mirror of
https://github.com/Sea-Haven-Industries/file-share.git
synced 2026-09-30 12:23:17 +00:00
The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy.
49 lines
1.4 KiB
HCL
49 lines
1.4 KiB
HCL
resource "aws_security_group" "file_share" {
|
|
name = "file-share"
|
|
description = "SMB, FileBrowser, and SFTP from office LANs"
|
|
vpc_id = data.aws_vpc.syslog.id
|
|
|
|
tags = {
|
|
Name = "file-share"
|
|
}
|
|
}
|
|
|
|
resource "aws_vpc_security_group_egress_rule" "all" {
|
|
security_group_id = aws_security_group.file_share.id
|
|
ip_protocol = "-1"
|
|
cidr_ipv4 = "0.0.0.0/0"
|
|
description = "Outbound for package install, Secrets Manager, and SSM"
|
|
}
|
|
|
|
resource "aws_vpc_security_group_ingress_rule" "smb" {
|
|
for_each = toset(local.office_lan_cidrs)
|
|
|
|
security_group_id = aws_security_group.file_share.id
|
|
ip_protocol = "tcp"
|
|
from_port = 445
|
|
to_port = 445
|
|
cidr_ipv4 = each.value
|
|
description = "SMB from office LAN"
|
|
}
|
|
|
|
resource "aws_vpc_security_group_ingress_rule" "filebrowser" {
|
|
for_each = toset(local.office_lan_cidrs)
|
|
|
|
security_group_id = aws_security_group.file_share.id
|
|
ip_protocol = "tcp"
|
|
from_port = 8080
|
|
to_port = 8080
|
|
cidr_ipv4 = each.value
|
|
description = "FileBrowser from office LAN"
|
|
}
|
|
|
|
resource "aws_vpc_security_group_ingress_rule" "sftp" {
|
|
for_each = toset(local.office_lan_cidrs)
|
|
|
|
security_group_id = aws_security_group.file_share.id
|
|
ip_protocol = "tcp"
|
|
from_port = 22
|
|
to_port = 22
|
|
cidr_ipv4 = each.value
|
|
description = "SFTP from office LAN"
|
|
}
|