Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
72 changes: 72 additions & 0 deletions terraform/services/020-vpc-network/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
# VPC Network
Establishes network configuration for our VPCs to support in-network traffic.
CMS Cloud generates our VPCs, though we set this configuration.


<!-- BEGIN_TF_DOCS -->
<!--WARNING: GENERATED CONTENT with terraform-docs, e.g.
'terraform-docs --config "$(git rev-parse --show-toplevel)/.terraform-docs.yml" .'
Manually updating sections between TF_DOCS tags may be overwritten.
See https://terraform-docs.io/user-guide/configuration/ for more information.
-->
## Providers

| Name | Version |
|------|---------|
| <a name="provider_aws"></a> [aws](#provider\_aws) | 6.67.0 |

<!--WARNING: GENERATED CONTENT with terraform-docs, e.g.
'terraform-docs --config "$(git rev-parse --show-toplevel)/.terraform-docs.yml" .'
Manually updating sections between TF_DOCS tags may be overwritten.
See https://terraform-docs.io/user-guide/configuration/ for more information.
-->
## Requirements

| Name | Version |
|------|---------|
| <a name="requirement_aws"></a> [aws](#requirement\_aws) | ~>6.0 |

<!--WARNING: GENERATED CONTENT with terraform-docs, e.g.
'terraform-docs --config "$(git rev-parse --show-toplevel)/.terraform-docs.yml" .'
Manually updating sections between TF_DOCS tags may be overwritten.
See https://terraform-docs.io/user-guide/configuration/ for more information.
-->
## Inputs

| Name | Description | Type | Default | Required |
|------|-------------|------|---------|:--------:|
| <a name="input_app"></a> [app](#input\_app) | The application name (ab2d, bcda, dpc, cdap) | `string` | n/a | yes |
| <a name="input_env"></a> [env](#input\_env) | The application environment (dev, test, mgmt, sbx, sandbox, prod) | `string` | n/a | yes |

<!--WARNING: GENERATED CONTENT with terraform-docs, e.g.
'terraform-docs --config "$(git rev-parse --show-toplevel)/.terraform-docs.yml" .'
Manually updating sections between TF_DOCS tags may be overwritten.
See https://terraform-docs.io/user-guide/configuration/ for more information.
-->
## Modules

| Name | Source | Version |
|------|--------|---------|
| <a name="module_platform"></a> [platform](#module\_platform) | ../../modules/platform | n/a |

<!--WARNING: GENERATED CONTENT with terraform-docs, e.g.
'terraform-docs --config "$(git rev-parse --show-toplevel)/.terraform-docs.yml" .'
Manually updating sections between TF_DOCS tags may be overwritten.
See https://terraform-docs.io/user-guide/configuration/ for more information.
-->
## Resources

| Name | Type |
|------|------|
| [aws_vpc_endpoint.s3](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/vpc_endpoint) | resource |
| [aws_route_tables.private](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/route_tables) | data source |

<!--WARNING: GENERATED CONTENT with terraform-docs, e.g.
'terraform-docs --config "$(git rev-parse --show-toplevel)/.terraform-docs.yml" .'
Manually updating sections between TF_DOCS tags may be overwritten.
See https://terraform-docs.io/user-guide/configuration/ for more information.
-->
## Outputs

No outputs.
<!-- END_TF_DOCS -->
1 change: 1 addition & 0 deletions terraform/services/020-vpc-network/conf.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
TARGET_ENVS="cdap-test cdap-prod ab2d-test bcda-test dpc-test"
7 changes: 7 additions & 0 deletions terraform/services/020-vpc-network/data.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
data "aws_route_tables" "private" {
vpc_id = module.platform.vpc_id
filter {
name = "tag:Tier"
values = ["private"]
}
}
7 changes: 7 additions & 0 deletions terraform/services/020-vpc-network/main.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
resource "aws_vpc_endpoint" "s3" {
vpc_id = module.platform.vpc_id
service_name = "com.amazonaws.${module.platform.primary_region.name}.s3"
vpc_endpoint_type = "Gateway"
route_table_ids = data.aws_route_tables.private.ids
tags = merge(module.platform.default_tags, { Name = "${var.app}-east-${var.env}-s3-gw-endpoint" })
}
37 changes: 37 additions & 0 deletions terraform/services/020-vpc-network/tofu.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = "~>6.0"
}
}

backend "s3" {
key = "vpc-network/terraform.tfstate"
}
}

provider "aws" {
region = "us-east-1"
default_tags {
tags = module.platform.default_tags
}
}

provider "aws" {
alias = "secondary"
region = "us-west-2"
default_tags {
tags = module.platform.default_tags
}
}

module "platform" {
source = "../../modules/platform"
providers = { aws = aws, aws.secondary = aws.secondary }

app = var.app
env = var.env
root_module = "https://github.com/CMSgov/cdap/tree/main/terraform/services/${basename(abspath(path.module))}/"
service = replace(basename(abspath(path.module)), "/^[0-9]+-/", "")
}
17 changes: 17 additions & 0 deletions terraform/services/020-vpc-network/variables.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
variable "app" {
description = "The application name (ab2d, bcda, dpc, cdap)"
type = string
validation {
condition = contains(["ab2d", "bcda", "dpc", "cdap"], var.app)
error_message = "Valid value for app is ab2d, bcda, dpc, or cdap."
}
}

variable "env" {
description = "The application environment (dev, test, mgmt, sbx, sandbox, prod)"
type = string
validation {
condition = contains(["dev", "test", "sandbox", "prod"], var.env)
error_message = "Valid value for env is dev, test, sandbox, or prod."
}
}
12 changes: 12 additions & 0 deletions terraform/services/900-github-actions-role/policy_cdap_only.tf
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,18 @@ data "aws_iam_policy_document" "github_actions_cdap" {
resources = ["*"]
}

# VPC network management
statement {
sid = "VPCNetwork"
actions = [
"ec2:CreateVpcEndpoint",
"ec2:DescribeVpcEndpoints",
"ec2:ModifyVpcEndpoint",
"ec2:DeleteVpcEndpoints"
]
resources = ["*"]
}

# ECR Read — CDAP needs to describe all apps' repositories
# for cross-app infrastructure management
statement {
Expand Down