-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathsecurity_groups.tf
More file actions
128 lines (106 loc) · 2.63 KB
/
Copy pathsecurity_groups.tf
File metadata and controls
128 lines (106 loc) · 2.63 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
resource "aws_security_group" "public_sg" {
name = "public-sg"
description = "Security group for EC2 instance with public IP"
depends_on = [aws_vpc.main]
vpc_id = aws_vpc.main.id
ingress {
from_port = 0
to_port = 65535
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
egress {
from_port = 0
to_port = 0
protocol = "-1"
cidr_blocks = ["0.0.0.0/0"]
}
tags = var.public_sg_tag
}
resource "aws_security_group" "private_sg" {
name = "private-sg"
description = "Security group for EC2 instances without public IP"
depends_on = [aws_vpc.main]
vpc_id = aws_vpc.main.id
ingress {
from_port = var.ssh_port
to_port = var.ssh_port
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
ingress {
from_port = var.http_port
to_port = var.http_port
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
ingress {
from_port = var.https_port
to_port = var.https_port
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
ingress {
from_port = var.custom_port
to_port = var.custom_port
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
egress {
from_port = 0
to_port = 0
protocol = "-1"
cidr_blocks = ["0.0.0.0/0"]
}
tags = var.private_sg_tag
}
resource "aws_security_group" "postgresql_sg" {
name = "rds-sg"
description = "Allow SSH and PostgressQL traffic"
depends_on = [aws_vpc.main]
vpc_id = aws_vpc.main.id
ingress {
from_port = var.ssh_port
to_port = var.ssh_port
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"] # allow traffic from any IP address
}
ingress {
from_port = var.postgressql_port
to_port = var.postgressql_port
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"] # allow traffic from any IP address
}
egress {
from_port = 0
to_port = 0
protocol = "-1"
cidr_blocks = ["0.0.0.0/0"] # allow traffic to any IP address
}
tags = var.rds_sg_tag
}
resource "aws_security_group" "load_balancer_sg" {
name = "load-balancer-sg"
description = "Allow HTTP and HTTPS traffic"
depends_on = [aws_vpc.main]
vpc_id = aws_vpc.main.id
ingress {
from_port = var.http_port
to_port = var.http_port
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
ingress {
from_port = var.https_port
to_port = var.https_port
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
egress {
from_port = 0
to_port = 0
protocol = "-1"
cidr_blocks = ["0.0.0.0/0"]
}
tags = var.load_balancer_sg_tag
}