Jeremy Cooper [AFS MBP] 7a4b5e6e65 Updates tfsec/chekov ignores | S3 Enable Logging/Versioning 3 年之前
..
000-mdradmin-bootstrap ac925e94dd Fixes for Updated Terraform 3 年之前
001-tfstate ac925e94dd Fixes for Updated Terraform 3 年之前
004-iam-okta 2a6064b310 Update Terraform Provider Plugin - Vault | AWS 3 年之前
005-standard-iam 4524a12bc6 Updates tags for tfsec/checkov Ignore comments 3 年之前
006-account-standards 4524a12bc6 Updates tags for tfsec/checkov Ignore comments 3 年之前
006-account-standards-regional 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules 3 年之前
008-xdr-binaries 7a4b5e6e65 Updates tfsec/chekov ignores | S3 Enable Logging/Versioning 3 年之前
010-public-dns 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules 3 年之前
010-shared-ami-key 7a4b5e6e65 Updates tfsec/chekov ignores | S3 Enable Logging/Versioning 3 年之前
011-defpoint_com-legacy-dns 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules 3 年之前
019-qualys-service-account 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules 3 年之前
050-lcp-ami-sharing 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules 3 年之前
072-salt-master-inventory-role 4524a12bc6 Updates tags for tfsec/checkov Ignore comments 3 年之前
110-xdr-binaries-write-role 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules 3 年之前
300-s3-xdr-trumpet 7a4b5e6e65 Updates tfsec/chekov ignores | S3 Enable Logging/Versioning 3 年之前
us-east-2 7a4b5e6e65 Updates tfsec/chekov ignores | S3 Enable Logging/Versioning 3 年之前
us-west-1 7a4b5e6e65 Updates tfsec/chekov ignores | S3 Enable Logging/Versioning 3 年之前
us-west-2 7a4b5e6e65 Updates tfsec/chekov ignores | S3 Enable Logging/Versioning 3 年之前
README.md 671dc26b50 Initial Commit 5 年之前
account.hcl 5cea7b75ca Updates tag for IAM tfsec Ignore Comments and legacy URL for IP list 3 年之前

README.md

README

I'm not sure if this is a helpful readme or not tbh

Authentication

A handful of these need the static access keys for the MDRAdmin account, mostly because at that point of setting up a new AWS account we don't have the okta integration in place.

Subfolders / subprojects

Subdirectory auth Purpose
000-mdradmin-bootstrap MDRAdmin + aws-mfa Configures MDRAdmin Account to have IAM rights to create terraform state
001-tfstate MDRAdmin + aws-mfa Creates TF state s3 bucket, dynamodb tables
005-iam okta + saml2aws Fundamental IAM setup - does OKTA linkage, sets up user roles and policies
common okta + saml2aws Variable / provider definitions used across multiple chunks