Переглянути джерело

* Fix small issues with v4.0.11 codebuild iam stuff
* Fix TQ server volume sizes (based on running product a while)

v4.0.12

Duane Waddle 3 роки тому
батько
коміт
7ae6577541
2 змінених файлів з 4 додано та 4 видалено
  1. 2 2
      base/standard_iam/codebuild.tf
  2. 2 2
      base/threatquotient/main.tf

+ 2 - 2
base/standard_iam/codebuild.tf

@@ -61,7 +61,7 @@ resource "aws_iam_policy" "codebuild_basic_policy" {
   name               = "codebuild_basic_policy"
   path               = "/aws_services/"
   description        = "Policy for AWS codebuild to build AMIs"
-	policy             = data.aws_iam_policy_document.codebuild_build_ec2_amis.json
+	policy             = data.aws_iam_policy_document.codebuild_base_policy.json
 }
 
 data "aws_iam_policy_document" "codebuild_base_policy" {
@@ -206,7 +206,7 @@ data "aws_iam_policy_document" "codebuild_build_ec2_amis" {
 			"kms:CreateGrant",
 		]
     condition {
-			test = "bool"
+			test = "Bool"
 			variable = "kms:GrantIsForAWSResource"
 			values = [ "true" ]
     }

+ 2 - 2
base/threatquotient/main.tf

@@ -35,7 +35,7 @@ resource "aws_instance" "instance" {
   # These device definitions are optional, but added for clarity.
   root_block_device {
       volume_type = local.ebs_volume_type
-      volume_size = "60"
+      volume_size = "200"
       delete_on_termination = true
       encrypted = true
       kms_key_id = data.aws_kms_key.ebs-key.arn
@@ -70,7 +70,7 @@ resource "aws_instance" "instance" {
     # /var
     device_name = "/dev/xvdo"
     volume_type = local.ebs_volume_type
-    volume_size = 80
+    volume_size = 200
     delete_on_termination = true
     encrypted = true
     kms_key_id = data.aws_kms_key.ebs-key.arn