mirror of
https://github.com/Sea-Haven-Industries/apm-wo-analysis.git
synced 2026-09-30 07:43:15 +00:00
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* feat(infra): migrate pipeline and Grafana to HCP Terraform (PLAT-75) Move apm-wo-analysis into seahaven-prod under workspace apm-wo-analysis-prod with in-repo hcptf/githubdeploy IAM, stub Lambdas, and GitHub Actions zip CD. * chore(iam): add Checkov skip comments for HCP IAM documents Pre-push HIGH findings are the DLM snapshot describe, tagged EC2 creates, exec boundary DescribeLogGroups star, and the drop-uploader user policy.
89 lines
2.1 KiB
HCL
89 lines
2.1 KiB
HCL
data "aws_iam_policy_document" "dlm_assume" {
|
|
statement {
|
|
effect = "Allow"
|
|
actions = ["sts:AssumeRole"]
|
|
|
|
principals {
|
|
type = "Service"
|
|
identifiers = ["dlm.amazonaws.com"]
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role" "dlm" {
|
|
name = "apm-wo-analysis-grafana-dlm"
|
|
path = "/tf-managed/"
|
|
description = "DLM snapshot role for the Grafana instance volume"
|
|
assume_role_policy = data.aws_iam_policy_document.dlm_assume.json
|
|
permissions_boundary = aws_iam_policy.exec_boundary.arn
|
|
}
|
|
|
|
data "aws_iam_policy_document" "dlm" {
|
|
# checkov:skip=CKV_AWS_111: DLM CreateSnapshot/Describe* require Resource=*. Role is boundary-attached and limited to the tagged Grafana volume.
|
|
statement {
|
|
sid = "DlmSnapshots"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ec2:CreateSnapshot",
|
|
"ec2:CreateSnapshots",
|
|
"ec2:DeleteSnapshot",
|
|
"ec2:DescribeInstances",
|
|
"ec2:DescribeVolumes",
|
|
"ec2:DescribeSnapshots",
|
|
"ec2:DescribeTags",
|
|
"ec2:CreateTags",
|
|
"ec2:DeleteTags",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "DlmKms"
|
|
effect = "Allow"
|
|
actions = [
|
|
"kms:CreateGrant",
|
|
"kms:DescribeKey",
|
|
"kms:GenerateDataKeyWithoutPlaintext",
|
|
"kms:ReEncryptFrom",
|
|
"kms:ReEncryptTo",
|
|
"kms:ListGrants",
|
|
]
|
|
resources = [
|
|
"arn:aws:kms:${var.aws_region}:${local.account_id}:key/*",
|
|
]
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role_policy" "dlm" {
|
|
name = "grafana-dlm-snapshots"
|
|
role = aws_iam_role.dlm.id
|
|
policy = data.aws_iam_policy_document.dlm.json
|
|
}
|
|
|
|
resource "aws_dlm_lifecycle_policy" "grafana" {
|
|
description = "Daily snapshot of the apm-wo grafana volume"
|
|
execution_role_arn = aws_iam_role.dlm.arn
|
|
state = "ENABLED"
|
|
|
|
policy_details {
|
|
resource_types = ["INSTANCE"]
|
|
|
|
target_tags = {
|
|
(local.grafana_backup_tag) = "true"
|
|
}
|
|
|
|
schedule {
|
|
name = "daily"
|
|
|
|
create_rule {
|
|
interval = 24
|
|
interval_unit = "HOURS"
|
|
times = ["07:00"]
|
|
}
|
|
|
|
retain_rule {
|
|
count = 7
|
|
}
|
|
}
|
|
}
|
|
}
|