syslog-server/terraform/s3.tf
Adam Moussa 7287fcf0d1
feat(infra): archive UniFi All Traffic to S3 via Vector (PLAT-206)
Replace the public rsyslog-to-CloudWatch collector with Vector over a
prod 10.40 IPsec VGW, Firehose, 90-day S3, Glue, and Athena.
2026-09-17 14:40:18 -04:00

106 lines
1.8 KiB
HCL

resource "aws_s3_bucket" "unifi" {
bucket = local.bucket_name
tags = {
Name = local.bucket_name
}
}
resource "aws_s3_bucket_public_access_block" "unifi" {
bucket = aws_s3_bucket.unifi.id
block_public_acls = true
block_public_policy = true
ignore_public_acls = true
restrict_public_buckets = true
}
resource "aws_s3_bucket_ownership_controls" "unifi" {
bucket = aws_s3_bucket.unifi.id
rule {
object_ownership = "BucketOwnerEnforced"
}
}
resource "aws_s3_bucket_server_side_encryption_configuration" "unifi" {
bucket = aws_s3_bucket.unifi.id
rule {
apply_server_side_encryption_by_default {
sse_algorithm = "AES256"
}
}
}
resource "aws_s3_bucket_lifecycle_configuration" "unifi" {
bucket = aws_s3_bucket.unifi.id
rule {
id = "expire-logs"
status = "Enabled"
filter {
prefix = "format="
}
expiration {
days = local.logs_expire_days
}
}
rule {
id = "expire-athena-results"
status = "Enabled"
filter {
prefix = local.athena_results_prefix
}
expiration {
days = local.athena_results_expire_days
}
}
rule {
id = "expire-errors"
status = "Enabled"
filter {
prefix = "errors/"
}
expiration {
days = 14
}
}
}
data "aws_iam_policy_document" "bucket" {
statement {
sid = "DenyInsecureTransport"
effect = "Deny"
actions = ["s3:*"]
principals {
type = "*"
identifiers = ["*"]
}
resources = [
aws_s3_bucket.unifi.arn,
"${aws_s3_bucket.unifi.arn}/*",
]
condition {
test = "Bool"
variable = "aws:SecureTransport"
values = ["false"]
}
}
}
resource "aws_s3_bucket_policy" "unifi" {
bucket = aws_s3_bucket.unifi.id
policy = data.aws_iam_policy_document.bucket.json
}