Initial commit

This commit is contained in:
drewmullen
2022-07-06 09:17:41 -04:00
committed by Rodrigue Koffi
parent eaee1ddedd
commit 0262a8a45d
25 changed files with 559 additions and 10 deletions
+42
View File
@@ -0,0 +1,42 @@
build/
plan.out
plan.out.json
# Local .terraform directories
.terraform/
# .tfstate files
*.tfstate
*.tfstate.*
# Crash log files
crash.log
# Exclude all .tfvars files, which are likely to contain sentitive data, such as
# password, private keys, and other secrets. These should not be part of version
# control as they are data points which are potentially sensitive and subject
# to change depending on the environment.
#
*.tfvars
# Ignore override files as they are usually used to override resources locally and so
# are not checked in
override.tf
override.tf.json
*_override.tf
*_override.tf.json
# Include override files you do wish to add to version control using negated pattern
#
# !example_override.tf
# Include tfplan files to ignore the plan output of command: terraform plan -out=tfplan
# example: *tfplan*
# Ignore CLI configuration files
.terraformrc
terraform.rc
.terraform.lock.hcl
go.mod
go.sum
+57
View File
@@ -0,0 +1,57 @@
# Creating modules for AWS I&A Organization
This repo template is used to seed Terraform Module templates for the [AWS I&A GitHub organization](https://github.com/aws-ia). Usage of this template is allowed per included license. PRs to this template will be considered but are not guaranteed to be included. Consider creating an issue to discuss a feature you want to include before taking the time to create a PR.
### TL;DR
1. [install pre-commit](https://pre-commit.com/)
2. configure pre-commit: `pre-commit install`
3. install required tools
- [tflint](https://github.com/terraform-linters/tflint)
- [tfsec](https://aquasecurity.github.io/tfsec/v1.0.11/)
- [terraform-docs](https://github.com/terraform-docs/terraform-docs)
- [golang](https://go.dev/doc/install) (for macos you can use `brew`)
- [coreutils](https://www.gnu.org/software/coreutils/)
Write code according to [I&A module standards](https://aws-ia.github.io/standards-terraform/)
## Module Documentation
**Do not manually update README.md**. `terraform-docs` is used to generate README files. For any instructions an content, please update [.header.md](./.header.md) then simply run `terraform-docs ./` or allow the `pre-commit` to do so.
## Terratest
Please include tests to validate your examples/<> root modules, at a minimum. This can be accomplished with usually only slight modifications to the [boilerplate test provided in this template](./test/examples_basic_test.go)
### Configure and run Terratest
1. Install
[golang](https://go.dev/doc/install) (for macos you can use `brew`)
2. Change directory into the test folder.
`cd test`
3. Initialize your test
go mod init github.com/[github org]/[repository]
`go mod init github.com/aws-ia/terraform-aws-vpc`
4. Run tidy
`git mod tidy`
5. Install Terratest
`go get github.com/gruntwork-io/terratest/modules/terraform`
6. Run test (You can have multiple test files).
- Run all tests
`go test`
- Run a specific test with a timeout
`go test -run examples_basic_test.go -timeout 45m`
## Module Standards
For best practices and information on developing with Terraform, see the [I&A Module Standards](https://aws-ia.github.io/standards-terraform/)
## Continuous Integration
The I&A team uses AWS CodeBuild to perform continuous integration (CI) within the organization. Our CI uses the a repo's `.pre-commit-config.yaml` file as well as some other checks. All PRs with other CI will be rejected. See our [FAQ](https://aws-ia.github.io/standards-terraform/faq/#are-modules-protected-by-ci-automation) for more details.
+11
View File
@@ -0,0 +1,11 @@
---
fail_fast: false
minimum_pre_commit_version: "2.6.0"
repos:
-
repo: https://github.com/aws-ia/pre-commit-configs
# To update run:
# pre-commit autoupdate --freeze
rev: 80ed3f0a164f282afaac0b6aec70e20f7e541932 # frozen: v1.5.0
hooks:
- id: aws-ia-meta-hook
+20
View File
@@ -0,0 +1,20 @@
formatter: markdown
header-from: .header.md
settings:
anchor: true
color: true
default: true
escape: true
html: true
indent: 2
required: true
sensitive: true
type: true
sort:
enabled: true
by: required
output:
file: README.md
mode: replace
+66
View File
@@ -0,0 +1,66 @@
# https://github.com/terraform-linters/tflint/blob/master/docs/user-guide/module-inspection.md
# borrowed & modified indefinitely from https://github.com/ksatirli/building-infrastructure-you-can-mostly-trust/blob/main/.tflint.hcl
plugin "aws" {
enabled = true
version = "0.14.0"
source = "github.com/terraform-linters/tflint-ruleset-aws"
}
config {
module = true
force = false
}
rule "terraform_required_providers" {
enabled = true
}
rule "terraform_required_version" {
enabled = true
}
rule "terraform_naming_convention" {
enabled = true
format = "snake_case"
}
rule "terraform_typed_variables" {
enabled = true
}
rule "terraform_unused_declarations" {
enabled = true
}
rule "terraform_comment_syntax" {
enabled = true
}
rule "terraform_deprecated_index" {
enabled = true
}
rule "terraform_deprecated_interpolation" {
enabled = true
}
rule "terraform_documented_outputs" {
enabled = true
}
rule "terraform_documented_variables" {
enabled = true
}
rule "terraform_module_pinned_source" {
enabled = true
}
rule "terraform_standard_module_structure" {
enabled = true
}
rule "terraform_workspace_remote" {
enabled = true
}
@@ -0,0 +1,39 @@
{
"checks": [
{
"code": "CUS002",
"description": "Check to IMDSv2 is required on EC2 instances created by this Launch Template",
"impact": "Instance metadata service can be interacted with freely",
"resolution": "Enable HTTP token requirement for IMDS",
"requiredTypes": [
"resource"
],
"requiredLabels": [
"aws_launch_configuration"
],
"severity": "CRITICAL",
"matchSpec": {
"action": "isPresent",
"name": "metadata_options",
"subMatch": {
"action": "and",
"predicateMatchSpec": [
{
"action": "equals",
"name": "http_tokens",
"value": "required"
}
]
}
},
"errorMessage": "is missing `metadata_options` block - it is required with `http_tokens` set to `required` to make Instance Metadata Service more secure.",
"relatedLinks": [
"https://tfsec.dev/docs/aws/ec2/enforce-http-token-imds#aws/ec2",
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_configuration#metadata-options",
"https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service"
]
}
]
}
@@ -0,0 +1,39 @@
{
"checks": [
{
"code": "CUS001",
"description": "Check to IMDSv2 is required on EC2 instances created by this Launch Template",
"impact": "Instance metadata service can be interacted with freely",
"resolution": "Enable HTTP token requirement for IMDS",
"requiredTypes": [
"resource"
],
"requiredLabels": [
"aws_launch_template"
],
"severity": "CRITICAL",
"matchSpec": {
"action": "isPresent",
"name": "metadata_options",
"subMatch": {
"action": "and",
"predicateMatchSpec": [
{
"action": "equals",
"name": "http_tokens",
"value": "required"
}
]
}
},
"errorMessage": "is missing `metadata_options` block - it is required with `http_tokens` set to `required` to make Instance Metadata Service more secure.",
"relatedLinks": [
"https://tfsec.dev/docs/aws/ec2/enforce-http-token-imds#aws/ec2",
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_template#metadata-options",
"https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service"
]
}
]
}
+27
View File
@@ -0,0 +1,27 @@
{
"checks": [
{
"code": "CUS003",
"description": "Use `aws_launch_template` over `aws_launch_configuration",
"impact": "Launch configurations are not capable of versions",
"resolution": "Convert resource type and attributes to `aws_launch_template`",
"requiredTypes": [
"resource"
],
"requiredLabels": [
"aws_launch_configuration"
],
"severity": "MEDIUM",
"matchSpec": {
"action": "notPresent",
"name": "image_id"
},
"errorMessage": "should be changed to `aws_launch_template` since the functionality is the same but templates can be versioned.",
"relatedLinks": [
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_template",
"https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service"
]
}
]
}
@@ -0,0 +1,27 @@
{
"checks": [
{
"code": "CUS005",
"description": "Security group rules should be defined with `aws_security_group_rule` instead of embedded.",
"impact": "Embedded security group rules can cause issues during configuration updates.",
"resolution": "Move `egress` rules to `aws_security_group_rule` and attach to `aws_security_group`.",
"requiredTypes": [
"resource"
],
"requiredLabels": [
"aws_security_group"
],
"severity": "MEDIUM",
"matchSpec": {
"action": "notPresent",
"name": "egress"
},
"errorMessage": "`egress` rules should be moved to `aws_security_group_rule` and attached to `aws_security_group` instead of embedded.",
"relatedLinks": [
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group_rule",
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group"
]
}
]
}
@@ -0,0 +1,27 @@
{
"checks": [
{
"code": "CUS004",
"description": "Security group rules should be defined with `aws_security_group_rule` instead of embedded.",
"impact": "Embedded security group rules can cause issues during configuration updates.",
"resolution": "Move `ingress` rules to `aws_security_group_rule` and attach to `aws_security_group`.",
"requiredTypes": [
"resource"
],
"requiredLabels": [
"aws_security_group"
],
"severity": "MEDIUM",
"matchSpec": {
"action": "notPresent",
"name": "ingress"
},
"errorMessage": "`ingress` rules should be moved to `aws_security_group_rule` and attached to `aws_security_group` instead of embedded.",
"relatedLinks": [
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group_rule",
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group"
]
}
]
}
+1
View File
@@ -0,0 +1 @@
* @aws-ia/aws-ia
+27 -1
View File
@@ -1,4 +1,3 @@
Apache License
Version 2.0, January 2004
http://www.apache.org/licenses/
@@ -173,3 +172,30 @@
defend, and hold each Contributor harmless for any liability
incurred by, or claims asserted against, such Contributor by reason
of your accepting any such warranty or additional liability.
END OF TERMS AND CONDITIONS
APPENDIX: How to apply the Apache License to your work.
To apply the Apache License to your work, attach the following
boilerplate notice, with the fields enclosed by brackets "[]"
replaced with your own identifying information. (Don't include
the brackets!) The text should be enclosed in the appropriate
comment syntax for the file format. We also recommend that a
file or class name and description of purpose be included on the
same "printed page" as the copyright notice for easier
identification within third-party archives.
Copyright [yyyy] [name of copyright owner]
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
+7
View File
@@ -0,0 +1,7 @@
Copyright 2016-2022 Amazon.com, Inc. or its affiliates. All Rights Reserved.
Licensed under the Apache License, Version 2.0 (the "License"). You may not use this file except in compliance with the License. A copy of the License is located at
http://aws.amazon.com/apache2.0/
or in the "license" file accompanying this file. This file is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
+80 -9
View File
@@ -1,17 +1,88 @@
## My Project
<!-- BEGIN_TF_DOCS -->
# Creating modules for AWS I&A Organization
TODO: Fill this README out!
This repo template is used to seed Terraform Module templates for the [AWS I&A GitHub organization](https://github.com/aws-ia). Usage of this template is allowed per included license. PRs to this template will be considered but are not guaranteed to be included. Consider creating an issue to discuss a feature you want to include before taking the time to create a PR.
### TL;DR
Be sure to:
1. [install pre-commit](https://pre-commit.com/)
2. configure pre-commit: `pre-commit install`
3. install required tools
- [tflint](https://github.com/terraform-linters/tflint)
- [tfsec](https://aquasecurity.github.io/tfsec/v1.0.11/)
- [terraform-docs](https://github.com/terraform-docs/terraform-docs)
- [golang](https://go.dev/doc/install) (for macos you can use `brew`)
- [coreutils](https://www.gnu.org/software/coreutils/)
* Change the title in this README
* Edit your repository description on GitHub
Write code according to [I&A module standards](https://aws-ia.github.io/standards-terraform/)
## Security
## Module Documentation
See [CONTRIBUTING](CONTRIBUTING.md#security-issue-notifications) for more information.
**Do not manually update README.md**. `terraform-docs` is used to generate README files. For any instructions an content, please update [.header.md](./.header.md) then simply run `terraform-docs ./` or allow the `pre-commit` to do so.
## License
## Terratest
This project is licensed under the Apache-2.0 License.
Please include tests to validate your examples/<> root modules, at a minimum. This can be accomplished with usually only slight modifications to the [boilerplate test provided in this template](./test/examples\_basic\_test.go)
### Configure and run Terratest
1. Install
[golang](https://go.dev/doc/install) (for macos you can use `brew`)
2. Change directory into the test folder.
`cd test`
3. Initialize your test
go mod init github.com/[github org]/[repository]
`go mod init github.com/aws-ia/terraform-aws-vpc`
4. Run tidy
`git mod tidy`
5. Install Terratest
`go get github.com/gruntwork-io/terratest/modules/terraform`
6. Run test (You can have multiple test files).
- Run all tests
`go test`
- Run a specific test with a timeout
`go test -run examples_basic_test.go -timeout 45m`
## Module Standards
For best practices and information on developing with Terraform, see the [I&A Module Standards](https://aws-ia.github.io/standards-terraform/)
## Continuous Integration
The I&A team uses AWS CodeBuild to perform continuous integration (CI) within the organization. Our CI uses the a repo's `.pre-commit-config.yaml` file as well as some other checks. All PRs with other CI will be rejected. See our [FAQ](https://aws-ia.github.io/standards-terraform/faq/#are-modules-protected-by-ci-automation) for more details.
## Requirements
| Name | Version |
|------|---------|
| <a name="requirement_terraform"></a> [terraform](#requirement\_terraform) | >= 0.14.0 |
| <a name="requirement_aws"></a> [aws](#requirement\_aws) | >= 4.0.0, < 5.0.0 |
| <a name="requirement_awscc"></a> [awscc](#requirement\_awscc) | >= 0.24.0 |
## Providers
No providers.
## Modules
No modules.
## Resources
No resources.
## Inputs
No inputs.
## Outputs
No outputs.
<!-- END_TF_DOCS -->
View File
+29
View File
@@ -0,0 +1,29 @@
<!-- BEGIN_TF_DOCS -->
## Requirements
| Name | Version |
|------|---------|
| <a name="requirement_terraform"></a> [terraform](#requirement\_terraform) | >= 0.14.0 |
| <a name="requirement_aws"></a> [aws](#requirement\_aws) | >= 3.72.0 |
| <a name="requirement_awscc"></a> [awscc](#requirement\_awscc) | >= 0.11.0 |
## Providers
No providers.
## Modules
No modules.
## Resources
No resources.
## Inputs
No inputs.
## Outputs
No outputs.
<!-- END_TF_DOCS -->
+5
View File
@@ -0,0 +1,5 @@
#####################################################################################
# Terraform module examples are meant to show an _example_ on how to use a module
# per use-case. The code below should not be copied directly but referenced in order
# to build your own root module that invokes this module
#####################################################################################
View File
+21
View File
@@ -0,0 +1,21 @@
terraform {
required_version = ">= 0.14.0"
required_providers {
aws = {
source = "hashicorp/aws"
version = ">= 3.72.0"
}
awscc = {
source = "hashicorp/awscc"
version = ">= 0.11.0"
}
}
}
provider "awscc" {
user_agent = [{
product_name = "terraform-awscc-"
product_version = "0.0.1"
comment = "V1/AWS-D69B4015/<github repo id>"
}]
}
View File
View File
View File
+13
View File
@@ -0,0 +1,13 @@
terraform {
required_version = ">= 0.14.0"
required_providers {
aws = {
source = "hashicorp/aws"
version = ">= 4.0.0, < 5.0.0"
}
awscc = {
source = "hashicorp/awscc"
version = ">= 0.24.0"
}
}
}
+21
View File
@@ -0,0 +1,21 @@
package test
import (
"testing"
"github.com/gruntwork-io/terratest/modules/terraform"
)
func TestExamplesBasic(t *testing.T) {
terraformOptions := &terraform.Options{
TerraformDir: "../examples/basic",
// Vars: map[string]interface{}{
// "myvar": "test",
// "mylistvar": []string{"list_item_1"},
// },
}
defer terraform.Destroy(t, terraformOptions)
terraform.InitAndApply(t, terraformOptions)
}
View File