fix major issues
This commit is contained in:
47
.gitignore
vendored
Normal file
47
.gitignore
vendored
Normal file
@@ -0,0 +1,47 @@
|
||||
# Local .terraform directories
|
||||
.terraform/
|
||||
|
||||
# .tfstate files
|
||||
*.tfstate
|
||||
*.tfstate.*
|
||||
|
||||
# Crash log files
|
||||
crash.log
|
||||
crash.*.log
|
||||
|
||||
# Exclude all .tfvars files, which are likely to contain sensitive data, such as
|
||||
# password, private keys, and other secrets. These should not be part of version
|
||||
# control as they are data points which are potentially sensitive and subject
|
||||
# to change depending on the environment.
|
||||
*.tfvars
|
||||
*.tfvars.json
|
||||
|
||||
# Ignore override files as they are usually used to override resources locally and so
|
||||
# are not checked in
|
||||
override.tf
|
||||
override.tf.json
|
||||
*_override.tf
|
||||
*_override.tf.json
|
||||
|
||||
# Ignore transient lock info files created by terraform apply
|
||||
.terraform.tfstate.lock.info
|
||||
|
||||
# Include override files you do wish to add to version control using negated pattern
|
||||
# !example_override.tf
|
||||
|
||||
# Include tfplan files to ignore the plan output of command: terraform plan -out=tfplan
|
||||
# example: *tfplan*
|
||||
|
||||
# Ignore CLI configuration files
|
||||
.terraformrc
|
||||
terraform.rc
|
||||
|
||||
# Optional: ignore graph output files generated by `terraform graph`
|
||||
# *.dot
|
||||
|
||||
# Optional: ignore plan files saved before destroying Terraform configuration
|
||||
# Uncomment the line below if you want to ignore planout files.
|
||||
# planout
|
||||
|
||||
*.tfvars
|
||||
.*.lock.hcl
|
||||
64
.terraform.lock.hcl
generated
Normal file
64
.terraform.lock.hcl
generated
Normal file
@@ -0,0 +1,64 @@
|
||||
# This file is maintained automatically by "terraform init".
|
||||
# Manual edits may be lost in future updates.
|
||||
|
||||
provider "registry.terraform.io/hashicorp/random" {
|
||||
version = "3.9.0"
|
||||
hashes = [
|
||||
"h1:OO+IuvQJSPmWdN8AyyIEvPJbLvDQpgX/zbktoa9KsJE=",
|
||||
"zh:161ad0bd9a75768c82f53fb6e7172a9d8be2d4889b012645a34795031aaf1bf1",
|
||||
"zh:19dc9a5b17729725ccfc4f45b0500af0ee5bc6b6b160c7adb8f2bf617d2c80ea",
|
||||
"zh:269eda8fe42daa7974d5a34d166c3ba9defe80cde86c01e4dadcfdf2e1f05e5f",
|
||||
"zh:373f7c65566f8f2cc7f45d698654feb9d988996957e1266a69ca00c52d6d16d0",
|
||||
"zh:5599d16804c41c83009ec621b6d6b6f74e102f5827678a4750f8809055546b61",
|
||||
"zh:583be0440469a22bff70dcfa56593b01566860b29607437264adb51060cf46fc",
|
||||
"zh:5f211d8ec3f2e1f414870d9584bfe26e6995560ef81c748f8447a48164767398",
|
||||
"zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3",
|
||||
"zh:7b547fd16216761ef86efc3ed516ac5ac0c5c42b7c7eb24a08cef2d93f69ed5e",
|
||||
"zh:7e7c0679daf2a382151d05068c8c3f0dae6b7b7dccf818827b73dd08638df2ef",
|
||||
"zh:8089dec888a8038b9b4fb23b3df7e1057293dbc5b60b42cc47ff690d69d4b61b",
|
||||
"zh:c51f15a031edfd6f23ce8ced3446ca7f8d8d647e2499890d7d5d10d5016d7257",
|
||||
"zh:c94784f005708890dc6895afd53636ec00ec1e430b15d41e5aebfb1d4b39bd04",
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/hashicorp/tls" {
|
||||
version = "4.3.0"
|
||||
hashes = [
|
||||
"h1:5bCU/c+2HUh7GhclzNSH6gAuoCS4inW3obEtRAwu6WQ=",
|
||||
"zh:0ab58d6f8991d436c7d2dbd89ed814709b949b07ac5a54ee53b0aec1fa772a8b",
|
||||
"zh:60b347abcb56f45d97c56f14d895069cd15a83993f199777f571b79fea3642ee",
|
||||
"zh:6889be32640349230de3f23856e6f04e0e9ced4a84a27d3f552fa54684448218",
|
||||
"zh:73f8e1ecf7135033165fb14b7e8bf4d656f3ce13065ec35762ea0481975328c7",
|
||||
"zh:94ce25ee253eca0b42cae9c856b36bca8103b6453012d1b279c3623c805f2d42",
|
||||
"zh:96bc6de9fd67bc446fd11257872e1ffb1029a996ed1d65a3f6b43f6d408ad9ab",
|
||||
"zh:97c609a310a51bfd504d704e036d72064a84bf0bdb36cc08cd4cc66098212b41",
|
||||
"zh:a12c16e94533c5bd123f75032576b9dc91dd5d5ccd5f7cf331d0f2e1adc55cf8",
|
||||
"zh:c4f014f876adf7af57188795050bda5b0029d8c7d7773031102b6c36dcf1fc21",
|
||||
"zh:d9b0a21583aaa3df3a95394fb949a3c515ff71c2ff5a1fc4a73d364aa90bfca5",
|
||||
"zh:da510d22f0c6d71ad19a76406f106b782448f512375787ecfabb338ed1e311a7",
|
||||
"zh:f0e9447a9ce3a24cdaa113089e65663c836d8b9bfdb915a1c0284e0112cab5c0",
|
||||
"zh:f569b65999264a9416862bca5cd2a6177d94ccb0424f3a4ef424428912b9cb3c",
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/oracle/oci" {
|
||||
version = "8.22.0"
|
||||
hashes = [
|
||||
"h1:xLLhJqN7B91cVYZMEmiY0dAPcEVnUFBiw5k8fu+tWsw=",
|
||||
"zh:0006fcdb52d37285b73c83e91cb5e298b05a6935a15ea865e83a5529ecaef868",
|
||||
"zh:249e76d8a172e11e5e06f77663541537c4c216b847e8d624bb5a9f32529e0aec",
|
||||
"zh:3cf68a19afd7fa3ffa5506025a262d94772177ed3d3f1004eeaeaec4ab197c22",
|
||||
"zh:3f488e5a32374e3a5d9953023c27e4b21d113800c9a50247092f0220316453db",
|
||||
"zh:6dca79b3f8fd2c2b6841ba63cb7ac3e673cd334ffc8937c651588edfc87dcc90",
|
||||
"zh:7263f3973d49cf80d88b8ec60c42cf81cd2a060281a6f8ac8500b64ae41b20a3",
|
||||
"zh:7ca0fd995a102ce1852000dbb9601609e559adf8e34606237e6c3cf5d94caa7e",
|
||||
"zh:7e11709bcb11076141b8df41084573159de8b663ffb8345ccbd380768a1b2d82",
|
||||
"zh:90782c215c3671cfc9d6ee853af8cd16c0fdd8c817b2672bc001b2d57a2bcb65",
|
||||
"zh:9b12af85486a96aedd8d7984b0ff811a4b42e3d88dad1a3fb4c0b580d04fa425",
|
||||
"zh:a083575c5047062f162b9fffe078852ca0f44bf0293275038fe22d29f67a655a",
|
||||
"zh:b2709a6a63e7510e869a0ff2c6f688b4a3d9e24f7a92588b8bad19d74b4c8892",
|
||||
"zh:b403b916a94a2d782b44286f958e90c6efd6e97def7772059d1a0ef028eb0480",
|
||||
"zh:b787c10f06889433c9f559a0961b7548f49fd826129c279f3301aa1df5f95074",
|
||||
"zh:f234bd1b208ebe25cdfe4edb9b3665d3055f7a8df0ea00d6f10a9ea1ceb99455",
|
||||
]
|
||||
}
|
||||
@@ -29,4 +29,6 @@ data "oci_mysql_mysql_configurations" "sei_mysql_configurations" {
|
||||
state = "ACTIVE"
|
||||
shape_name = "MySQL.4"
|
||||
type = ["DEFAULT"]
|
||||
}
|
||||
}
|
||||
|
||||
data "oci_core_services" "all_services" {}
|
||||
@@ -34,4 +34,18 @@ resource "oci_core_network_security_group_security_rule" "nsg_db_security_ingres
|
||||
}
|
||||
}
|
||||
}
|
||||
#--------------------------------------------------------------------------------------------------------------------------------------------
|
||||
#--------------------------------------------------------------------------------------------------------------------------------------------
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_db_security_egress_rule_01" {
|
||||
network_security_group_id = oci_core_network_security_group.db-server-nsg.id
|
||||
description = "Egress to OSN"
|
||||
destination = lookup(data.oci_core_services.all_services.services[1], "cidr_block")
|
||||
destination_type = "SERVICE_CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 443
|
||||
min = 443
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -19,4 +19,33 @@ resource "oci_core_network_security_group_security_rule" "jod_servers_security_i
|
||||
}
|
||||
}
|
||||
|
||||
#--------------------------------------------------------------------------------------------------------------------------------------------
|
||||
#--------------------------------------------------------------------------------------------------------------------------------------------
|
||||
resource "oci_core_network_security_group_security_rule" "jod_servers_security_egress_rule_01" {
|
||||
network_security_group_id = oci_core_network_security_group.jod-servers-nsg.id
|
||||
description = "Egress to OSN"
|
||||
destination = lookup(data.oci_core_services.all_services.services[1], "cidr_block")
|
||||
destination_type = "SERVICE_CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 443
|
||||
min = 443
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "jod_servers_security_egress_rule_02" {
|
||||
network_security_group_id = oci_core_network_security_group.jod-servers-nsg.id
|
||||
description = "Egress to Internet only port TCP/443"
|
||||
destination = var.cidr_anywhere
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 443
|
||||
min = 443
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -20,4 +20,33 @@ resource "oci_core_network_security_group_security_rule" "nsg_memcached_ingress_
|
||||
}
|
||||
|
||||
|
||||
#--------------------------------------------------------------------------------------------------------------------------------------------
|
||||
#--------------------------------------------------------------------------------------------------------------------------------------------
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_memcached_egress_rule_01" {
|
||||
network_security_group_id = oci_core_network_security_group.memcached-servers-nsg.id
|
||||
description = "Egress to OSN"
|
||||
destination = lookup(data.oci_core_services.all_services.services[1], "cidr_block")
|
||||
destination_type = "SERVICE_CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 443
|
||||
min = 443
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_memcached_egress_rule_02" {
|
||||
network_security_group_id = oci_core_network_security_group.memcached-servers-nsg.id
|
||||
description = "Egress to Internet port TCP/443"
|
||||
destination = var.cidr_anywhere
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 443
|
||||
min = 443
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -51,6 +51,51 @@ resource "oci_core_network_security_group_security_rule" "sei_servers_security_i
|
||||
|
||||
#--------------------------------------------------------------------------------------------------------------------------------------------
|
||||
resource "oci_core_network_security_group_security_rule" "sei_servers_security_egress_rule_01" {
|
||||
network_security_group_id = oci_core_network_security_group.sei-servers-nsg.id
|
||||
description = "Egress to Internet port TCP/80"
|
||||
destination = var.cidr_anywhere
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 80
|
||||
min = 80
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "sei_servers_security_egress_rule_02" {
|
||||
network_security_group_id = oci_core_network_security_group.sei-servers-nsg.id
|
||||
description = "Egress to OSN port TCP/443"
|
||||
destination = lookup(data.oci_core_services.all_services.services[1], "cidr_block")
|
||||
destination_type = "SERVICE_CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 443
|
||||
min = 443
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "sei_servers_security_egress_rule_03" {
|
||||
network_security_group_id = oci_core_network_security_group.sei-servers-nsg.id
|
||||
description = "Egress to Internet port TCP/443"
|
||||
destination = var.cidr_anywhere
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 443
|
||||
min = 443
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "sei_servers_security_egress_rule_04" {
|
||||
network_security_group_id = oci_core_network_security_group.sei-servers-nsg.id
|
||||
description = "Egress MySQL to sn-database"
|
||||
destination = var.cidr_subnet_database
|
||||
@@ -65,51 +110,6 @@ resource "oci_core_network_security_group_security_rule" "sei_servers_security_e
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "sei_servers_security_egress_rule_02" {
|
||||
network_security_group_id = oci_core_network_security_group.sei-servers-nsg.id
|
||||
description = "Egress MySQL Heatware to sn-database"
|
||||
destination = var.cidr_subnet_database
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 33060
|
||||
min = 33060
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "sei_servers_security_egress_rule_03" {
|
||||
network_security_group_id = oci_core_network_security_group.sei-servers-nsg.id
|
||||
description = "Egress SOLR to sn-database"
|
||||
destination = var.cidr_subnet_app
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 8983
|
||||
min = 8983
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "sei_servers_security_egress_rule_04" {
|
||||
network_security_group_id = oci_core_network_security_group.sei-servers-nsg.id
|
||||
description = "Egress Memcached to sn-app"
|
||||
destination = var.cidr_subnet_app
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 11211
|
||||
min = 11211
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "sei_servers_security_egress_rule_05" {
|
||||
network_security_group_id = oci_core_network_security_group.sei-servers-nsg.id
|
||||
description = "Egress Jod to sn-app"
|
||||
@@ -124,4 +124,49 @@ resource "oci_core_network_security_group_security_rule" "sei_servers_security_e
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "sei_servers_security_egress_rule_06" {
|
||||
network_security_group_id = oci_core_network_security_group.sei-servers-nsg.id
|
||||
description = "Egress SOLR to sn-database"
|
||||
destination = var.cidr_subnet_app
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 8983
|
||||
min = 8983
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "sei_servers_security_egress_rule_07" {
|
||||
network_security_group_id = oci_core_network_security_group.sei-servers-nsg.id
|
||||
description = "Egress Memcached to sn-app"
|
||||
destination = var.cidr_subnet_app
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 11211
|
||||
min = 11211
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "sei_servers_security_egress_rule_08" {
|
||||
network_security_group_id = oci_core_network_security_group.sei-servers-nsg.id
|
||||
description = "Egress MySQL Heatware to sn-database"
|
||||
destination = var.cidr_subnet_database
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 33060
|
||||
min = 33060
|
||||
}
|
||||
}
|
||||
}
|
||||
#--------------------------------------------------------------------------------------------------------------------------------------------
|
||||
@@ -51,6 +51,51 @@ resource "oci_core_network_security_group_security_rule" "nsg_sip-server_ingress
|
||||
|
||||
#--------------------------------------------------------------------------------------------------------------------------------------------
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_rule_01" {
|
||||
network_security_group_id = oci_core_network_security_group.sip-servers-nsg.id
|
||||
description = "Egress to Internet port TCP/80"
|
||||
destination = var.cidr_anywhere
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 80
|
||||
min = 80
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_rule_02" {
|
||||
network_security_group_id = oci_core_network_security_group.sip-servers-nsg.id
|
||||
description = "Egress to OSN"
|
||||
destination = lookup(data.oci_core_services.all_services.services[1], "cidr_block")
|
||||
destination_type = "SERVICE_CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 443
|
||||
min = 443
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_rule_03" {
|
||||
network_security_group_id = oci_core_network_security_group.sip-servers-nsg.id
|
||||
description = "Egress to Internet port TCP/443"
|
||||
destination = var.cidr_anywhere
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 443
|
||||
min = 443
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_rule_04" {
|
||||
network_security_group_id = oci_core_network_security_group.sip-servers-nsg.id
|
||||
description = "Egress MySQL to sn-database"
|
||||
destination = var.cidr_subnet_database
|
||||
@@ -65,22 +110,7 @@ resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_rule_02" {
|
||||
network_security_group_id = oci_core_network_security_group.sip-servers-nsg.id
|
||||
description = "Egress MySQL Heatware to sn-database"
|
||||
destination = var.cidr_subnet_database
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 33060
|
||||
min = 33060
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_rule_03" {
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_rule_05" {
|
||||
network_security_group_id = oci_core_network_security_group.sip-servers-nsg.id
|
||||
description = "Egress SOLR to sn-database"
|
||||
destination = var.cidr_subnet_app
|
||||
@@ -95,7 +125,7 @@ resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_rule_04" {
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_rule_06" {
|
||||
network_security_group_id = oci_core_network_security_group.sip-servers-nsg.id
|
||||
description = "Egress Memcached to sn-app"
|
||||
destination = var.cidr_subnet_app
|
||||
@@ -109,4 +139,21 @@ resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_sip-server_egress_rule_07" {
|
||||
network_security_group_id = oci_core_network_security_group.sip-servers-nsg.id
|
||||
description = "Egress MySQL Heatware to sn-database"
|
||||
destination = var.cidr_subnet_database
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 33060
|
||||
min = 33060
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
#--------------------------------------------------------------------------------------------------------------------------------------------
|
||||
@@ -33,6 +33,36 @@ resource "oci_core_network_security_group_security_rule" "nsg_solr-server_ingres
|
||||
}
|
||||
}
|
||||
}
|
||||
#--------------------------------------------------------------------------------------------------------------------------------------------
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_solr_servers_security_egress_rule_01" {
|
||||
network_security_group_id = oci_core_network_security_group.solr-server-nsg.id
|
||||
description = "Egress to OSN"
|
||||
destination = lookup(data.oci_core_services.all_services.services[1], "cidr_block")
|
||||
destination_type = "SERVICE_CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 443
|
||||
min = 443
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_solr_servers_security_egress_rule_02" {
|
||||
network_security_group_id = oci_core_network_security_group.solr-server-nsg.id
|
||||
description = "Egress to Internet only port TCP/443"
|
||||
destination = var.cidr_anywhere
|
||||
destination_type = "CIDR_BLOCK"
|
||||
direction = "EGRESS"
|
||||
protocol = "6"
|
||||
tcp_options {
|
||||
destination_port_range {
|
||||
max = 443
|
||||
min = 443
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "oci_core_network_security_group_security_rule" "nsg_solr_servers_security_egress_rule_03" {
|
||||
network_security_group_id = oci_core_network_security_group.solr-server-nsg.id
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
resource "oci_waf_web_app_firewall_policy" "sei-waf-policy" {
|
||||
count = var.var.enable_waf == "true" ? 1 : 0
|
||||
count = var.enable_waf == "true" ? 1 : 0
|
||||
compartment_id = var.ocid_compartment_networking
|
||||
display_name = "sei-waf-policy-${var.environment}-v01"
|
||||
actions {
|
||||
|
||||
@@ -28,8 +28,7 @@ resource "oci_core_instance" "memcached-instance" {
|
||||
|
||||
lifecycle {
|
||||
ignore_changes = [
|
||||
source_details [ "source_id" ],
|
||||
#metadata [ "user_data" ]
|
||||
source_details [ "source_id" ]
|
||||
]
|
||||
}
|
||||
}
|
||||
@@ -13,7 +13,7 @@ resource "oci_core_instance" "sei-instance" {
|
||||
create_vnic_details {
|
||||
subnet_id = var.ocid_subnet_app
|
||||
assign_public_ip = false
|
||||
nsg_ids = [ oci_core_network_security_group.sei-public-nsg.id]
|
||||
nsg_ids = [ oci_core_network_security_group.sei-servers-nsg.id ]
|
||||
}
|
||||
|
||||
source_details {
|
||||
@@ -28,8 +28,7 @@ resource "oci_core_instance" "sei-instance" {
|
||||
|
||||
lifecycle {
|
||||
ignore_changes = [
|
||||
source_details [ "source_id" ],
|
||||
#metadata [ "user_data" ]
|
||||
source_details [ "source_id" ]
|
||||
]
|
||||
}
|
||||
}
|
||||
@@ -28,8 +28,7 @@ resource "oci_core_instance" "sip-instance" {
|
||||
|
||||
lifecycle {
|
||||
ignore_changes = [
|
||||
source_details [ "source_id" ],
|
||||
#metadata [ "user_data" ]
|
||||
source_details [ "source_id" ]
|
||||
]
|
||||
}
|
||||
|
||||
|
||||
@@ -13,7 +13,7 @@ resource "oci_core_instance" "solr-instance" {
|
||||
create_vnic_details {
|
||||
subnet_id = var.ocid_subnet_app
|
||||
assign_public_ip = false
|
||||
nsg_ids = [ oci_core_network_security_group.solr-servers-nsg.id ]
|
||||
nsg_ids = [ oci_core_network_security_group.solr-server-nsg.id ]
|
||||
}
|
||||
|
||||
source_details {
|
||||
@@ -28,8 +28,7 @@ resource "oci_core_instance" "solr-instance" {
|
||||
|
||||
lifecycle {
|
||||
ignore_changes = [
|
||||
source_details [ "source_id" ],
|
||||
#metadata [ "user_data" ]
|
||||
source_details [ "source_id" ]
|
||||
]
|
||||
}
|
||||
}
|
||||
@@ -1,31 +1,31 @@
|
||||
#================================================================================================================================================================================================
|
||||
# Parameters to authenticate with Oracle Cloud Infrastructure
|
||||
tenancy_ocid = ""
|
||||
user_ocid = ""
|
||||
fingerprint = ""
|
||||
private_key_path = "/home/opc/.oci/terraform_key.pem"
|
||||
region = "sa-saopaulo-1"
|
||||
tenancy_ocid = "ocid1.tenancy.oc1..aaaaaaaacjlkusgiuurcxl3aun3cubeohplc73z4dmzkrfxr2utn4jcmhoua"
|
||||
user_ocid = "ocid1.user.oc1..aaaaaaaaa53ciz3hwz7hcy3elmwhshbgccip3escjrwfv7gj2epckfgi4ria"
|
||||
fingerprint = "85:12:60:87:db:dd:c8:ca:69:98:22:93:6f:b0:22:2e"
|
||||
private_key_path = "/Users/guilherme.silva/data/ORACLE/ssh-keys/terraform-guilherme-silva.pem"
|
||||
region = "us-ashburn-1"
|
||||
|
||||
#================================================================================================================================================================================================
|
||||
# The environment that you're creating resources for: test, dev, prod, or staging
|
||||
environment="hml"
|
||||
#================================================================================================================================================================================================
|
||||
# The environment compartments
|
||||
ocid_compartment_app = ""
|
||||
ocid_compartment_database = ""
|
||||
ocid_compartment_security = ""
|
||||
ocid_compartment_networking = ""
|
||||
ocid_compartment_app = "ocid1.compartment.oc1..aaaaaaaamrvydbfbzcb3ys7dln2sl2giax43iuf6zi6uny3inhtu46ummv7a"
|
||||
ocid_compartment_database = "ocid1.compartment.oc1..aaaaaaaamrvydbfbzcb3ys7dln2sl2giax43iuf6zi6uny3inhtu46ummv7a"
|
||||
ocid_compartment_security = "ocid1.compartment.oc1..aaaaaaaamrvydbfbzcb3ys7dln2sl2giax43iuf6zi6uny3inhtu46ummv7a"
|
||||
ocid_compartment_networking = "ocid1.compartment.oc1..aaaaaaaamrvydbfbzcb3ys7dln2sl2giax43iuf6zi6uny3inhtu46ummv7a"
|
||||
#================================================================================================================================================================================================
|
||||
# The environment networks
|
||||
ocid_vcn_3_tier = ""
|
||||
ocid_subnet_app = ""
|
||||
ocid_subnet_database = ""
|
||||
ocid_subnet_public = ""
|
||||
ocid_vcn_3_tier = "ocid1.vcn.oc1.iad.amaaaaaa6g6dsryau6nt4gzyxxyfk7p5lqfw7hpeb6mwcbyx6ajaofcr777a"
|
||||
ocid_subnet_app = "ocid1.subnet.oc1.iad.aaaaaaaa2k4ptjjqoondfuyhr26llwzdj6apmml2fu63ar4kpglnshq6cj5a"
|
||||
ocid_subnet_database = "ocid1.subnet.oc1.iad.aaaaaaaa2k4ptjjqoondfuyhr26llwzdj6apmml2fu63ar4kpglnshq6cj5a"
|
||||
ocid_subnet_public = "ocid1.subnet.oc1.iad.aaaaaaaavq5dwjkkdiwqtrbz24thcsrng22bnj5swd2jaaxfuxrmmi4wfipq"
|
||||
#================================================================================================================================================================================================
|
||||
# The CIDR networks
|
||||
cidr_subnet_app = "172.20.2.64/26"
|
||||
cidr_subnet_database = "172.20.2.128/26"
|
||||
cidr_subnet_web = "172.20.2.0/26"
|
||||
cidr_subnet_app = "10.0.0.128/25"
|
||||
cidr_subnet_database = "10.0.0.128/25"
|
||||
cidr_subnet_web = "10.0.0.0/25"
|
||||
cidr_anywhere = "0.0.0.0/0"
|
||||
#================================================================================================================================================================================================
|
||||
# SEI Variables
|
||||
@@ -57,14 +57,14 @@ solr_fqdn = ""
|
||||
memcached_amount_instances = "1"
|
||||
memcached_prefix_hostname = "memcached-server"
|
||||
memcached_shape = "VM.Standard.E4.Flex"
|
||||
memcached_amount_memory = "2"
|
||||
memcached_amount_memory = "4"
|
||||
memcached_amount_ocpus = "1"
|
||||
#================================================================================================================================================================================================
|
||||
# JodServer Variables
|
||||
jod_amount_instances = "1"
|
||||
jod_prefix_hostname = "jod-server"
|
||||
jod_shape = "VM.Standard.E4.Flex"
|
||||
jod_amount_memory = "2"
|
||||
jod_amount_memory = "4"
|
||||
jod_amount_ocpus = "1"
|
||||
#================================================================================================================================================================================================
|
||||
# Public Load Balancer Variables
|
||||
|
||||
@@ -1,15 +0,0 @@
|
||||
# Copyright (c) 2023, 2025, Oracle and/or its affiliates.
|
||||
# Licensed under the Universal Permissive License v 1.0 as shown at https://oss.oracle.com/licenses/upl/
|
||||
|
||||
# ------------------------------------------------------
|
||||
variable "sei_nfs_name" {
|
||||
type = string
|
||||
default = "nfs-sei"
|
||||
description = "Nome do FSS para o SEI"
|
||||
}
|
||||
|
||||
variable "sei_mount_target_ip_address" {
|
||||
type = string
|
||||
default = "10.191.228.100"
|
||||
description = "IP Address para o mount target"
|
||||
}
|
||||
Reference in New Issue
Block a user