- Installs Tamr on VM
- Adds required variables
tamr_config_file,tamr_zip_uri, andtamr_filesystem_bucket - Adds optional variable
tamr_instance_install_directory
- Grants permissions to add tags when tag value is set
- Adds the variable
require_http_tokensto control enabling of IMDSv2
- Removes the following input variables from the main module:
arn_partitionvpc_id
- Removes unused variables from examples
- Adjusts AWS provider constraints to allow newer versions
- Updates version file to prevent the major upgrade to the AWS provider version 4.0.
- Updates examples to use the newest version of the s3-module.
- Updates examples to use new versions of modules.
- Deprecates
s3_policy_arnsin favor ofadditional_policy_arns. - Allows the creation of the Cloudwatch log group and passes it to the shell script.
- Adds
minimal-logsexample which allows the use of cloudwatch in an automated fashion.
- Adds new variable
private_ipsto limit which private IPs can be assigned to the ENI attached to the Tamr EC2 Instance
- Adds new variable
emr_abac_valid_tagsto be used in IAM Policies conditions for creating EMR Resources using ABAC
- Adds tags to the EC2 instance's root EBS volume
- Adds network interface resource used as the default network interface on the EC2 instance in order to support tags
(Major version note: Tamr VM recreates as a new taggable network interface is created and assigned at
device_index = 0)
- Adds new variable
tagsto set tags for all resources - Deprecates
additional_tagsin favor oftags
- Adds new variable
permissions_boundaryto set the permissions boundary for the IAM Role used by the Tamr EC2 Instance
- Update to policy to remove wildcards wherever possible
- New configuration variables:
tamr_emr_cluster_idstamr_emr_role_arns
- Nested security group module refactored to only return the list of ingress ports instead of creating the security groups
- Output changed from
tamr_security_group_idtosecurity_group_ids - New input variables for the main module:
security_group_ids
- Removed input variables from the main module:
ingress_cidr_blocksingress_security_groupsegress_cidr_blocksegress_security_groupsportssecurity_group_tagssg_name
- New input variables for the security group module:
additional_ports
- Removed input variables from the security group module:
*_portadditional_tagsingress_cidr_blocksingress_security_groupsegress_cidr_blocksegress_security_groupsenable_*sg_namevpc_id
- Upgrades and pins
terraform-aws-modules/key-pair/awsto version 1.0.0
- Fixes a bug where policy does not attach if you taint the module
- Simplifies example by creating fewer buckets and adding a 'name-prefix' variable
- Updates minimum Terraform version to 13
- Updates minimum AWS provider version to 3.36.0
- Adds new variable
arn_partitionto set the partition of any ARNs referenced in this module
- Adds ability to pass in
bootstrap_scriptsthat will run during the boot cycle when you first launch an instance. - Adds example usage of
bootstrap_scripts
- Removes input variables
aws_emrfs_hbase_bucket_name,aws_emrfs_hbase_logs_bucket_name,aws_emrfs_spark_logs_bucket_name, andaws_emrfs_user_policy_name- Modifies minimal example accordingly to show dependency on terraform-aws-s3 module for creating S3 buckets and S3 IAM policies
- Add
enable_volume_encryptioninput variable for encrypting root block device
- Removes
aws_account_idinput variable - Updates minimal example to create required resources
- Adds
s3_policy_arnsinput variable to pass S3 bucket access policies to Tamr user IAM role.
- Adds ListObjects to the s3 policy
- Updates the policy to support both static and ephemeral EMR clusters
- Initing project
- Create role policy with minimal permissions needed to spin up an EMR cluster and submit jobs, S3 permissions for primary and backup filesystem
- Resource to attach role policy to existing user (assumption that IAM role already exists)
- Policies can be locked down by specifying the ARN for which permission is granted
- Create security groups for Tamr instance running on AWS EC2. Rules are attached using the security group rules resource
- Create IAM role for Tamr instance running on AWS EC2
- Create EC2 instance with attached roles and security groups