diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..7275136 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,3 @@ +# These owners will be the default owners for everything in the repo. Unless a later match takes precedence + +* @douglas-f ksnavely-cf diff --git a/.github/ISSUE_TEMPLATE/bug_report.md b/.github/ISSUE_TEMPLATE/bug_report.md new file mode 100644 index 0000000..891c617 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.md @@ -0,0 +1,27 @@ +--- +name: Bug report +about: Create a report to help us improve +title: '' +labels: '' +assignees: '' + +--- + +**Describe the bug** +A clear and concise description of what the bug is. + +**To Reproduce** +Steps to reproduce the behavior: +1. Go to '...' +2. Click on '....' +3. Scroll down to '....' +4. See error + +**Expected behavior** +A clear and concise description of what you expected to happen. + +**Screenshots** +If applicable, add screenshots to help explain your problem. + +**Additional context** +Add any other context about the problem here. diff --git a/.github/ISSUE_TEMPLATE/enhancement-request.md b/.github/ISSUE_TEMPLATE/enhancement-request.md new file mode 100644 index 0000000..5f3d52a --- /dev/null +++ b/.github/ISSUE_TEMPLATE/enhancement-request.md @@ -0,0 +1,20 @@ +--- +name: Enhancement request +about: Suggest an idea for this project +title: '' +labels: '' +assignees: '' + +--- + +**Is your feature request related to a problem? Please describe.** +A clear and concise description of what the problem is. Ex. I'm always frustrated when [...] + +**Describe the solution you'd like** +A clear and concise description of what you want to happen. + +**Describe alternatives you've considered** +A clear and concise description of any alternative solutions or features you've considered. + +**Additional context** +Add any other context or screenshots about the feature request here. diff --git a/.github/workflows/org-checkov.yml b/.github/workflows/org-checkov.yml new file mode 100644 index 0000000..02816b0 --- /dev/null +++ b/.github/workflows/org-checkov.yml @@ -0,0 +1,14 @@ +name: Org Checkov +on: + pull_request: + paths: + - '**.tf' + branches: + - main + workflow_call: + +jobs: + check-markdown: + uses: Coalfire-CF/Actions/.github/workflows/org-checkov.yml@main + with: + skip-path: examples diff --git a/.github/workflows/org-md-lint.yml b/.github/workflows/org-md-lint.yml new file mode 100644 index 0000000..43447a0 --- /dev/null +++ b/.github/workflows/org-md-lint.yml @@ -0,0 +1,12 @@ +name: Markdown Lint +on: + pull_request: + paths: + - '**.md' + branches: + - main + workflow_call: + +jobs: + check-markdown: + uses: Coalfire-CF/Actions/.github/workflows/org-markdown-lint.yml@main \ No newline at end of file diff --git a/.github/workflows/org-release.yml b/.github/workflows/org-release.yml new file mode 100644 index 0000000..5095d16 --- /dev/null +++ b/.github/workflows/org-release.yml @@ -0,0 +1,11 @@ +name: Org Release +on: + pull_request: + types: + - closed + branches: + - main + +jobs: + create-release: + uses: Coalfire-CF/Actions/.github/workflows/org-release.yml@main \ No newline at end of file diff --git a/.github/workflows/org-terraform-docs.yml b/.github/workflows/org-terraform-docs.yml new file mode 100644 index 0000000..273ff8a --- /dev/null +++ b/.github/workflows/org-terraform-docs.yml @@ -0,0 +1,8 @@ +name: Org Terraform Docs +on: + pull_request: + workflow_call: + +jobs: + terraform-docs: + uses: Coalfire-CF/Actions/.github/workflows/org-terraform-docs.yml@main \ No newline at end of file diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..532c5d2 --- /dev/null +++ b/.gitignore @@ -0,0 +1,37 @@ +# Local .terraform directories +**/.terraform/* +.terraform.lock.hcl + +# .tfstate files +*.tfstate +*.tfstate.* + +# Crash log files +crash.log + +# Ignore override files as they are usually used to override resources locally and so +# are not checked in +override.tf +override.tf.json +*_override.tf +*_override.tf.json + +# Include tfplan files to ignore the plan output of command: terraform plan -out=tfplan +# example: *tfplan* + +.idea +.idea/* +.vscode +.vscode/ +*.iml +*.zip +.DS_Store + +# NessusBurp Install files are too large to commit +**/nessusburp/*.exe +**/nessusburp/*.msi +**/nessusburp/*.txt + +# Ansible +*.pub +*.ppk diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..2f6939f --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,72 @@ +# Contributing + +When contributing to this repository, please first discuss the change you wish to make via issue, +email, or any other method with the owners of this repository before making a change. + +Please note we have a code of conduct, please follow it in all your interactions with the project. + +## Pull Request Process + +1. Ensure any install or build dependencies are removed before the end of the layer when doing a + build. +2. Update the README.md with details of changes to the interface, this includes new environment + variables, exposed ports, useful file locations and container parameters. +3. Increase the version numbers in any examples files and the README.md to the new version that this + Pull Request would represent. The versioning scheme we use is [SemVer](http://semver.org/). +4. You may merge the Pull Request in once you have the sign-off of two other developers, or if you + do not have permission to do that, you may request the second reviewer to merge it for you. + +## Coalfire Code of Conduct + +## Our Pledge + +In the interest of fostering an open and welcoming environment, we, as contributors and project maintainers, pledge to make participation in our project and our community a harassment-free experience for everyone. + +## Our Values + +We pledge to act and interact in ways that contribute to an open, welcoming, diverse, inclusive, and healthy community. Our community reflects our company values: + +Respect: We believe in acknowledging the rights, beliefs, and perspectives of others. + +Excellence: We endeavor to adopt best practices in everything we do. + +Leadership: We encourage thought leadership and innovation. + +Integrity: We uphold the highest ethical standards in all our interactions. + +Teamwork: We believe in the power of working together to achieve our common goals. + +Enthusiasm: We approach every task with energy and eagerness. + +## Expected Behavior + +Demonstrate empathy and kindness toward other people. + +Be respectful of differing opinions, viewpoints, and experiences. + +Offer and gracefully accept constructive feedback. + +Show courtesy and respect in public and private communications. + +Avoid personal attacks directed toward other contributors. + +## Unacceptable Behavior + +Any form of discrimination and harassment is unacceptable. This includes but is not +limited to; offensive comments related to gender, sexual orientation, race, religion, disability, physical appearance, or other protected categories. + +Public or private harassment, deliberate intimidation, violence, or threats of. + +Publishing others’ private information, such as a physical or email address, without their explicit permission. + +• The use of sexualized language or imagery and unwelcome sexual attention or advances. + +• Trolling, insulting/derogatory comments, and personal or political attacks. + +## Reporting & Enforcement + +We encourage all communities to resolve issues on their own whenever possible. If you are unable to resolve the matter for any reason, or if the behavior is threatening or harassing, report it. We are dedicated to providing an environment where participants feel welcome and safe. Instances of abusive, harassing, or otherwise unacceptable behavior may be reported by contacting the project team at . All complaints will be reviewed and investigated promptly and fairly. Confidentiality will be maintained for the reporter of an incident. + +We will use our discretion in determining when and how we follow up with reported incidents. Consequences of violating this code may include, but are not limited to, a temporary or permanent ban from project participation, removal of contributions, and reporting the incident to employers or legal authorities as appropriate. + +This Code of Conduct is a living document and will evolve with the community. The project maintainers reserve the right to update this code as necessary. Any changes will be communicated to community members. diff --git a/License.md b/License.md new file mode 100644 index 0000000..5b57eee --- /dev/null +++ b/License.md @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2023 Coalfire Systems, Inc. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. \ No newline at end of file diff --git a/README.md b/README.md new file mode 100644 index 0000000..32a89f7 --- /dev/null +++ b/README.md @@ -0,0 +1,89 @@ +![Coalfire](coalfire_logo.png) + +# AWS Security Group Terraform Module + +## Description + +This module creates an AWS security group with a network interface attachment to connect to an existing network interface. + +## Dependencies + +Any resources requiring security groups + +## Resource List + +- Security Group +- Network Interface Associations (optional) + +## Deployment Steps + +This module can be called as outlined below. + +- Change directories to the `examples/simple` directory. +- From the `examples/simple` directory run `terraform init`. +- Ensure that the `tfvars/example.tfvars` variables are correct (especially the profile) or create a new tfvars file with the correct variables +- Run `terraform plan -var-file tfvars/examples.tfvars` (or the newly created file) to review the resources being created. +- If everything looks correct in the plan output, run `terraform apply -var-file tfvars/examples.tfvars`. + +## Usage + +The directory `examples/simple` shows a basic declaration and use of the module, whereas `examples/network-associations` demonstrates the module's ability to create associations between the security group and any network interfaces (when provided with a list of desired network interface ids). + + +## Requirements + +| Name | Version | +|------|---------| +| [terraform](#requirement\_terraform) | >= 1.5.0 | +| [aws](#requirement\_aws) | ~> 5.0 | + +## Providers + +| Name | Version | +|------|---------| +| [aws](#provider\_aws) | ~> 5.0 | + +## Modules + +No modules. + +## Resources + +| Name | Type | +|------|------| +| [aws_network_interface_sg_attachment.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/network_interface_sg_attachment) | resource | +| [aws_security_group.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group) | resource | +| [aws_network_interface.interfaces](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/network_interface) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| [description](#input\_description) | This overwrites the default generated description for the security group | `string` | `"Managed by Terraform"` | no | +| [egress\_rules](#input\_egress\_rules) | The list of rules for egress traffic. Required fields for each rule are 'protocol', 'from\_port', 'to\_port', and at least one of 'cidr\_blocks', 'ipv6\_cidr\_blocks', 'security\_groups', 'self', or 'prefix\_list\_sg'. Optional fields are 'description' and those not used from the previous list |
list(object({
protocol = string
from_port = string
to_port = string
cidr_blocks = optional(list(string), [])
ipv6_cidr_blocks = optional(list(string), [])
prefix_list_ids = optional(list(string), [])
security_groups = optional(list(string), [])
self = optional(bool)
description = optional(string, "Managed by Terraform")
}))
| `[]` | no | +| [ingress\_rules](#input\_ingress\_rules) | The list of rules for ingress traffic. Required fields for each rule are 'protocol', 'from\_port', 'to\_port', and at least one of 'cidr\_blocks', 'ipv6\_cidr\_blocks', 'security\_groups', 'self', or 'prefix\_list\_sg'. Optional fields are 'description' and those not used from the previous list |
list(object({
protocol = string
from_port = string
to_port = string
cidr_blocks = optional(list(string), [])
ipv6_cidr_blocks = optional(list(string), [])
prefix_list_ids = optional(list(string), [])
security_groups = optional(list(string), [])
self = optional(bool)
description = optional(string, "Managed by Terraform")
}))
| `[]` | no | +| [name](#input\_name) | The name of the created security group. Conflicts with 'sg\_name\_prefix' | `string` | `""` | no | +| [network\_interface\_resource\_associations](#input\_network\_interface\_resource\_associations) | The IDs of already existing network interfaces to be associated with the created security group. If used, do not declare sg in the creation of those resources | `list(string)` | `[]` | no | +| [sg\_name\_prefix](#input\_sg\_name\_prefix) | The prefix to be used while generating a unique name for the security group. Conflicts with 'sg\_name' | `string` | `""` | no | +| [tags](#input\_tags) | Tags to add to the created security group | `map(string)` | `{}` | no | +| [vpc\_id](#input\_vpc\_id) | The ID of the VPC that the security group will be associated with | `string` | `null` | no | + +## Outputs + +| Name | Description | +|------|-------------| +| [associated\_network\_interfaces](#output\_associated\_network\_interfaces) | The ARNs of the network interfaces associated to the security group by this module | +| [id](#output\_id) | The id of the created security group | + + +## Contributing + +If you're interested in contributing to our projects, please review the [Contributing Guidelines](CONTRIBUTING.md). And send an email to [our team](contributing@coalfire.com) to receive a copy of our CLA and start the onboarding process. + +## License + +[![License](https://img.shields.io/badge/license-MIT-blue.svg)](https://opensource.org/license/mit/) + +### Copyright + +Copyright © 2023 Coalfire Systems Inc. diff --git a/coalfire_logo.png b/coalfire_logo.png new file mode 100644 index 0000000..1f0c5e4 Binary files /dev/null and b/coalfire_logo.png differ diff --git a/examples/network-associations/README.md b/examples/network-associations/README.md new file mode 100644 index 0000000..68986d3 --- /dev/null +++ b/examples/network-associations/README.md @@ -0,0 +1,9 @@ +## Security Group module network association example + +One of the prerequisites of the security group module is that it is capable of creating network associations on its own. + +This example should create three (3) EC2 instances, two of which will be attached to the security group by the module itself, and the third will attach the security group inline. + +Any resource that has a network interface attached to it can input the ID of the network interface in order to make an association. + +NOTE: Using the security group to associate a network interface that is attached to an instance that has already associated itself with the security group in its declaraction WILL NOT WORK. \ No newline at end of file diff --git a/examples/network-associations/main.tf b/examples/network-associations/main.tf new file mode 100644 index 0000000..3ea5af0 --- /dev/null +++ b/examples/network-associations/main.tf @@ -0,0 +1,90 @@ +data "aws_ami" "ami" { + most_recent = true + + filter { + name = "name" + values = ["amzn-ami-hvm-*"] + } + + owners = ["amazon"] +} + +data "aws_region" "current" {} + +resource "aws_vpc" "main" { + cidr_block = var.vpc_cidr +} + +resource "aws_subnet" "main" { + vpc_id = aws_vpc.main.id + cidr_block = var.subnet_cidr +} + +resource "aws_instance" "instance1" { + instance_type = "t2.micro" + ami = data.aws_ami.ami.id + + subnet_id = aws_subnet.main.id + + tags = { + type = "security-group-test-instance" + } +} + +resource "aws_instance" "instance2" { + instance_type = "t2.micro" + ami = data.aws_ami.ami.id + + subnet_id = aws_subnet.main.id + + tags = { + type = "security-group-test-instance" + } +} + +resource "aws_instance" "instance3" { + instance_type = "t2.micro" + ami = data.aws_ami.ami.id + + subnet_id = aws_subnet.main.id + + vpc_security_group_ids = [module.example_sg.id] + + tags = { + type = "security-group-test-instance" + } +} + +module "example_sg" { + source = "github.com/Coalfire-CF/terraform-aws-securitygroup" + + name = "security_group_module_example_sg" + + vpc_id = aws_vpc.main.id + + ingress_rules = [{ + protocol = "tcp" + from_port = "443" + to_port = "443" + cidr_blocks = [aws_vpc.main.cidr_block] + }, + { + # ssh + protocol = "tcp" + from_port = "22" + to_port = "22" + cidr_blocks = [aws_vpc.main.cidr_block] + }] + + egress_rules = [{ + protocol = "-1" + from_port = "0" + to_port = "0" + cidr_blocks = ["0.0.0.0/0"] + }] + + network_interface_resource_associations = [ + aws_instance.instance1.primary_network_interface_id, + aws_instance.instance2.primary_network_interface_id + ] +} diff --git a/examples/network-associations/outputs.tf b/examples/network-associations/outputs.tf new file mode 100644 index 0000000..8c7b58d --- /dev/null +++ b/examples/network-associations/outputs.tf @@ -0,0 +1,9 @@ +output "sg_id" { + value = module.example_sg.id + description = "The ID of the created security group" +} + +output "associated_network_interfaces" { + value = module.example_sg.associated_network_interfaces + description = "The ARNs of the network interfaces attached by the SG module" +} \ No newline at end of file diff --git a/examples/network-associations/providers.tf b/examples/network-associations/providers.tf new file mode 100644 index 0000000..e962798 --- /dev/null +++ b/examples/network-associations/providers.tf @@ -0,0 +1,16 @@ +terraform { + required_version = ">= 1.5" + + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.15.0, < 6.0" + } + } +} + +provider "aws" { + region = var.aws_region + profile = var.profile + use_fips_endpoint = true +} \ No newline at end of file diff --git a/examples/network-associations/tfvars/example.tfvars b/examples/network-associations/tfvars/example.tfvars new file mode 100644 index 0000000..a37217f --- /dev/null +++ b/examples/network-associations/tfvars/example.tfvars @@ -0,0 +1,4 @@ +aws_region = "us-east-2" +profile = "sandbox" +vpc_cidr = "10.2.0.0/24" +subnet_cidr = "10.2.0.0/24" diff --git a/examples/network-associations/variables.tf b/examples/network-associations/variables.tf new file mode 100644 index 0000000..4421985 --- /dev/null +++ b/examples/network-associations/variables.tf @@ -0,0 +1,22 @@ +variable "aws_region" { + description = "The region where things will be deployed by default" + type = string + default = "us-east-1" +} + +variable "profile" { + description = "The name of the profile to get AWS credentials from" + type = string +} + +variable "vpc_cidr" { + description = "The cidr block for the vpc created for testing the security group" + type = string + default = "10.1.0.0/24" +} + +variable "subnet_cidr" { + description = "The cidr block for the subnet created for testing the security group" + type = string + default = "10.1.0.0/24" +} diff --git a/examples/simple/README.md b/examples/simple/README.md new file mode 100644 index 0000000..932bf5a --- /dev/null +++ b/examples/simple/README.md @@ -0,0 +1,3 @@ +## Security Group module simple example + +This example creates a security group, using the security group module, along with a VPC, subnet, and EC2 instance. The EC2 instance attached the security group itself as opposed to having the module create the association. \ No newline at end of file diff --git a/examples/simple/main.tf b/examples/simple/main.tf new file mode 100644 index 0000000..b7bd1c4 --- /dev/null +++ b/examples/simple/main.tf @@ -0,0 +1,64 @@ +data "aws_ami" "ami" { + most_recent = true + + filter { + name = "name" + values = ["amzn-ami-hvm-*"] + } + + owners = ["amazon"] +} + +resource "aws_vpc" "main" { + cidr_block = var.vpc_cidr +} + +resource "aws_subnet" "main" { + vpc_id = aws_vpc.main.id + cidr_block = var.subnet_cidr +} + +resource "aws_instance" "example" { + instance_type = "t2.micro" + ami = data.aws_ami.ami.id + + subnet_id = aws_subnet.main.id + + vpc_security_group_ids = [module.example_sg.id] + + tags = { + type = "security-group-test-instance" + } +} + +module "example_sg" { + source = "github.com/Coalfire-CF/terraform-aws-securitygroup" + + name = "security_group_module_example_sg" + + vpc_id = aws_vpc.main.id + + ingress_rules = [ + { + protocol = "tcp" + from_port = "443" + to_port = "443" + cidr_blocks = [aws_vpc.main.cidr_block] + }, + { + protocol = "tcp" + from_port = "22" + to_port = "22" + cidr_blocks = [aws_vpc.main.cidr_block] + } + ] + + egress_rules = [ + { + protocol = "-1" + from_port = "0" + to_port = "0" + cidr_blocks = ["0.0.0.0/0"] + } + ] +} diff --git a/examples/simple/providers.tf b/examples/simple/providers.tf new file mode 100644 index 0000000..e962798 --- /dev/null +++ b/examples/simple/providers.tf @@ -0,0 +1,16 @@ +terraform { + required_version = ">= 1.5" + + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.15.0, < 6.0" + } + } +} + +provider "aws" { + region = var.aws_region + profile = var.profile + use_fips_endpoint = true +} \ No newline at end of file diff --git a/examples/simple/tfvars/example.tfvars b/examples/simple/tfvars/example.tfvars new file mode 100644 index 0000000..a37217f --- /dev/null +++ b/examples/simple/tfvars/example.tfvars @@ -0,0 +1,4 @@ +aws_region = "us-east-2" +profile = "sandbox" +vpc_cidr = "10.2.0.0/24" +subnet_cidr = "10.2.0.0/24" diff --git a/examples/simple/variables.tf b/examples/simple/variables.tf new file mode 100644 index 0000000..4421985 --- /dev/null +++ b/examples/simple/variables.tf @@ -0,0 +1,22 @@ +variable "aws_region" { + description = "The region where things will be deployed by default" + type = string + default = "us-east-1" +} + +variable "profile" { + description = "The name of the profile to get AWS credentials from" + type = string +} + +variable "vpc_cidr" { + description = "The cidr block for the vpc created for testing the security group" + type = string + default = "10.1.0.0/24" +} + +variable "subnet_cidr" { + description = "The cidr block for the subnet created for testing the security group" + type = string + default = "10.1.0.0/24" +} diff --git a/locals.tf b/locals.tf new file mode 100644 index 0000000..8658dc2 --- /dev/null +++ b/locals.tf @@ -0,0 +1,9 @@ +locals { + use_prefix = var.sg_name_prefix != "" ? true : false +} + +# Ensure dynamic blocks run +locals { + ingress_rules = var.ingress_rules == null ? [] : var.ingress_rules + egress_rules = var.egress_rules == null ? [] : var.egress_rules +} \ No newline at end of file diff --git a/main.tf b/main.tf new file mode 100644 index 0000000..16f99d6 --- /dev/null +++ b/main.tf @@ -0,0 +1,32 @@ +resource "aws_security_group" "this" { + name = local.use_prefix ? null : var.name + name_prefix = local.use_prefix ? var.sg_name_prefix : null + + description = var.description + + vpc_id = var.vpc_id + + ingress = [ + for rule in local.ingress_rules : merge(null, rule) + ] + + egress = [ + for rule in local.egress_rules : merge(null, rule) + ] + + tags = var.tags +} + +resource "aws_network_interface_sg_attachment" "this" { + count = length(var.network_interface_resource_associations) + + security_group_id = aws_security_group.this.id + network_interface_id = var.network_interface_resource_associations[count.index] +} + +# For exporting network interface ARNs +data "aws_network_interface" "interfaces" { + count = length(var.network_interface_resource_associations) + + id = var.network_interface_resource_associations[count.index] +} diff --git a/outputs.tf b/outputs.tf new file mode 100644 index 0000000..27a0c05 --- /dev/null +++ b/outputs.tf @@ -0,0 +1,9 @@ +output "id" { + value = aws_security_group.this.id + description = "The id of the created security group" +} + +output "associated_network_interfaces" { + value = data.aws_network_interface.interfaces.*.arn + description = "The ARNs of the network interfaces associated to the security group by this module" +} \ No newline at end of file diff --git a/providers.tf b/providers.tf new file mode 100644 index 0000000..e9962df --- /dev/null +++ b/providers.tf @@ -0,0 +1,10 @@ +terraform { + required_version = ">= 1.5.0" + + required_providers { + aws = { + source = "hashicorp/aws" + version = "~> 5.0" + } + } +} \ No newline at end of file diff --git a/variables.tf b/variables.tf new file mode 100644 index 0000000..fc06004 --- /dev/null +++ b/variables.tf @@ -0,0 +1,67 @@ +variable "name" { + description = "The name of the created security group. Conflicts with 'sg_name_prefix'" + type = string + default = "" +} + +variable "sg_name_prefix" { + description = "The prefix to be used while generating a unique name for the security group. Conflicts with 'sg_name'" + type = string + default = "" +} + +variable "tags" { + description = "Tags to add to the created security group" + type = map(string) + default = {} +} + +variable "description" { + description = "This overwrites the default generated description for the security group" + type = string + default = "Managed by Terraform" +} + +variable "vpc_id" { + description = "The ID of the VPC that the security group will be associated with" + type = string + default = null +} + +variable "network_interface_resource_associations" { + description = "The IDs of already existing network interfaces to be associated with the created security group. If used, do not declare sg in the creation of those resources" + type = list(string) + default = [] +} + +variable "ingress_rules" { + description = "The list of rules for ingress traffic. Required fields for each rule are 'protocol', 'from_port', 'to_port', and at least one of 'cidr_blocks', 'ipv6_cidr_blocks', 'security_groups', 'self', or 'prefix_list_sg'. Optional fields are 'description' and those not used from the previous list" + type = list(object({ + protocol = string + from_port = string + to_port = string + cidr_blocks = optional(list(string), []) + ipv6_cidr_blocks = optional(list(string), []) + prefix_list_ids = optional(list(string), []) + security_groups = optional(list(string), []) + self = optional(bool) + description = optional(string, "Managed by Terraform") + })) + default = [] +} + +variable "egress_rules" { + description = "The list of rules for egress traffic. Required fields for each rule are 'protocol', 'from_port', 'to_port', and at least one of 'cidr_blocks', 'ipv6_cidr_blocks', 'security_groups', 'self', or 'prefix_list_sg'. Optional fields are 'description' and those not used from the previous list" + type = list(object({ + protocol = string + from_port = string + to_port = string + cidr_blocks = optional(list(string), []) + ipv6_cidr_blocks = optional(list(string), []) + prefix_list_ids = optional(list(string), []) + security_groups = optional(list(string), []) + self = optional(bool) + description = optional(string, "Managed by Terraform") + })) + default = [] +} \ No newline at end of file