file-share/terraform/network.tf
Adam Moussa 7cb3f6510f
feat(infra): add HCP Terraform for the prod file share (PLAT-77)
The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy.
2026-09-28 16:38:03 -04:00

59 lines
1.3 KiB
HCL

data "aws_vpc" "syslog" {
filter {
name = "tag:Name"
values = ["syslog-server-vpc"]
}
}
data "aws_internet_gateway" "syslog" {
filter {
name = "tag:Name"
values = ["syslog-server-igw"]
}
}
data "aws_vpn_gateway" "syslog" {
filter {
name = "tag:Name"
values = ["syslog-server-office"]
}
attached_vpc_id = data.aws_vpc.syslog.id
}
data "aws_route_table" "syslog_public" {
vpc_id = data.aws_vpc.syslog.id
filter {
name = "tag:Name"
values = ["syslog-server-public"]
}
}
resource "aws_subnet" "file_share" {
vpc_id = data.aws_vpc.syslog.id
cidr_block = local.subnet_cidr
availability_zone = local.subnet_az
map_public_ip_on_launch = true
tags = {
Name = "file-share"
}
lifecycle {
precondition {
condition = one(data.aws_internet_gateway.syslog.attachments[*].vpc_id) == data.aws_vpc.syslog.id
error_message = "syslog IGW is not attached to the syslog VPC."
}
precondition {
condition = data.aws_vpn_gateway.syslog.attached_vpc_id == data.aws_vpc.syslog.id
error_message = "syslog VPN gateway is not attached to the syslog VPC."
}
}
}
resource "aws_route_table_association" "file_share" {
subnet_id = aws_subnet.file_share.id
route_table_id = data.aws_route_table.syslog_public.id
}