Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 6 additions & 2 deletions modules/vpc/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ For this reason, we recommend managing the tags externally of the resource itsel

| Name | Version |
|------|---------|
| <a name="provider_aws"></a> [aws](#provider\_aws) | 5.36.0 |
| <a name="provider_aws"></a> [aws](#provider\_aws) | >= 3.64.2 |

## Modules

Expand All @@ -60,27 +60,31 @@ No modules.
| [aws_route_table.public_route_table](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/route_table) | resource |
| [aws_route_table_association.private_assoc](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/route_table_association) | resource |
| [aws_route_table_association.public_assoc](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/route_table_association) | resource |
| [aws_security_group.s3tables_endpoint](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group) | resource |
| [aws_subnet.private](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/subnet) | resource |
| [aws_subnet.public](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/subnet) | resource |
| [aws_vpc.vpc](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/vpc) | resource |
| [aws_vpc_endpoint.s3_gateway_endpoint](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/vpc_endpoint) | resource |
| [aws_vpc_endpoint.s3tables_endpoint](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/vpc_endpoint) | resource |
| [aws_availability_zones.available](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/availability_zones) | data source |

## Inputs

| Name | Description | Type | Default | Required |
|------|-------------|------|---------|:--------:|
| <a name="input_additional_tags"></a> [additional\_tags](#input\_additional\_tags) | Additional tags to apply to the resources. Note that this module sets the tags Name, Type, and Vendor by default. They can be overwritten, but it is not recommended. | `map(string)` | `{}` | no |
| <a name="input_availability_zones"></a> [availability\_zones](#input\_availability\_zones) | The availability zones to provision. If specified will ignore num\_azs | `list(string)` | `[]` | no |
| <a name="input_disable_nat_gateway"></a> [disable\_nat\_gateway](#input\_disable\_nat\_gateway) | If set to true, will not create NAT Gateway and EC2 Nodes should put in public subnets. This could be useful when wanna save costs from nat gateway. | `bool` | `false` | no |
| <a name="input_enable_s3_gateway_endpoint"></a> [enable\_s3\_gateway\_endpoint](#input\_enable\_s3\_gateway\_endpoint) | If set to true, will create S3 VPC Endpoint. This could be useful when wanna save costs from NAT Gateway. | `bool` | `false` | no |
| <a name="input_enable_s3tables_endpoint"></a> [enable\_s3tables\_endpoint](#input\_enable\_s3tables\_endpoint) | If set to true, will create an Interface VPC Endpoint for the S3 Tables service so S3 Tables traffic stays on the AWS private network. Set to false in regions where S3 Tables is not yet available (apply will fail with InvalidServiceName otherwise). | `bool` | `true` | no |
| <a name="input_num_azs"></a> [num\_azs](#input\_num\_azs) | The number of availability zones to provision | `number` | `2` | no |
| <a name="input_private_subnet_newbits"></a> [private\_subnet\_newbits](#input\_private\_subnet\_newbits) | The number of bits to added to the VPC CIDR prefix. For instance, if your VPC CIDR is a /16 and you set this number to 4, the subnets will be /20s. | `number` | `4` | no |
| <a name="input_private_subnet_start"></a> [private\_subnet\_start](#input\_private\_subnet\_start) | The starting octet for the private subnet CIDR blocks generated by this module. | `number` | `0` | no |
| <a name="input_public_subnet_auto_ip"></a> [public\_subnet\_auto\_ip](#input\_public\_subnet\_auto\_ip) | n/a | `bool` | `false` | no |
| <a name="input_public_subnet_newbits"></a> [public\_subnet\_newbits](#input\_public\_subnet\_newbits) | The number of bits to added to the VPC CIDR prefix. For instance, if your VPC CIDR is a /16 and you set this number to 4, the subnets will be /20s. | `number` | `4` | no |
| <a name="input_public_subnet_start"></a> [public\_subnet\_start](#input\_public\_subnet\_start) | The starting octet for the public subnet CIDR blocks generated by this module. | `number` | `8` | no |
| <a name="input_region"></a> [region](#input\_region) | n/a | `string` | n/a | yes |
| <a name="input_tags"></a> [tags](#input\_tags) | Additional to apply to the resources. Note that this module sets the tags Name, Type, and Vendor by default. They can be overwritten, but it is not recommended. | `map(string)` | `{}` | no |
| <a name="input_tags"></a> [tags](#input\_tags) | Deprecated: use additional\_tags instead. | `map(string)` | `{}` | no |
| <a name="input_vpc_cidr"></a> [vpc\_cidr](#input\_vpc\_cidr) | The CIDR range to be used by the AWS VPC. We recommend using a /16 prefix to automatically generate /20 subnets. If you are using a smaller or larger prefix, refer to the subnet\_newbits variable to ensure that the generated subnet ranges are a valid for EKS (minimum /20 is recommended). | `string` | n/a | yes |
| <a name="input_vpc_name"></a> [vpc\_name](#input\_vpc\_name) | The name used for the VPC and associated resources | `string` | n/a | yes |

Expand Down
57 changes: 56 additions & 1 deletion modules/vpc/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ data "aws_availability_zones" "available" {
locals {
azs = length(var.availability_zones) > 0 ? var.availability_zones : data.aws_availability_zones.available.names
num_azs = length(var.availability_zones) > 0 ? length(var.availability_zones) : var.num_azs
tags = merge(var.tags, var.additional_tags)
tags = merge(var.tags, var.additional_tags)
}

resource "aws_vpc" "vpc" {
Expand Down Expand Up @@ -168,4 +168,59 @@ resource "aws_vpc_endpoint" "s3_gateway_endpoint" {
POLICY

tags = merge({ "Vendor" = "StreamNative", Name = "${var.vpc_name}-s3-gateway-endpoint" }, local.tags)
}

# S3 Tables traffic (s3tables.<region>.amazonaws.com) is not routed through
# the S3 gateway endpoint above. AWS publishes the s3tables service as an
# Interface VPC endpoint only, so provision one in the private subnets and
# enable private DNS to keep the traffic on the AWS private network. Set
# `enable_s3tables_endpoint = false` in regions where S3 Tables is not yet
# available (terraform apply will otherwise fail with InvalidServiceName).
resource "aws_security_group" "s3tables_endpoint" {
count = var.enable_s3tables_endpoint ? 1 : 0

name = "${var.vpc_name}-s3tables-endpoint"
description = "Allow HTTPS to the S3 Tables VPC interface endpoint"
vpc_id = aws_vpc.vpc.id

ingress {
description = "HTTPS from VPC"
from_port = 443
to_port = 443
protocol = "tcp"
cidr_blocks = [aws_vpc.vpc.cidr_block]
}

tags = merge({ "Vendor" = "StreamNative", Name = "${var.vpc_name}-s3tables-endpoint-sg" }, local.tags)

lifecycle {
ignore_changes = [tags]
}
}

resource "aws_vpc_endpoint" "s3tables_endpoint" {
count = var.enable_s3tables_endpoint ? 1 : 0

vpc_id = aws_vpc.vpc.id
service_name = format("com.amazonaws.%s.s3tables", var.region)
vpc_endpoint_type = "Interface"
subnet_ids = aws_subnet.private[*].id
security_group_ids = [aws_security_group.s3tables_endpoint[0].id]
private_dns_enabled = true

policy = <<POLICY
{
"Version": "2008-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": "*",
"Resource": "*"
}
]
}
POLICY

tags = merge({ "Vendor" = "StreamNative", Name = "${var.vpc_name}-s3tables-endpoint" }, local.tags)
}
6 changes: 6 additions & 0 deletions modules/vpc/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -93,4 +93,10 @@ variable "enable_s3_gateway_endpoint" {
type = bool
default = false
description = "If set to true, will create S3 VPC Endpoint. This could be useful when wanna save costs from NAT Gateway."
}

variable "enable_s3tables_endpoint" {
type = bool
default = true
description = "If set to true, will create an Interface VPC Endpoint for the S3 Tables service so S3 Tables traffic stays on the AWS private network. Set to false in regions where S3 Tables is not yet available (apply will fail with InvalidServiceName otherwise)."
}
Loading