file-share/terraform/security.tf
Adam Moussa 7c72159f31
feat(infra): add HCP Terraform for the prod file share (PLAT-77) (#56)
* feat(infra): add HCP Terraform for the prod file share (PLAT-77)

The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy.

* fix(infra): pin FileBrowser version to a release tag (PLAT-77)

The version is interpolated into the boot script. Reject anything that is not a vX.Y.Z tag.

* fix(infra): keep the file share off the public internet (PLAT-77)

The instance has no public IP. Office routes use the syslog VPN gateway and other egress uses a NAT gateway. DLM targets the tagged data volume, and replacement detaches stop the instance first.
2026-09-29 22:32:39 +00:00

49 lines
1.4 KiB
HCL

resource "aws_security_group" "file_share" {
name = "file-share"
description = "SMB, FileBrowser, and SFTP from office LANs"
vpc_id = data.aws_vpc.syslog.id
tags = {
Name = "file-share"
}
}
resource "aws_vpc_security_group_egress_rule" "all" {
security_group_id = aws_security_group.file_share.id
ip_protocol = "-1"
cidr_ipv4 = "0.0.0.0/0"
description = "Outbound for package install, Secrets Manager, and SSM"
}
resource "aws_vpc_security_group_ingress_rule" "smb" {
for_each = toset(local.office_lan_cidrs)
security_group_id = aws_security_group.file_share.id
ip_protocol = "tcp"
from_port = 445
to_port = 445
cidr_ipv4 = each.value
description = "SMB from office LAN"
}
resource "aws_vpc_security_group_ingress_rule" "filebrowser" {
for_each = toset(local.office_lan_cidrs)
security_group_id = aws_security_group.file_share.id
ip_protocol = "tcp"
from_port = 8080
to_port = 8080
cidr_ipv4 = each.value
description = "FileBrowser from office LAN"
}
resource "aws_vpc_security_group_ingress_rule" "sftp" {
for_each = toset(local.office_lan_cidrs)
security_group_id = aws_security_group.file_share.id
ip_protocol = "tcp"
from_port = 22
to_port = 22
cidr_ipv4 = each.value
description = "SFTP from office LAN"
}