-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathmain-puppet.tf
74 lines (62 loc) · 2.01 KB
/
main-puppet.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
module "puppet-server" {
source = "./modules/gp-instance"
enabled = var.puppet
subnet_id = aws_subnet.a.id
sg_ids = [aws_default_security_group.sg.id, aws_security_group.puppet-server.id]
region = var.region
hostname = "puppet.${var.route53_domain}"
route53_zoneID = var.route53_zoneID
dnsupdate_rolearn = var.dnsupdate_rolearn
dnsupdate_region = var.dnsupdate_region
public_ip = true
instance_type = "t3.small"
template_path = "${path.module}/templates/puppet-server-user_data.tpl"
template_vars = {
hostname = module.puppet-server.hostname
keypubic = var.keypublic
username = var.username
puppet_domain = var.route53_domain
puppet_version = var.puppet_version
puppetdb_version = var.puppetdb_version
}
ipv6 = var.ipv6
username = var.username
keypublic = var.keypublic
tags = {
Name = "${var.vpcname}-puppet-server"
environment = var.environment
deployment = var.deployment
OWNER = var.OWNER
ROLE = var.ROLE
AlwaysOn = var.AlwaysOn
puppet_version = var.puppet_version
}
}
# Final Output summarising VPN Credentials, IP Addresses and DNS Names
output "Puppet_Hostname" {
# sensitive = true
value = var.puppet ? module.puppet-server.internal_hostname : ""
}
########################
# SECURITY GROUP #
########################
resource "aws_security_group" "puppet-server" {
vpc_id = aws_vpc.vpc.id
name = "${var.vpcname}_puppet-server"
description = "${var.vpcname} puppet server"
ingress {
from_port = 8140
to_port = 8140
protocol = "tcp"
cidr_blocks = var.fw_app_cidr_ipv4
ipv6_cidr_blocks = var.fw_app_cidr_ipv6
}
tags = {
Name = "${var.vpcname}_puppet-server"
environment = var.environment
deployment = var.deployment
OWNER = var.OWNER
ROLE = var.ROLE
AlwaysOn = var.AlwaysOn
}
}