mirror of
https://github.com/Sea-Haven-Industries/file-share.git
synced 2026-09-30 04:23:11 +00:00
* feat(infra): add HCP Terraform for the prod file share (PLAT-77) The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy. * fix(infra): pin FileBrowser version to a release tag (PLAT-77) The version is interpolated into the boot script. Reject anything that is not a vX.Y.Z tag. * fix(infra): keep the file share off the public internet (PLAT-77) The instance has no public IP. Office routes use the syslog VPN gateway and other egress uses a NAT gateway. DLM targets the tagged data volume, and replacement detaches stop the instance first.
49 lines
1.4 KiB
HCL
49 lines
1.4 KiB
HCL
resource "aws_security_group" "file_share" {
|
|
name = "file-share"
|
|
description = "SMB, FileBrowser, and SFTP from office LANs"
|
|
vpc_id = data.aws_vpc.syslog.id
|
|
|
|
tags = {
|
|
Name = "file-share"
|
|
}
|
|
}
|
|
|
|
resource "aws_vpc_security_group_egress_rule" "all" {
|
|
security_group_id = aws_security_group.file_share.id
|
|
ip_protocol = "-1"
|
|
cidr_ipv4 = "0.0.0.0/0"
|
|
description = "Outbound for package install, Secrets Manager, and SSM"
|
|
}
|
|
|
|
resource "aws_vpc_security_group_ingress_rule" "smb" {
|
|
for_each = toset(local.office_lan_cidrs)
|
|
|
|
security_group_id = aws_security_group.file_share.id
|
|
ip_protocol = "tcp"
|
|
from_port = 445
|
|
to_port = 445
|
|
cidr_ipv4 = each.value
|
|
description = "SMB from office LAN"
|
|
}
|
|
|
|
resource "aws_vpc_security_group_ingress_rule" "filebrowser" {
|
|
for_each = toset(local.office_lan_cidrs)
|
|
|
|
security_group_id = aws_security_group.file_share.id
|
|
ip_protocol = "tcp"
|
|
from_port = 8080
|
|
to_port = 8080
|
|
cidr_ipv4 = each.value
|
|
description = "FileBrowser from office LAN"
|
|
}
|
|
|
|
resource "aws_vpc_security_group_ingress_rule" "sftp" {
|
|
for_each = toset(local.office_lan_cidrs)
|
|
|
|
security_group_id = aws_security_group.file_share.id
|
|
ip_protocol = "tcp"
|
|
from_port = 22
|
|
to_port = 22
|
|
cidr_ipv4 = each.value
|
|
description = "SFTP from office LAN"
|
|
}
|