{"_id":"@authn-sh/cdk","_rev":"7-723026b249dc87d5d6cb2c4b87ead24c","name":"@authn-sh/cdk","dist-tags":{"latest":"0.7.1"},"versions":{"0.3.0":{"name":"@authn-sh/cdk","version":"0.3.0","keywords":["authn","authentication","identity","sso","jwt","aws","cdk","constructs","ecs","fargate"],"license":"AGPL-3.0-only","_id":"@authn-sh/cdk@0.3.0","maintainers":[{"name":"vagnercsouza","email":"vagnercsouzam@gmail.com"}],"homepage":"https://authn.sh","bugs":{"url":"https://github.com/authn-sh/cdk/issues"},"dist":{"shasum":"99139add89aa93497018bc5820bbf2f4c85bb612","tarball":"https://registry.npmjs.org/@authn-sh/cdk/-/cdk-0.3.0.tgz","fileCount":48,"integrity":"sha512-ZpAafsm9Ol1aYJKsdkFROUp1cMP/E5nUSIYENkD7x3t0ADtDGCy8awYm2kPBFJaGwTJMfICTL8n4T0Y/hLvvZg==","signatures":[{"sig":"MEYCIQC8uZu4f3CYNDEZNiGC0mZvcDwKFnYqJ8NgMfX1YUe7FQIhAJu/j7ls4nigmr24+W0F1qBU1MrohfakdsvEtf74rrvc","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@authn-sh%2fcdk@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":145416},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"gitHead":"afa84d86dbf2f8c5c6022028cd3a02a59f3a1342","scripts":{"test":"jest","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","watch":"tsc -p tsconfig.build.json --watch"},"_npmUser":{"name":"vagnercsouza","email":"vagnercsouzam@gmail.com"},"repository":{"url":"git+https://github.com/authn-sh/cdk.git","type":"git"},"_npmVersion":"10.8.2","description":"AWS CDK constructs for deploying authn.sh on AWS. Self-hosted authentication-as-a-service.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"yaml":"^2.5.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.2.5","constructs":"^10.4.0","typescript":"^5.6.2","@types/jest":"^29.5.13","@types/node":"^20.16.10","aws-cdk-lib":"^2.160.0"},"peerDependencies":{"constructs":"^10.4.0","aws-cdk-lib":"^2.160.0"},"_npmOperationalInternal":{"tmp":"tmp/cdk_0.3.0_1778425409976_0.7322816118780544","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@authn-sh/cdk","version":"0.4.0","keywords":["authn","authentication","identity","sso","jwt","aws","cdk","constructs","ecs","fargate"],"license":"AGPL-3.0-only","_id":"@authn-sh/cdk@0.4.0","maintainers":[{"name":"vagnercsouza","email":"vagnercsouzam@gmail.com"}],"homepage":"https://authn.sh","bugs":{"url":"https://github.com/authn-sh/cdk/issues"},"dist":{"shasum":"a9b2bfbd46fd8d07892620600f7507d28843dd85","tarball":"https://registry.npmjs.org/@authn-sh/cdk/-/cdk-0.4.0.tgz","fileCount":48,"integrity":"sha512-3sTXBYdrTEkwzCjBy72TF6vjbNbenuZKgO7mspDLLmdLMl82hvuIMCng4TyAqtGvMgMOipDZqdF4XlDHiqzfmQ==","signatures":[{"sig":"MEYCIQDpiXw6OJ+gGf4fe/jt4RpzDt67yKBVykSWUkUqCfKbLQIhAJLFFxxItyeY8NYrRVQxRUd7sekUtQF87be6ftyFyy1O","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@authn-sh%2fcdk@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":155005},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"gitHead":"66199b6a969867a888b5f4768128197a85fa58b1","scripts":{"test":"jest","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","watch":"tsc -p tsconfig.build.json --watch"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a6d17211-c8c7-4f19-b852-aa3d78f187b2"}},"repository":{"url":"git+https://github.com/authn-sh/cdk.git","type":"git"},"_npmVersion":"11.11.0","description":"AWS CDK constructs for deploying authn.sh on AWS. Self-hosted authentication-as-a-service.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"yaml":"^2.5.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.2.5","constructs":"^10.4.0","typescript":"^5.6.2","@types/jest":"^29.5.13","@types/node":"^20.16.10","aws-cdk-lib":"^2.160.0"},"peerDependencies":{"constructs":"^10.4.0","aws-cdk-lib":"^2.160.0"},"_npmOperationalInternal":{"tmp":"tmp/cdk_0.4.0_1778434010329_0.005205165777024456","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@authn-sh/cdk","version":"0.4.1","keywords":["authn","authentication","identity","sso","jwt","aws","cdk","constructs","ecs","fargate"],"license":"AGPL-3.0-only","_id":"@authn-sh/cdk@0.4.1","maintainers":[{"name":"vagnercsouza","email":"vagnercsouzam@gmail.com"}],"homepage":"https://authn.sh","bugs":{"url":"https://github.com/authn-sh/cdk/issues"},"dist":{"shasum":"fee3fb11398843e16773e6c3b5e4bee0e6957e3d","tarball":"https://registry.npmjs.org/@authn-sh/cdk/-/cdk-0.4.1.tgz","fileCount":48,"integrity":"sha512-wmxUQUF7VHmKzJ90HzHuMKePRaKUWvWzV1if1W5F1/Yy0pD+/gThTa/buUyvjY3Tln60HjLsLLqNkhhtLLl+xA==","signatures":[{"sig":"MEUCIQD7VJ6D/zosLdCXHjtuCvyAMo4FA8UtyTgKeLZP/cDqPgIgeyxtnP+IKPysPAW3KBI7cHoo2CuKqnAzb+h1gJb5pFQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@authn-sh%2fcdk@0.4.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":154917},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"gitHead":"e78b82e6125de1dcaf83cdfd299d98a865b72163","scripts":{"test":"jest","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","watch":"tsc -p tsconfig.build.json --watch"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a6d17211-c8c7-4f19-b852-aa3d78f187b2"}},"repository":{"url":"git+https://github.com/authn-sh/cdk.git","type":"git"},"_npmVersion":"11.11.0","description":"AWS CDK constructs for deploying authn.sh on AWS. Self-hosted authentication-as-a-service.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"yaml":"^2.5.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.2.5","constructs":"^10.4.0","typescript":"^5.6.2","@types/jest":"^29.5.13","@types/node":"^20.16.10","aws-cdk-lib":"^2.160.0"},"peerDependencies":{"constructs":"^10.4.0","aws-cdk-lib":"^2.160.0"},"_npmOperationalInternal":{"tmp":"tmp/cdk_0.4.1_1778513955316_0.19977570671661882","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@authn-sh/cdk","version":"0.5.0","keywords":["authn","authentication","identity","sso","jwt","aws","cdk","constructs","ecs","fargate"],"license":"AGPL-3.0-only","_id":"@authn-sh/cdk@0.5.0","maintainers":[{"name":"vagnercsouza","email":"vagnercsouzam@gmail.com"}],"homepage":"https://authn.sh","bugs":{"url":"https://github.com/authn-sh/cdk/issues"},"dist":{"shasum":"cf187e282ea25eeb3446610d0eee331678b25d54","tarball":"https://registry.npmjs.org/@authn-sh/cdk/-/cdk-0.5.0.tgz","fileCount":48,"integrity":"sha512-REQ+L+TqTXDHACgnmR45HLeWF+2DXuN7dokTHZ14oKZdjGxkkoWQ7Vya4EChKQGJzlet6hnDt+RgrrhRfyc1mg==","signatures":[{"sig":"MEUCIE7qzX0Zg5JpsumzfHgjWhTgTYT5nGsNyqGJ7SKJ4ZW/AiEApsoOJdMAA8k+CydNN9UpXCWzvqKibudXBywehKyK+Cw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@authn-sh%2fcdk@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":156567},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"gitHead":"3a6ee00fb600f5fbbd5e3d38487c321f37f3ef7f","scripts":{"test":"jest","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","watch":"tsc -p tsconfig.build.json --watch"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a6d17211-c8c7-4f19-b852-aa3d78f187b2"}},"repository":{"url":"git+https://github.com/authn-sh/cdk.git","type":"git"},"_npmVersion":"11.11.0","description":"AWS CDK constructs for deploying authn.sh on AWS. Self-hosted authentication-as-a-service.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"yaml":"^2.5.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.2.5","constructs":"^10.4.0","typescript":"^5.6.2","@types/jest":"^29.5.13","@types/node":"^20.16.10","aws-cdk-lib":"^2.160.0"},"peerDependencies":{"constructs":"^10.4.0","aws-cdk-lib":"^2.160.0"},"_npmOperationalInternal":{"tmp":"tmp/cdk_0.5.0_1778538204295_0.661582664951236","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@authn-sh/cdk","version":"0.6.0","keywords":["authn","authentication","identity","sso","jwt","aws","cdk","constructs","ecs","fargate"],"license":"AGPL-3.0-only","_id":"@authn-sh/cdk@0.6.0","maintainers":[{"name":"vagnercsouza","email":"vagnercsouzam@gmail.com"}],"homepage":"https://authn.sh","bugs":{"url":"https://github.com/authn-sh/cdk/issues"},"dist":{"shasum":"48fcab0a917ea51914ab4c05179cae869be57cc7","tarball":"https://registry.npmjs.org/@authn-sh/cdk/-/cdk-0.6.0.tgz","fileCount":48,"integrity":"sha512-8qVxr9AnN80V/KdTmZWcghMk0UTvv4MbJu5MQb4TEvnrJVM+8EtlrFwvG8V6l3r9R+jCNVv4y56z7JJthyzVmg==","signatures":[{"sig":"MEYCIQCp3L1S1g/R6urHwqcpgenkwYfdBPN6SayjWO/JNGSdvwIhAOkbY/Ht/g5yaQc+K/s7XIXBZ9VTNKMxHIR+KyAXY53J","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@authn-sh%2fcdk@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":161751},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"gitHead":"b025204666bf4dd821d6c4e5113b6498b213dfdd","scripts":{"test":"jest","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","watch":"tsc -p tsconfig.build.json --watch"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a6d17211-c8c7-4f19-b852-aa3d78f187b2"}},"repository":{"url":"git+https://github.com/authn-sh/cdk.git","type":"git"},"_npmVersion":"11.11.0","description":"AWS CDK constructs for deploying authn.sh on AWS. Self-hosted authentication-as-a-service.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"yaml":"^2.5.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.2.5","constructs":"^10.4.0","typescript":"^5.6.2","@types/jest":"^29.5.13","@types/node":"^20.16.10","aws-cdk-lib":"^2.160.0"},"peerDependencies":{"constructs":"^10.4.0","aws-cdk-lib":"^2.160.0"},"_npmOperationalInternal":{"tmp":"tmp/cdk_0.6.0_1778585224969_0.8072564950846419","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@authn-sh/cdk","version":"0.7.0","keywords":["authn","authentication","identity","sso","jwt","aws","cdk","constructs","ecs","fargate"],"license":"AGPL-3.0-only","_id":"@authn-sh/cdk@0.7.0","maintainers":[{"name":"vagnercsouza","email":"vagnercsouzam@gmail.com"}],"homepage":"https://authn.sh","bugs":{"url":"https://github.com/authn-sh/cdk/issues"},"dist":{"shasum":"d50d1650076d28f4a5dd9579a782c2403205ac89","tarball":"https://registry.npmjs.org/@authn-sh/cdk/-/cdk-0.7.0.tgz","fileCount":48,"integrity":"sha512-eF8XpmOLlZGLSi61878sUMayUwSahtnFOM3FEeuuLJCIwy13Namqn4fAIQpcU3b5usCaMZd6eUS/Rpen8nB8AA==","signatures":[{"sig":"MEQCICWOgKfiMcggVqoEwsCBtgRt3BNdKxqAuntkvC1l4cE3AiAvbDHqvFw4d3dbTf5jNsJ3lMBQ9A+UTB/L1LiVlmuQ+g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@authn-sh%2fcdk@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":163472},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"gitHead":"c98257d7f8ec788e8816f2f8b6aa01156050a3d5","scripts":{"test":"jest","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","watch":"tsc -p tsconfig.build.json --watch"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a6d17211-c8c7-4f19-b852-aa3d78f187b2"}},"repository":{"url":"git+https://github.com/authn-sh/cdk.git","type":"git"},"_npmVersion":"11.11.0","description":"AWS CDK constructs for deploying authn.sh on AWS. Self-hosted authentication-as-a-service.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"yaml":"^2.5.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.2.5","constructs":"^10.4.0","typescript":"^5.6.2","@types/jest":"^29.5.13","@types/node":"^20.16.10","aws-cdk-lib":"^2.160.0"},"peerDependencies":{"constructs":"^10.4.0","aws-cdk-lib":"^2.160.0"},"_npmOperationalInternal":{"tmp":"tmp/cdk_0.7.0_1778616414055_0.3089964473034901","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@authn-sh/cdk","version":"0.7.1","description":"AWS CDK constructs for deploying authn.sh on AWS. Self-hosted authentication-as-a-service.","license":"AGPL-3.0-only","homepage":"https://authn.sh","repository":{"type":"git","url":"git+https://github.com/authn-sh/cdk.git"},"bugs":{"url":"https://github.com/authn-sh/cdk/issues"},"keywords":["authn","authentication","identity","sso","jwt","aws","cdk","constructs","ecs","fargate"],"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"scripts":{"build":"tsc -p tsconfig.build.json","watch":"tsc -p tsconfig.build.json --watch","test":"jest","clean":"rm -rf dist"},"peerDependencies":{"aws-cdk-lib":"^2.160.0","constructs":"^10.4.0"},"dependencies":{"yaml":"^2.5.1"},"devDependencies":{"@types/jest":"^29.5.13","@types/node":"^20.16.10","aws-cdk-lib":"^2.160.0","constructs":"^10.4.0","jest":"^29.7.0","ts-jest":"^29.2.5","typescript":"^5.6.2"},"publishConfig":{"access":"public"},"gitHead":"3c4ccd66b90dc75248e56fd0f893596e16c97abf","_id":"@authn-sh/cdk@0.7.1","_nodeVersion":"24.15.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-mjHzi8uXM7/POrirZyODC1lknZcFbpbowIfyfzED5ZJ62zcXWowvp5AHgf5SyGYHvjhk2LDaz8zy0aYWxCQRow==","shasum":"0e2f4e1738a613677b2f0e388b7978b46dd9d90c","tarball":"https://registry.npmjs.org/@authn-sh/cdk/-/cdk-0.7.1.tgz","fileCount":48,"unpackedSize":165208,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@authn-sh%2fcdk@0.7.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDUXxGoE7ydcL2KFi3U8e22mwBQZ/k1s9LY9dpH//VwxwIgKQRo+Zd1geUoDR5UYDeiASoO/wEu51qB5dwEaZmjvdQ="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a6d17211-c8c7-4f19-b852-aa3d78f187b2"}},"directories":{},"maintainers":[{"name":"vagnercsouza","email":"vagnercsouzam@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cdk_0.7.1_1778852217406_0.3390532907050512"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-10T15:03:29.887Z","modified":"2026-05-15T13:36:57.851Z","0.3.0":"2026-05-10T15:03:30.131Z","0.4.0":"2026-05-10T17:26:50.500Z","0.4.1":"2026-05-11T15:39:15.510Z","0.5.0":"2026-05-11T22:23:24.477Z","0.6.0":"2026-05-12T11:27:05.139Z","0.7.0":"2026-05-12T20:06:54.204Z","0.7.1":"2026-05-15T13:36:57.539Z"},"bugs":{"url":"https://github.com/authn-sh/cdk/issues"},"license":"AGPL-3.0-only","homepage":"https://authn.sh","keywords":["authn","authentication","identity","sso","jwt","aws","cdk","constructs","ecs","fargate"],"repository":{"type":"git","url":"git+https://github.com/authn-sh/cdk.git"},"description":"AWS CDK constructs for deploying authn.sh on AWS. Self-hosted authentication-as-a-service.","maintainers":[{"name":"vagnercsouza","email":"vagnercsouzam@gmail.com"}],"readme":"# @authn-sh/cdk\n\nAWS CDK constructs for deploying [authn.sh](https://authn.sh) on AWS. Sibling project to the [Helm chart](https://github.com/authn-sh/helm).\n\nPulls `ghcr.io/authn-sh/authn:0.7.0` by default and ships with a reference single-account stack — VPC, RDS Postgres (Multi-AZ), ElastiCache for Valkey (Redis-protocol-compatible), ECS Fargate (ARM64) for `web` / `worker` / `scheduler`, internal ALB, ACM, optional CloudFront + WAF. Pass `image.tag` explicitly to pin a specific (e.g. alpha) build.\n\n## Compatibility\n\n| `@authn-sh/cdk` | Default `image.tag` | Chart parity | authn server release |\n|---|---|---|---|\n| `0.7.x` | `0.7.0` | `authn-sh/helm@0.7.0` | v0.7 (OAuth provider mode — env as an OAuth 2.0 / OIDC IdP — and JWT templates) |\n| `0.6.x` | `0.6.0` | `authn-sh/helm@0.6.0` | v0.6 (Enterprise SSO — unified SAML + OIDC, SCIM 2.0 provisioning, verified-domain sign-in routing) |\n| `0.5.x` | `0.5.0` | `authn-sh/helm@0.5.0` | v0.5 (Passkeys, Appearance, Localization, six new OAuth presets) |\n| `0.4.x` | `0.4.0` | `authn-sh/helm@0.4.0` | v0.4 (OAuth social sign-in, phone numbers, SMS engine, `phone_code` 2FA) |\n| `0.3.x` | `0.3.0` | `authn-sh/helm@0.3.0` | v0.3 (MFA: TOTP + backup codes) |\n\n## Install\n\n```bash\nnpm install @authn-sh/cdk aws-cdk-lib constructs\n```\n\n## Quickstart — TypeScript\n\n```ts\nimport { App } from 'aws-cdk-lib';\nimport { InstanceClass, InstanceSize } from 'aws-cdk-lib/aws-ec2';\nimport { AuthnSingleAccountStack } from '@authn-sh/cdk';\n\nconst app = new App();\n\nnew AuthnSingleAccountStack(app, 'Authn', {\n  env: { account: process.env.CDK_DEFAULT_ACCOUNT, region: 'us-east-1' },\n  config: {\n    appUrl: 'https://authn.example.com',\n    routingMode: 'subdomain',\n    defaultFromEmail: 'no-reply@authn.example.com',\n    edge: { hostedZoneId: 'Z0123456789ABCDEFGHIJ' },\n    database: { instanceClass: InstanceClass.T4G, instanceSize: InstanceSize.SMALL, multiAz: true },\n  },\n});\n```\n\n`cdk deploy` and the stack provisions everything.\n\n## Quickstart — YAML config\n\nFor operators who don't want to write TypeScript, point the reference stack at a YAML file:\n\n```yaml\n# authn.config.yaml\nappUrl: https://authn.example.com\nroutingMode: subdomain\ndefaultFromEmail: no-reply@authn.example.com\n\nedge:\n  hostedZoneId: Z0123456789ABCDEFGHIJ\n  customDomainDriver: manual\n\ndatabase:\n  instanceClass: t4g\n  instanceSize: small\n  multiAz: true\n\ncache:\n  enabled: true\n  multiAz: true\n```\n\n```ts\nimport { App } from 'aws-cdk-lib';\nimport { AuthnSingleAccountStack, loadConfig } from '@authn-sh/cdk';\n\nconst app = new App();\nnew AuthnSingleAccountStack(app, 'Authn', {\n  env: { account: process.env.CDK_DEFAULT_ACCOUNT, region: 'us-east-1' },\n  config: loadConfig('./authn.config.yaml'),\n});\n```\n\nSee [`examples/single-account-minimal/`](./examples/single-account-minimal) for a runnable starter.\n\n## Routing modes\n\n- `subdomain` (default) — wildcard DNS + TLS required. Each tenant environment lives at `<routing_label>.<APP_HOST>`. Wildcard ACM cert auto-provisioned in `us-east-1` with DNS-01 validation against the configured hosted zone.\n- `path` — single host. Tenant envs live at `<APP_HOST>/<routing_label>`. Simpler — no wildcard cert.\n\n## Bring-your-own database / cache\n\nEither provision managed RDS + ElastiCache (default) or point at existing endpoints:\n\n```yaml\ndatabase:\n  enabled: false\nexternalDatabase:\n  host: postgres.internal\n  port: 5432\n  database: authn\n  username: authn\n\ncache:\n  enabled: false\nexternalRedis:\n  host: redis.internal\n  port: 6379\n```\n\nPasswords go through the same `secrets` map as inline credentials — see below.\n\n## Secrets\n\nSecrets live in AWS Secrets Manager. Either inject inline values (creates a new secret in your account) or pass an existing Secrets Manager ARN:\n\n```yaml\nsecrets:\n  existingSecretArn: arn:aws:secretsmanager:us-east-1:123456789012:secret:authn-prod-AbCdEf\n  # or:\n  values:\n    APP_KEY: \"base64:...\"          # `openssl rand -base64 32 | sed 's/^/base64:/'`\n    AUTHN_BOOTSTRAP_ADMIN_EMAIL: op@example.com\n    AUTHN_BOOTSTRAP_ADMIN_PASSWORD: change-me-please\n    AUTHN_BOOTSTRAP_WORKSPACE_NAME: My workspace\n    DB_PASSWORD: ...\n    REDIS_PASSWORD: ...\n    MAIL_PASSWORD: ...\n```\n\nECS task definitions reference the secret via the `secrets:` block — values never appear in env vars or stack outputs.\n\n## SMS\n\nv0.4 introduces an SMS engine for phone-number verification and the `phone_code` second factor. The construct exposes a typed `sms` block:\n\n```yaml\nsms:\n  driver: twilio   # or \"vonage\" / \"null\" (default)\n  fromNumber: \"+15551234567\"\n  twilio:\n    accountSid: ACxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\n    authTokenSecretArn: arn:aws:secretsmanager:us-east-1:123456789012:secret:authn-twilio-AbCdEf\n    messagingServiceSid: MGxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\n```\n\nThe `*SecretArn` fields point at AWS Secrets Manager secrets — the construct wires them onto the `web` + `worker` task definitions as ECS secrets. The `scheduler` doesn't dispatch SMS, so it's left out. Per-environment overrides still go through the BAPI `Environment.sms.*` config at runtime.\n\n## Enterprise SSO\n\nv0.6 introduces unified SAML + OIDC enterprise connections plus SCIM 2.0 directory sync. Both surfaces are configured at the application layer (BAPI / FAPI `/v1/.../enterprise-connections` + `/scim/v2/*`) and need no CDK wiring — the construct exposes one optional config block for the SAML SP signing key, used to sign outbound AuthnRequests when an IdP rejects unsigned ones:\n\n```yaml\nenterpriseSso:\n  samlSpSigningKeySecretArn: arn:aws:secretsmanager:us-east-1:123456789012:secret:authn-saml-sp-signing-AbCdEf\n```\n\nWhen set, the secret is wired into every task definition as the `AUTHN_SAML_SP_SIGNING_KEY_B64` env (via `Secret.fromSecretsManager`). The value is a base64-encoded PEM-format private key. Both fields on the block are optional — connections without a configured SP signing key skip signing AuthnRequests, which most IdPs accept. A per-connection `EnterpriseConnection.saml_signing_key` (stored encrypted on the application-side row) takes precedence over the env-var fallback when set.\n\n## Custom domains\n\nThe `authn` app supports customer-provided domains (e.g., `auth.customer.com`) via a pluggable driver. The CDK construct provisions the AWS-side resources each driver needs:\n\n| `customDomainDriver` | Provisions |\n|---|---|\n| `cloudfront-saas` | CloudFront multi-tenant distribution + IAM permissions on the task role for `cloudfront:*DistributionTenant*` and `acm:*` |\n| `cloudflare-saas` | No AWS-side provisioning; expects `CLOUDFLARE_API_TOKEN` + `CLOUDFLARE_ZONE_ID` to be set on the app |\n| `manual` (default) | Nothing — operator manages the edge themselves |\n| `null` | Tests only |\n\n## Custom domains: one CNAME for customers\n\nWhen you choose `cloudfront-saas`, the construct provisions the multi-tenant distribution and exports its domain. Point a stable CNAME (e.g., `cname.authn.example.com`) at it and tell your customers to CNAME their own domains there.\n\n## After install\n\nThe bootstrap one-shot task runs on first deploy. Tail it via the CloudWatch log group `/aws/ecs/<stack>/bootstrap`. The first operator's `pk_live_…` and `sk_live_…` keys are printed once. Save them.\n\n## Upgrade\n\nBump `image.tag` and `cdk deploy`. Migrations run as part of the bootstrap task on each deploy (idempotent).\n\n## License\n\n[AGPL-3.0-only](./LICENSE).\n","readmeFilename":"README.md"}