Skip to content

Commit 3fc76bc

Browse files
committed
correct the parking database module name and add the bucket and kms key arn to redshift module
1 parent 5583379 commit 3fc76bc

File tree

3 files changed

+24
-9
lines changed

3 files changed

+24
-9
lines changed

terraform/etl/42-redshift.tf

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,10 +10,12 @@ module "redshift" {
1010
refined_zone_bucket_arn = module.refined_zone_data_source.bucket_arn
1111
trusted_zone_bucket_arn = module.trusted_zone_data_source.bucket_arn
1212
raw_zone_bucket_arn = module.raw_zone_data_source.bucket_arn
13+
user_uploads_bucket_arn = module.user_uploads_data_source.bucket_arn
1314
landing_zone_kms_key_arn = module.landing_zone_data_source.kms_key_arn
1415
raw_zone_kms_key_arn = module.raw_zone_data_source.kms_key_arn
1516
refined_zone_kms_key_arn = module.refined_zone_data_source.kms_key_arn
1617
trusted_zone_kms_key_arn = module.trusted_zone_data_source.kms_key_arn
18+
user_uploads_kms_key_arn = module.user_uploads_data_source.kms_key_arn
1719
secrets_manager_key = data.aws_kms_key.secrets_manager_key.arn
1820
additional_iam_roles = local.is_production_environment ? [] : [aws_iam_role.parking_redshift_copier[0].arn]
1921
}
@@ -48,7 +50,7 @@ locals {
4850
replace(module.department_parking_data_source.refined_zone_catalog_database_name, "-", "_") = module.department_parking_data_source.refined_zone_catalog_database_name,
4951
replace(module.department_parking_data_source.trusted_zone_catalog_database_name, "-", "_") = module.department_parking_data_source.trusted_zone_catalog_database_name,
5052
replace("parking-ringgo-sftp-raw-zone", "-", "_") = "parking-ringgo-sftp-raw-zone",
51-
replace(aws_glue_catalog_database.parking_user_uploads.name, "-", "_") = aws_glue_catalog_database.parking_user_uploads.name,
53+
replace(aws_glue_catalog_database.department_user_uploads["parking"].name, "-", "_") = aws_glue_catalog_database.department_user_uploads["parking"].name,
5254

5355
replace(module.department_finance_data_source.raw_zone_catalog_database_name, "-", "_") = module.department_finance_data_source.raw_zone_catalog_database_name,
5456
replace(module.department_finance_data_source.refined_zone_catalog_database_name, "-", "_") = module.department_finance_data_source.refined_zone_catalog_database_name,
@@ -127,7 +129,7 @@ locals {
127129
"liberator_refined_zone",
128130
replace(module.department_parking_data_source.trusted_zone_catalog_database_name, "-", "_"),
129131
replace("parking-ringgo-sftp-raw-zone", "-", "_"),
130-
replace(aws_glue_catalog_database.parking_user_uploads.name, "-", "_"),
132+
replace(aws_glue_catalog_database.department_user_uploads["parking"].name, "-", "_"),
131133
], local.unrestricted_schemas)
132134
},
133135
{
@@ -311,7 +313,7 @@ locals {
311313
"liberator_refined_zone",
312314
replace(module.department_parking_data_source.trusted_zone_catalog_database_name, "-", "_"),
313315
replace("parking-ringgo-sftp-raw-zone", "-", "_"),
314-
replace(aws_glue_catalog_database.parking_user_uploads.name, "-", "_")
316+
replace(aws_glue_catalog_database.department_user_uploads["parking"].name, "-", "_")
315317
]
316318
roles_to_inherit_permissions_from = [
317319
local.unrestricted_data_role_name

terraform/modules/redshift/01-inputs-required.tf

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -62,3 +62,13 @@ variable "secrets_manager_key" {
6262
description = "ARN of secrets manager KMS key"
6363
type = string
6464
}
65+
66+
variable "user_uploads_bucket_arn" {
67+
description = "ARN of user uploads bucket"
68+
type = string
69+
}
70+
71+
variable "user_uploads_kms_key_arn" {
72+
description = "ARN of user uploads KMS key"
73+
type = string
74+
}

terraform/modules/redshift/10-redshift.tf

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,9 @@ data "aws_iam_policy_document" "redshift" {
3636
"${var.trusted_zone_bucket_arn}/*",
3737
var.trusted_zone_bucket_arn,
3838
"${var.raw_zone_bucket_arn}/*",
39-
var.raw_zone_bucket_arn
39+
var.raw_zone_bucket_arn,
40+
"${var.user_uploads_bucket_arn}/*",
41+
var.user_uploads_bucket_arn
4042
]
4143
}
4244
statement {
@@ -55,6 +57,7 @@ data "aws_iam_policy_document" "redshift" {
5557
var.raw_zone_kms_key_arn,
5658
var.refined_zone_kms_key_arn,
5759
var.trusted_zone_kms_key_arn,
60+
var.user_uploads_kms_key_arn,
5861
]
5962
}
6063
}
@@ -165,11 +168,11 @@ resource "aws_security_group" "redshift_cluster_security_group" {
165168
}
166169

167170
ingress {
168-
description = "Allows inbound traffic from the Qlik EC2 data gateway"
169-
from_port = 5439
170-
to_port = 5439
171-
protocol = "tcp"
172-
cidr_blocks = ["10.120.32.49/32"]
171+
description = "Allows inbound traffic from the Qlik EC2 data gateway"
172+
from_port = 5439
173+
to_port = 5439
174+
protocol = "tcp"
175+
cidr_blocks = ["10.120.32.49/32"]
173176
}
174177
ingress {
175178
description = "Allows security group based inbound traffic"

0 commit comments

Comments
 (0)