Fred Damstra [afs macbook] 53038e7221 Updates 005-iam to latest to remove path restrictions %!s(int64=2) %!d(string=hai) anos
..
000-mdradmin-bootstrap ac925e94dd Fixes for Updated Terraform %!s(int64=3) %!d(string=hai) anos
001-tfstate ac925e94dd Fixes for Updated Terraform %!s(int64=3) %!d(string=hai) anos
004-iam-okta 53038e7221 Updates 005-iam to latest to remove path restrictions %!s(int64=2) %!d(string=hai) anos
005-standard-iam 4524a12bc6 Updates tags for tfsec/checkov Ignore comments %!s(int64=3) %!d(string=hai) anos
006-account-standards 2036be1230 Updates Account Standards to Latest Tag for NodeJS Version Bump %!s(int64=2) %!d(string=hai) anos
006-account-standards-regional 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules %!s(int64=3) %!d(string=hai) anos
008-xdr-binaries 7a4b5e6e65 Updates tfsec/chekov ignores | S3 Enable Logging/Versioning %!s(int64=3) %!d(string=hai) anos
010-shared-ami-key 7a4b5e6e65 Updates tfsec/chekov ignores | S3 Enable Logging/Versioning %!s(int64=3) %!d(string=hai) anos
050-lcp-ami-sharing 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules %!s(int64=3) %!d(string=hai) anos
072-salt-master-inventory-role 4524a12bc6 Updates tags for tfsec/checkov Ignore comments %!s(int64=3) %!d(string=hai) anos
075-codebuild-ecr-base 7a4b5e6e65 Updates tfsec/chekov ignores | S3 Enable Logging/Versioning %!s(int64=3) %!d(string=hai) anos
080-codebuild-ecr-sample d8231ee65c Updates IMDS syntax & ECR encryption syntax | tfsec/chekov ignores %!s(int64=3) %!d(string=hai) anos
081-codebuild-rpm-collectd 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules %!s(int64=3) %!d(string=hai) anos
085-codebuild-ecr-customer-portal 2a6064b310 Update Terraform Provider Plugin - Vault | AWS %!s(int64=3) %!d(string=hai) anos
090-codebuild-rpm-tmux 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules %!s(int64=3) %!d(string=hai) anos
095-codebuild-rpm-aws-efs-utils 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules %!s(int64=3) %!d(string=hai) anos
100-codebuild-rpm-syslog-ng 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules %!s(int64=3) %!d(string=hai) anos
105-codebuild-ecr-mcas-container d8231ee65c Updates IMDS syntax & ECR encryption syntax | tfsec/chekov ignores %!s(int64=3) %!d(string=hai) anos
110-xdr-binaries-write-role 1519a2cd30 Migrated most variables out of xdr-terraform-live and into xdr-terraform-modules %!s(int64=3) %!d(string=hai) anos
300-s3-xdr-trumpet 7a4b5e6e65 Updates tfsec/chekov ignores | S3 Enable Logging/Versioning %!s(int64=3) %!d(string=hai) anos
350-codebuild-ecr-content-generator-build-image 2a6064b310 Update Terraform Provider Plugin - Vault | AWS %!s(int64=3) %!d(string=hai) anos
351-codebuild-splunk-uf-configs 2a6064b310 Update Terraform Provider Plugin - Vault | AWS %!s(int64=3) %!d(string=hai) anos
355-codebuild-xdr-base-image 2a6064b310 Update Terraform Provider Plugin - Vault | AWS %!s(int64=3) %!d(string=hai) anos
360-codebuild-vpc f13bb5c77c Updates modules for VPN update and employee_ips fixes %!s(int64=3) %!d(string=hai) anos
365-codebuild-oci-lcp-magic-machine 277c88dca3 Updates tfsec & checkov ignores + syntax updates %!s(int64=3) %!d(string=hai) anos
370-codebuild-vmware-lcp-magic-machine 277c88dca3 Updates tfsec & checkov ignores + syntax updates %!s(int64=3) %!d(string=hai) anos
375-codebuild-xdr-master-image 2a6064b310 Update Terraform Provider Plugin - Vault | AWS %!s(int64=3) %!d(string=hai) anos
380-codebuild-xdr-minion-image 2a6064b310 Update Terraform Provider Plugin - Vault | AWS %!s(int64=3) %!d(string=hai) anos
385-codebuild-xdr-threatq-image 2a6064b310 Update Terraform Provider Plugin - Vault | AWS %!s(int64=3) %!d(string=hai) anos
390-codebuild-xdr-ubuntu-base-image 2a6064b310 Update Terraform Provider Plugin - Vault | AWS %!s(int64=3) %!d(string=hai) anos
395-codebuild-xdr-ubuntu-minion-image 2a6064b310 Update Terraform Provider Plugin - Vault | AWS %!s(int64=3) %!d(string=hai) anos
disabled ca7e99d645 Applied `terragunt hclfmt` to all modules %!s(int64=3) %!d(string=hai) anos
us-gov-west-1 7a4b5e6e65 Updates tfsec/chekov ignores | S3 Enable Logging/Versioning %!s(int64=3) %!d(string=hai) anos
README.md e9366e6600 Merges mdr-common-services and afs-mdr-common-services-gov directories %!s(int64=5) %!d(string=hai) anos
account.hcl 5cea7b75ca Updates tag for IAM tfsec Ignore Comments and legacy URL for IP list %!s(int64=3) %!d(string=hai) anos

README.md

Common Services - GovCloud

I'm not sure if this is a helpful readme or not tbh

Authentication

A handful of these need the static access keys for the MDRAdmin account, mostly because at that point of setting up a new AWS account we don't have the okta integration in place.

Subfolders / subprojects

Subdirectory auth Purpose
000-mdradmin-bootstrap MDRAdmin + aws-mfa Configures MDRAdmin Account to have IAM rights to create terraform state
001-tfstate MDRAdmin + aws-mfa Creates TF state s3 bucket, dynamodb tables
005-iam okta + saml2aws Fundamental IAM setup - does OKTA linkage, sets up user roles and policies