-
Notifications
You must be signed in to change notification settings - Fork 1.2k
/
main.tf
88 lines (83 loc) · 3.37 KB
/
main.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
/**
* Copyright 2019 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
/******************************************
VPC configuration
*****************************************/
module "vpc" {
source = "./modules/vpc"
network_name = var.network_name
auto_create_subnetworks = var.auto_create_subnetworks
routing_mode = var.routing_mode
project_id = var.project_id
description = var.description
shared_vpc_host = var.shared_vpc_host
delete_default_internet_gateway_routes = var.delete_default_internet_gateway_routes
mtu = var.mtu
enable_ipv6_ula = var.enable_ipv6_ula
internal_ipv6_range = var.internal_ipv6_range
network_firewall_policy_enforcement_order = var.network_firewall_policy_enforcement_order
network_profile = var.network_profile
}
/******************************************
Subnet configuration
*****************************************/
module "subnets" {
source = "./modules/subnets"
project_id = var.project_id
network_name = module.vpc.network_name
subnets = var.subnets
secondary_ranges = var.secondary_ranges
}
/******************************************
Routes
*****************************************/
module "routes" {
source = "./modules/routes"
project_id = var.project_id
network_name = module.vpc.network_name
routes = var.routes
module_depends_on = [module.subnets.subnets]
}
/******************************************
Firewall rules
*****************************************/
locals {
rules = [
for f in var.firewall_rules : {
name = f.name
direction = f.direction
disabled = lookup(f, "disabled", null)
priority = lookup(f, "priority", null)
description = lookup(f, "description", null)
ranges = lookup(f, "ranges", null)
source_tags = lookup(f, "source_tags", null)
source_service_accounts = lookup(f, "source_service_accounts", null)
target_tags = lookup(f, "target_tags", null)
target_service_accounts = lookup(f, "target_service_accounts", null)
allow = lookup(f, "allow", [])
deny = lookup(f, "deny", [])
log_config = lookup(f, "log_config", null)
}
]
}
module "firewall_rules" {
source = "./modules/firewall-rules"
project_id = var.project_id
network_name = module.vpc.network_name
rules = local.rules
ingress_rules = var.ingress_rules
egress_rules = var.egress_rules
}