arunodhayamsam 027d5f
#Create the VPC 
arunodhayamsam 027d5f
resource "aws_vpc" "MAIN" {
arunodhayamsam 027d5f
  cidr_block           = "${var.vpc_cidr}"
arunodhayamsam 027d5f
  enable_dns_hostnames = true 
arunodhayamsam 027d5f
  enable_dns_support   = true
arunodhayamsam 027d5f
  instance_tenancy     = "default"
arunodhayamsam 027d5f
  tags                 = {
arunodhayamsam 027d5f
      Name             = "lufi-master-vpc"
arunodhayamsam 027d5f
  }
arunodhayamsam 027d5f
}
arunodhayamsam 027d5f
arunodhayamsam 027d5f
# Create InternetGateWay and attach to VPC
arunodhayamsam 027d5f
arunodhayamsam 027d5f
resource "aws_internet_gateway" "IGW" {
arunodhayamsam 027d5f
  vpc_id           = "${aws_vpc.MAIN.id}"
arunodhayamsam 027d5f
  tags = {
arunodhayamsam 027d5f
    "Name"         = "lufi-master-igw"
arunodhayamsam 027d5f
  } 
arunodhayamsam 027d5f
}
arunodhayamsam 027d5f
arunodhayamsam 027d5f
# Create a public subnet
arunodhayamsam 027d5f
arunodhayamsam 027d5f
resource "aws_subnet" "publicsubnet" {
arunodhayamsam 027d5f
  vpc_id                  = "${aws_vpc.MAIN.id}" 
arunodhayamsam 027d5f
  cidr_block              = "${var.public_subnet_cidr}"
arunodhayamsam 027d5f
  map_public_ip_on_launch = true
arunodhayamsam 027d5f
  tags                    = {
arunodhayamsam 027d5f
      Name                = "lufi-master-us-east-1-public"
arunodhayamsam 027d5f
  }  
arunodhayamsam 027d5f
}
arunodhayamsam 027d5f
arunodhayamsam 027d5f
# Create routeTable
arunodhayamsam 027d5f
resource "aws_route_table" "publicroute" {
arunodhayamsam 027d5f
    vpc_id         = "${aws_vpc.MAIN.id}"
arunodhayamsam 027d5f
    route {
arunodhayamsam 027d5f
        cidr_block = "0.0.0.0/0"
arunodhayamsam 027d5f
        gateway_id = "${aws_internet_gateway.IGW.id}"
arunodhayamsam 027d5f
    }
arunodhayamsam 027d5f
             
arunodhayamsam 027d5f
    tags           = {
arunodhayamsam 027d5f
      Name         = "lufi-master-us-east-1-public-rt"
arunodhayamsam 027d5f
 }
arunodhayamsam 027d5f
}
arunodhayamsam 027d5f
arunodhayamsam 027d5f
resource "aws_main_route_table_association" "mainRTB" {
arunodhayamsam 027d5f
  vpc_id         = "${aws_vpc.MAIN.id}"
arunodhayamsam 027d5f
  route_table_id = "${aws_route_table.publicroute.id}"
arunodhayamsam 027d5f
}
arunodhayamsam 027d5f
## Create security group
arunodhayamsam 027d5f
resource "aws_security_group" "security" {
arunodhayamsam 027d5f
  name             = "lufi-master-sg"  
arunodhayamsam 027d5f
  description      = "allow all traffic"
arunodhayamsam 027d5f
  vpc_id           = "${aws_vpc.MAIN.id}"
arunodhayamsam 027d5f
arunodhayamsam 027d5f
  ingress  {
arunodhayamsam 027d5f
    description    =  "allow all traffic"
arunodhayamsam 027d5f
    from_port      = "0"
arunodhayamsam 027d5f
    to_port        = "65535"  
arunodhayamsam 027d5f
    protocol       = "tcp"
arunodhayamsam 027d5f
    cidr_blocks    = ["0.0.0.0/0"]
arunodhayamsam 027d5f
  }
arunodhayamsam 027d5f
  ingress  {
arunodhayamsam 027d5f
    description    = "allow port SSH"
arunodhayamsam 027d5f
    from_port      = "22"
arunodhayamsam 027d5f
    to_port        = "22"
arunodhayamsam 027d5f
    protocol       = "tcp"
arunodhayamsam 027d5f
    cidr_blocks    = ["0.0.0.0/0"]
arunodhayamsam 027d5f
  }
arunodhayamsam 027d5f
  egress  {
arunodhayamsam 027d5f
    from_port      = 0
arunodhayamsam 027d5f
    to_port        = 0
arunodhayamsam 027d5f
    protocol       = "-1"
arunodhayamsam 027d5f
    cidr_blocks    = ["0.0.0.0/0"]
arunodhayamsam 027d5f
  }
arunodhayamsam 027d5f
  
arunodhayamsam 027d5f
}
arunodhayamsam 027d5f
arunodhayamsam 027d5f
#Create key_pair for the instance
arunodhayamsam 027d5f
arunodhayamsam 027d5f
resource "aws_key_pair" "genkey" {
arunodhayamsam 027d5f
  key_name           = "lufi.webapp"
arunodhayamsam 027d5f
  public_key         = "${file(var.public_key)}"
arunodhayamsam 027d5f
}
arunodhayamsam 027d5f
arunodhayamsam 027d5f
# Craete ec2 instance
arunodhayamsam 027d5f
resource "aws_instance" "ec2_instance" {
arunodhayamsam 027d5f
  ami                = "ami-04505e74c0741db8d"
arunodhayamsam 027d5f
  instance_type      = "t2.medium"
arunodhayamsam 027d5f
  associate_public_ip_address = "true"
arunodhayamsam 027d5f
  subnet_id          = "${aws_subnet.publicsubnet.id}"
arunodhayamsam 027d5f
  vpc_security_group_ids = ["${aws_security_group.security.id}"]
arunodhayamsam 027d5f
  key_name           = "lufi.webapp"
arunodhayamsam 027d5f
arunodhayamsam 027d5f
  connection          {
arunodhayamsam 027d5f
    agent            = false
arunodhayamsam 027d5f
    type             = "ssh"
arunodhayamsam 027d5f
    host             = aws_instance.ec2_instance.public_dns 
arunodhayamsam 027d5f
    private_key      = "${file(var.private_key)}"
arunodhayamsam 027d5f
    user             = "${var.user}"
arunodhayamsam 027d5f
  }
arunodhayamsam 027d5f
arunodhayamsam 027d5f
  provisioner "remote-exec" {
arunodhayamsam 027d5f
    inline = [
arunodhayamsam 027d5f
      "sudo apt update -y",
arunodhayamsam 027d5f
      "sudo apt install python3.9 -y",
arunodhayamsam 027d5f
      ]
arunodhayamsam 027d5f
  }
arunodhayamsam 027d5f
arunodhayamsam 027d5f
  provisioner "local-exec" {
arunodhayamsam 027d5f
    command = <
arunodhayamsam 027d5f
      sleep 120 && \
arunodhayamsam 027d5f
      > hosts && \
arunodhayamsam 027d5f
      echo "[Lufi]" | tee -a hosts && \
arunodhayamsam 027d5f
      echo "${aws_instance.ec2_instance.public_ip} ansible_user=${var.user} ansible_ssh_private_key_file=${var.private_key}" | tee -a hosts && \
arunodhayamsam 027d5f
      export ANSIBLE_HOST_KEY_CHECKING=False && \
arunodhayamsam 027d5f
      ansible-playbook -u ${var.user} --private-key ${var.private_key} -i hosts site.yml
arunodhayamsam 027d5f
    EOT
arunodhayamsam 027d5f
  }
arunodhayamsam 027d5f
  
arunodhayamsam 027d5f
  tags               = {
arunodhayamsam 027d5f
    Name             = "${var.instance_name}"
arunodhayamsam 027d5f
  }
arunodhayamsam 027d5f
}
arunodhayamsam 027d5f
arunodhayamsam 027d5f
arunodhayamsam 027d5f