Difference between revisions of "Terraform resource: aws security group"

From wikieduonline
Jump to navigation Jump to search
Line 63: Line 63:
 
* <code>[[security_groups]], [[network_configuration]]</code>: <code>[[aws_ecs_service]]</code>
 
* <code>[[security_groups]], [[network_configuration]]</code>: <code>[[aws_ecs_service]]</code>
 
* <code>[[vpc_security_group_ids]]</code>: <code>[[aws_instance]], [[aws_db_instance]]</code>
 
* <code>[[vpc_security_group_ids]]</code>: <code>[[aws_instance]], [[aws_db_instance]]</code>
* <code>[[aws_network_interface_sg_attachment]]</code>
 
 
* <code>[[aws_instance]]</code>
 
* <code>[[aws_instance]]</code>
 
* <code>[[aws_network_interface_sg_attachment]]</code>
 
* <code>[[aws_network_interface_sg_attachment]]</code>

Revision as of 09:07, 13 March 2023

aws_security_group

Examples

resource "aws_security_group" "allow_ssh" {
  name        = "allow_ssh"
  description = "Allow ssh inbound traffic from Internet"

  ingress {
    description      = "SSH from Internet"
    from_port        = 22
    to_port          = 22
    protocol         = "tcp"
    cidr_blocks      = ["0.0.0.0/0"]
    ipv6_cidr_blocks = ["::/0"]
  }

  tags = {
    Name = "allow_ssh"
  }
}



resource "aws_security_group" "allow_tls" {
  name        = "allow_tls"
  description = "Allow TLS inbound traffic"
  vpc_id      = aws_vpc.main.id

  ingress {
    description      = "TLS from VPC"
    from_port        = 443
    to_port          = 443
    protocol         = "tcp"
    cidr_blocks      = [aws_vpc.main.cidr_block]
    ipv6_cidr_blocks = [aws_vpc.main.ipv6_cidr_block]
  } 

  egress {
    from_port        = 0
    to_port          = 0
    protocol         = "-1"
    cidr_blocks      = ["0.0.0.0/0"]
    ipv6_cidr_blocks = ["::/0"]
  }

  tags = {
    Name = "allow_tls"
  }
}

Arguments

Related terms

See also

Advertising: