diff --git a/services/terraform/self-host/.gitignore b/services/terraform/self-host/.gitignore --- a/services/terraform/self-host/.gitignore +++ b/services/terraform/self-host/.gitignore @@ -1,3 +1,5 @@ +.env + # Local .terraform directories **/.terraform/* diff --git a/services/terraform/self-host/aws_db.tf b/services/terraform/self-host/aws_db.tf --- a/services/terraform/self-host/aws_db.tf +++ b/services/terraform/self-host/aws_db.tf @@ -1,20 +1,27 @@ +locals { + mariadb_database_name = local.local_with_default_environment_vars.COMM_DATABASE_DATABASE + mariadb_username = local.local_with_default_environment_vars.COMM_DATABASE_USER + mariadb_password = local.local_with_default_environment_vars.COMM_DATABASE_PASSWORD + mariadb_port = jsondecode(local.local_with_default_environment_vars.COMM_DATABASE_PORT) +} + # MariaDB Security Group resource "aws_security_group" "keyserver_mariadb_security_group" { name = "keyserver-mariadb-sg" - description = "Allow inbound traffic on port 3307 and all outbound traffic" + description = "Allow inbound traffic on mariadb port and all outbound traffic" vpc_id = local.vpc_id # Inbound rules ingress { - from_port = 3307 - to_port = 3307 + from_port = local.mariadb_port + to_port = local.mariadb_port protocol = "tcp" security_groups = [aws_security_group.keyserver_service.id] } ingress { - from_port = 3307 - to_port = 3307 + from_port = local.mariadb_port + to_port = local.mariadb_port protocol = "tcp" cidr_blocks = ["${var.allowed_ip}/32"] } @@ -40,12 +47,12 @@ instance_class = "db.m6g.large" db_subnet_group_name = aws_db_subnet_group.public_db_subnet_group.name vpc_security_group_ids = [aws_security_group.keyserver_mariadb_security_group.id] - username = var.mariadb_username - password = var.mariadb_password + username = local.mariadb_username + password = local.mariadb_password parameter_group_name = aws_db_parameter_group.mariadb_parameter_group.name storage_encrypted = true publicly_accessible = true - port = 3307 + port = local.mariadb_port skip_final_snapshot = true } @@ -103,11 +110,11 @@ provisioner "local-exec" { command = <