", testutil.ConvertConfigVariable(testConfigVarsHttp["default_cache_duration"])),

// Cache Config Checks
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.cache_config.query_string_vary_enabled", "true"),
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.cache_config.cache_key_headers.#", "1"),
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.cache_config.cache_key_headers.0", "Authorization"),
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.cache_config.query_string_vary_parameters.#", "2"),
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.cache_config.query_string_vary_parameters.0", "utm_source"),
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.cache_config.query_string_vary_parameters.1", "page"),

// WAF Checks
testutil.CheckObjectAttr("stackit_cdn_distribution.distribution", "config.waf", testConfigVarsHttp["waf"]),

Expand Down Expand Up @@ -380,6 +392,14 @@ func TestAccCDNDistributionHttp(t *testing.T) {
resource.TestCheckResourceAttr("data.stackit_cdn_distribution.distribution", "config.monthly_limit_bytes", testutil.ConvertConfigVariable(testConfigVarsHttp["monthly_limit_bytes"])),
resource.TestCheckResourceAttr("data.stackit_cdn_distribution.distribution", "config.default_cache_duration", testutil.ConvertConfigVariable(testConfigVarsHttp["default_cache_duration"])),

// Cache Config Checks inside Data Source
resource.TestCheckResourceAttr("data.stackit_cdn_distribution.distribution", "config.cache_config.query_string_vary_enabled", "true"),
resource.TestCheckResourceAttr("data.stackit_cdn_distribution.distribution", "config.cache_config.cache_key_headers.#", "1"),
resource.TestCheckResourceAttr("data.stackit_cdn_distribution.distribution", "config.cache_config.cache_key_headers.0", "Authorization"),
resource.TestCheckResourceAttr("data.stackit_cdn_distribution.distribution", "config.cache_config.query_string_vary_parameters.#", "2"),
resource.TestCheckResourceAttr("data.stackit_cdn_distribution.distribution", "config.cache_config.query_string_vary_parameters.0", "utm_source"),
resource.TestCheckResourceAttr("data.stackit_cdn_distribution.distribution", "config.cache_config.query_string_vary_parameters.1", "page"),

// WAF Checks inside Data Source
testutil.CheckObjectAttr("data.stackit_cdn_distribution.distribution", "config.waf", testConfigVarsHttp["waf"]),

Expand Down Expand Up @@ -435,6 +455,14 @@ func TestAccCDNDistributionHttp(t *testing.T) {
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.monthly_limit_bytes", testutil.ConvertConfigVariable(configVarsHttpUpdated()["monthly_limit_bytes"])),
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.default_cache_duration", testutil.ConvertConfigVariable(configVarsHttpUpdated()["default_cache_duration"])),

// Cache Config Checks
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.cache_config.query_string_vary_enabled", "false"),
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.cache_config.cache_key_headers.#", "1"),
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.cache_config.cache_key_headers.0", "Authorization"),
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.cache_config.query_string_vary_parameters.#", "2"),
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.cache_config.query_string_vary_parameters.0", "utm_source"),
resource.TestCheckResourceAttr("stackit_cdn_distribution.distribution", "config.cache_config.query_string_vary_parameters.1", "page"),

// Checking WAF Mutated Configurations
testutil.CheckObjectAttr("stackit_cdn_distribution.distribution", "config.waf", configVarsHttpUpdated()["waf"]),

Expand Down
57 changes: 56 additions & 1 deletion stackit/internal/services/cdn/distribution/datasource.go
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,9 @@ var dataSourceConfigTypes = map[string]attr.Type{
"tls": types.ObjectType{
AttrTypes: tlsTypes, // Shared from resource.go
},
"cache_config": types.ObjectType{
AttrTypes: cacheConfigTypes, // Shared from resource.go
},
"strip_response_cookies": types.BoolType,
"forward_host_header": types.BoolType,
}
Expand Down Expand Up @@ -228,6 +231,26 @@ func (r *distributionDataSource) Schema(_ context.Context, _ datasource.SchemaRe
},
},
},
"cache_config": schema.SingleNestedAttribute{
Description: schemaDescriptions["config_cache_config"],
Computed: true,
Attributes: map[string]schema.Attribute{
"cache_key_headers": schema.ListAttribute{
Description: schemaDescriptions["config_cache_config_cache_key_headers"],
Computed: true,
ElementType: types.StringType,
},
"query_string_vary_enabled": schema.BoolAttribute{
Description: schemaDescriptions["config_cache_config_query_string_vary_enabled"],
Computed: true,
},
"query_string_vary_parameters": schema.ListAttribute{
Description: schemaDescriptions["config_cache_config_query_string_vary_parameters"],
Computed: true,
ElementType: types.StringType,
},
},
},
"strip_response_cookies": schema.BoolAttribute{
Computed: true,
Description: schemaDescriptions["config_strip_response_cookies"],
Expand Down Expand Up @@ -691,7 +714,38 @@ func mapDataSourceFields(ctx context.Context, distribution *cdnSdk.Distribution,

tlsVal, diagTls := types.ObjectValue(tlsTypes, tlsObjAttrs)
if diagTls.HasError() {
return core.DiagsToError(diagWaf)
return core.DiagsToError(diagTls)
}

var cacheKeyHeaders []attr.Value
if headers := distribution.Config.CacheConfig.CacheKeyHeaders; headers != nil {
for _, h := range headers {
cacheKeyHeaders = append(cacheKeyHeaders, types.StringValue(h))
}
}
cacheKeyHeadersList, diags := types.ListValue(types.StringType, cacheKeyHeaders)
if diags.HasError() {
return core.DiagsToError(diags)
}

var queryStringVaryParams []attr.Value
if params := distribution.Config.CacheConfig.QueryStringVaryParameters; params != nil {
for _, p := range params {
queryStringVaryParams = append(queryStringVaryParams, types.StringValue(p))
}
}
queryStringVaryParamsList, diags := types.ListValue(types.StringType, queryStringVaryParams)
if diags.HasError() {
return core.DiagsToError(diags)
}

cacheConfigVal, diagCache := types.ObjectValue(cacheConfigTypes, map[string]attr.Value{
"cache_key_headers": cacheKeyHeadersList,
"query_string_vary_enabled": types.BoolValue(distribution.Config.CacheConfig.QueryStringVaryEnabled),
"query_string_vary_parameters": queryStringVaryParamsList,
})
if diagCache.HasError() {
return core.DiagsToError(diagCache)
}

// blockedIps
Expand Down Expand Up @@ -733,6 +787,7 @@ func mapDataSourceFields(ctx context.Context, distribution *cdnSdk.Distribution,
"redirects": redirectsVal,
"waf": wafVal,
"tls": tlsVal,
"cache_config": cacheConfigVal,
"strip_response_cookies": types.BoolValue(distribution.Config.StripResponseCookies),
"forward_host_header": types.BoolValue(distribution.Config.ForwardHostHeader),
})
Expand Down
Loading