Terraform module updates (#43543)
This commit is contained in:
@@ -10,6 +10,10 @@ on:
|
||||
description: Dry run only? No "terraform apply"
|
||||
type: boolean
|
||||
default: false
|
||||
skip_free:
|
||||
description: Skip "Terraform Apply Free" and only run the dogfood apply?
|
||||
type: boolean
|
||||
default: false
|
||||
|
||||
# This allows a subsequently queued workflow run to interrupt previous runs
|
||||
concurrency:
|
||||
@@ -75,7 +79,7 @@ jobs:
|
||||
|
||||
- uses: hashicorp/setup-terraform@633666f66e0061ca3b725c73b2ec20cd13a8fdd1 # v2.0.3
|
||||
with:
|
||||
terraform_version: 1.10.2
|
||||
terraform_version: 1.12.0
|
||||
terraform_wrapper: false
|
||||
- name: Terraform Init
|
||||
id: init
|
||||
@@ -113,7 +117,7 @@ jobs:
|
||||
SLACK_WEBHOOK_TYPE: INCOMING_WEBHOOK
|
||||
# Note: This will cause the geolite2 image to be built twice, but that cannot be avoided without refactoring the terraform to not tag it based upon timestamp.
|
||||
- name: Terraform Apply Free
|
||||
if: inputs.dry_run == false
|
||||
if: inputs.dry_run == false && inputs.skip_free == false
|
||||
id: apply-free
|
||||
run: terraform apply -target=module.free -target=module.migrations_free -target=module.geolite2 -auto-approve
|
||||
- name: Terraform Apply
|
||||
|
||||
@@ -108,7 +108,7 @@ jobs:
|
||||
go-version-file: 'go.mod'
|
||||
- uses: hashicorp/setup-terraform@633666f66e0061ca3b725c73b2ec20cd13a8fdd1 # v2.0.3
|
||||
with:
|
||||
terraform_version: 1.10.2
|
||||
terraform_version: 1.12.0
|
||||
terraform_wrapper: false
|
||||
- name: Terraform Init
|
||||
id: init
|
||||
|
||||
@@ -93,7 +93,7 @@ jobs:
|
||||
go-version-file: 'go.mod'
|
||||
- uses: hashicorp/setup-terraform@633666f66e0061ca3b725c73b2ec20cd13a8fdd1 # v2.0.3
|
||||
with:
|
||||
terraform_version: 1.10.2
|
||||
terraform_version: 1.12.0
|
||||
terraform_wrapper: false
|
||||
- name: Terraform Init
|
||||
id: init
|
||||
|
||||
@@ -56,7 +56,7 @@ jobs:
|
||||
go-version-file: 'go.mod'
|
||||
- uses: hashicorp/setup-terraform@633666f66e0061ca3b725c73b2ec20cd13a8fdd1 # v2.0.3
|
||||
with:
|
||||
terraform_version: 1.10.2
|
||||
terraform_version: 1.12.0
|
||||
terraform_wrapper: false
|
||||
- name: Terraform Init
|
||||
id: init
|
||||
|
||||
@@ -41,7 +41,7 @@ jobs:
|
||||
- name: Install terraform
|
||||
uses: hashicorp/setup-terraform@633666f66e0061ca3b725c73b2ec20cd13a8fdd1 # v2.0.3
|
||||
with:
|
||||
terraform_version: 1.10.4
|
||||
terraform_version: 1.12.0
|
||||
# If we want to test more of these, consider using a matrix. With a matrix of directories, all terraform modules could be fully tested and potentially in parallel.
|
||||
- name: Validate loadtesting
|
||||
working-directory: ./infrastructure/loadtesting/terraform
|
||||
|
||||
+50
-30
@@ -21,25 +21,25 @@ provider "registry.terraform.io/hashicorp/archive" {
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/hashicorp/aws" {
|
||||
version = "6.32.1"
|
||||
constraints = ">= 2.67.0, >= 3.0.0, >= 4.6.0, >= 4.8.0, >= 4.9.0, >= 4.18.0, >= 4.27.0, >= 4.30.0, >= 4.40.0, >= 4.52.0, >= 5.0.0, >= 5.68.0, >= 5.99.0, >= 5.100.0, >= 6.0.0"
|
||||
version = "6.40.0"
|
||||
constraints = ">= 2.67.0, >= 3.0.0, >= 4.8.0, >= 4.9.0, >= 4.40.0, >= 4.52.0, >= 5.0.0, >= 5.68.0, >= 5.73.0, >= 5.89.0, >= 5.99.0, >= 5.100.0, >= 6.34.0, >= 6.37.0, >= 6.39.0"
|
||||
hashes = [
|
||||
"h1:j691GxEePvwjhYV08mwgTLD/CiCG4YHdZOXL+gV6qt0=",
|
||||
"zh:024d2cc116c8c83bb63b71623e3654109948791b250929449f4533b06678d574",
|
||||
"zh:0ee944eb1c0b28957ad04541546ebac66f81b74ae811d20bcd7043d0313722e1",
|
||||
"zh:43f1b6bcc2d6ba34dd4f02aab2ef3923281cf82455e608ac1ea493374dbb132d",
|
||||
"zh:52e91c66c3d946d9d24ecf6684e23337abbe7e93a7e8d927f8b7cc69d096215e",
|
||||
"zh:5d8030a02b61256fb6ee51efe70c1ddfc0d57b4dc0f25c621afddab81575a9c2",
|
||||
"zh:67b25c8732af678af5772cf57bfb68937bdb535ef06f7f353202e272d843f52c",
|
||||
"zh:6e846e85e55d7c49820410fb3db338e2d2adf19e3481558e3bec0d63b953c521",
|
||||
"zh:8d4922a86a39cb2788c14f430008fcaf236b0023260439bc95cc7758d5b76f4a",
|
||||
"h1:Li1WiMXyFcGfuph9iGIdTScJFNjhkSR/MkuvpapGYYg=",
|
||||
"zh:05171de71e4236b41740c6a4d4145cc38399b344535e7768e5380d0fdcb95609",
|
||||
"zh:17910a059ac677c21b61ed5da94cffba40f7cb13ddd78c818458d122cf3ef9a9",
|
||||
"zh:2f072f335d3f422bbe0f3fd46eba70a52caf43e09ee97599c26f713dbac48fed",
|
||||
"zh:316da833674982910718aae754f4db0fcc89f0466ca2ca66219fe7fa435950be",
|
||||
"zh:3fcdde0076bebfaeb0c61960b3e03cf3e2c5a978f7a4ebb0aa42e6b36209044a",
|
||||
"zh:48cecf9748a3354ccd08275da8b34a42b3367247fc2de398e03ae4e8463299aa",
|
||||
"zh:4ae0f7e76c61a4820405bd3f340b156f42f7f4480715865b008636c61fbbfa30",
|
||||
"zh:5add497a7ff7063425c65460c6bc40701cf0e59e09b379e7f535fa37c8ebd80a",
|
||||
"zh:7a26b4507c99382cefba2b189d4c5ebed939de8fb663a193b65d37934603804d",
|
||||
"zh:9b12af85486a96aedd8d7984b0ff811a4b42e3d88dad1a3fb4c0b580d04fa425",
|
||||
"zh:9e3d4d1848fc6675c6bd88087188f229c4ec98b1a35de97c2697a0160fb76678",
|
||||
"zh:b21c1b932c896c21988baac3b1cbc8b51843581b8fabf5e396952a329c9e6a12",
|
||||
"zh:df8e5b1a2713880e2b3c489cc22ad3b14490e1702a1637273f91747bf091c071",
|
||||
"zh:ec66785d40f7c04f138bb94fec55b8ddaae6fcc9cb25cc388989150bfaf2de4c",
|
||||
"zh:f1ecb00fcfdb0c2aec3622549c023f469db401f395bc25bbddfe5cf8b51cd046",
|
||||
"zh:fca78bf28897c8077130ce8d0f4d67900dbd77619adb1326bcd017ef421e5f1f",
|
||||
"zh:bad959d58660f6a0b0f950b038c76f378cfe045ba8560a0c3bbf8886f62d81be",
|
||||
"zh:cf7af6468288a36b02d009045dd4a67c24ad99bbcad406bab0f9c12776d5d99c",
|
||||
"zh:cfb683320d6d8bc1a5640538af62a5f9da285e28d0daca9e91d667d6e25585d9",
|
||||
"zh:de7d26ac15362942f590175e425160a2fbf0fe0960afec40b4af78076d4fb9fb",
|
||||
"zh:fe2fd136b68ea1941da60d8991d3857dd721b180d49502121f3ea8688a812704",
|
||||
]
|
||||
}
|
||||
|
||||
@@ -64,22 +64,22 @@ provider "registry.terraform.io/hashicorp/external" {
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/hashicorp/local" {
|
||||
version = "2.7.0"
|
||||
version = "2.8.0"
|
||||
constraints = ">= 1.0.0"
|
||||
hashes = [
|
||||
"h1:sSwlfp2etjCaE9hIF7bJBDjRIhDCVFglEOVyiCI7vgs=",
|
||||
"zh:261fec71bca13e0a7812dc0d8ae9af2b4326b24d9b2e9beab3d2400fab5c5f9a",
|
||||
"zh:308da3b5376a9ede815042deec5af1050ec96a5a5410a2206ae847d82070a23e",
|
||||
"zh:3d056924c420464dc8aba10e1915956b2e5c4d55b11ffff79aa8be563fbfe298",
|
||||
"zh:643256547b155459c45e0a3e8aab0570db59923c68daf2086be63c444c8c445b",
|
||||
"h1:3jWHVwO5QUIS9V1NsK10ZzdpkK2ABuB4G+UIWrVeGp4=",
|
||||
"zh:05f18164beab4a84753e5fedf463771ee0c6eca8e90346b8766f1e1c186dec1e",
|
||||
"zh:563a0702e3711e25ba8930120899b681378b50cbb957fd204b37745c7c9b5f40",
|
||||
"zh:5b56ab2ed70ed92721febb4a070af0837f1084c44825c18e4b95f7efb1d45d26",
|
||||
"zh:6cbedc09b67a5cdb9501ff1b18a315fa46a38e0530424cab1c7f4b3acc75f489",
|
||||
"zh:71b3bd50f89fb385a42a436ba2ce2b8e00f9de53535ce956deff1477b0b117dc",
|
||||
"zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3",
|
||||
"zh:7aa4d0b853f84205e8cf79f30c9b2c562afbfa63592f7231b6637e5d7a6b5b27",
|
||||
"zh:7dc251bbc487d58a6ab7f5b07ec9edc630edb45d89b761dba28e0e2ba6b1c11f",
|
||||
"zh:7ee0ca546cd065030039168d780a15cbbf1765a4c70cd56d394734ab112c93da",
|
||||
"zh:b1d5d80abb1906e6c6b3685a52a0192b4ca6525fe090881c64ec6f67794b1300",
|
||||
"zh:d81ea9856d61db3148a4fc6c375bf387a721d78fc1fea7a8823a027272a47a78",
|
||||
"zh:df0a1f0afc947b8bfc88617c1ad07a689ce3bd1a29fd97318392e6bdd32b230b",
|
||||
"zh:dfbcad800240e0c68c43e0866f2a751cff09777375ec701918881acf67a268da",
|
||||
"zh:9d45ac0a00b85cabdd398b859349d17f124c598b6e6bf272f1bb01321ce708a8",
|
||||
"zh:a453efe8641a8f31fe806b597bf2b34d7b78b971a8e3919061ea89d61fda7b8d",
|
||||
"zh:ac692bacb8c3dca8b5b37e5383168aca1f87d3cd7b40615efd300defb76494f5",
|
||||
"zh:bda9e90c8547d90c9c573206985c5675cc1406047605af037a5069942c3c5966",
|
||||
"zh:c30a1967de040d00f5038086dd53cdbfb78cc05d1dbc75037410f011bf2a20d8",
|
||||
"zh:c80bbd1c3f56b3c836d80cf93ac0e8809305c2642f0c98b54bf5d05d3b12718c",
|
||||
]
|
||||
}
|
||||
|
||||
@@ -123,6 +123,26 @@ provider "registry.terraform.io/hashicorp/random" {
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/hashicorp/time" {
|
||||
version = "0.13.1"
|
||||
constraints = ">= 0.13.0"
|
||||
hashes = [
|
||||
"h1:ZT5ppCNIModqk3iOkVt5my8b8yBHmDpl663JtXAIRqM=",
|
||||
"zh:02cb9aab1002f0f2a94a4f85acec8893297dc75915f7404c165983f720a54b74",
|
||||
"zh:04429b2b31a492d19e5ecf999b116d396dac0b24bba0d0fb19ecaefe193fdb8f",
|
||||
"zh:26f8e51bb7c275c404ba6028c1b530312066009194db721a8427a7bc5cdbc83a",
|
||||
"zh:772ff8dbdbef968651ab3ae76d04afd355c32f8a868d03244db3f8496e462690",
|
||||
"zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3",
|
||||
"zh:898db5d2b6bd6ca5457dccb52eedbc7c5b1a71e4a4658381bcbb38cedbbda328",
|
||||
"zh:8de913bf09a3fa7bedc29fec18c47c571d0c7a3d0644322c46f3aa648cf30cd8",
|
||||
"zh:9402102c86a87bdfe7e501ffbb9c685c32bbcefcfcf897fd7d53df414c36877b",
|
||||
"zh:b18b9bb1726bb8cfbefc0a29cf3657c82578001f514bcf4c079839b6776c47f0",
|
||||
"zh:b9d31fdc4faecb909d7c5ce41d2479dd0536862a963df434be4b16e8e4edc94d",
|
||||
"zh:c951e9f39cca3446c060bd63933ebb89cedde9523904813973fbc3d11863ba75",
|
||||
"zh:e5b773c0d07e962291be0e9b413c7a22c044b8c7b58c76e8aa91d1659990dfb5",
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/hashicorp/tls" {
|
||||
version = "4.2.1"
|
||||
hashes = [
|
||||
|
||||
@@ -6,6 +6,8 @@ locals {
|
||||
FLEET_LOGGING_TRACING_ENABLED = "true"
|
||||
FLEET_LOGGING_TRACING_TYPE = "elasticapm"
|
||||
FLEET_MYSQL_MAX_OPEN_CONNS = "25"
|
||||
FLEET_MYSQL_CONN_MAX_LIFETIME = "14400"
|
||||
FLEET_MYSQL_READ_REPLICA_CONN_MAX_LIFETIME = "14400"
|
||||
FLEET_VULNERABILITIES_DATABASES_PATH = "/home/fleet"
|
||||
FLEET_OSQUERY_ENABLE_ASYNC_HOST_PROCESSING = "false"
|
||||
# ELASTIC_APM_SERVER_URL = var.elastic_url
|
||||
@@ -61,7 +63,7 @@ locals {
|
||||
}
|
||||
|
||||
module "free" {
|
||||
source = "github.com/fleetdm/fleet-terraform//byo-vpc?ref=tf-mod-byo-vpc-v1.18.3"
|
||||
source = "github.com/fleetdm/fleet-terraform//byo-vpc?ref=tf-mod-byo-vpc-v1.27.1"
|
||||
vpc_config = {
|
||||
name = local.customer_free
|
||||
vpc_id = module.main.vpc.vpc_id
|
||||
@@ -90,7 +92,10 @@ module "free" {
|
||||
}
|
||||
}
|
||||
redis_config = {
|
||||
name = local.customer_free
|
||||
name = local.customer_free
|
||||
engine = "redis"
|
||||
engine_version = "7.1"
|
||||
family = "redis7"
|
||||
log_delivery_configuration = [
|
||||
{
|
||||
destination = "dogfood-free-redis-logs"
|
||||
@@ -106,6 +111,17 @@ module "free" {
|
||||
}
|
||||
ecs_cluster = {
|
||||
cluster_name = local.customer_free
|
||||
cluster_configuration = {
|
||||
execute_command_configuration = {
|
||||
logging = "OVERRIDE"
|
||||
log_configuration = {
|
||||
cloud_watch_log_group_name = "/aws/ecs/${local.customer_free}"
|
||||
}
|
||||
}
|
||||
}
|
||||
cloudwatch_log_group = {
|
||||
retention_in_days = 365
|
||||
}
|
||||
}
|
||||
fleet_config = {
|
||||
image = local.geolite2_image
|
||||
@@ -193,7 +209,7 @@ resource "aws_route53_record" "free" {
|
||||
}
|
||||
|
||||
module "ses-free" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/ses?ref=tf-mod-addon-ses-v1.4.0"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/ses?ref=tf-mod-addon-ses-v1.4.1"
|
||||
zone_id = aws_route53_zone.free.zone_id
|
||||
domain = "free.fleetdm.com"
|
||||
extra_txt_records = []
|
||||
@@ -207,7 +223,7 @@ module "migrations_free" {
|
||||
depends_on = [
|
||||
module.geolite2
|
||||
]
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/migrations?ref=tf-mod-addon-migrations-v2.2.1"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/migrations?ref=tf-mod-addon-migrations-v2.2.2"
|
||||
ecs_cluster = module.free.byo-db.byo-ecs.service.cluster
|
||||
task_definition = module.free.byo-db.byo-ecs.task_definition.family
|
||||
task_definition_revision = module.free.byo-db.byo-ecs.task_definition.revision
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
import {
|
||||
to = module.monitoring.aws_cloudwatch_log_group.cron_monitoring_lambda[0]
|
||||
id = "/aws/lambda/${local.customer}_cron_monitoring"
|
||||
}
|
||||
@@ -71,6 +71,8 @@ locals {
|
||||
FLEET_LOGGING_ENABLE_TOPICS = "deprecated-field-names"
|
||||
FLEET_MYSQL_MAX_OPEN_CONNS = "10"
|
||||
FLEET_MYSQL_READ_REPLICA_MAX_OPEN_CONNS = "10"
|
||||
FLEET_MYSQL_CONN_MAX_LIFETIME = "14400"
|
||||
FLEET_MYSQL_READ_REPLICA_CONN_MAX_LIFETIME = "14400"
|
||||
FLEET_VULNERABILITIES_DATABASES_PATH = "/home/fleet"
|
||||
FLEET_OSQUERY_ENABLE_ASYNC_HOST_PROCESSING = "false"
|
||||
FLEET_OSQUERY_POLICY_UPDATE_INTERVAL = "30m"
|
||||
@@ -145,7 +147,7 @@ locals {
|
||||
}
|
||||
|
||||
module "main" {
|
||||
source = "github.com/fleetdm/fleet-terraform?ref=tf-mod-root-v1.21.0"
|
||||
source = "github.com/fleetdm/fleet-terraform?ref=tf-mod-root-v1.26.1"
|
||||
certificate_arn = module.acm.acm_certificate_arn
|
||||
vpc = {
|
||||
name = local.customer
|
||||
@@ -175,7 +177,10 @@ module "main" {
|
||||
}
|
||||
}
|
||||
redis_config = {
|
||||
name = local.customer
|
||||
name = local.customer
|
||||
engine = "redis"
|
||||
engine_version = "7.1"
|
||||
family = "redis7"
|
||||
log_delivery_configuration = [{
|
||||
destination = "dogfood-redis-logs"
|
||||
destination_type = "cloudwatch-logs"
|
||||
@@ -185,6 +190,17 @@ module "main" {
|
||||
}
|
||||
ecs_cluster = {
|
||||
cluster_name = local.customer
|
||||
cluster_configuration = {
|
||||
execute_command_configuration = {
|
||||
logging = "OVERRIDE"
|
||||
log_configuration = {
|
||||
cloud_watch_log_group_name = "/aws/ecs/${local.customer}"
|
||||
}
|
||||
}
|
||||
}
|
||||
cloudwatch_log_group = {
|
||||
retention_in_days = 365
|
||||
}
|
||||
}
|
||||
fleet_config = {
|
||||
image = local.geolite2_image
|
||||
@@ -250,6 +266,7 @@ module "main" {
|
||||
bucket_prefix = "${local.customer}-software-installers-"
|
||||
create_kms_key = true
|
||||
kms_alias = "${local.customer}-software-installers"
|
||||
cloudfront_distribution_arn = "arn:aws:cloudfront::160035666661:distribution/E3T927IDMQ7AE4"
|
||||
enable_bucket_versioning = true
|
||||
expire_noncurrent_versions = true
|
||||
noncurrent_version_expiration_days = 30
|
||||
@@ -486,7 +503,7 @@ module "migrations" {
|
||||
depends_on = [
|
||||
module.geolite2
|
||||
]
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/migrations?ref=tf-mod-addon-migrations-v2.2.1"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/migrations?ref=tf-mod-addon-migrations-v2.2.2"
|
||||
ecs_cluster = module.main.byo-vpc.byo-db.byo-ecs.service.cluster
|
||||
task_definition = module.main.byo-vpc.byo-db.byo-ecs.task_definition.family
|
||||
task_definition_revision = module.main.byo-vpc.byo-db.byo-ecs.task_definition.revision
|
||||
@@ -509,7 +526,7 @@ module "mdm" {
|
||||
}
|
||||
|
||||
module "firehose-logging" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/byo-firehose-logging-destination/firehose?ref=tf-mod-addon-byo-firehose-logging-destination-firehose-v2.0.3"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/byo-firehose-logging-destination/firehose?ref=tf-mod-addon-byo-firehose-logging-destination-firehose-v2.0.4"
|
||||
firehose_results_name = "osquery_results"
|
||||
firehose_status_name = "osquery_status"
|
||||
firehose_audit_name = "fleet_audit"
|
||||
@@ -518,14 +535,14 @@ module "firehose-logging" {
|
||||
}
|
||||
|
||||
module "osquery-carve" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/osquery-carve?ref=tf-mod-addon-osquery-carve-v1.1.1"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/osquery-carve?ref=tf-mod-addon-osquery-carve-v1.3.1"
|
||||
osquery_carve_s3_bucket = {
|
||||
name = "fleet-${local.customer}-osquery-carve"
|
||||
}
|
||||
}
|
||||
|
||||
module "monitoring" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/monitoring?ref=tf-mod-addon-monitoring-v1.9.0"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/monitoring?ref=tf-mod-addon-monitoring-v1.12.0"
|
||||
customer_prefix = local.customer
|
||||
fleet_ecs_service_name = module.main.byo-vpc.byo-db.byo-ecs.service.name
|
||||
albs = [
|
||||
@@ -603,7 +620,7 @@ module "monitoring" {
|
||||
}
|
||||
|
||||
module "logging_alb" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/logging-alb?ref=tf-mod-addon-logging-alb-v1.4.0"
|
||||
source = "github.com/fleetdm/fleet-terraform/addons/logging-alb?depth=1&ref=tf-mod-addon-logging-alb-v2.2.2"
|
||||
prefix = local.customer
|
||||
enable_athena = true
|
||||
}
|
||||
@@ -686,7 +703,7 @@ module "notify_slack_p2" {
|
||||
}
|
||||
|
||||
module "ses" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/ses?ref=tf-mod-addon-ses-v1.4.0"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/ses?ref=tf-mod-addon-ses-v1.4.1"
|
||||
zone_id = aws_route53_zone.main.zone_id
|
||||
domain = "dogfood.fleetdm.com"
|
||||
extra_txt_records = []
|
||||
@@ -746,7 +763,7 @@ module "geolite2" {
|
||||
}
|
||||
|
||||
module "vuln-processing" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/external-vuln-scans?ref=tf-mod-addon-external-vuln-scans-v2.3.0"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/external-vuln-scans?ref=tf-mod-addon-external-vuln-scans-v2.5.0"
|
||||
ecs_cluster = module.main.byo-vpc.byo-db.byo-ecs.service.cluster
|
||||
execution_iam_role_arn = module.main.byo-vpc.byo-db.byo-ecs.execution_iam_role_arn
|
||||
subnets = module.main.byo-vpc.byo-db.byo-ecs.service.network_configuration[0].subnets
|
||||
@@ -807,10 +824,9 @@ resource "aws_iam_policy" "osquery_sidecar" {
|
||||
}
|
||||
|
||||
module "cloudfront-software-installers" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/cloudfront-software-installers?ref=tf-mod-addon-cloudfront-software-installers-v1.1.0"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/cloudfront-software-installers?ref=tf-mod-addon-cloudfront-software-installers-v2.0.0"
|
||||
customer = local.customer
|
||||
s3_bucket = module.main.byo-vpc.byo-db.byo-ecs.fleet_s3_software_installers_config.bucket_name
|
||||
s3_kms_key_id = module.main.byo-vpc.byo-db.byo-ecs.fleet_s3_software_installers_config.kms_key_id
|
||||
public_key = var.cloudfront_public_key
|
||||
private_key = var.cloudfront_private_key
|
||||
enable_logging = true
|
||||
|
||||
@@ -39,6 +39,8 @@ locals {
|
||||
FLEET_FILESYSTEM_RESULT_LOG_FILE = "/dev/null"
|
||||
FLEET_MYSQL_MAX_OPEN_CONNS = "10"
|
||||
FLEET_MYSQL_READ_REPLICA_MAX_OPEN_CONNS = "10"
|
||||
FLEET_MYSQL_CONN_MAX_LIFETIME = "14400"
|
||||
FLEET_MYSQL_READ_REPLICA_CONN_MAX_LIFETIME = "14400"
|
||||
FLEET_OSQUERY_ASYNC_HOST_REDIS_SCAN_KEYS_COUNT = "10000"
|
||||
FLEET_REDIS_MAX_OPEN_CONNS = "500"
|
||||
FLEET_REDIS_MAX_IDLE_CONNS = "500"
|
||||
|
||||
@@ -30,7 +30,7 @@ resource "aws_route53_record" "main" {
|
||||
}
|
||||
|
||||
module "loadtest" {
|
||||
source = "github.com/fleetdm/fleet-terraform//byo-vpc?ref=tf-mod-root-v1.18.3"
|
||||
source = "github.com/fleetdm/fleet-terraform//byo-vpc?ref=tf-mod-root-v1.26.1"
|
||||
vpc_config = {
|
||||
name = local.customer
|
||||
vpc_id = data.terraform_remote_state.shared.outputs.vpc.vpc_id
|
||||
@@ -58,6 +58,9 @@ module "loadtest" {
|
||||
}
|
||||
redis_config = {
|
||||
name = local.customer
|
||||
engine = "redis"
|
||||
engine_version = "7.1"
|
||||
family = "redis7"
|
||||
instance_type = var.redis_instance_size
|
||||
cluster_size = var.redis_instance_count
|
||||
subnets = data.terraform_remote_state.shared.outputs.vpc.private_subnets
|
||||
@@ -192,7 +195,7 @@ module "acm" {
|
||||
}
|
||||
|
||||
module "ses" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/ses?ref=tf-mod-addon-ses-v1.4.0"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/ses?ref=tf-mod-addon-ses-v1.4.1"
|
||||
zone_id = data.aws_route53_zone.main.id
|
||||
domain = "${terraform.workspace}.loadtest.fleetdm.com"
|
||||
extra_txt_records = []
|
||||
@@ -203,7 +206,7 @@ module "ses" {
|
||||
}
|
||||
|
||||
module "migrations" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/migrations?ref=tf-mod-addon-migrations-v2.2.1"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/migrations?ref=tf-mod-addon-migrations-v2.2.2"
|
||||
ecs_cluster = module.loadtest.byo-db.byo-ecs.service.cluster
|
||||
task_definition = module.loadtest.byo-db.byo-ecs.task_definition.family
|
||||
task_definition_revision = module.loadtest.byo-db.byo-ecs.task_definition.revision
|
||||
@@ -221,7 +224,7 @@ module "migrations" {
|
||||
}
|
||||
|
||||
module "vuln-processing" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/external-vuln-scans?ref=tf-mod-addon-external-vuln-scans-v2.3.0"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/external-vuln-scans?ref=tf-mod-addon-external-vuln-scans-v2.5.0"
|
||||
ecs_cluster = module.loadtest.byo-db.byo-ecs.service.cluster
|
||||
execution_iam_role_arn = module.loadtest.byo-db.byo-ecs.execution_iam_role_arn
|
||||
subnets = module.loadtest.byo-db.byo-ecs.service.network_configuration[0].subnets
|
||||
@@ -247,14 +250,14 @@ module "mdm" {
|
||||
}
|
||||
|
||||
module "osquery-carve" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/osquery-carve?ref=tf-mod-addon-osquery-carve-v1.1.1"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/osquery-carve?ref=tf-mod-addon-osquery-carve-v1.3.1"
|
||||
osquery_carve_s3_bucket = {
|
||||
name = "${local.customer}-osquery-carve"
|
||||
}
|
||||
}
|
||||
|
||||
module "logging_alb" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/logging-alb?ref=tf-mod-addon-logging-alb-v1.6.2"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/logging-alb?ref=tf-mod-addon-logging-alb-v2.2.2"
|
||||
prefix = local.customer
|
||||
alt_path_prefix = local.customer
|
||||
enable_athena = true
|
||||
|
||||
@@ -1,8 +1,7 @@
|
||||
module "cloudfront-software-installers" {
|
||||
source = "github.com/fleetdm/fleet-terraform/addons/cloudfront-software-installers?ref=tf-mod-addon-cloudfront-software-installers-v1.2.0"
|
||||
source = "github.com/fleetdm/fleet-terraform/addons/cloudfront-software-installers?ref=tf-mod-addon-cloudfront-software-installers-v2.0.0"
|
||||
customer = terraform.workspace
|
||||
s3_bucket = module.loadtest.byo-db.byo-ecs.fleet_s3_software_installers_config.bucket_name
|
||||
s3_kms_key_id = module.loadtest.byo-db.byo-ecs.fleet_s3_software_installers_config.kms_key_id
|
||||
public_key = tls_private_key.cloudfront_key.public_key_pem
|
||||
private_key = tls_private_key.cloudfront_key.private_key_pem_pkcs8
|
||||
enable_logging = true
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
module "logging_firehose" {
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/logging-destination-firehose?ref=tf-mod-addon-logging-destination-firehose-v1.2.4"
|
||||
source = "github.com/fleetdm/fleet-terraform//addons/logging-destination-firehose?ref=tf-mod-addon-logging-destination-firehose-v1.2.6"
|
||||
prefix = local.customer
|
||||
osquery_results_s3_bucket = {
|
||||
name = "${local.customer}-osquery-results-firehose-policy"
|
||||
|
||||
Reference in New Issue
Block a user