apm-wo-analysis/terraform/vpc.tf
Adam Moussa f13d2e3ff1
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
feat(infra): migrate pipeline and Grafana to HCP Terraform (PLAT-75) (#57)
* feat(infra): migrate pipeline and Grafana to HCP Terraform (PLAT-75)

Move apm-wo-analysis into seahaven-prod under workspace apm-wo-analysis-prod
with in-repo hcptf/githubdeploy IAM, stub Lambdas, and GitHub Actions zip CD.

* chore(iam): add Checkov skip comments for HCP IAM documents

Pre-push HIGH findings are the DLM snapshot describe, tagged EC2 creates,
exec boundary DescribeLogGroups star, and the drop-uploader user policy.
2026-09-16 20:33:24 +00:00

103 lines
2.1 KiB
HCL

resource "aws_vpc" "grafana" {
cidr_block = var.vpc_cidr
enable_dns_support = true
enable_dns_hostnames = true
tags = {
Name = "apm-wo-analysis-grafana"
}
}
resource "aws_internet_gateway" "grafana" {
vpc_id = aws_vpc.grafana.id
tags = {
Name = "apm-wo-analysis-grafana"
}
}
resource "aws_subnet" "public" {
for_each = local.public_subnet_cidrs
vpc_id = aws_vpc.grafana.id
cidr_block = each.value
availability_zone = each.key
map_public_ip_on_launch = true
tags = {
Name = "apm-wo-analysis-grafana-public-${each.key}"
}
}
resource "aws_subnet" "private" {
for_each = local.private_subnet_cidrs
vpc_id = aws_vpc.grafana.id
cidr_block = each.value
availability_zone = each.key
tags = {
Name = "apm-wo-analysis-grafana-private-${each.key}"
}
}
resource "aws_eip" "nat" {
domain = "vpc"
tags = {
Name = "apm-wo-analysis-grafana-nat"
}
depends_on = [aws_internet_gateway.grafana]
}
resource "aws_nat_gateway" "grafana" {
allocation_id = aws_eip.nat.id
subnet_id = aws_subnet.public["${var.aws_region}a"].id
tags = {
Name = "apm-wo-analysis-grafana"
}
}
resource "aws_route_table" "public" {
vpc_id = aws_vpc.grafana.id
tags = {
Name = "apm-wo-analysis-grafana-public"
}
}
resource "aws_route" "public_internet" {
route_table_id = aws_route_table.public.id
destination_cidr_block = "0.0.0.0/0"
gateway_id = aws_internet_gateway.grafana.id
}
resource "aws_route_table_association" "public" {
for_each = aws_subnet.public
subnet_id = each.value.id
route_table_id = aws_route_table.public.id
}
resource "aws_route_table" "private" {
vpc_id = aws_vpc.grafana.id
tags = {
Name = "apm-wo-analysis-grafana-private"
}
}
resource "aws_route" "private_nat" {
route_table_id = aws_route_table.private.id
destination_cidr_block = "0.0.0.0/0"
nat_gateway_id = aws_nat_gateway.grafana.id
}
resource "aws_route_table_association" "private" {
for_each = aws_subnet.private
subnet_id = each.value.id
route_table_id = aws_route_table.private.id
}