mirror of
https://github.com/Sea-Haven-Industries/file-share.git
synced 2026-09-30 20:33:17 +00:00
* feat(infra): add HCP Terraform for the prod file share (PLAT-77) The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy. * fix(infra): pin FileBrowser version to a release tag (PLAT-77) The version is interpolated into the boot script. Reject anything that is not a vX.Y.Z tag. * fix(infra): keep the file share off the public internet (PLAT-77) The instance has no public IP. Office routes use the syslog VPN gateway and other egress uses a NAT gateway. DLM targets the tagged data volume, and replacement detaches stop the instance first.
44 lines
1.2 KiB
HCL
44 lines
1.2 KiB
HCL
resource "aws_instance" "this" {
|
|
count = local.create_instance ? 1 : 0
|
|
|
|
ami = var.ami_id
|
|
instance_type = "t4g.small"
|
|
subnet_id = aws_subnet.file_share.id
|
|
vpc_security_group_ids = [aws_security_group.file_share.id]
|
|
iam_instance_profile = aws_iam_instance_profile.this.name
|
|
associate_public_ip_address = false
|
|
user_data = local.user_data
|
|
user_data_replace_on_change = false
|
|
|
|
root_block_device {
|
|
volume_size = 20
|
|
volume_type = "gp3"
|
|
encrypted = true
|
|
}
|
|
|
|
metadata_options {
|
|
http_endpoint = "enabled"
|
|
http_tokens = "required"
|
|
}
|
|
|
|
tags = {
|
|
Name = "file-share"
|
|
"file-share-backup" = "true"
|
|
}
|
|
|
|
lifecycle {
|
|
postcondition {
|
|
condition = self.public_ip == null || self.public_ip == ""
|
|
error_message = "file-share must not have a public IP."
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_volume_attachment" "data" {
|
|
count = local.create_instance ? 1 : 0
|
|
|
|
device_name = "/dev/xvdf"
|
|
volume_id = var.data_volume_id
|
|
instance_id = aws_instance.this[0].id
|
|
stop_instance_before_detaching = true
|
|
}
|