|
@@ -3,14 +3,15 @@ module "ebs_root_encrypt_decrypt" {
|
|
|
|
|
|
name = "ebs_root_encrypt_decrypt"
|
|
name = "ebs_root_encrypt_decrypt"
|
|
alias = "alias/ebs_root_encrypt_decrypt"
|
|
alias = "alias/ebs_root_encrypt_decrypt"
|
|
- description = "Default key for encrypting and decryption EBS volumes."
|
|
|
|
|
|
+ description = "encrypt and decrypt root volume" # updated to match legacy
|
|
tags = merge(var.standard_tags, var.tags)
|
|
tags = merge(var.standard_tags, var.tags)
|
|
- key_admin_arns = [ ]
|
|
|
|
- key_user_arns = [ ]
|
|
|
|
- key_attacher_arns = [ ]
|
|
|
|
|
|
+ key_admin_arns = var.extra_ebs_key_admins
|
|
|
|
+ key_user_arns = var.extra_ebs_key_users
|
|
|
|
+ key_attacher_arns = var.extra_ebs_key_attachers
|
|
standard_tags = var.standard_tags
|
|
standard_tags = var.standard_tags
|
|
aws_account_id = var.aws_account_id
|
|
aws_account_id = var.aws_account_id
|
|
aws_partition = var.aws_partition
|
|
aws_partition = var.aws_partition
|
|
|
|
+ is_legacy = var.is_legacy
|
|
}
|
|
}
|
|
|
|
|
|
# Note: The following wasn't configured in tf11
|
|
# Note: The following wasn't configured in tf11
|