mirror of
https://github.com/Sea-Haven-Industries/file-share.git
synced 2026-09-30 03:13:11 +00:00
* feat(infra): add HCP Terraform for the prod file share (PLAT-77) The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy. * fix(infra): pin FileBrowser version to a release tag (PLAT-77) The version is interpolated into the boot script. Reject anything that is not a vX.Y.Z tag. * fix(infra): keep the file share off the public internet (PLAT-77) The instance has no public IP. Office routes use the syslog VPN gateway and other egress uses a NAT gateway. DLM targets the tagged data volume, and replacement detaches stop the instance first.
28 lines
927 B
HCL
28 lines
927 B
HCL
locals {
|
|
project = "file-share"
|
|
environment = "prod"
|
|
|
|
hcp_project = "seahaven-prod"
|
|
hcp_workspace = "file-share-prod"
|
|
apply_role = "hcptf-file-share"
|
|
plan_role = "hcptf-file-share-plan"
|
|
stack_name = local.project
|
|
stack_prefix = "file-share-"
|
|
|
|
instance_role_name = "file-share-role"
|
|
instance_profile_name = "file-share-profile"
|
|
boundary_name = "file-share-instance-boundary"
|
|
|
|
office_lan_cidrs = ["10.10.0.0/16", "10.30.0.0/16"]
|
|
subnet_cidr = "10.40.20.0/24"
|
|
subnet_az = "us-east-1a"
|
|
|
|
create_instance = var.data_volume_id != ""
|
|
|
|
dlm_service_role_arn = "arn:aws:iam::${data.aws_caller_identity.current.account_id}:role/aws-service-role/dlm.amazonaws.com/AWSServiceRoleForDataLifecycleManager"
|
|
|
|
user_data = templatefile("${path.module}/user_data.sh.tftpl", {
|
|
aws_region = var.aws_region
|
|
filebrowser_version = var.filebrowser_version
|
|
})
|
|
}
|