infra: add rds and s3 resources
This commit is contained in:
@@ -0,0 +1,113 @@
|
|||||||
|
resource "aws_db_subnet_group" "main" {
|
||||||
|
name = "cibello-prod-db-subnet"
|
||||||
|
subnet_ids = [aws_subnet.private_1.id, aws_subnet.private_2.id]
|
||||||
|
tags = {
|
||||||
|
Name = "cibello-prod-db-subnet"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_db_instance" "main" {
|
||||||
|
identifier = "cibello-prod-db"
|
||||||
|
engine = "postgres"
|
||||||
|
engine_version = "16"
|
||||||
|
instance_class = "db.t4g.micro"
|
||||||
|
allocated_storage = 20
|
||||||
|
max_allocated_storage = 100
|
||||||
|
storage_type = "gp3"
|
||||||
|
storage_encrypted = true
|
||||||
|
db_name = "cibello"
|
||||||
|
username = "cibello_admin"
|
||||||
|
password = aws_ssm_parameter.db_password.value
|
||||||
|
db_subnet_group_name = aws_db_subnet_group.main.name
|
||||||
|
vpc_security_group_ids = [aws_security_group.db.id]
|
||||||
|
publicly_accessible = false
|
||||||
|
backup_retention_period = 7
|
||||||
|
deletion_protection = true
|
||||||
|
skip_final_snapshot = false
|
||||||
|
final_snapshot_identifier = "cibello-prod-db-final"
|
||||||
|
multi_az = false
|
||||||
|
apply_immediately = false
|
||||||
|
|
||||||
|
tags = {
|
||||||
|
Name = "cibello-prod-db"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_s3_bucket" "production" {
|
||||||
|
bucket = "cibello-production"
|
||||||
|
tags = {
|
||||||
|
Name = "cibello-production"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_s3_bucket_public_access_block" "production" {
|
||||||
|
bucket = aws_s3_bucket.production.id
|
||||||
|
|
||||||
|
block_public_acls = true
|
||||||
|
block_public_policy = true
|
||||||
|
ignore_public_acls = true
|
||||||
|
restrict_public_buckets = true
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_s3_bucket_server_side_encryption_configuration" "production" {
|
||||||
|
bucket = aws_s3_bucket.production.id
|
||||||
|
|
||||||
|
rule {
|
||||||
|
apply_server_side_encryption_by_default {
|
||||||
|
sse_algorithm = "AES256"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_s3_bucket_lifecycle_configuration" "production" {
|
||||||
|
bucket = aws_s3_bucket.production.id
|
||||||
|
|
||||||
|
rule {
|
||||||
|
id = "temporary"
|
||||||
|
status = "Enabled"
|
||||||
|
filter {
|
||||||
|
prefix = "temporary/"
|
||||||
|
}
|
||||||
|
expiration {
|
||||||
|
days = 7
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
rule {
|
||||||
|
id = "scans"
|
||||||
|
status = "Enabled"
|
||||||
|
filter {
|
||||||
|
prefix = "scans/"
|
||||||
|
}
|
||||||
|
transition {
|
||||||
|
days = 90
|
||||||
|
storage_class = "STANDARD_IA"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_s3_bucket" "web" {
|
||||||
|
bucket = "cibello-web"
|
||||||
|
tags = {
|
||||||
|
Name = "cibello-web"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_s3_bucket_public_access_block" "web" {
|
||||||
|
bucket = aws_s3_bucket.web.id
|
||||||
|
|
||||||
|
block_public_acls = true
|
||||||
|
block_public_policy = true
|
||||||
|
ignore_public_acls = true
|
||||||
|
restrict_public_buckets = true
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_s3_bucket_server_side_encryption_configuration" "web" {
|
||||||
|
bucket = aws_s3_bucket.web.id
|
||||||
|
|
||||||
|
rule {
|
||||||
|
apply_server_side_encryption_by_default {
|
||||||
|
sse_algorithm = "AES256"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user