|
arunodhayamsam |
3b074a |
locals {
|
|
arunodhayamsam |
3b074a |
user_data_vars = {
|
|
arunodhayamsam |
3b074a |
user = var.lufi_owner
|
|
arunodhayamsam |
3b074a |
group = var.lufi_group
|
|
arunodhayamsam |
3b074a |
directory = var.app_dir
|
|
arunodhayamsam |
3b074a |
contact_lufi = var.contact
|
|
arunodhayamsam |
3b074a |
report_lufi = var.report
|
|
arunodhayamsam |
3b074a |
}
|
|
arunodhayamsam |
3b074a |
}
|
|
arunodhayamsam |
3b074a |
|
|
arunodhayamsam |
027d5f |
#Create the VPC
|
|
arunodhayamsam |
17bcb2 |
resource "aws_vpc" "vpc" {
|
|
arunodhayamsam |
027d5f |
cidr_block = "${var.vpc_cidr}"
|
|
arunodhayamsam |
027d5f |
enable_dns_hostnames = true
|
|
arunodhayamsam |
027d5f |
enable_dns_support = true
|
|
arunodhayamsam |
027d5f |
instance_tenancy = "default"
|
|
arunodhayamsam |
027d5f |
tags = {
|
|
arunodhayamsam |
027d5f |
Name = "lufi-master-vpc"
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
027d5f |
# Create InternetGateWay and attach to VPC
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
027d5f |
resource "aws_internet_gateway" "IGW" {
|
|
arunodhayamsam |
17bcb2 |
vpc_id = "${aws_vpc.vpc.id}"
|
|
arunodhayamsam |
027d5f |
tags = {
|
|
arunodhayamsam |
027d5f |
"Name" = "lufi-master-igw"
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
027d5f |
# Create a public subnet
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
027d5f |
resource "aws_subnet" "publicsubnet" {
|
|
arunodhayamsam |
17bcb2 |
vpc_id = "${aws_vpc.vpc.id}"
|
|
arunodhayamsam |
027d5f |
cidr_block = "${var.public_subnet_cidr}"
|
|
arunodhayamsam |
027d5f |
map_public_ip_on_launch = true
|
|
arunodhayamsam |
027d5f |
tags = {
|
|
arunodhayamsam |
027d5f |
Name = "lufi-master-us-east-1-public"
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
027d5f |
# Create routeTable
|
|
arunodhayamsam |
17bcb2 |
resource "aws_route_table" "public" {
|
|
arunodhayamsam |
17bcb2 |
vpc_id = "${aws_vpc.vpc.id}"
|
|
arunodhayamsam |
027d5f |
route {
|
|
arunodhayamsam |
027d5f |
cidr_block = "0.0.0.0/0"
|
|
arunodhayamsam |
027d5f |
gateway_id = "${aws_internet_gateway.IGW.id}"
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
027d5f |
tags = {
|
|
arunodhayamsam |
027d5f |
Name = "lufi-master-us-east-1-public-rt"
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
027d5f |
resource "aws_main_route_table_association" "mainRTB" {
|
|
arunodhayamsam |
17bcb2 |
vpc_id = "${aws_vpc.vpc.id}"
|
|
arunodhayamsam |
17bcb2 |
route_table_id = "${aws_route_table.public.id}"
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
## Create security group
|
|
arunodhayamsam |
027d5f |
resource "aws_security_group" "security" {
|
|
arunodhayamsam |
027d5f |
name = "lufi-master-sg"
|
|
arunodhayamsam |
027d5f |
description = "allow all traffic"
|
|
arunodhayamsam |
17bcb2 |
vpc_id = "${aws_vpc.vpc.id}"
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
027d5f |
ingress {
|
|
arunodhayamsam |
027d5f |
description = "allow all traffic"
|
|
arunodhayamsam |
027d5f |
from_port = "0"
|
|
arunodhayamsam |
027d5f |
to_port = "65535"
|
|
arunodhayamsam |
027d5f |
protocol = "tcp"
|
|
arunodhayamsam |
027d5f |
cidr_blocks = ["0.0.0.0/0"]
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
ingress {
|
|
arunodhayamsam |
027d5f |
description = "allow port SSH"
|
|
arunodhayamsam |
027d5f |
from_port = "22"
|
|
arunodhayamsam |
027d5f |
to_port = "22"
|
|
arunodhayamsam |
027d5f |
protocol = "tcp"
|
|
arunodhayamsam |
027d5f |
cidr_blocks = ["0.0.0.0/0"]
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
egress {
|
|
arunodhayamsam |
027d5f |
from_port = 0
|
|
arunodhayamsam |
027d5f |
to_port = 0
|
|
arunodhayamsam |
027d5f |
protocol = "-1"
|
|
arunodhayamsam |
027d5f |
cidr_blocks = ["0.0.0.0/0"]
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
027d5f |
#Create key_pair for the instance
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
027d5f |
resource "aws_key_pair" "genkey" {
|
|
arunodhayamsam |
027d5f |
key_name = "lufi.webapp"
|
|
arunodhayamsam |
027d5f |
public_key = "${file(var.public_key)}"
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
17bcb2 |
# Add ubuntu AMI
|
|
arunodhayamsam |
17bcb2 |
data "aws_ami" "ubuntu" {
|
|
arunodhayamsam |
17bcb2 |
most_recent = true
|
|
arunodhayamsam |
17bcb2 |
owners = ["099720109477"]
|
|
arunodhayamsam |
17bcb2 |
|
|
arunodhayamsam |
17bcb2 |
filter {
|
|
arunodhayamsam |
17bcb2 |
name = "name"
|
|
arunodhayamsam |
17bcb2 |
values = ["ubuntu/images/hvm-ssd/ubuntu-focal-20.04-amd64-server-*"]
|
|
arunodhayamsam |
17bcb2 |
}
|
|
arunodhayamsam |
17bcb2 |
}
|
|
arunodhayamsam |
17bcb2 |
|
|
arunodhayamsam |
027d5f |
# Craete ec2 instance
|
|
arunodhayamsam |
027d5f |
resource "aws_instance" "ec2_instance" {
|
|
arunodhayamsam |
17bcb2 |
ami = "${data.aws_ami.ubuntu.id}"
|
|
arunodhayamsam |
027d5f |
instance_type = "t2.medium"
|
|
arunodhayamsam |
027d5f |
associate_public_ip_address = "true"
|
|
arunodhayamsam |
027d5f |
subnet_id = "${aws_subnet.publicsubnet.id}"
|
|
arunodhayamsam |
027d5f |
vpc_security_group_ids = ["${aws_security_group.security.id}"]
|
|
arunodhayamsam |
3b074a |
user_data = templatefile("${path.module}/lufi_startup.sh", local.user_data_vars)
|
|
arunodhayamsam |
027d5f |
key_name = "lufi.webapp"
|
|
arunodhayamsam |
027d5f |
|
|
arunodhayamsam |
027d5f |
tags = {
|
|
arunodhayamsam |
027d5f |
Name = "${var.instance_name}"
|
|
arunodhayamsam |
027d5f |
}
|
|
arunodhayamsam |
027d5f |
}
|