infra: add rds and s3 resources
This commit is contained in:
@@ -0,0 +1,113 @@
|
||||
resource "aws_db_subnet_group" "main" {
|
||||
name = "cibello-prod-db-subnet"
|
||||
subnet_ids = [aws_subnet.private_1.id, aws_subnet.private_2.id]
|
||||
tags = {
|
||||
Name = "cibello-prod-db-subnet"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_db_instance" "main" {
|
||||
identifier = "cibello-prod-db"
|
||||
engine = "postgres"
|
||||
engine_version = "16"
|
||||
instance_class = "db.t4g.micro"
|
||||
allocated_storage = 20
|
||||
max_allocated_storage = 100
|
||||
storage_type = "gp3"
|
||||
storage_encrypted = true
|
||||
db_name = "cibello"
|
||||
username = "cibello_admin"
|
||||
password = aws_ssm_parameter.db_password.value
|
||||
db_subnet_group_name = aws_db_subnet_group.main.name
|
||||
vpc_security_group_ids = [aws_security_group.db.id]
|
||||
publicly_accessible = false
|
||||
backup_retention_period = 7
|
||||
deletion_protection = true
|
||||
skip_final_snapshot = false
|
||||
final_snapshot_identifier = "cibello-prod-db-final"
|
||||
multi_az = false
|
||||
apply_immediately = false
|
||||
|
||||
tags = {
|
||||
Name = "cibello-prod-db"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_s3_bucket" "production" {
|
||||
bucket = "cibello-production"
|
||||
tags = {
|
||||
Name = "cibello-production"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_s3_bucket_public_access_block" "production" {
|
||||
bucket = aws_s3_bucket.production.id
|
||||
|
||||
block_public_acls = true
|
||||
block_public_policy = true
|
||||
ignore_public_acls = true
|
||||
restrict_public_buckets = true
|
||||
}
|
||||
|
||||
resource "aws_s3_bucket_server_side_encryption_configuration" "production" {
|
||||
bucket = aws_s3_bucket.production.id
|
||||
|
||||
rule {
|
||||
apply_server_side_encryption_by_default {
|
||||
sse_algorithm = "AES256"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_s3_bucket_lifecycle_configuration" "production" {
|
||||
bucket = aws_s3_bucket.production.id
|
||||
|
||||
rule {
|
||||
id = "temporary"
|
||||
status = "Enabled"
|
||||
filter {
|
||||
prefix = "temporary/"
|
||||
}
|
||||
expiration {
|
||||
days = 7
|
||||
}
|
||||
}
|
||||
|
||||
rule {
|
||||
id = "scans"
|
||||
status = "Enabled"
|
||||
filter {
|
||||
prefix = "scans/"
|
||||
}
|
||||
transition {
|
||||
days = 90
|
||||
storage_class = "STANDARD_IA"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_s3_bucket" "web" {
|
||||
bucket = "cibello-web"
|
||||
tags = {
|
||||
Name = "cibello-web"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_s3_bucket_public_access_block" "web" {
|
||||
bucket = aws_s3_bucket.web.id
|
||||
|
||||
block_public_acls = true
|
||||
block_public_policy = true
|
||||
ignore_public_acls = true
|
||||
restrict_public_buckets = true
|
||||
}
|
||||
|
||||
resource "aws_s3_bucket_server_side_encryption_configuration" "web" {
|
||||
bucket = aws_s3_bucket.web.id
|
||||
|
||||
rule {
|
||||
apply_server_side_encryption_by_default {
|
||||
sse_algorithm = "AES256"
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user