apm-wo-analysis/terraform/dlm.tf

90 lines
2.1 KiB
Terraform
Raw Normal View History

data "aws_iam_policy_document" "dlm_assume" {
statement {
effect = "Allow"
actions = ["sts:AssumeRole"]
principals {
type = "Service"
identifiers = ["dlm.amazonaws.com"]
}
}
}
resource "aws_iam_role" "dlm" {
name = "apm-wo-analysis-grafana-dlm"
path = "/tf-managed/"
description = "DLM snapshot role for the Grafana instance volume"
assume_role_policy = data.aws_iam_policy_document.dlm_assume.json
permissions_boundary = aws_iam_policy.exec_boundary.arn
}
data "aws_iam_policy_document" "dlm" {
# checkov:skip=CKV_AWS_111: DLM CreateSnapshot/Describe* require Resource=*. Role is boundary-attached and limited to the tagged Grafana volume.
statement {
sid = "DlmSnapshots"
effect = "Allow"
actions = [
"ec2:CreateSnapshot",
"ec2:CreateSnapshots",
"ec2:DeleteSnapshot",
"ec2:DescribeInstances",
"ec2:DescribeVolumes",
"ec2:DescribeSnapshots",
"ec2:DescribeTags",
"ec2:CreateTags",
"ec2:DeleteTags",
]
resources = ["*"]
}
statement {
sid = "DlmKms"
effect = "Allow"
actions = [
"kms:CreateGrant",
"kms:DescribeKey",
"kms:GenerateDataKeyWithoutPlaintext",
"kms:ReEncryptFrom",
"kms:ReEncryptTo",
"kms:ListGrants",
]
resources = [
"arn:aws:kms:${var.aws_region}:${local.account_id}:key/*",
]
}
}
resource "aws_iam_role_policy" "dlm" {
name = "grafana-dlm-snapshots"
role = aws_iam_role.dlm.id
policy = data.aws_iam_policy_document.dlm.json
}
resource "aws_dlm_lifecycle_policy" "grafana" {
description = "Daily snapshot of the apm-wo grafana volume"
execution_role_arn = aws_iam_role.dlm.arn
state = "ENABLED"
policy_details {
resource_types = ["INSTANCE"]
target_tags = {
(local.grafana_backup_tag) = "true"
}
schedule {
name = "daily"
create_rule {
interval = 24
interval_unit = "HOURS"
times = ["07:00"]
}
retain_rule {
count = 7
}
}
}
}