mirror of
https://github.com/Sea-Haven-Industries/forgejo.git
synced 2026-09-30 04:13:11 +00:00
118 lines
3 KiB
Terraform
118 lines
3 KiB
Terraform
|
|
resource "aws_security_group" "alb" {
|
||
|
|
name = "forgejo-alb"
|
||
|
|
description = "Public entry for the Forgejo ALB"
|
||
|
|
vpc_id = var.existing_vpc_id
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_vpc_security_group_ingress_rule" "alb_http" {
|
||
|
|
security_group_id = aws_security_group.alb.id
|
||
|
|
cidr_ipv4 = "0.0.0.0/0"
|
||
|
|
from_port = 80
|
||
|
|
to_port = 80
|
||
|
|
ip_protocol = "tcp"
|
||
|
|
description = "HTTP. Redirects to HTTPS after enable_https."
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_vpc_security_group_ingress_rule" "alb_https" {
|
||
|
|
security_group_id = aws_security_group.alb.id
|
||
|
|
cidr_ipv4 = "0.0.0.0/0"
|
||
|
|
from_port = 443
|
||
|
|
to_port = 443
|
||
|
|
ip_protocol = "tcp"
|
||
|
|
description = "HTTPS"
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_vpc_security_group_egress_rule" "alb_to_instance" {
|
||
|
|
security_group_id = aws_security_group.alb.id
|
||
|
|
referenced_security_group_id = aws_security_group.instance.id
|
||
|
|
from_port = 3000
|
||
|
|
to_port = 3000
|
||
|
|
ip_protocol = "tcp"
|
||
|
|
description = "Forgejo HTTP"
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_lb" "forgejo" {
|
||
|
|
name = "forgejo"
|
||
|
|
internal = false
|
||
|
|
load_balancer_type = "application"
|
||
|
|
security_groups = [aws_security_group.alb.id]
|
||
|
|
subnets = var.existing_public_subnet_ids
|
||
|
|
drop_invalid_header_fields = true
|
||
|
|
enable_deletion_protection = true
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_lb_target_group" "forgejo" {
|
||
|
|
name = "forgejo"
|
||
|
|
port = 3000
|
||
|
|
protocol = "HTTP"
|
||
|
|
vpc_id = var.existing_vpc_id
|
||
|
|
|
||
|
|
health_check {
|
||
|
|
path = "/"
|
||
|
|
matcher = "200,302"
|
||
|
|
healthy_threshold = 2
|
||
|
|
unhealthy_threshold = 2
|
||
|
|
}
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_lb_target_group_attachment" "forgejo" {
|
||
|
|
target_group_arn = aws_lb_target_group.forgejo.arn
|
||
|
|
target_id = aws_instance.forgejo.id
|
||
|
|
port = 3000
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_acm_certificate" "forgejo" {
|
||
|
|
domain_name = "forgejo.seahaven.com"
|
||
|
|
validation_method = "DNS"
|
||
|
|
|
||
|
|
lifecycle {
|
||
|
|
create_before_destroy = true
|
||
|
|
}
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_lb_listener" "http" {
|
||
|
|
count = var.enable_https ? 0 : 1
|
||
|
|
|
||
|
|
load_balancer_arn = aws_lb.forgejo.arn
|
||
|
|
port = 80
|
||
|
|
protocol = "HTTP"
|
||
|
|
|
||
|
|
default_action {
|
||
|
|
type = "forward"
|
||
|
|
target_group_arn = aws_lb_target_group.forgejo.arn
|
||
|
|
}
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_lb_listener" "http_redirect" {
|
||
|
|
count = var.enable_https ? 1 : 0
|
||
|
|
|
||
|
|
load_balancer_arn = aws_lb.forgejo.arn
|
||
|
|
port = 80
|
||
|
|
protocol = "HTTP"
|
||
|
|
|
||
|
|
default_action {
|
||
|
|
type = "redirect"
|
||
|
|
|
||
|
|
redirect {
|
||
|
|
port = "443"
|
||
|
|
protocol = "HTTPS"
|
||
|
|
status_code = "HTTP_301"
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_lb_listener" "https" {
|
||
|
|
count = var.enable_https ? 1 : 0
|
||
|
|
|
||
|
|
load_balancer_arn = aws_lb.forgejo.arn
|
||
|
|
port = 443
|
||
|
|
protocol = "HTTPS"
|
||
|
|
ssl_policy = "ELBSecurityPolicy-TLS13-1-2-2021-06"
|
||
|
|
certificate_arn = aws_acm_certificate.forgejo.arn
|
||
|
|
|
||
|
|
default_action {
|
||
|
|
type = "forward"
|
||
|
|
target_group_arn = aws_lb_target_group.forgejo.arn
|
||
|
|
}
|
||
|
|
}
|