update
This commit is contained in:
153
terraform/aws_network/02_dmz_route.tf
Normal file
153
terraform/aws_network/02_dmz_route.tf
Normal file
@@ -0,0 +1,153 @@
|
||||
|
||||
|
||||
output "sbn_dmz_prod_a_id" {
|
||||
value = aws_subnet.sbn-prod-dmz-a.id
|
||||
}
|
||||
|
||||
output "sbn_dmz_prod_b_id" {
|
||||
value = aws_subnet.sbn-prod-dmz-b.id
|
||||
}
|
||||
|
||||
output "sbn_dmz_prod_c_id" {
|
||||
value = aws_subnet.sbn-prod-dmz-c.id
|
||||
}
|
||||
|
||||
resource "aws_subnet" "sbn-prod-dmz-a" {
|
||||
availability_zone = "ap-northeast-2a"
|
||||
cidr_block = "172.24.0.0/24"
|
||||
enable_resource_name_dns_a_record_on_launch = true
|
||||
private_dns_hostname_type_on_launch = "resource-name"
|
||||
tags = {
|
||||
"Name"= "sbn-prod-dmz-a.datasaker"
|
||||
"SubnetType" = "Utility"
|
||||
"kubernetes.io/cluster/datasaker" = "owned"
|
||||
"kubernetes.io/cluster/prod.datasaker.io" = "shared"
|
||||
"kubernetes.io/role/nlb" = "1"
|
||||
"kubernetes.io/role/internal-nlb" = "1"
|
||||
}
|
||||
vpc_id = aws_vpc.vpc-prod-datasaker.id
|
||||
}
|
||||
|
||||
resource "aws_subnet" "sbn-prod-dmz-b" {
|
||||
availability_zone = "ap-northeast-2b"
|
||||
cidr_block = "172.24.1.0/24"
|
||||
enable_resource_name_dns_a_record_on_launch = true
|
||||
private_dns_hostname_type_on_launch = "resource-name"
|
||||
tags = {
|
||||
"Name" = "sbn-prod-dmz-b.datasaker"
|
||||
"SubnetType" = "Utility"
|
||||
"kubernetes.io/cluster/datasaker" = "owned"
|
||||
"kubernetes.io/cluster/prod.datasaker.io" = "shared"
|
||||
"kubernetes.io/role/nlb" = "1"
|
||||
"kubernetes.io/role/internal-nlb" = "1"
|
||||
}
|
||||
vpc_id = aws_vpc.vpc-prod-datasaker.id
|
||||
}
|
||||
|
||||
resource "aws_subnet" "sbn-prod-dmz-c" {
|
||||
availability_zone = "ap-northeast-2c"
|
||||
cidr_block = "172.24.2.0/24"
|
||||
enable_resource_name_dns_a_record_on_launch = true
|
||||
private_dns_hostname_type_on_launch = "resource-name"
|
||||
tags = {
|
||||
"Name" = "sbn-prod-dmz-c.datasaker"
|
||||
"SubnetType" = "Utility"
|
||||
"kubernetes.io/cluster/datasaker" = "owned"
|
||||
"kubernetes.io/cluster/prod.datasaker.io" = "shared"
|
||||
"kubernetes.io/role/nlb" = "1"
|
||||
"kubernetes.io/role/internal-nlb" = "1"
|
||||
}
|
||||
vpc_id = aws_vpc.vpc-prod-datasaker.id
|
||||
}
|
||||
|
||||
resource "aws_route_table" "rt-prod-datasaker-pub" {
|
||||
tags = {
|
||||
"Name" = "rt-prod-datasaker-pub"
|
||||
}
|
||||
vpc_id = aws_vpc.vpc-prod-datasaker.id
|
||||
}
|
||||
|
||||
resource "aws_route" "r-0-0-0-0--0" {
|
||||
destination_cidr_block = "0.0.0.0/0"
|
||||
gateway_id = aws_internet_gateway.igw-prod-datasaker.id
|
||||
route_table_id = aws_route_table.rt-prod-datasaker-pub.id
|
||||
}
|
||||
|
||||
resource "aws_route" "r-__--0" {
|
||||
destination_ipv6_cidr_block = "::/0"
|
||||
gateway_id = aws_internet_gateway.igw-prod-datasaker.id
|
||||
route_table_id = aws_route_table.rt-prod-datasaker-pub.id
|
||||
}
|
||||
resource "aws_route_table_association" "rta-prod-dmz-a" {
|
||||
route_table_id = aws_route_table.rt-prod-datasaker-pub.id
|
||||
subnet_id = aws_subnet.sbn-prod-dmz-a.id
|
||||
}
|
||||
|
||||
resource "aws_route_table_association" "rta-prod-dmz-b" {
|
||||
route_table_id = aws_route_table.rt-prod-datasaker-pub.id
|
||||
subnet_id = aws_subnet.sbn-prod-dmz-b.id
|
||||
}
|
||||
|
||||
resource "aws_route_table_association" "rta-prod-dmz-c" {
|
||||
route_table_id = aws_route_table.rt-prod-datasaker-pub.id
|
||||
subnet_id = aws_subnet.sbn-prod-dmz-c.id
|
||||
}
|
||||
|
||||
resource "aws_eip" "eip-bastion-prod-datasaker" {
|
||||
vpc = true
|
||||
tags = {
|
||||
Name = "eip-bastion-prod-datasaker"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_eip" "eip-natgw-prod-a-datasaker" {
|
||||
vpc = true
|
||||
tags = {
|
||||
Name = "eip-natgw-prod-a-datasaker"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_eip" "eip-natgw-prod-b-datasaker" {
|
||||
vpc = true
|
||||
tags = {
|
||||
Name = "eip-natgw-prod-b-datasaker"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_eip" "eip-natgw-prod-c-datasaker" {
|
||||
vpc = true
|
||||
tags = {
|
||||
Name = "eip-natgw-prod-c-datasaker"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_nat_gateway" "natgw-prod-a-datasaker" {
|
||||
allocation_id = aws_eip.eip-natgw-prod-a-datasaker.id
|
||||
subnet_id = aws_subnet.sbn-prod-dmz-a.id
|
||||
|
||||
tags = {
|
||||
Name = "natgw-prod-a-datasaker"
|
||||
}
|
||||
depends_on = [aws_internet_gateway.igw-prod-datasaker]
|
||||
}
|
||||
|
||||
resource "aws_nat_gateway" "natgw-prod-b-datasaker" {
|
||||
allocation_id = aws_eip.eip-natgw-prod-b-datasaker.id
|
||||
subnet_id = aws_subnet.sbn-prod-dmz-b.id
|
||||
|
||||
tags = {
|
||||
Name = "natgw-prod-b-datasaker"
|
||||
}
|
||||
depends_on = [aws_internet_gateway.igw-prod-datasaker]
|
||||
}
|
||||
|
||||
resource "aws_nat_gateway" "natgw-prod-c-datasaker" {
|
||||
allocation_id = aws_eip.eip-natgw-prod-c-datasaker.id
|
||||
subnet_id = aws_subnet.sbn-prod-dmz-c.id
|
||||
|
||||
tags = {
|
||||
Name = "natgw-prod-c-datasaker"
|
||||
}
|
||||
depends_on = [aws_internet_gateway.igw-prod-datasaker]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user