From bbd9935ff96c800435b8583c1610828cbb156969 Mon Sep 17 00:00:00 2001 From: Julio Faerman Date: Fri, 11 Aug 2023 11:27:47 +0000 Subject: [PATCH] wup --- qpizza-tf/bastion/main.tf | 46 ++++++++++++++++++++++++ qpizza-tf/bastion/outputs.tf | 0 qpizza-tf/bastion/variables.tf | 17 +++++++++ qpizza-tf/database/main.tf | 59 +++++++++++++++++++++++++++++++ qpizza-tf/database/outputs.tf | 3 ++ qpizza-tf/database/variables.tf | 8 +++++ qpizza-tf/main.tf | 20 +++++++++-- qpizza-tf/networking/variables.tf | 3 -- qpizza-tf/outputs.tf | 6 +++- qpizza-tf/secrets/main.tf | 11 ++++++ qpizza-tf/secrets/outputs.tf | 0 qpizza-tf/secrets/variables.tf | 9 +++++ qpizza-tf/variables.tf | 2 +- 13 files changed, 177 insertions(+), 7 deletions(-) create mode 100644 qpizza-tf/bastion/main.tf create mode 100644 qpizza-tf/bastion/outputs.tf create mode 100644 qpizza-tf/bastion/variables.tf create mode 100644 qpizza-tf/database/main.tf create mode 100644 qpizza-tf/database/outputs.tf create mode 100644 qpizza-tf/database/variables.tf create mode 100644 qpizza-tf/secrets/main.tf create mode 100644 qpizza-tf/secrets/outputs.tf create mode 100644 qpizza-tf/secrets/variables.tf diff --git a/qpizza-tf/bastion/main.tf b/qpizza-tf/bastion/main.tf new file mode 100644 index 0000000..6d9e69c --- /dev/null +++ b/qpizza-tf/bastion/main.tf @@ -0,0 +1,46 @@ +resource "tls_private_key" "that" { + algorithm = "RSA" + rsa_bits = 4096 +} + +resource "aws_key_pair" "that" { + key_name = var.key_name + public_key = tls_private_key.that.public_key_openssh +} + +resource "aws_security_group" "bastion_sg" { + description = "Security group for Bastion" + vpc_id = var.vpc_id + + ingress { + from_port = 22 + to_port = 22 + protocol = "tcp" + cidr_blocks = ["0.0.0.0/0"] + } + + egress { + from_port = 0 + to_port = 0 + protocol = "-1" + cidr_blocks = ["0.0.0.0/0"] + } +} + +data "aws_ssm_parameter" "ami_id" { + name = "/aws/service/ami-amazon-linux-latest/al2023-ami-kernel-6.1-arm64" +} + + +resource "aws_instance" "bastion" { + ami = data.aws_ssm_parameter.ami_id.value + instance_type = var.bastion_instance_type + subnet_id = var.subnet_id + vpc_security_group_ids = [aws_security_group.bastion_sg.id] + key_name = aws_key_pair.that.key_name + user_data = <