mirror of
https://github.com/BagelHole/DevOps-Security-Agent-Skills.git
synced 2026-08-22 12:49:53 +02:00
153 lines
3.5 KiB
Terraform
153 lines
3.5 KiB
Terraform
# AWS VPC Module Template
|
|
# Production-ready VPC with public and private subnets
|
|
|
|
variable "vpc_cidr" {
|
|
description = "CIDR block for VPC"
|
|
type = string
|
|
default = "10.0.0.0/16"
|
|
}
|
|
|
|
variable "availability_zones" {
|
|
description = "Availability zones"
|
|
type = list(string)
|
|
default = ["us-east-1a", "us-east-1b", "us-east-1c"]
|
|
}
|
|
|
|
variable "enable_nat_gateway" {
|
|
description = "Enable NAT Gateway for private subnets"
|
|
type = bool
|
|
default = true
|
|
}
|
|
|
|
locals {
|
|
public_subnets = [for i, az in var.availability_zones : cidrsubnet(var.vpc_cidr, 8, i)]
|
|
private_subnets = [for i, az in var.availability_zones : cidrsubnet(var.vpc_cidr, 8, i + 10)]
|
|
}
|
|
|
|
# VPC
|
|
resource "aws_vpc" "main" {
|
|
cidr_block = var.vpc_cidr
|
|
enable_dns_hostnames = true
|
|
enable_dns_support = true
|
|
|
|
tags = {
|
|
Name = "${var.project_name}-vpc"
|
|
}
|
|
}
|
|
|
|
# Internet Gateway
|
|
resource "aws_internet_gateway" "main" {
|
|
vpc_id = aws_vpc.main.id
|
|
|
|
tags = {
|
|
Name = "${var.project_name}-igw"
|
|
}
|
|
}
|
|
|
|
# Public Subnets
|
|
resource "aws_subnet" "public" {
|
|
count = length(var.availability_zones)
|
|
vpc_id = aws_vpc.main.id
|
|
cidr_block = local.public_subnets[count.index]
|
|
availability_zone = var.availability_zones[count.index]
|
|
map_public_ip_on_launch = true
|
|
|
|
tags = {
|
|
Name = "${var.project_name}-public-${var.availability_zones[count.index]}"
|
|
"kubernetes.io/role/elb" = "1"
|
|
}
|
|
}
|
|
|
|
# Private Subnets
|
|
resource "aws_subnet" "private" {
|
|
count = length(var.availability_zones)
|
|
vpc_id = aws_vpc.main.id
|
|
cidr_block = local.private_subnets[count.index]
|
|
availability_zone = var.availability_zones[count.index]
|
|
|
|
tags = {
|
|
Name = "${var.project_name}-private-${var.availability_zones[count.index]}"
|
|
"kubernetes.io/role/internal-elb" = "1"
|
|
}
|
|
}
|
|
|
|
# Elastic IP for NAT Gateway
|
|
resource "aws_eip" "nat" {
|
|
count = var.enable_nat_gateway ? 1 : 0
|
|
domain = "vpc"
|
|
|
|
tags = {
|
|
Name = "${var.project_name}-nat-eip"
|
|
}
|
|
}
|
|
|
|
# NAT Gateway
|
|
resource "aws_nat_gateway" "main" {
|
|
count = var.enable_nat_gateway ? 1 : 0
|
|
allocation_id = aws_eip.nat[0].id
|
|
subnet_id = aws_subnet.public[0].id
|
|
|
|
tags = {
|
|
Name = "${var.project_name}-nat"
|
|
}
|
|
|
|
depends_on = [aws_internet_gateway.main]
|
|
}
|
|
|
|
# Public Route Table
|
|
resource "aws_route_table" "public" {
|
|
vpc_id = aws_vpc.main.id
|
|
|
|
route {
|
|
cidr_block = "0.0.0.0/0"
|
|
gateway_id = aws_internet_gateway.main.id
|
|
}
|
|
|
|
tags = {
|
|
Name = "${var.project_name}-public-rt"
|
|
}
|
|
}
|
|
|
|
# Private Route Table
|
|
resource "aws_route_table" "private" {
|
|
vpc_id = aws_vpc.main.id
|
|
|
|
dynamic "route" {
|
|
for_each = var.enable_nat_gateway ? [1] : []
|
|
content {
|
|
cidr_block = "0.0.0.0/0"
|
|
nat_gateway_id = aws_nat_gateway.main[0].id
|
|
}
|
|
}
|
|
|
|
tags = {
|
|
Name = "${var.project_name}-private-rt"
|
|
}
|
|
}
|
|
|
|
# Route Table Associations
|
|
resource "aws_route_table_association" "public" {
|
|
count = length(var.availability_zones)
|
|
subnet_id = aws_subnet.public[count.index].id
|
|
route_table_id = aws_route_table.public.id
|
|
}
|
|
|
|
resource "aws_route_table_association" "private" {
|
|
count = length(var.availability_zones)
|
|
subnet_id = aws_subnet.private[count.index].id
|
|
route_table_id = aws_route_table.private.id
|
|
}
|
|
|
|
# Outputs
|
|
output "vpc_id" {
|
|
value = aws_vpc.main.id
|
|
}
|
|
|
|
output "public_subnet_ids" {
|
|
value = aws_subnet.public[*].id
|
|
}
|
|
|
|
output "private_subnet_ids" {
|
|
value = aws_subnet.private[*].id
|
|
}
|