365 lines
8.7 KiB
Terraform
365 lines
8.7 KiB
Terraform
terraform {
|
|
required_providers {
|
|
aws = {
|
|
source = "hashicorp/aws"
|
|
version = "5.39.0"
|
|
}
|
|
}
|
|
backend "s3" {
|
|
encrypt = true
|
|
}
|
|
}
|
|
|
|
provider "aws" {
|
|
|
|
default_tags {
|
|
tags = {
|
|
Terraform = "true"
|
|
}
|
|
}
|
|
}
|
|
|
|
# s3 bucket - devops
|
|
resource "aws_s3_bucket" "devops" {
|
|
bucket = local.devops_s3_bucket_name
|
|
tags = local.common_tags
|
|
}
|
|
|
|
resource "aws_s3_bucket_policy" "deny_insecure_communication" {
|
|
bucket = aws_s3_bucket.devops.id
|
|
policy = data.aws_iam_policy_document.deny_insecure_communication.json
|
|
}
|
|
|
|
# s3 bucket - raw-data-ingestion
|
|
resource "aws_s3_bucket" "raw_data_ingestion" {
|
|
bucket = local.raw_data_ingestion_s3_bucket_name
|
|
tags = local.common_tags
|
|
}
|
|
|
|
resource "aws_s3_bucket_policy" "raw_data_ingestion_policy" {
|
|
bucket = aws_s3_bucket.raw_data_ingestion.id
|
|
policy = data.aws_iam_policy_document.raw_data_ingestion_deny_insecure_communication.json
|
|
}
|
|
|
|
# s3 bucket - mwaa_resources
|
|
resource "aws_s3_bucket" "mwaa_resources" {
|
|
bucket = local.mwaa_resources_s3_bucket_name
|
|
tags = local.common_tags
|
|
}
|
|
|
|
resource "aws_s3_bucket_policy" "mwaa_resources_policy" {
|
|
bucket = aws_s3_bucket.mwaa_resources.id
|
|
policy = data.aws_iam_policy_document.mwaa_resources_deny_insecure_communication.json
|
|
}
|
|
|
|
# Deny insecure s3 bucket policy
|
|
data "aws_iam_policy_document" "deny_insecure_communication" {
|
|
statement {
|
|
sid = "DenyInsecureCommunications"
|
|
|
|
principals {
|
|
type = "*"
|
|
identifiers = ["*"]
|
|
}
|
|
|
|
condition {
|
|
test = "Bool"
|
|
variable = "aws:SecureTransport"
|
|
values = ["false"]
|
|
}
|
|
|
|
effect = "Deny"
|
|
|
|
actions = ["s3:*"]
|
|
|
|
resources = [
|
|
aws_s3_bucket.devops.arn,
|
|
"${aws_s3_bucket.devops.arn}/*",
|
|
]
|
|
}
|
|
}
|
|
|
|
# Deny insecure s3 bucket policy - raw_data_ingestion
|
|
data "aws_iam_policy_document" "raw_data_ingestion_deny_insecure_communication" {
|
|
statement {
|
|
sid = "DenyInsecureCommunications"
|
|
|
|
principals {
|
|
type = "*"
|
|
identifiers = ["*"]
|
|
}
|
|
|
|
condition {
|
|
test = "Bool"
|
|
variable = "aws:SecureTransport"
|
|
values = ["false"]
|
|
}
|
|
|
|
effect = "Deny"
|
|
|
|
actions = ["s3:*"]
|
|
|
|
resources = [
|
|
aws_s3_bucket.raw_data_ingestion.arn,
|
|
"${aws_s3_bucket.raw_data_ingestion.arn}/*",
|
|
]
|
|
}
|
|
}
|
|
|
|
# Deny insecure s3 bucket policy - mwaa_resources
|
|
data "aws_iam_policy_document" "mwaa_resources_deny_insecure_communication" {
|
|
statement {
|
|
sid = "DenyInsecureCommunications"
|
|
|
|
principals {
|
|
type = "*"
|
|
identifiers = ["*"]
|
|
}
|
|
|
|
condition {
|
|
test = "Bool"
|
|
variable = "aws:SecureTransport"
|
|
values = ["false"]
|
|
}
|
|
|
|
effect = "Deny"
|
|
|
|
actions = ["s3:*"]
|
|
|
|
resources = [
|
|
aws_s3_bucket.mwaa_resources.arn,
|
|
"${aws_s3_bucket.mwaa_resources.arn}/*",
|
|
]
|
|
}
|
|
}
|
|
|
|
# IAM role - snowflake-integration-role
|
|
resource "aws_iam_role" "snowflake_integration_role" {
|
|
name = local.snowflake_integration_role_name
|
|
|
|
assume_role_policy = jsonencode({
|
|
Version = "2012-10-17"
|
|
Statement = [
|
|
{
|
|
Action = "sts:AssumeRole"
|
|
Effect = "Allow"
|
|
Sid = ""
|
|
Principal = {
|
|
AWS = "arn:aws:iam::851725635820:user/3nmi0000-s"
|
|
}
|
|
Condition = {
|
|
StringEquals = {
|
|
"sts:ExternalId" = var.storage_integration_external_id
|
|
}
|
|
}
|
|
},
|
|
]
|
|
})
|
|
}
|
|
|
|
# Construct IAM Policy for snowflake-integration-role
|
|
data "aws_iam_policy_document" "snowflake_integration_policy_document" {
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:PutObject",
|
|
"s3:GetObject",
|
|
"s3:GetObjectVersion",
|
|
"s3:DeleteObject",
|
|
"s3:DeleteObjectVersion"
|
|
]
|
|
resources = ["${aws_s3_bucket.raw_data_ingestion.arn}*"]
|
|
}
|
|
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:ListBucket",
|
|
"s3:GetBucketLocation"
|
|
]
|
|
resources = ["${aws_s3_bucket.raw_data_ingestion.arn}"]
|
|
|
|
condition {
|
|
test = "StringLike"
|
|
variable = "s3:prefix"
|
|
values = ["*"]
|
|
}
|
|
}
|
|
}
|
|
|
|
# IAM Policy for snowflake-integration-role
|
|
resource "aws_iam_policy" "snowflake_integration_policy" {
|
|
name = local.snowflake_integration_policy_name
|
|
description = "Client textract permissions"
|
|
policy = data.aws_iam_policy_document.snowflake_integration_policy_document.json
|
|
}
|
|
|
|
# Attach IAM Policy to snowflake-integration-role
|
|
resource "aws_iam_role_policy_attachment" "snowflake_integration_policy_attachment" {
|
|
role = aws_iam_role.snowflake_integration_role.name
|
|
policy_arn = aws_iam_policy.snowflake_integration_policy.arn
|
|
}
|
|
|
|
|
|
# IAM role - cross-account-role
|
|
resource "aws_iam_role" "cross_account_role" {
|
|
count = var.environment != "dev"? 1 : 0
|
|
name = local.cross_account_role_name
|
|
|
|
assume_role_policy = jsonencode({
|
|
Version = "2012-10-17"
|
|
Statement = [
|
|
{
|
|
Action = "sts:AssumeRole"
|
|
Effect = "Allow"
|
|
Sid = ""
|
|
Principal = {
|
|
AWS = "arn:aws:iam::${var.cross_account_target_account_id}:root"
|
|
}
|
|
},
|
|
]
|
|
})
|
|
}
|
|
|
|
# Construct IAM Policy for cross-account-role
|
|
data "aws_iam_policy_document" "cross_account_policy_document" {
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:PutObject",
|
|
"s3:GetObject",
|
|
"s3:ListBucket",
|
|
"s3:PutObjectAcl",
|
|
"s3:GetObjectVersion"
|
|
]
|
|
resources = [
|
|
"${aws_s3_bucket.raw_data_ingestion.arn}",
|
|
"${aws_s3_bucket.raw_data_ingestion.arn}/*"
|
|
]
|
|
}
|
|
}
|
|
|
|
# IAM Policy for cross-account-role
|
|
resource "aws_iam_policy" "cross_account_policy" {
|
|
count = var.environment != "dev"? 1 : 0
|
|
name = local.cross_account_policy_name
|
|
description = "This role is used for other AWS account to assume inorder to drop files to our data ingestion bucket. At the time of creation, this is being used by CODE DEV to drop all clients list."
|
|
policy = data.aws_iam_policy_document.cross_account_policy_document.json
|
|
}
|
|
|
|
# Attach IAM Policy to cross-account-role
|
|
resource "aws_iam_role_policy_attachment" "cross_account_policy_attachment" {
|
|
count = var.environment != "dev"? 1 : 0
|
|
role = aws_iam_role.cross_account_role[count.index].name
|
|
policy_arn = aws_iam_policy.cross_account_policy[count.index].arn
|
|
}
|
|
|
|
# IAM role - mwaa-exec-role
|
|
resource "aws_iam_role" "mwaa_exec_role" {
|
|
name = local.mwaa_exec_role_role_name
|
|
|
|
assume_role_policy = jsonencode({
|
|
Version = "2012-10-17"
|
|
Statement = [
|
|
{
|
|
Action = "sts:AssumeRole"
|
|
Effect = "Allow"
|
|
Sid = ""
|
|
Principal = {
|
|
Service = ["airflow-env.amazonaws.com","airflow.amazonaws.com"]
|
|
}
|
|
},
|
|
]
|
|
})
|
|
}
|
|
|
|
# Construct IAM Policy for mwaa-exec-role
|
|
data "aws_iam_policy_document" "mwaa_exec_policy_document" {
|
|
statement {
|
|
effect = "Allow"
|
|
actions = ["s3:*"]
|
|
resources = [
|
|
"${aws_s3_bucket.raw_data_ingestion.arn}/*"
|
|
]
|
|
}
|
|
statement {
|
|
effect = "Allow"
|
|
actions = ["airflow:CreateCliToken"]
|
|
resources = [
|
|
"arn:aws:airflow:us-east-2:${var.aws_account_id}:environment/doczy-${var.environment}-infra-mwaa"
|
|
]
|
|
}
|
|
statement {
|
|
effect = "Allow"
|
|
actions = ["airflow:PublishMetrics"]
|
|
resources = [
|
|
"arn:aws:airflow:us-east-2:${var.aws_account_id}:environment/doczy-${var.environment}-infra-mwaa"
|
|
]
|
|
}
|
|
statement {
|
|
effect = "Deny"
|
|
actions = ["s3:ListAllMyBuckets"]
|
|
resources = [
|
|
"${aws_s3_bucket.mwaa_resources.arn}",
|
|
"${aws_s3_bucket.mwaa_resources.arn}/*"
|
|
]
|
|
}
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:GetObject*",
|
|
"s3:GetBucket*",
|
|
"s3:List*",
|
|
"s3:PutObject"
|
|
]
|
|
resources = [
|
|
"${aws_s3_bucket.mwaa_resources.arn}",
|
|
"${aws_s3_bucket.mwaa_resources.arn}/*"
|
|
]
|
|
}
|
|
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"logs:CreateLogStream",
|
|
"logs:CreateLogGroup",
|
|
"logs:PutLogEvents",
|
|
"logs:GetLogEvents",
|
|
"logs:GetLogRecord",
|
|
"logs:GetLogGroupFields",
|
|
"logs:GetQueryResults"
|
|
]
|
|
resources = [
|
|
"arn:aws:logs:us-east-2:${var.aws_account_id}:log-group:airflow-doczy-${var.environment}-infra-mwaa-*"
|
|
]
|
|
}
|
|
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"logs:DescribeLogGroups"
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
effect = "Allow"
|
|
actions = [
|
|
"cloudwatch:PutMetricData"
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
}
|
|
|
|
# IAM Policy for mwaa-exec-role
|
|
resource "aws_iam_policy" "mwaa_exec_policy" {
|
|
name = local.mwaa_exec_policy_name
|
|
description = ""
|
|
policy = data.aws_iam_policy_document.mwaa_exec_policy_document.json
|
|
}
|
|
|
|
# Attach IAM Policy to mwaa-exec-role
|
|
resource "aws_iam_role_policy_attachment" "mwaa_exec_policy_attachment" {
|
|
role = aws_iam_role.mwaa_exec_role.name
|
|
policy_arn = aws_iam_policy.mwaa_exec_policy.arn
|
|
} |