You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+12-3Lines changed: 12 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -68,11 +68,12 @@ module "network" {
68
68
| create\_dbsubgroup\_private | Create Private Subgroup |`bool`|`false`| no |
69
69
| create\_dbsubgroup\_public | Create Public Subgroup |`bool`|`false`| no |
70
70
| create\_dbsubgroup\_secure | Create Secure Subgroup |`bool`|`true`| no |
71
+
| db\_subnet\_group\_secure\_name\_compat | Use previous DB subnet group name (<name>-dbsubnet) for backwards compability (secure only) |`bool`|`false`| no |
71
72
| eip\_allocation\_ids | User-specified primary or secondary private IP address to associate with the Elastic IP address |`list(string)`|`[]`| no |
72
73
| enable\_firewall\_default\_rule | Enable or disable the default stateful rule. |`bool`|`true`| no |
73
74
| firewall\_custom\_rule\_arn | The stateful rule group arn created outside the module |`list(string)`|`[]`| no |
74
75
| firewall\_custom\_rules | The stateful rule group rules specifications in Suricata file format, with one rule per line |`list(string)`|`[]`| no |
75
-
| firewall\_domain\_list | List the domain names you want to take action on. |`list(any)`| <pre>[<br> ".amazonaws.com",<br> ".github.com"<br>]</pre> | no |
76
+
| firewall\_domain\_list | List the domain names you want to take action on. |`list(any)`| <pre>[<br> ".amazonaws.com",<br> ".github.com"<br>]</pre> | no |
76
77
| firewall\_netnum\_offset | Start with this subnet for secure ones, plus number of AZs |`number`|`14`| no |
77
78
| kms\_key\_arn | The ARN of the KMS Key to use when encrypting log data. |`string`|`""`| no |
78
79
| kubernetes\_clusters | List of kubernetes cluster names to creates tags in public and private subnets of this VPC |`list(string)`|`[]`| no |
@@ -93,6 +94,7 @@ module "network" {
93
94
| public\_nacl\_outbound\_tcp\_ports | TCP Ports to allow outbound to external services (use [0] to allow all ports) |`list(string)`| <pre>[<br> "0"<br>]</pre> | no |
94
95
| public\_nacl\_outbound\_udp\_ports | UDP Ports to allow outbound to external services (use [0] to allow all ports) |`list(string)`| <pre>[<br> "0"<br>]</pre> | no |
95
96
| public\_netnum\_offset | Start with this subnet for public ones, plus number of AZs |`number`|`0`| no |
97
+
| secure\_nacl\_allow\_public | Allow traffic between public and secure |`bool`|`false`| no |
96
98
| secure\_netnum\_offset | Start with this subnet for secure ones, plus number of AZs |`number`|`10`| no |
97
99
| tags | Extra tags to attach to resources |`map(string)`|`{}`| no |
98
100
| transit\_nacl\_inbound\_tcp\_ports | TCP Ports to allow inbound on transit subnet via NACLs (this list cannot be empty) |`list(string)`| <pre>[<br> "1194"<br>]</pre> | no |
@@ -103,8 +105,15 @@ module "network" {
103
105
| vpc\_cidr\_summ | Define cidr used to summarize subnets by tier |`string`|`"/0"`| no |
104
106
| vpc\_endpoint\_dynamodb\_gateway | Enable or disable VPC Endpoint for DynamoDB (Gateway) |`bool`|`true`| no |
105
107
| vpc\_endpoint\_s3\_gateway | Enable or disable VPC Endpoint for S3 Gateway |`bool`|`true`| no |
106
-
| vpc\_endpoint\_s3\_policy | A policy to attach to the endpoint that controls access to the service |`string`|<pre>{ "Statement": <br> [<br> {<br> "Action": <br> "\*\",<br> "Effect\": <br> "Allow\",<br> "Resource\":<br> "\*\",<br> "Principal\":<br> \"*\" <br> } <br> ] <br>}</pre> | no |
107
-
| vpc\_endpoints | AWS services to create a VPC endpoint on private subnets for (e.g: ssm, ec2, ecr.dkr) |<pre>list(object(<br>{<br>name = string<br>policy = <br> optional(string)<br>allowed_cidrs =<br> optional(list<br> (string))<br>}<br>))</pre> |`[]`| no |
108
+
| vpc\_endpoint\_s3\_policy | A policy to attach to the endpoint that controls access to the service | `string` | `" {
0 commit comments