Repository navigation
Expand file tree
/
Copy pathmain.tf
More file actions
96 lines (84 loc) · 3.81 KB
/
Copy pathmain.tf
File metadata and controls
96 lines (84 loc) · 3.81 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
locals {
redis_port = 6379
}
resource "aws_elasticache_replication_group" "comet-ml-ec-redis" {
engine = var.elasticache_engine
engine_version = var.elasticache_engine_version
transit_encryption_enabled = var.elasticache_transit_encryption
auth_token = var.elasticache_auth_token
# AWS provider v6 errors when auth_token_update_strategy is set on a replication
# group that has no auth_token, with one exception: the explicit removal path
# auth_token=null + auth_token_update_strategy="DELETE" must reach AWS.
auth_token_update_strategy = (var.elasticache_auth_token != null || var.elasticache_auth_token_update_strategy == "DELETE") ? var.elasticache_auth_token_update_strategy : null
automatic_failover_enabled = var.elasticache_automatic_failover_enabled
multi_az_enabled = var.elasticache_multi_az_enabled
preferred_cache_cluster_azs = var.elasticache_preferred_cache_cluster_azs
replication_group_id = "cometml-ec-redis-${var.environment}"
node_type = var.elasticache_instance_type
num_cache_clusters = var.elasticache_num_cache_nodes
parameter_group_name = var.elasticache_param_group_name
port = local.redis_port
subnet_group_name = aws_elasticache_subnet_group.comet-ml-ec-subnet-group.name
security_group_ids = [aws_security_group.redis_inbound_sg.id]
description = "Redis for CometML"
apply_immediately = true
tags = merge(
var.common_tags,
{
Name = "cometml-ec-redis-${var.environment}"
}
)
}
resource "aws_elasticache_subnet_group" "comet-ml-ec-subnet-group" {
name = "cometml-ec-sng-${var.environment}"
subnet_ids = var.elasticache_private_subnets
tags = merge(
var.common_tags,
{
Name = "cometml-ec-sng-${var.environment}"
}
)
}
resource "aws_security_group" "redis_inbound_sg" {
name = "cometml_redis_in_sg_${var.environment}"
description = "Redis Security Group"
vpc_id = var.vpc_id
tags = merge(
var.common_tags,
{
Name = "cometml_redis_in_sg_${var.environment}"
}
)
}
resource "aws_vpc_security_group_ingress_rule" "redis_port_inbound_rule" {
security_group_id = aws_security_group.redis_inbound_sg.id
from_port = local.redis_port
to_port = local.redis_port
ip_protocol = "tcp"
referenced_security_group_id = var.elasticache_allow_from_sg
}
# EKS Auto Mode nodes attach the cluster primary SG (not the managed node SG that
# elasticache_allow_from_sg references), so they need their own ingress rule to reach
# Redis. Only created when the Auto Mode SG is passed in.
resource "aws_vpc_security_group_ingress_rule" "redis_port_inbound_auto_mode" {
count = var.elasticache_auto_mode_allow_from_sg != null ? 1 : 0
security_group_id = aws_security_group.redis_inbound_sg.id
from_port = local.redis_port
to_port = local.redis_port
ip_protocol = "tcp"
referenced_security_group_id = var.elasticache_auto_mode_allow_from_sg
description = "Redis from EKS Auto Mode nodes (cluster primary SG)"
}
# VPN ingress to Redis (DND-752) — gated by enable_vpn_redis_access. Allows
# operators on the VPN to connect to Redis via kubectl port-forward through
# the cluster's Redis SG.
resource "aws_vpc_security_group_ingress_rule" "redis_vpn" {
count = var.enable_vpn_redis_access ? 1 : 0
security_group_id = aws_security_group.redis_inbound_sg.id
description = "VPN client access (DND-752)"
from_port = local.redis_port
to_port = local.redis_port
ip_protocol = "tcp"
cidr_ipv4 = var.vpn_client_cidr
tags = merge(var.common_tags, { Name = "redis-vpn-access" })
}