main.tf 1.6 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667
  1. data "aws_caller_identity" "current" {
  2. }
  3. data "aws_region" "current" {
  4. }
  5. locals {
  6. account_id = data.aws_caller_identity.current.account_id
  7. bucket_name = coalesce(
  8. var.bucket_name,
  9. "${local.account_id}-${local.region}-s3logging-${var.bucket_suffix}"
  10. )
  11. region = data.aws_region.current.name
  12. }
  13. # Ignore logging requirement - access logging for a logging bucket is a little meta
  14. #tfsec:ignore:AWS002
  15. resource "aws_s3_bucket" "this" {
  16. bucket = local.bucket_name
  17. acl = "log-delivery-write"
  18. tags = var.tags
  19. dynamic "lifecycle_rule" {
  20. iterator = rule
  21. for_each = var.lifecycle_rules
  22. content {
  23. id = rule.value.id
  24. enabled = rule.value.enabled
  25. prefix = lookup(rule.value, "prefix", null)
  26. abort_incomplete_multipart_upload_days = lookup(rule.value, "abort_incomplete_multipart_upload_days", 0)
  27. expiration {
  28. days = lookup(rule.value, "expiration", 2147483647)
  29. }
  30. noncurrent_version_expiration {
  31. days = lookup(rule.value, "noncurrent_version_expiration", 2147483647)
  32. }
  33. }
  34. }
  35. server_side_encryption_configuration {
  36. rule {
  37. apply_server_side_encryption_by_default {
  38. sse_algorithm = "aws:kms"
  39. }
  40. }
  41. }
  42. versioning {
  43. enabled = var.versioning_enabled
  44. }
  45. lifecycle {
  46. ignore_changes = [versioning[0].mfa_delete]
  47. }
  48. }
  49. resource "aws_s3_bucket_public_access_block" "this" {
  50. bucket = aws_s3_bucket.this.id
  51. block_public_acls = true
  52. block_public_policy = true
  53. ignore_public_acls = true
  54. restrict_public_buckets = true
  55. }