mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 09:33:13 +00:00
Add import-only dev and staging state with least-privilege HCP authentication and plan safety guards.
66 lines
1.7 KiB
HCL
66 lines
1.7 KiB
HCL
resource "aws_db_subnet_group" "poc" {
|
|
name = "shoc-backend-tf-poc"
|
|
subnet_ids = var.private_subnet_ids
|
|
|
|
tags = {
|
|
Name = "shoc-backend-tf-poc"
|
|
}
|
|
|
|
depends_on = [terraform_data.account_guard]
|
|
}
|
|
|
|
resource "aws_db_instance" "poc" {
|
|
identifier = var.rds_identifier
|
|
engine = "sqlserver-ex"
|
|
instance_class = var.rds_instance_class
|
|
license_model = "license-included"
|
|
|
|
allocated_storage = var.rds_allocated_storage
|
|
max_allocated_storage = var.rds_allocated_storage
|
|
storage_type = "gp3"
|
|
storage_encrypted = true
|
|
|
|
username = var.rds_master_username
|
|
manage_master_user_password = true
|
|
|
|
db_subnet_group_name = aws_db_subnet_group.poc.name
|
|
vpc_security_group_ids = [aws_security_group.rds.id]
|
|
publicly_accessible = false
|
|
multi_az = false
|
|
port = 1433
|
|
|
|
backup_retention_period = 1
|
|
deletion_protection = false
|
|
skip_final_snapshot = true
|
|
apply_immediately = true
|
|
copy_tags_to_snapshot = true
|
|
|
|
tags = {
|
|
Name = var.rds_identifier
|
|
}
|
|
|
|
timeouts {
|
|
create = "90m"
|
|
update = "90m"
|
|
delete = "90m"
|
|
}
|
|
}
|
|
|
|
data "aws_secretsmanager_secret_version" "rds_master" {
|
|
secret_id = aws_db_instance.poc.master_user_secret[0].secret_arn
|
|
depends_on = [aws_db_instance.poc]
|
|
}
|
|
|
|
locals {
|
|
rds_master = jsondecode(data.aws_secretsmanager_secret_version.rds_master.secret_string)
|
|
|
|
connection_string = join(";", [
|
|
"Server=${aws_db_instance.poc.address},${aws_db_instance.poc.port}",
|
|
"Initial Catalog=${var.database_name}",
|
|
"User Id=${local.rds_master["username"]}",
|
|
"Password=${local.rds_master["password"]}",
|
|
"Encrypt=True",
|
|
"TrustServerCertificate=True",
|
|
"MultipleActiveResultSets=true",
|
|
])
|
|
}
|