#terraform-aws-modules (2020-04)
Terraform Modules
Discussions related to https://github.com/terraform-aws-modules
Archive: https://archive.sweetops.com/terraform-aws-modules/
2020-04-02
data:image/s3,"s3://crabby-images/44902/449029945fc1a4b20fc4380407df7a1de709e0f8" alt="curious deviant avatar"
Hello, requesting some thoughts/opinions. So I am looking at building reusable tf modules for my teams. We are divided in our opinion on whether we should use a mono-repo and have sub-directories for each aws resource or one github repo per resource. On my previous projects, I have done the later. Each component has it’s own lifecycle (tagging etc. ) that way and also only the required modules get downloaded and not the entire mono-repo during terraform get. What do you guys think ?
data:image/s3,"s3://crabby-images/d5031/d5031300af44c892cac3b8f038d2084cc70b2b00" alt="maarten avatar"
One repo per module, yes definitely! On the strict aws resource split, I think this should never be a strict rule and should be evaluated on a per-case basis. If you are extremely strict with the one-resource per module then in many cases just just create a simple “abstraction” around a resource which doesn’t need abstraction because it’s super simple to begin with. I think it’s better to define in the team how great modules look like by having certain community modules as example. Whenever there is a debate on style or structure, a team member should be able to argue that it makes sense to do so because x and y. Cheers.
data:image/s3,"s3://crabby-images/44902/449029945fc1a4b20fc4380407df7a1de709e0f8" alt="curious deviant avatar"
Thank you so much for your response .. That’s definitely the way to go.
data:image/s3,"s3://crabby-images/c8934/c893460846f34e2e99dff467d5edba93d5582035" alt="vFondevilla avatar"
data:image/s3,"s3://crabby-images/c8934/c893460846f34e2e99dff467d5edba93d5582035" alt="vFondevilla avatar"
In my case we’re doing modules not for each resource but for each “infrastructure component”. For example we have a module for codepipeline which include codebuild, codecommit and all the IAM around it.
data:image/s3,"s3://crabby-images/52f5e/52f5ef30e89d02426b188df6fafde7e3cd5a85c7" alt="Shawn Petersen avatar"
i agree with separate repos from an access perspective, especially with different teams. You might not want some teams accessing/building vpc or iam resources, while letting them build out ec2 or s3 etc…
2020-04-03
2020-04-04
2020-04-06
data:image/s3,"s3://crabby-images/30fed/30fed0f1a890fae3dc0ada85fc2b9530ac716af4" alt="Taco avatar"
Hello - I am using the terraform-aws-alb
module and am trying to figure out how to attach targets to the created load balancer. I have instances that are running due to the autoscale_group
module, but I’m uncertain how to attach them. I’ve looked at the regular Terraform aws_lb_target_group_attachment
resource, but haven’t worked out how to deal with the fact that I have two instances but target_id
on aws_lb_target_group_attachment
appears to only take one id. Any guidance would be much appreciated.
data:image/s3,"s3://crabby-images/67e68/67e683361c271c4e26e156c64a1a2d27db2b053d" alt="David avatar"
Are you using the https://github.com/terraform-aws-modules/terraform-aws-autoscaling module? I don’t see any module named autoscale_group
on the main module registry.
If so, you just put the alb target group arns from the load balancer module into the autoscaling module, with something like target_group_arns = module.alb.target_group_arns
Regardless of module, target_group_arns
is a field on the aws_autoscaling_group
terraform resource
Terraform module which creates Auto Scaling resources on AWS - terraform-aws-modules/terraform-aws-autoscaling
data:image/s3,"s3://crabby-images/30fed/30fed0f1a890fae3dc0ada85fc2b9530ac716af4" alt="Taco avatar"
Thanks, and sorry for the typo. Your info helped.
2020-04-07
data:image/s3,"s3://crabby-images/30fed/30fed0f1a890fae3dc0ada85fc2b9530ac716af4" alt="Taco avatar"
A follow up to yesterday’s question. I am using the CloudPosse ALB module (https://github.com/cloudposse/terraform-aws-alb) in conjunction with the CloudPosse ASG module (https://github.com/cloudposse/terraform-aws-ec2-autoscale-group). I linked them via target_group_arns
as suggested yesterday. I instructed the ASG to used a standard, Linux AMI as its image, and I also tell the ASG to install httpd, etc. via userdata
. However, I keep getting a 504 Gateway Time-out error. During troubleshooting, I noticed that the registered targets in my target group are failing their health check with 504 errors. When I look at the actual EC2 instances, they are using the default VPC security group which has no ingress or egress rules. So I found my 504 problem, but I’m not certain why my targets don’t have the proper security groups. The module is generating the expected security group to let in [0.0.0.0/0] over port 80, but that security group is not assigned to the targets in my target group. I see that the security groups are assigned to the ENIs, but that’s it. Any help/advice is most appreciated.
Terraform module to provision a standard ALB for HTTP/HTTP traffic - cloudposse/terraform-aws-alb
Terraform module to provision Auto Scaling Group and Launch Template on AWS - cloudposse/terraform-aws-ec2-autoscale-group
data:image/s3,"s3://crabby-images/30fed/30fed0f1a890fae3dc0ada85fc2b9530ac716af4" alt="Taco avatar"
May have figured this out. I needed to get the security group from the ALB module and feed it into the ASG module.
2020-04-09
data:image/s3,"s3://crabby-images/ae085/ae0855a28d49850942169c22e0609ff980d1b9aa" alt="Bircan Bilici avatar"
Hi Guys, I’ve added some additional parameters into terraform-aws-codebuild https://github.com/cloudposse/terraform-aws-codebuild/pull/53 Can some one review pls. Thnks
what Added support for : private repository auth git_submodules_config vpc_config logs_config git_clone_depth why They were missing, and I needed them
data:image/s3,"s3://crabby-images/87b43/87b437757588ae6fd32acd80580a9548a283a76d" alt="Alex Siegman avatar"
Just a quick one to add a missing output: https://github.com/cloudposse/terraform-aws-rds/pull/59
what Adds the ARN of the RDS cluster as an output why Due to some weirdness in the API, you can't make read replicas in different subnet groups without using the ARN. See referenced issue. …
2020-04-14
data:image/s3,"s3://crabby-images/0704f/0704fa2c4de34bfc92a8ecd50096a4fa8404549a" alt="joshmyers avatar"
Hey @Maxim Mironenko (Cloud Posse) - any movement on https://github.com/cloudposse/terraform-aws-tfstate-backend/pull/43 ?
Whilst the current option policy ensures server-side encryption, encryption of the transport mechanism isn't enforced. This change extends the S3 bucket policy to enforce encryption in transit,…
data:image/s3,"s3://crabby-images/0704f/0704fa2c4de34bfc92a8ecd50096a4fa8404549a" alt="joshmyers avatar"
Looks like it is failing because of an unrelated README change?
Whilst the current option policy ensures server-side encryption, encryption of the transport mechanism isn't enforced. This change extends the S3 bucket policy to enforce encryption in transit,…
data:image/s3,"s3://crabby-images/941e1/941e161227fe81194fbcdfed270e2112ea5c0de4" alt="bazbremner avatar"
(I’m the author)
data:image/s3,"s3://crabby-images/941e1/941e161227fe81194fbcdfed270e2112ea5c0de4" alt="bazbremner avatar"
This does seem a bit of an odd failure. @Maxim Mironenko (Cloud Posse) if there’s anything I can do, let me know
data:image/s3,"s3://crabby-images/bc38e/bc38e529d2aaa7d65a302b2c4f50b7316325cf1a" alt="Maxim Mironenko (Cloud Posse) avatar"
@bazbremner having some issues with GitHub actions. They recently did some changes related to tokens. I am on it
2020-04-15
data:image/s3,"s3://crabby-images/85e13/85e13e8855021e0317d54fd9d2ffea672526ab3b" alt="Partha avatar"
Hi All, Can some suggest module for ElastiCache (REDIS)
data:image/s3,"s3://crabby-images/0efef/0efefde13e528ab6ca09c42a6edba20efd5a9477" alt="drexler avatar"
Hi im trying to create a multiple subnets with terraform-aws-multi-az-subnets
. However, since count
is not allowed within modules, is there a way to use a single module and have some kind of iteration over the cidr lists to generate the subnets?
data:image/s3,"s3://crabby-images/2a6c6/2a6c695b8614351039c75f2ee697c4c216e6a766" alt="github140 avatar"
Maybe the module terraform-aws-vpc module fits your need.
data:image/s3,"s3://crabby-images/0efef/0efefde13e528ab6ca09c42a6edba20efd5a9477" alt="drexler avatar"
i had used that module but i needed more fine-grained control over the subnets created. Essentially needed 4 subnets per AZ with a greater IP range in the private ones. I ended up rolling it with the existing TF resources.
2020-04-16
2020-04-20
data:image/s3,"s3://crabby-images/17c19/17c198162babe5ef0242fce2ead5561b10cc8803" alt="cabrinha avatar"
Hello there, I’d like to disable the creation of the s3 endpoint when using the EMR module: https://github.com/cloudposse/terraform-aws-emr-cluster/pull/14 – I’ve already got an S3 endpoint managed somewhere else.
what Add the variable create_vpc_endpoint_s3 to control VPC S3 Endpoint creation why Users may already have their own S3 Endpoint in the selected VPC. If they do, this module fails because there…
data:image/s3,"s3://crabby-images/bc38e/bc38e529d2aaa7d65a302b2c4f50b7316325cf1a" alt="Maxim Mironenko (Cloud Posse) avatar"
@cabrinha there is a minor change request for your PR. also, after it will be addressed I will run rebuild README.md routine, so please, make sure your repo allow write access for our bot
what Add the variable create_vpc_endpoint_s3 to control VPC S3 Endpoint creation why Users may already have their own S3 Endpoint in the selected VPC. If they do, this module fails because there…
data:image/s3,"s3://crabby-images/17c19/17c198162babe5ef0242fce2ead5561b10cc8803" alt="cabrinha avatar"
Thanks for looking at this so quickly @Maxim Mironenko (Cloud Posse) – I’ve updated the PR with your suggestion.
data:image/s3,"s3://crabby-images/17c19/17c198162babe5ef0242fce2ead5561b10cc8803" alt="cabrinha avatar"
How do I allow write access for the bot?
data:image/s3,"s3://crabby-images/bc38e/bc38e529d2aaa7d65a302b2c4f50b7316325cf1a" alt="Maxim Mironenko (Cloud Posse) avatar"
no need, we are fine, bot works well
data:image/s3,"s3://crabby-images/17c19/17c198162babe5ef0242fce2ead5561b10cc8803" alt="cabrinha avatar"
data:image/s3,"s3://crabby-images/17c19/17c198162babe5ef0242fce2ead5561b10cc8803" alt="cabrinha avatar"
How can I duplicate the README and FMT commands you guys run on your PRs in my own org?
data:image/s3,"s3://crabby-images/bc38e/bc38e529d2aaa7d65a302b2c4f50b7316325cf1a" alt="Maxim Mironenko (Cloud Posse) avatar"
it is as easy as running:
make init
make readme/deps
make readme
data:image/s3,"s3://crabby-images/bc38e/bc38e529d2aaa7d65a302b2c4f50b7316325cf1a" alt="Maxim Mironenko (Cloud Posse) avatar"
and for FMT:
make terraform/install TERRAFORM_VERSION=0.12.19
terraform fmt -recursive
data:image/s3,"s3://crabby-images/bc38e/bc38e529d2aaa7d65a302b2c4f50b7316325cf1a" alt="Maxim Mironenko (Cloud Posse) avatar"
if you don’t want to do so on your host machine, you can use docker image
data:image/s3,"s3://crabby-images/bc38e/bc38e529d2aaa7d65a302b2c4f50b7316325cf1a" alt="Maxim Mironenko (Cloud Posse) avatar"
for example this one: https://github.com/cloudposse/geodesic
Geodesic is a cloud automation shell. It's the fastest way to get up and running with a rock solid, production grade cloud platform built on top of strictly Open Source tools. ★ this repo! h…
data:image/s3,"s3://crabby-images/17c19/17c198162babe5ef0242fce2ead5561b10cc8803" alt="cabrinha avatar"
Would I be able to copy this file into my own repos and use it the same way?
data:image/s3,"s3://crabby-images/17c19/17c198162babe5ef0242fce2ead5561b10cc8803" alt="cabrinha avatar"
Terraform module to provision an Elastic MapReduce (EMR) cluster on AWS - cloudposse/terraform-aws-emr-cluster
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
@Andriy Knysh (Cloud Posse) is the master of how that works. @Maxim Mironenko (Cloud Posse) though is getting caught up
data:image/s3,"s3://crabby-images/17c19/17c198162babe5ef0242fce2ead5561b10cc8803" alt="cabrinha avatar"
It’d also be great if we could get read-only access to these firebase workflows that are running against these modules too. Not a necessity but, interesting.
data:image/s3,"s3://crabby-images/bc38e/bc38e529d2aaa7d65a302b2c4f50b7316325cf1a" alt="Maxim Mironenko (Cloud Posse) avatar"
<https://github.com/cloudposse/terraform-aws-emr-cluster/actions>
and
<https://github.com/cloudposse/actions/actions>
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
@cabrinha you need a few steps to be able to use GitHub actions like we do:
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
- Copy
slash-command-dispatch.yml
to your repo
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
- Add the repo access token as secret
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
- The action above calls these workflows https://github.com/cloudposse/actions/tree/master/.github/workflows
Our Library of GitHub Actions. Contribute to cloudposse/actions development by creating an account on GitHub.
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
which you need to have as well
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
we separated the dispatched from the executor since we use one executor for all our repos (we just add the dispatcher to them) - so it’s easy to update it in one place
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
but you can use the dispatcher and the executor from just one repo
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
@Maxim Mironenko (Cloud Posse)
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
data:image/s3,"s3://crabby-images/17c19/17c198162babe5ef0242fce2ead5561b10cc8803" alt="cabrinha avatar"
The bot and these commands are really nice!
2020-04-22
data:image/s3,"s3://crabby-images/30994/30994b883331c5aa17117e06b3f5d3e078824456" alt="sheldonh avatar"
Anyone have a module I can plugin to get RDS event logging for cloudwatch events pushed to cloudwatch logs+pager duty or similar destination. I saw an older cloudposse one, some promise. Anything else?
2020-04-24
data:image/s3,"s3://crabby-images/b17c9/b17c9c459863927d8fcde73c8a29aabcac61b95e" alt="navdeep avatar"
@Andriy Knysh (Cloud Posse) i have been using cloudposse for long time , hey just need a direction for how to include a provision for reading a another account bucket i have been using private subnet for emr clusters
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
for cross-account access, you need to add permissions on both sides
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
on the one side, add an S3 bucket policy with permissions for the other account’s entities (users, groups or roles) to access the bucket
data:image/s3,"s3://crabby-images/b17c9/b17c9c459863927d8fcde73c8a29aabcac61b95e" alt="navdeep avatar"
yeah this i have added
data:image/s3,"s3://crabby-images/b17c9/b17c9c459863927d8fcde73c8a29aabcac61b95e" alt="navdeep avatar"
on emr side on ec2 roles ?
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
on the other side, add permissions to users/groups/roles to access the bucket
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
(I don’t know about your architecture so can’t advise on where to add those roles, emr or ec2)
data:image/s3,"s3://crabby-images/b17c9/b17c9c459863927d8fcde73c8a29aabcac61b95e" alt="navdeep avatar"
hmm,
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
it also depends on how you use it, just EC2 or Kubernetes
data:image/s3,"s3://crabby-images/b17c9/b17c9c459863927d8fcde73c8a29aabcac61b95e" alt="navdeep avatar"
this is pure emr on aws
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
but the description above applies to any case
data:image/s3,"s3://crabby-images/b17c9/b17c9c459863927d8fcde73c8a29aabcac61b95e" alt="navdeep avatar"
yes
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
@navdeep EMR is a complicated topic. If you show me the code where you think you should do it, I would be able to help you
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
Terraform module to provision an Elastic MapReduce (EMR) cluster on AWS - cloudposse/terraform-aws-emr-cluster
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
give me about 30 mins, I’ll find some code for EMR
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
@navdeep on the bucket side, you add this:
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
variable "s3_bucket_allow_access_principal_arns" {
type = list(string)
description = "ARNs of the principals that should be allowed to access the datalake S3 bucket, e.g. ARNs of other AWS accounts for cross-account access"
default = []
}
data "aws_iam_policy_document" "datalake_bucket_access" {
statement {
effect = "Allow"
actions = [
"s3:AbortMultipartUpload",
"s3:GetBucketLocation",
"s3:GetObject",
"s3:ListBucket",
"s3:ListBucketMultipartUploads",
"s3:PutObject",
"s3:PutObjectAcl"
]
resources = [
aws_s3_bucket.datalake.arn,
"${aws_s3_bucket.datalake.arn}/*"
]
principals {
type = "AWS"
identifiers = var.s3_bucket_allow_access_principal_arns
}
}
}
resource "aws_s3_bucket_policy" "datalake_bucket_access" {
bucket = aws_s3_bucket.datalake.id
policy = data.aws_iam_policy_document.datalake_bucket_access.json
}
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
@navdeep actually, what problem are you trying to solve? Why your bucket is in different account from the EMR cluster?
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
what we did for a client, we created EMR cluster and S3 bucket in one account (let’s call it data
. Then created Firehoses in other accounts (e.g. prod
, staging
). Then we added a bucket policy to allow access from those Forehoses (cross-account). Then allowed the Firehoses to write to the bucket (cross-account)
data:image/s3,"s3://crabby-images/b17c9/b17c9c459863927d8fcde73c8a29aabcac61b95e" alt="navdeep avatar"
so company has multiple accounts and thats because of different business verticals, i tried to put above policy before too,thanks for mentioning ,
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
The applications deployed in the other accounts (prod, staging, dev) have permissions to write data to the corresponding Firehoses (in the same account). Then, the Firehoses send data to the bucket in the data
account. The EMR cluster in the data
account (specifically, Hive and Presto) can access the S3 bucket in that account
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
Note that you can’t have a Firehose in the data
account and push data from apps in other accounts - ASW SDKs don’t have the possibility to push to Firehose in another account
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
that’s why we created Firehoses in all other accounts and allowed them to write to the datalake bucket in data
account
data:image/s3,"s3://crabby-images/b17c9/b17c9c459863927d8fcde73c8a29aabcac61b95e" alt="navdeep avatar"
hmm correct this seems to be a good design, this is more of a legacy we are carrying
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
But to do what you mentioned (EMR in one account, the bucket in another), I think you need to add resource "aws_iam_role_policy_attachment"
(with permissions to accesss the bucket cross-account) to these roles:
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
Terraform module to provision an Elastic MapReduce (EMR) cluster on AWS - cloudposse/terraform-aws-emr-cluster
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
Terraform module to provision an Elastic MapReduce (EMR) cluster on AWS - cloudposse/terraform-aws-emr-cluster
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
(not sure to both or just one of those, did not test it cross-account)
data:image/s3,"s3://crabby-images/b17c9/b17c9c459863927d8fcde73c8a29aabcac61b95e" alt="navdeep avatar"
hmm ok i will check and if it can be configured i will push a PR,
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
thanks
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
you can add additional variables to add additional policies to those two roles
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
(would be a good addition to the module)
data:image/s3,"s3://crabby-images/b17c9/b17c9c459863927d8fcde73c8a29aabcac61b95e" alt="navdeep avatar"
hey yup, though what worked us is adding read policy to give access to ec2 role we are creating in this module , shall i push a PR to add this in documentation ? if you need to read data from different account give following policy to ec2 role getting created
data:image/s3,"s3://crabby-images/b17c9/b17c9c459863927d8fcde73c8a29aabcac61b95e" alt="navdeep avatar"
and hey thanks again !!
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
thanks @navdeep
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
PRs always welcome
2020-04-26
2020-04-27
data:image/s3,"s3://crabby-images/0704f/0704fa2c4de34bfc92a8ecd50096a4fa8404549a" alt="joshmyers avatar"
Hey folks - Opened a smol PR - https://github.com/cloudposse/terraform-aws-route53-alias/pull/21 was hoping for maybe a quick turnaround? cc @Erik Osterman (Cloud Posse) / @Maxim Mironenko (Cloud Posse)
what Allow for allow_overwrite functionality why I want to manage some existing records with Terraform, so need this functionality which switches the action to an UPSERT, from CREATE. See https://w…
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
@Andriy Knysh (Cloud Posse) can you review this
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
yes
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
set the channel topic: Terraform Modules
data:image/s3,"s3://crabby-images/0704f/0704fa2c4de34bfc92a8ecd50096a4fa8404549a" alt="joshmyers avatar"
Thank you!
data:image/s3,"s3://crabby-images/3a2ce/3a2ce4c6bc76226bf51216a9ec67ba1e2791323a" alt="Andriy Knysh (Cloud Posse) avatar"
Terraform Module to Define Vanity Host/Domain (e.g. [brand.com](http://brand.com)
) as an ALIAS record - cloudposse/terraform-aws-route53-alias
data:image/s3,"s3://crabby-images/0704f/0704fa2c4de34bfc92a8ecd50096a4fa8404549a" alt="joshmyers avatar"
Thanks @Andriy Knysh (Cloud Posse)!! Hope you’re good!
Terraform Module to Define Vanity Host/Domain (e.g. [brand.com](http://brand.com)
) as an ALIAS record - cloudposse/terraform-aws-route53-alias