소스 검색

Merge pull request #86 from mdr-engineering/feature/bp_MSOCI-1455_migrate_salt_master

Adds Salt Master in Test Env
Brad Poulton 4 년 전
부모
커밋
68108dd2aa
3개의 변경된 파일76개의 추가작업 그리고 0개의 파일을 삭제
  1. 31 0
      globals.hcl
  2. 42 0
      test/aws-us-gov/mdr-test-c2/071-instance-salt-master/terragrunt.hcl
  3. 3 0
      test/aws-us-gov/mdr-test-c2/account.hcl

+ 31 - 0
globals.hcl

@@ -26,6 +26,37 @@ locals {
     "97.117.78.121/32",    # Colby Williams
   ]
   portal_test_whitelist = local.trusted_ips # for now, an alias
+
+  #Customer External IPs
+  #To increase flexibility and to provide better documentation,
+  #break up the IPs based on on-prem and not on-prem. 
+
+  #### AFS ON-PREM POP ####
+  afs_pop = [
+    "170.248.172.0/23",
+  ]
+
+  # AFS Azure POP external IPs
+  afs_azure_pop = [
+    "20.190.250.137/32",     # EastUS2_External_Access
+    "52.232.227.197/32",     # Azure US-East Palo
+    "52.185.64.173/32",      # CentralUS_External_Access
+    "52.242.225.98/32",      # Azure US-Central Palo 20200721
+    "52.177.84.83/32",       # Lab_External_Access
+  ]
+
+  #### NGA ####
+  nga_pop = [
+    "199.16.64.3/32"
+  ]
+
+  xdr_interconnect = [
+    "18.252.61.218/32",
+    "18.252.67.171/32",
+    "18.253.123.98/32",
+    "18.253.98.90/32",
+  ]  
+
   dns_zone_map = {
     "accenturefederalcyber.com" = "Z03575081VGXN3FUZ8ERU"
     "accenturefederalcyber.net" = "Z07771312N8X39HKP141M"

+ 42 - 0
test/aws-us-gov/mdr-test-c2/071-instance-salt-master/terragrunt.hcl

@@ -0,0 +1,42 @@
+locals {
+  # If you want to use any of the variables in _this_ file, you have to load them here.
+  # However, they will all be available as inputs to the module loaded in terraform.source
+  # below.
+  environment_vars = read_terragrunt_config(find_in_parent_folders("env.hcl"))
+  partition_vars = read_terragrunt_config(find_in_parent_folders("partition.hcl"))
+  region_vars = read_terragrunt_config(find_in_parent_folders("region.hcl"))
+  account_vars = read_terragrunt_config(find_in_parent_folders("account.hcl"))
+  global_vars = read_terragrunt_config(find_in_parent_folders("globals.hcl"))
+}
+
+# Terragrunt will copy the Terraform configurations specified by the source parameter, along with any files in the
+# working directory, into a temporary folder, and execute your Terraform commands in that folder.
+terraform {
+  # Double slash is intentional and required to show root of modules
+  source = "git@github.mdr.defpoint.com:mdr-engineering/xdr-terraform-modules.git//base/salt_master?ref=v0.8.7"
+}
+
+dependency "vpc-access" {
+  config_path = "../010-vpc-access"
+}
+
+# Include all settings from the root terragrunt.hcl file
+include {
+  path = find_in_parent_folders()
+}
+
+# These are the variables we have to pass in to use the module specified in the terragrunt source above
+inputs = {
+  # All of the inputs from the inherited hcl files are available automatically
+  # (via the `inputs` section of the root `terragrunt.hcl`). However, modules
+  # will be more flexible if you specify particular input values.
+  tags = {
+    Purpose = "Salt Master"
+    Terraform = "aws/${basename(get_parent_terragrunt_dir())}/${path_relative_to_include()}/"
+  }
+  instance_name = "salt-master"
+  instance_type = local.account_vars.locals.salt_master_instance_type
+  vpc_id = dependency.vpc-access.outputs.vpc_id
+  azs = dependency.vpc-access.outputs.azs
+  subnets = dependency.vpc-access.outputs.public_subnets
+}

+ 3 - 0
test/aws-us-gov/mdr-test-c2/account.hcl

@@ -68,6 +68,9 @@ locals {
   # Bastion
   bastion_instance_type = "t3a.micro"
 
+  # Salt Master
+  salt_master_instance_type = "t3a.large"
+
   # For testing
   create_test_instance = false
   test_instance_key_name = "fdamstra" # They with which to provision the test instance