Skip to content

Commit 8b5380a

Browse files
m0xxaknysh
authored andcommitted
Allow additional security groups to ec2 instances (#103)
* allow additional security groups to ec2 instances * update readme for additional_security_groups
1 parent 9cfbd59 commit 8b5380a

File tree

4 files changed

+96
-46
lines changed

4 files changed

+96
-46
lines changed

README.md

Lines changed: 87 additions & 44 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,43 @@
1-
<!-- This file was automatically generated by the `build-harness`. Make all changes to `README.yaml` and run `make readme` to rebuild this file. -->
1+
<!--
2+
3+
4+
5+
6+
7+
8+
9+
10+
11+
12+
13+
14+
15+
16+
** DO NOT EDIT THIS FILE
17+
**
18+
** This file was automatically generated by the `build-harness`.
19+
** 1) Make all changes to `README.yaml`
20+
** 2) Run `make init` (you only need to do this once)
21+
** 3) Run`make readme` to rebuild this file.
22+
**
23+
** (We maintain HUNDREDS of open source projects. This is how we maintain our sanity.)
24+
**
25+
26+
27+
28+
29+
30+
31+
32+
33+
34+
35+
36+
37+
38+
39+
40+
-->
241
[![README Header][readme_header_img]][readme_header_link]
342

443
[![Cloud Posse][logo]](https://cpco.io/homepage)
@@ -158,9 +197,10 @@ Available targets:
158197

159198
| Name | Description | Type | Default | Required |
160199
|------|-------------|:----:|:-----:|:-----:|
200+
| additional_security_groups | List of security groups to be allowed to connect to the EC2 instances | list(string) | `<list>` | no |
161201
| additional_settings | Additional Elastic Beanstalk setttings. For full list of options, see https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/command-options-general.html | object | `<list>` | no |
162202
| alb_zone_id | ALB zone id | map(string) | `<map>` | no |
163-
| allowed_security_groups | List of security groups to be allowed to connect to the EC2 instances | list(string) | `<list>` | no |
203+
| allowed_security_groups | List of security groups to add to the EC2 instances | list(string) | `<list>` | no |
164204
| application_port | Port application is listening on | number | `80` | no |
165205
| application_subnets | List of subnets to place EC2 instances | list(string) | - | yes |
166206
| associate_public_ip_address | Whether to associate public IP addresses to the instances | bool | `false` | no |
@@ -271,42 +311,47 @@ Check out these related projects.
271311

272312
## Help
273313

274-
**Got a question?**
314+
**Got a question?** We got answers.
275315

276316
File a GitHub [issue](https://github.com/cloudposse/terraform-aws-elastic-beanstalk-environment/issues), send us an [email][email] or join our [Slack Community][slack].
277317

278318
[![README Commercial Support][readme_commercial_support_img]][readme_commercial_support_link]
279319

280-
## Commercial Support
281-
282-
Work directly with our team of DevOps experts via email, slack, and video conferencing.
283-
284-
We provide [*commercial support*][commercial_support] for all of our [Open Source][github] projects. As a *Dedicated Support* customer, you have access to our team of subject matter experts at a fraction of the cost of a full-time engineer.
320+
## DevOps Accelerator for Startups
285321

286-
[![E-Mail](https://img.shields.io/badge/[email protected])][email]
287322

288-
- **Questions.** We'll use a Shared Slack channel between your team and ours.
289-
- **Troubleshooting.** We'll help you triage why things aren't working.
290-
- **Code Reviews.** We'll review your Pull Requests and provide constructive feedback.
291-
- **Bug Fixes.** We'll rapidly work to fix any bugs in our projects.
292-
- **Build New Terraform Modules.** We'll [develop original modules][module_development] to provision infrastructure.
293-
- **Cloud Architecture.** We'll assist with your cloud strategy and design.
294-
- **Implementation.** We'll provide hands-on support to implement our reference architectures.
323+
We are a [**DevOps Accelerator**][commercial_support]. We'll help you build your cloud infrastructure from the ground up so you can own it. Then we'll show you how to operate it and stick around for as long as you need us.
295324

325+
[![Learn More](https://img.shields.io/badge/learn%20more-success.svg?style=for-the-badge)][commercial_support]
296326

327+
Work directly with our team of DevOps experts via email, slack, and video conferencing.
297328

298-
## Terraform Module Development
299-
300-
Are you interested in custom Terraform module development? Submit your inquiry using [our form][module_development] today and we'll get back to you ASAP.
329+
We deliver 10x the value for a fraction of the cost of a full-time engineer. Our track record is not even funny. If you want things done right and you need it done FAST, then we're your best bet.
301330

331+
- **Reference Architecture.** You'll get everything you need from the ground up built using 100% infrastructure as code.
332+
- **Release Engineering.** You'll have end-to-end CI/CD with unlimited staging environments.
333+
- **Site Reliability Engineering.** You'll have total visibility into your apps and microservices.
334+
- **Security Baseline.** You'll have built-in governance with accountability and audit logs for all changes.
335+
- **GitOps.** You'll be able to operate your infrastructure via Pull Requests.
336+
- **Training.** You'll receive hands-on training so your team can operate what we build.
337+
- **Questions.** You'll have a direct line of communication between our teams via a Shared Slack channel.
338+
- **Troubleshooting.** You'll get help to triage when things aren't working.
339+
- **Code Reviews.** You'll receive constructive feedback on Pull Requests.
340+
- **Bug Fixes.** We'll rapidly work with you to fix any bugs in our projects.
302341

303342
## Slack Community
304343

305344
Join our [Open Source Community][slack] on Slack. It's **FREE** for everyone! Our "SweetOps" community is where you get to talk with others who share a similar vision for how to rollout and manage infrastructure. This is the best place to talk shop, ask questions, solicit feedback, and work together as a community to build totally *sweet* infrastructure.
306345

307346
## Newsletter
308347

309-
Signup for [our newsletter][newsletter] that covers everything on our technology radar. Receive updates on what we're up to on GitHub as well as awesome new projects we discover.
348+
Sign up for [our newsletter][newsletter] that covers everything on our technology radar. Receive updates on what we're up to on GitHub as well as awesome new projects we discover.
349+
350+
## Office Hours
351+
352+
[Join us every Wednesday via Zoom][office_hours] for our weekly "Lunch & Learn" sessions. It's **FREE** for everyone!
353+
354+
[![zoom](https://img.cloudposse.com/fit-in/200x200/https://cloudposse.com/wp-content/uploads/2019/08/Powered-by-Zoom.png")][office_hours]
310355

311356
## Contributing
312357

@@ -331,7 +376,7 @@ In general, PRs are welcome. We follow the typical "fork-and-pull" Git workflow.
331376

332377
## Copyright
333378

334-
Copyright © 2017-2019 [Cloud Posse, LLC](https://cpco.io/copyright)
379+
Copyright © 2017-2020 [Cloud Posse, LLC](https://cpco.io/copyright)
335380

336381

337382

@@ -410,33 +455,31 @@ Check out [our other projects][github], [follow us on twitter][twitter], [apply
410455
[DirectRoot_homepage]: https://github.com/DirectRoot
411456
[DirectRoot_avatar]: https://img.cloudposse.com/150x150/https://github.com/DirectRoot.png
412457

413-
414-
415458
[![README Footer][readme_footer_img]][readme_footer_link]
416459
[![Beacon][beacon]][website]
417460

418461
[logo]: https://cloudposse.com/logo-300x69.svg
419-
[docs]: https://cpco.io/docs
420-
[website]: https://cpco.io/homepage
421-
[github]: https://cpco.io/github
422-
[jobs]: https://cpco.io/jobs
423-
[hire]: https://cpco.io/hire
424-
[slack]: https://cpco.io/slack
425-
[linkedin]: https://cpco.io/linkedin
426-
[twitter]: https://cpco.io/twitter
427-
[testimonial]: https://cpco.io/leave-testimonial
428-
[newsletter]: https://cpco.io/newsletter
429-
[email]: https://cpco.io/email
430-
[commercial_support]: https://cpco.io/commercial-support
431-
[we_love_open_source]: https://cpco.io/we-love-open-source
432-
[module_development]: https://cpco.io/module-development
433-
[terraform_modules]: https://cpco.io/terraform-modules
434-
[readme_header_img]: https://cloudposse.com/readme/header/img?repo=cloudposse/terraform-aws-elastic-beanstalk-environment
435-
[readme_header_link]: https://cloudposse.com/readme/header/link?repo=cloudposse/terraform-aws-elastic-beanstalk-environment
436-
[readme_footer_img]: https://cloudposse.com/readme/footer/img?repo=cloudposse/terraform-aws-elastic-beanstalk-environment
437-
[readme_footer_link]: https://cloudposse.com/readme/footer/link?repo=cloudposse/terraform-aws-elastic-beanstalk-environment
438-
[readme_commercial_support_img]: https://cloudposse.com/readme/commercial-support/img?repo=cloudposse/terraform-aws-elastic-beanstalk-environment
439-
[readme_commercial_support_link]: https://cloudposse.com/readme/commercial-support/link?repo=cloudposse/terraform-aws-elastic-beanstalk-environment
462+
[docs]: https://cpco.io/docs?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=docs
463+
[website]: https://cpco.io/homepage?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=website
464+
[github]: https://cpco.io/github?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=github
465+
[jobs]: https://cpco.io/jobs?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=jobs
466+
[hire]: https://cpco.io/hire?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=hire
467+
[slack]: https://cpco.io/slack?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=slack
468+
[linkedin]: https://cpco.io/linkedin?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=linkedin
469+
[twitter]: https://cpco.io/twitter?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=twitter
470+
[testimonial]: https://cpco.io/leave-testimonial?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=testimonial
471+
[office_hours]: https://cloudposse.com/office-hours?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=office_hours
472+
[newsletter]: https://cpco.io/newsletter?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=newsletter
473+
[email]: https://cpco.io/email?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=email
474+
[commercial_support]: https://cpco.io/commercial-support?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=commercial_support
475+
[we_love_open_source]: https://cpco.io/we-love-open-source?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=we_love_open_source
476+
[terraform_modules]: https://cpco.io/terraform-modules?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=terraform_modules
477+
[readme_header_img]: https://cloudposse.com/readme/header/img
478+
[readme_header_link]: https://cloudposse.com/readme/header/link?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=readme_header_link
479+
[readme_footer_img]: https://cloudposse.com/readme/footer/img
480+
[readme_footer_link]: https://cloudposse.com/readme/footer/link?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=readme_footer_link
481+
[readme_commercial_support_img]: https://cloudposse.com/readme/commercial-support/img
482+
[readme_commercial_support_link]: https://cloudposse.com/readme/commercial-support/link?utm_source=github&utm_medium=readme&utm_campaign=cloudposse/terraform-aws-elastic-beanstalk-environment&utm_content=readme_commercial_support_link
440483
[share_twitter]: https://twitter.com/intent/tweet/?text=terraform-aws-elastic-beanstalk-environment&url=https://github.com/cloudposse/terraform-aws-elastic-beanstalk-environment
441484
[share_linkedin]: https://www.linkedin.com/shareArticle?mini=true&title=terraform-aws-elastic-beanstalk-environment&url=https://github.com/cloudposse/terraform-aws-elastic-beanstalk-environment
442485
[share_reddit]: https://reddit.com/submit/?url=https://github.com/cloudposse/terraform-aws-elastic-beanstalk-environment

docs/terraform.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,10 @@
22

33
| Name | Description | Type | Default | Required |
44
|------|-------------|:----:|:-----:|:-----:|
5+
| additional_security_groups | List of security groups to be allowed to connect to the EC2 instances | list(string) | `<list>` | no |
56
| additional_settings | Additional Elastic Beanstalk setttings. For full list of options, see https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/command-options-general.html | object | `<list>` | no |
67
| alb_zone_id | ALB zone id | map(string) | `<map>` | no |
7-
| allowed_security_groups | List of security groups to be allowed to connect to the EC2 instances | list(string) | `<list>` | no |
8+
| allowed_security_groups | List of security groups to add to the EC2 instances | list(string) | `<list>` | no |
89
| application_port | Port application is listening on | number | `80` | no |
910
| application_subnets | List of subnets to place EC2 instances | list(string) | - | yes |
1011
| associate_public_ip_address | Whether to associate public IP addresses to the instances | bool | `false` | no |

main.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -534,7 +534,7 @@ resource "aws_elastic_beanstalk_environment" "default" {
534534
setting {
535535
namespace = "aws:autoscaling:launchconfiguration"
536536
name = "SecurityGroups"
537-
value = aws_security_group.default.id
537+
value = join(",", compact(concat([aws_security_group.default.id], var.additional_security_groups)))
538538
}
539539

540540
setting {

variables.tf

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -74,6 +74,12 @@ variable "dns_subdomain" {
7474
}
7575

7676
variable "allowed_security_groups" {
77+
type = list(string)
78+
description = "List of security groups to add to the EC2 instances"
79+
default = []
80+
}
81+
82+
variable "additional_security_groups" {
7783
type = list(string)
7884
description = "List of security groups to be allowed to connect to the EC2 instances"
7985
default = []

0 commit comments

Comments
 (0)