main.tf 2.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596
  1. data "aws_caller_identity" "current" {
  2. }
  3. data "aws_region" "current" {
  4. }
  5. locals {
  6. account_id = data.aws_caller_identity.current.account_id
  7. bucket_name = coalesce(
  8. var.bucket_name,
  9. "${local.account_id}-${local.region}-s3logging-${var.bucket_suffix}"
  10. )
  11. region = data.aws_region.current.name
  12. }
  13. resource "aws_s3_bucket" "this" {
  14. bucket = local.bucket_name
  15. tags = var.tags
  16. }
  17. resource "aws_s3_bucket_acl" "log_bucket_acl" {
  18. bucket = aws_s3_bucket.this.id
  19. acl = "log-delivery-write"
  20. }
  21. resource "aws_s3_bucket_logging" "this" {
  22. bucket = aws_s3_bucket.this.id
  23. # Conformance Pack for CIS requires access logs on all S3 buckets and is a best
  24. # practice.
  25. #
  26. # Logging to the bucket itself is allowed, but if we ingest into splunk, make
  27. # sure we don't set up a feedback loop (splunk accesses s3 bucket to get a log
  28. # which creates a log which leads to splunk accessing the s3 bucket)
  29. target_bucket = local.bucket_name
  30. target_prefix = "${data.aws_caller_identity.current.account_id}-${data.aws_region.current.name}-${local.bucket_name}"
  31. }
  32. resource "aws_s3_bucket_versioning" "this" {
  33. bucket = aws_s3_bucket.this.id
  34. versioning_configuration {
  35. status = var.versioning_enabled == true ? "Enabled" : "Suspended"
  36. }
  37. }
  38. resource "aws_s3_bucket_server_side_encryption_configuration" "this" {
  39. bucket = aws_s3_bucket.this.id
  40. rule {
  41. apply_server_side_encryption_by_default {
  42. sse_algorithm = "aws:kms"
  43. }
  44. }
  45. }
  46. resource "aws_s3_bucket_lifecycle_configuration" "this" {
  47. bucket = aws_s3_bucket.this.id
  48. count = length(var.lifecycle_rules) > 0 ? 1 : 0 # handle the case of no lifecycle rules
  49. dynamic "rule" {
  50. for_each = var.lifecycle_rules
  51. content {
  52. id = rule.value.id
  53. status = rule.value.enabled == true ? "Enabled" : "Disabled"
  54. abort_incomplete_multipart_upload {
  55. days_after_initiation = lookup(rule.value, "abort_incomplete_multipart_upload_days", 0)
  56. }
  57. filter {
  58. prefix = lookup(rule.value, "prefix", null)
  59. }
  60. expiration {
  61. days = lookup(rule.value, "expiration", 2147483647)
  62. }
  63. noncurrent_version_expiration {
  64. noncurrent_days = lookup(rule.value, "noncurrent_version_expiration", 2147483647)
  65. }
  66. }
  67. }
  68. }
  69. resource "aws_s3_bucket_public_access_block" "this" {
  70. bucket = aws_s3_bucket.this.id
  71. block_public_acls = true
  72. block_public_policy = true
  73. ignore_public_acls = true
  74. restrict_public_buckets = true
  75. }