From ccd32c908af42e152be30285a5b7d06f703ac2b5 Mon Sep 17 00:00:00 2001 From: Scott Lowe Date: Mon, 23 Apr 2018 13:31:23 -0600 Subject: [PATCH] Add security group definitions Add definitions for security groups to allow etcd-related traffic Signed-off-by: Scott Lowe --- etcd/etcdv3-ansible-aws-tf/main.tf | 32 +++++++++++++++++++++++++++++- 1 file changed, 31 insertions(+), 1 deletion(-) diff --git a/etcd/etcdv3-ansible-aws-tf/main.tf b/etcd/etcdv3-ansible-aws-tf/main.tf index dd3b955..3471754 100644 --- a/etcd/etcdv3-ansible-aws-tf/main.tf +++ b/etcd/etcdv3-ansible-aws-tf/main.tf @@ -8,6 +8,36 @@ module "etcd-vpc" { subnet_map_pub_ip = "true" } +resource "aws_security_group" "etcd_sg" { + name = "etcd_sg" + description = "Allow traffic needed by etcd" + vpc_id = "${module.etcd-vpc.id}" +} + +resource "aws_security_group_rule" "etcd_sg_allow_sg" { + type = "ingress" + from_port = 0 + to_port = 65535 + protocol = "tcp" + source_security_group_id = "${aws_security_group.etcd_sg.id}" +} + +resource "aws_security_group_rule" "etcd_sg_allow_client" { + type = "ingress" + from_port = 2379 + to_port = 2379 + protocol = "tcp" + cidr_blocks = ["0.0.0.0/0"] +} + +resource "aws_security_group_rule" "etcd_sg_allow_peer" { + type = "ingress" + from_port = 2380 + to_port = 2380 + protocol = "tcp" + cidr_blocks = ["0.0.0.0/0"] +} + module "etcd" { source = "./modules/instance-cluster" @@ -18,6 +48,6 @@ module "etcd" { ssh_key = "${var.key_pair}" cluster_size = 3 subnet_list = ["${module.etcd-vpc.subnet_id}"] - sec_group_list = ["${module.etcd-vpc.default_sg_id}"] + sec_group_list = ["${module.etcd-vpc.default_sg_id}", "${aws_security_group.etcd_sg.id}"] role = "etcd" }