Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 
 
 
 
 

README.md

Security Group to Security Group Example

This example demonstrates using security groups as sources for ingress rules with the tf-aws-module_primitive-vpc_security_group_ingress_rule module.

Features Demonstrated

  • Security group reference as source
  • Database tier security (PostgreSQL and MySQL)
  • Multi-tier application architecture
  • Security group peering

Usage

terraform init
terraform plan -var-file=test.tfvars
terraform apply -var-file=test.tfvars
terraform destroy -var-file=test.tfvars

Resources Created

  • 1 VPC
  • 2 Security Groups (source and target)
  • 2 Security Group Ingress Rules (PostgreSQL and MySQL)

Architecture

This example simulates a multi-tier application:

  • Source SG: Application tier
  • Target SG: Database tier
  • Rules: Allow database access from application tier only

Requirements

Name Version
terraform ~> 1.0
aws ~> 5.100

Providers

Name Version
aws 5.100.0

Modules

Name Source Version
ingress_postgres_sg ../../ n/a
ingress_mysql_sg ../../ n/a

Resources

Name Type
aws_default_security_group.default resource
aws_security_group.source resource
aws_security_group.target resource
aws_vpc.test resource

Inputs

Name Description Type Default Required
resource_name_prefix Prefix for resource names string "sgir-sg-to-sg" no
vpc_cidr CIDR block for the VPC string "10.0.0.0/16" no

Outputs

Name Description
security_group_id ID of the target security group
ingress_rule_id ID of the PostgreSQL ingress rule
ingress_rule_arn ARN of the PostgreSQL ingress rule
effective_source Effective source for PostgreSQL ingress rule
source_security_group_id ID of the source security group
mysql_ingress_rule_id ID of the MySQL ingress rule