forked from petervansickel/terraform-icp-ibmcloud
-
Notifications
You must be signed in to change notification settings - Fork 2
/
security_group.tf
159 lines (141 loc) · 4.94 KB
/
security_group.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
resource "ibm_security_group" "cluster_private" {
name = "${var.deployment}-cluster-priv-${random_id.clusterid.hex}"
description = "allow intercluster communication"
}
resource "ibm_security_group_rule" "allow_ingress_from_self_priv" {
direction = "ingress"
ether_type = "IPv4"
remote_group_id = "${ibm_security_group.cluster_private.id}"
security_group_id = "${ibm_security_group.cluster_private.id}"
}
resource "ibm_security_group_rule" "allow_cluster_egress_private" {
direction = "egress"
ether_type = "IPv4"
security_group_id = "${ibm_security_group.cluster_private.id}"
}
resource "ibm_security_group" "cluster_public" {
count = "${var.private_network_only ? 0 : 1}"
name = "${var.deployment}-cluster-pub-${random_id.clusterid.hex}"
description = "allow intercluster communication"
}
resource "ibm_security_group_rule" "allow_ingress_from_self_pub" {
count = "${var.private_network_only ? 0 : 1}"
direction = "ingress"
ether_type = "IPv4"
remote_group_id = "${ibm_security_group.cluster_public.id}"
security_group_id = "${ibm_security_group.cluster_public.id}"
}
resource "ibm_security_group_rule" "allow_cluster_public" {
count = "${var.private_network_only ? 0 : 1}"
direction = "egress"
ether_type = "IPv4"
security_group_id = "${ibm_security_group.cluster_public.id}"
}
resource "ibm_security_group" "master_group" {
name = "${var.deployment}-master-${random_id.clusterid.hex}"
description = "allow incoming to master"
}
# restrict incoming on ports to LBaaS private subnet
resource "ibm_security_group_rule" "allow_port_8443" {
direction = "ingress"
ether_type = "IPv4"
protocol = "tcp"
port_range_min = 8443
port_range_max = 8443
security_group_id = "${ibm_security_group.master_group.id}"
#remote_ip = "${ibm_compute_vm_instance.icp-master.0.private_subnet}"
# Sometimes LBaaS can be placed on a different subnet
remote_ip = "0.0.0.0/0"
}
# restrict to LBaaS private subnet
resource "ibm_security_group_rule" "allow_port_8500" {
direction = "ingress"
ether_type = "IPv4"
protocol = "tcp"
port_range_min = 8500
port_range_max = 8500
security_group_id = "${ibm_security_group.master_group.id}"
# remote_ip = "${ibm_compute_vm_instance.icp-master.0.private_subnet}"
# Sometimes LBaaS can be placed on a different subnet
remote_ip = "0.0.0.0/0"
}
# restrict to LBaaS private subnet
resource "ibm_security_group_rule" "allow_port_8600" {
direction = "ingress"
ether_type = "IPv4"
protocol = "tcp"
port_range_min = 8600
port_range_max = 8600
security_group_id = "${ibm_security_group.master_group.id}"
# remote_ip = "${ibm_compute_vm_instance.icp-master.0.private_subnet}"
# Sometimes LBaaS can be placed on a different subnet
remote_ip = "0.0.0.0/0"
}
# TODO restrict to LBaaS private subnet
resource "ibm_security_group_rule" "allow_port_8001" {
direction = "ingress"
ether_type = "IPv4"
protocol = "tcp"
port_range_min = 8001
port_range_max = 8001
security_group_id = "${ibm_security_group.master_group.id}"
# remote_ip = "${ibm_compute_vm_instance.icp-master.0.private_subnet}"
# Sometimes LBaaS can be placed on a different subnet
remote_ip = "0.0.0.0/0"
}
# restrict to LBaaS private subnet
resource "ibm_security_group_rule" "allow_port_9443" {
direction = "ingress"
ether_type = "IPv4"
protocol = "tcp"
port_range_min = 9443
port_range_max = 9443
security_group_id = "${ibm_security_group.master_group.id}"
# remote_ip = "${ibm_compute_vm_instance.icp-master.0.private_subnet}"
# Sometimes LBaaS can be placed on a different subnet
remote_ip = "0.0.0.0/0"
}
resource "ibm_security_group_rule" "master_node_allow_outbound_public" {
direction = "egress"
ether_type = "IPv4"
security_group_id = "${ibm_security_group.master_group.id}"
}
# restrict to LBaaS private subnet
resource "ibm_security_group_rule" "allow_port_80" {
direction = "ingress"
ether_type = "IPv4"
protocol = "tcp"
port_range_min = 80
port_range_max = 80
security_group_id = "${ibm_security_group.proxy_group.id}"
# Sometimes LBaaS can be placed on a different subnet
remote_ip = "0.0.0.0/0"
}
# restrict to LBaaS private subnet
resource "ibm_security_group_rule" "allow_port_443" {
direction = "ingress"
ether_type = "IPv4"
protocol = "tcp"
port_range_min = 443
port_range_max = 443
security_group_id = "${ibm_security_group.proxy_group.id}"
# Sometimes LBaaS can be placed on a different subnet
remote_ip = "0.0.0.0/0"
}
resource "ibm_security_group" "proxy_group" {
name = "${var.deployment}-proxy-${random_id.clusterid.hex}"
description = "allow incoming to proxy"
}
resource "ibm_security_group" "boot_node_public" {
name = "${var.deployment}-boot-${random_id.clusterid.hex}"
description = "allow incoming ssh"
}
# TODO restrict to allowed CIDR
resource "ibm_security_group_rule" "allow_ssh" {
direction = "ingress"
ether_type = "IPv4"
protocol = "tcp"
port_range_min = 22
port_range_max = 22
security_group_id = "${ibm_security_group.boot_node_public.id}"
}