file-share/terraform/dlm.tf
Adam Moussa 7c72159f31
feat(infra): add HCP Terraform for the prod file share (PLAT-77) (#56)
* feat(infra): add HCP Terraform for the prod file share (PLAT-77)

The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy.

* fix(infra): pin FileBrowser version to a release tag (PLAT-77)

The version is interpolated into the boot script. Reject anything that is not a vX.Y.Z tag.

* fix(infra): keep the file share off the public internet (PLAT-77)

The instance has no public IP. Office routes use the syslog VPN gateway and other egress uses a NAT gateway. DLM targets the tagged data volume, and replacement detaches stop the instance first.
2026-09-29 22:32:39 +00:00

29 lines
563 B
HCL

resource "aws_dlm_lifecycle_policy" "nightly" {
description = "Nightly EBS snapshots for file share"
execution_role_arn = local.dlm_service_role_arn
state = "ENABLED"
policy_details {
resource_types = ["VOLUME"]
target_tags = {
"file-share-backup" = "true"
}
schedule {
name = "file-share-nightly"
create_rule {
interval = 24
interval_unit = "HOURS"
times = ["06:00"]
}
retain_rule {
count = 30
}
copy_tags = true
}
}
}