mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 15:23:12 +00:00
Add import-only dev and staging state with least-privilege HCP authentication and plan safety guards.
93 lines
2.7 KiB
HCL
93 lines
2.7 KiB
HCL
resource "aws_security_group" "eb" {
|
|
name = "shoc-backend-tf-poc-eb"
|
|
description = "Elastic Beanstalk instances for shoc-backend-tf-poc"
|
|
vpc_id = var.vpc_id
|
|
|
|
tags = {
|
|
Name = "shoc-backend-tf-poc-eb"
|
|
Project = "shoc-backend"
|
|
}
|
|
|
|
depends_on = [terraform_data.account_guard]
|
|
}
|
|
|
|
resource "aws_vpc_security_group_egress_rule" "eb_all" {
|
|
security_group_id = aws_security_group.eb.id
|
|
cidr_ipv4 = "0.0.0.0/0"
|
|
ip_protocol = "-1"
|
|
description = "Instances need outbound for Secrets Manager, Windows Update-style platform, and HTTPS."
|
|
}
|
|
|
|
resource "aws_security_group" "alb" {
|
|
name = "shoc-backend-tf-poc-alb"
|
|
description = "Application load balancer for shoc-backend-tf-poc"
|
|
vpc_id = var.vpc_id
|
|
|
|
tags = {
|
|
Name = "shoc-backend-tf-poc-alb"
|
|
Project = "shoc-backend"
|
|
}
|
|
|
|
depends_on = [terraform_data.account_guard]
|
|
}
|
|
|
|
resource "aws_vpc_security_group_ingress_rule" "alb_http" {
|
|
security_group_id = aws_security_group.alb.id
|
|
cidr_ipv4 = "0.0.0.0/0"
|
|
from_port = 80
|
|
to_port = 80
|
|
ip_protocol = "tcp"
|
|
description = "HTTP (redirected to HTTPS by the load balancer)"
|
|
}
|
|
|
|
resource "aws_vpc_security_group_ingress_rule" "alb_https" {
|
|
security_group_id = aws_security_group.alb.id
|
|
cidr_ipv4 = "0.0.0.0/0"
|
|
from_port = 443
|
|
to_port = 443
|
|
ip_protocol = "tcp"
|
|
description = "HTTPS"
|
|
}
|
|
|
|
resource "aws_vpc_security_group_egress_rule" "alb_all" {
|
|
security_group_id = aws_security_group.alb.id
|
|
cidr_ipv4 = "0.0.0.0/0"
|
|
ip_protocol = "-1"
|
|
}
|
|
|
|
resource "aws_vpc_security_group_ingress_rule" "eb_from_alb" {
|
|
security_group_id = aws_security_group.eb.id
|
|
referenced_security_group_id = aws_security_group.alb.id
|
|
from_port = 80
|
|
to_port = 80
|
|
ip_protocol = "tcp"
|
|
description = "ALB to instance HTTP"
|
|
}
|
|
|
|
resource "aws_security_group" "rds" {
|
|
name = "shoc-backend-tf-poc-rds"
|
|
description = "SQL Server for shoc-backend-tf-poc"
|
|
vpc_id = var.vpc_id
|
|
|
|
tags = {
|
|
Name = "shoc-backend-tf-poc-rds"
|
|
Project = "shoc-backend"
|
|
}
|
|
|
|
depends_on = [terraform_data.account_guard]
|
|
}
|
|
|
|
resource "aws_vpc_security_group_ingress_rule" "rds_from_eb" {
|
|
security_group_id = aws_security_group.rds.id
|
|
referenced_security_group_id = aws_security_group.eb.id
|
|
from_port = 1433
|
|
to_port = 1433
|
|
ip_protocol = "tcp"
|
|
description = "EB instances to SQL Server"
|
|
}
|
|
|
|
resource "aws_vpc_security_group_egress_rule" "rds_all" {
|
|
security_group_id = aws_security_group.rds.id
|
|
cidr_ipv4 = "0.0.0.0/0"
|
|
ip_protocol = "-1"
|
|
}
|