forked from terraform-aws-modules/terraform-aws-rds-aurora
-
Notifications
You must be signed in to change notification settings - Fork 0
/
variables.tf
444 lines (371 loc) · 12.4 KB
/
variables.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
variable "create_cluster" {
description = "Whether cluster should be created (it affects almost all resources)"
type = bool
default = true
}
variable "create_security_group" {
description = "Whether to create security group for RDS cluster"
type = bool
default = true
}
variable "name" {
description = "Name used across resources created"
type = string
default = ""
}
variable "subnets" {
description = "List of subnet IDs used by database subnet group created"
type = list(string)
default = []
}
variable "replica_count" {
description = "Number of reader nodes to create. If `replica_scale_enable` is `true`, the value of `replica_scale_min` is used instead."
type = number
default = 1
}
variable "allowed_security_groups" {
description = "A list of Security Group ID's to allow access to"
type = list(string)
default = []
}
variable "allowed_cidr_blocks" {
description = "A list of CIDR blocks which are allowed to access the database"
type = list(string)
default = []
}
variable "vpc_id" {
description = "VPC ID"
type = string
default = ""
}
variable "instance_type_replica" {
description = "Instance type to use at replica instance"
type = string
default = null
}
variable "instance_type" {
description = "Instance type to use at master instance. If instance_type_replica is not set it will use the same type for replica instances"
type = string
default = ""
}
variable "publicly_accessible" {
description = "Whether the DB should have a public IP address"
type = bool
default = false
}
variable "database_name" {
description = "Name for an automatically created database on cluster creation"
type = string
default = ""
}
variable "username" {
description = "Master DB username"
type = string
default = "root"
}
variable "create_random_password" {
description = "Whether to create random password for RDS primary cluster"
type = bool
default = true
}
variable "password" {
description = "Master DB password. Note - when specifying a value here, 'create_random_password' should be set to `false`"
type = string
default = ""
}
variable "is_primary_cluster" {
description = "Whether to create a primary cluster (set to false to be a part of a Global database)"
type = bool
default = true
}
variable "final_snapshot_identifier_prefix" {
description = "The prefix name to use when creating a final snapshot on cluster destroy, appends a random 8 digits to name to ensure it's unique too."
type = string
default = "final"
}
variable "skip_final_snapshot" {
description = "Determines whether a final DB snapshot is created before the DB cluster is deleted. If true is specified, no DB snapshot is created."
type = bool
default = false
}
variable "deletion_protection" {
description = "If the DB instance should have deletion protection enabled"
type = bool
default = false
}
variable "backup_retention_period" {
description = "How long to keep backups for (in days)"
type = number
default = 7
}
variable "preferred_backup_window" {
description = "When to perform DB backups"
type = string
default = "02:00-03:00"
}
variable "preferred_maintenance_window" {
description = "When to perform DB maintenance"
type = string
default = "sun:05:00-sun:06:00"
}
variable "port" {
description = "The port on which to accept connections"
type = string
default = ""
}
variable "apply_immediately" {
description = "Determines whether or not any DB modifications are applied immediately, or during the maintenance window"
type = bool
default = false
}
variable "monitoring_interval" {
description = "The interval (seconds) between points when Enhanced Monitoring metrics are collected"
type = number
default = 0
}
variable "allow_major_version_upgrade" {
description = "Determines whether major engine upgrades are allowed when changing engine version"
type = bool
default = false
}
variable "auto_minor_version_upgrade" {
description = "Determines whether minor engine upgrades will be performed automatically in the maintenance window"
type = bool
default = true
}
variable "db_parameter_group_name" {
description = "The name of a DB parameter group to use"
type = string
default = null
}
variable "db_cluster_parameter_group_name" {
description = "The name of a DB Cluster parameter group to use"
type = string
default = null
}
variable "scaling_configuration" {
description = "Map of nested attributes with scaling properties. Only valid when engine_mode is set to `serverless`"
type = map(string)
default = {}
}
variable "snapshot_identifier" {
description = "DB snapshot to create this database from"
type = string
default = null
}
variable "storage_encrypted" {
description = "Specifies whether the underlying storage layer should be encrypted"
type = bool
default = true
}
variable "kms_key_id" {
description = "The ARN for the KMS encryption key if one is set to the cluster"
type = string
default = ""
}
variable "engine" {
description = "Aurora database engine type, currently aurora, aurora-mysql or aurora-postgresql"
type = string
default = "aurora"
}
variable "engine_version" {
description = "Aurora database engine version"
type = string
default = "5.6.10a"
}
variable "enable_http_endpoint" {
description = "Whether or not to enable the Data API for a serverless Aurora database engine"
type = bool
default = false
}
variable "replica_scale_enabled" {
description = "Whether to enable autoscaling for RDS Aurora (MySQL) read replicas"
type = bool
default = false
}
variable "replica_scale_max" {
description = "Maximum number of read replicas permitted when autoscaling is enabled"
type = number
default = 0
}
variable "replica_scale_min" {
description = "Minimum number of read replicas permitted when autoscaling is enabled"
type = number
default = 2
}
variable "replica_scale_cpu" {
description = "CPU threshold which will initiate autoscaling"
type = number
default = 70
}
variable "replica_scale_connections" {
description = "Average number of connections threshold which will initiate autoscaling. Default value is 70% of db.r4.large's default max_connections"
type = number
default = 700
}
variable "replica_scale_in_cooldown" {
description = "Cooldown in seconds before allowing further scaling operations after a scale in"
type = number
default = 300
}
variable "replica_scale_out_cooldown" {
description = "Cooldown in seconds before allowing further scaling operations after a scale out"
type = number
default = 300
}
variable "tags" {
description = "A map of tags to add to all resources."
type = map(string)
default = {}
}
variable "cluster_tags" {
description = "A map of tags to add to only the RDS cluster. Used for AWS Instance Scheduler tagging"
type = map(string)
default = {}
}
variable "security_group_tags" {
description = "Additional tags for the security group"
type = map(string)
default = {}
}
variable "performance_insights_enabled" {
description = "Specifies whether Performance Insights is enabled or not"
type = bool
default = false
}
variable "performance_insights_kms_key_id" {
description = "The ARN for the KMS key to encrypt Performance Insights data"
type = string
default = ""
}
variable "iam_database_authentication_enabled" {
description = "Specifies whether IAM Database authentication should be enabled or not. Not all versions and instances are supported. Refer to the AWS documentation to see which versions are supported"
type = bool
default = false
}
variable "enabled_cloudwatch_logs_exports" {
description = "List of log types to export to cloudwatch - `audit`, `error`, `general`, `slowquery`, `postgresql`"
type = list(string)
default = []
}
variable "global_cluster_identifier" {
description = "The global cluster identifier specified on aws_rds_global_cluster"
type = string
default = ""
}
variable "engine_mode" {
description = "The database engine mode. Valid values: global, parallelquery, provisioned, serverless, multimaster"
type = string
default = "provisioned"
}
variable "replication_source_identifier" {
description = "ARN of a source DB cluster or DB instance if this DB cluster is to be created as a Read Replica"
type = string
default = ""
}
variable "source_region" {
description = "The source region for an encrypted replica DB cluster"
type = string
default = ""
}
variable "vpc_security_group_ids" {
description = "List of VPC security groups to associate to the cluster in addition to the SG we create in this module"
type = list(string)
default = []
}
variable "db_subnet_group_name" {
description = "The existing subnet group name to use"
type = string
default = ""
}
variable "predefined_metric_type" {
description = "The metric type to scale on. Valid values are RDSReaderAverageCPUUtilization and RDSReaderAverageDatabaseConnections"
type = string
default = "RDSReaderAverageCPUUtilization"
}
variable "backtrack_window" {
description = "The target backtrack window, in seconds. Only available for aurora engine currently. To disable backtracking, set this value to 0. Must be between 0 and 259200 (72 hours)"
type = number
default = 0
}
variable "copy_tags_to_snapshot" {
description = "Copy all Cluster tags to snapshots"
type = bool
default = false
}
variable "iam_roles" {
description = "A List of ARNs for the IAM roles to associate to the RDS Cluster"
type = list(string)
default = []
}
variable "security_group_description" {
description = "The description of the security group. If value is set to empty string it will contain cluster name in the description"
type = string
default = "Managed by Terraform"
}
variable "ca_cert_identifier" {
description = "The identifier of the CA certificate for the DB instance"
type = string
default = "rds-ca-2019"
}
variable "instances_parameters" {
description = "Customized instance settings. Supported keys: `instance_name`, `instance_type`, `instance_promotion_tier`, `publicly_accessible`"
type = list(map(string))
default = []
}
variable "s3_import" {
description = "Configuration map used to restore from a Percona Xtrabackup in S3 (only MySQL is supported)"
type = map(string)
default = null
}
# Enhanced monitoring role
variable "create_monitoring_role" {
description = "Whether to create the IAM role for RDS enhanced monitoring"
type = bool
default = true
}
variable "monitoring_role_arn" {
description = "IAM role used by RDS to send enhanced monitoring metrics to CloudWatch"
type = string
default = ""
}
variable "iam_role_name" {
description = "Friendly name of the role"
type = string
default = null
}
variable "iam_role_use_name_prefix" {
description = "Whether to use `iam_role_name` as is or create a unique name beginning with the `iam_role_name` as the prefix"
type = bool
default = false
}
variable "iam_role_description" {
description = "Description of the role"
type = string
default = null
}
variable "iam_role_path" {
description = "Path to the role"
type = string
default = null
}
variable "iam_role_managed_policy_arns" {
description = "Set of exclusive IAM managed policy ARNs to attach to the IAM role"
type = list(string)
default = null
}
variable "iam_role_permissions_boundary" {
description = "The ARN of the policy that is used to set the permissions boundary for the role"
type = string
default = null
}
variable "iam_role_force_detach_policies" {
description = "Whether to force detaching any policies the role has before destroying it"
type = bool
default = null
}
variable "iam_role_max_session_duration" {
description = "Maximum session duration (in seconds) that you want to set for the role"
type = number
default = null
}