-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathtf_cfn_template.json
More file actions
144 lines (134 loc) · 4.09 KB
/
Copy pathtf_cfn_template.json
File metadata and controls
144 lines (134 loc) · 4.09 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
AWSTemplateFormatVersion: 2010-09-09
Description: Base infrastructure for the Terraform remote backend
Parameters:
CommonTags:
Description: Common tags to be applied to resources
Type: CommaDelimitedList
Default: "eks-gha-karpenter,IaC-CFN"
prefix:
Description: Prefix used for naming AWS resources
Type: String
Default: "eksghakrpntr"
ddbPrefix:
Description: Prefix used for naming DynamoDB resource
Type: String
Default: "eksghakrpntr"
Resources:
KmsBucketKey:
Type: AWS::KMS::Key
Properties:
Description: Key to encrypt the terraform backend bucket
Enabled: True
EnableKeyRotation: True
KeyPolicy:
Version: 2012-10-17
Id: key-s3-bucket-terraform-backend
Statement:
- Sid: Enable IAM User Permissions
Effect: Allow
Principal:
AWS: !Sub arn:aws:iam::${AWS::AccountId}:root
Action: 'kms:*'
Resource: '*'
Tags:
-
Key: "Project"
Value: !Select [ 0, !Ref CommonTags ]
-
Key: "Creation_Method"
Value: !Select [ 1, !Ref CommonTags ]
TerraformRemoteBackendBucket:
Type: AWS::S3::Bucket
DeletionPolicy: Retain
Properties:
BucketName: !Sub "${prefix}-${AWS::AccountId}-${AWS::Region}-terraform-state-bucket"
BucketEncryption:
ServerSideEncryptionConfiguration:
- ServerSideEncryptionByDefault:
SSEAlgorithm: 'aws:kms'
KMSMasterKeyID: !GetAtt KmsBucketKey.KeyId
PublicAccessBlockConfiguration:
BlockPublicAcls: true
BlockPublicPolicy: true
IgnorePublicAcls: true
RestrictPublicBuckets: true
VersioningConfiguration:
Status: Enabled
LoggingConfiguration:
DestinationBucketName: !Ref AccessLogsBucket
LogFilePrefix: 'logs/'
Tags:
-
Key: "Project"
Value: !Select [ 0, !Ref CommonTags ]
-
Key: "Creation_Method"
Value: !Select [ 1, !Ref CommonTags ]
TerraformRemoteBackendBucketBucketPolicy:
Type: AWS::S3::BucketPolicy
Properties:
Bucket: !Ref TerraformRemoteBackendBucket
PolicyDocument:
Statement:
- Sid: DenyDeletingTerraformStateFiles
Effect: Deny
Principal: "*"
Action: "s3:DeleteObject"
Resource: !Sub "arn:aws:s3:::${TerraformRemoteBackendBucket}/*"
AccessLogsBucket:
Type: AWS::S3::Bucket
DeletionPolicy: Retain
Properties:
BucketName: !Sub ${prefix}-${AWS::AccountId}-${AWS::Region}-tf-backend-accesslogs
BucketEncryption:
ServerSideEncryptionConfiguration:
- ServerSideEncryptionByDefault:
SSEAlgorithm: AES256
PublicAccessBlockConfiguration:
BlockPublicAcls: true
BlockPublicPolicy: true
IgnorePublicAcls: true
RestrictPublicBuckets: true
VersioningConfiguration:
Status: Enabled
Tags:
-
Key: "Project"
Value: !Select [ 0, !Ref CommonTags ]
-
Key: "Creation_Method"
Value: !Select [ 1, !Ref CommonTags ]
TerrraformRemoteBackendDDB:
Type: AWS::DynamoDB::Table
Properties:
TableName: !Sub ${ddbPrefix}-terraform-backend
DeletionProtectionEnabled: true
BillingMode: PAY_PER_REQUEST
AttributeDefinitions:
- AttributeName: LockID
AttributeType: S
KeySchema:
- AttributeName: LockID
KeyType: HASH
SSESpecification:
SSEEnabled: true
SSEType: KMS
KMSMasterKeyId: !GetAtt KmsBucketKey.Arn
PointInTimeRecoverySpecification:
PointInTimeRecoveryEnabled: true
Tags:
-
Key: "Project"
Value: !Select [ 0, !Ref CommonTags ]
-
Key: "Creation_Method"
Value: !Select [ 1, !Ref CommonTags ]
Outputs:
TerraformBackendBucketName:
Value: !Ref TerraformRemoteBackendBucket
Export:
Name: 'TerraformBackendBucketName'
TerraformBackendDynamoDBName:
Value: !Ref TerrraformRemoteBackendDDB
Export:
Name: 'TerraformBackendDynamoDBName'