file-share/terraform/locals.tf
Adam Moussa 7c72159f31
feat(infra): add HCP Terraform for the prod file share (PLAT-77) (#56)
* feat(infra): add HCP Terraform for the prod file share (PLAT-77)

The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy.

* fix(infra): pin FileBrowser version to a release tag (PLAT-77)

The version is interpolated into the boot script. Reject anything that is not a vX.Y.Z tag.

* fix(infra): keep the file share off the public internet (PLAT-77)

The instance has no public IP. Office routes use the syslog VPN gateway and other egress uses a NAT gateway. DLM targets the tagged data volume, and replacement detaches stop the instance first.
2026-09-29 22:32:39 +00:00

28 lines
927 B
HCL

locals {
project = "file-share"
environment = "prod"
hcp_project = "seahaven-prod"
hcp_workspace = "file-share-prod"
apply_role = "hcptf-file-share"
plan_role = "hcptf-file-share-plan"
stack_name = local.project
stack_prefix = "file-share-"
instance_role_name = "file-share-role"
instance_profile_name = "file-share-profile"
boundary_name = "file-share-instance-boundary"
office_lan_cidrs = ["10.10.0.0/16", "10.30.0.0/16"]
subnet_cidr = "10.40.20.0/24"
subnet_az = "us-east-1a"
create_instance = var.data_volume_id != ""
dlm_service_role_arn = "arn:aws:iam::${data.aws_caller_identity.current.account_id}:role/aws-service-role/dlm.amazonaws.com/AWSServiceRoleForDataLifecycleManager"
user_data = templatefile("${path.module}/user_data.sh.tftpl", {
aws_region = var.aws_region
filebrowser_version = var.filebrowser_version
})
}