File tree Expand file tree Collapse file tree 3 files changed +53
-0
lines changed
Expand file tree Collapse file tree 3 files changed +53
-0
lines changed Original file line number Diff line number Diff line change @@ -7,3 +7,25 @@ resource "aws_security_group" "allow_sftp_egress" {
77 Name = " ${ local . csi } -sftp-egress"
88 }
99}
10+
11+ # trivy:ignore:aws-ec2-no-public-egress-sgr
12+ resource "aws_security_group_rule" "allow_sftp_egress_ssh" {
13+ description = " Allow SFTP egress within VPC on port 22"
14+ type = " egress"
15+ from_port = 22
16+ to_port = 22
17+ protocol = " tcp"
18+ cidr_blocks = [" 0.0.0.0/0" ]
19+ security_group_id = aws_security_group. allow_sftp_egress . id
20+ }
21+
22+ # trivy:ignore:aws-ec2-no-public-egress-sgr
23+ resource "aws_security_group_rule" "allow_sftp_egress_https" {
24+ description = " Allow SFTP egress within VPC on port 443"
25+ type = " egress"
26+ from_port = 443
27+ to_port = 443
28+ protocol = " tcp"
29+ cidr_blocks = [" 0.0.0.0/0" ]
30+ security_group_id = aws_security_group. allow_sftp_egress . id
31+ }
Original file line number Diff line number Diff line change 1+ data "aws_vpc" "account_vpc" {
2+ tags = {
3+ Component = " acct"
4+ }
5+ }
6+
7+ data "aws_subnets" "account_vpc_private_subnets" {
8+ filter {
9+ name = " vpc-id"
10+ values = [data . aws_vpc . account_vpc . id ]
11+ }
12+
13+ tags = {
14+ Tier = " Private"
15+ }
16+ }
17+
18+ data "aws_security_group" "account_vpc_sg_allow_sftp_egress" {
19+ vpc_id = data. aws_vpc . account_vpc . id
20+
21+ tags = {
22+ Name = " ${ data . aws_vpc . account_vpc . tags [" Project" ]} -${ data . aws_vpc . account_vpc . tags [" Environment" ]} -acct-vpc-sftp-egress"
23+ }
24+ }
Original file line number Diff line number Diff line change @@ -32,6 +32,13 @@ module "lambda_send_letter_proof" {
3232 maximum_concurrency = 5
3333 }
3434 }
35+
36+ vpc = {
37+ id = data.aws_vpc.account_vpc.id
38+ cidr_block = data.aws_vpc.account_vpc.cidr_block
39+ subnet_ids = data.aws_subnets.account_vpc_private_subnets
40+ security_group_ids = [aws_security_group.aws_security_group.account_vpc_sg_allow_sftp_egress.id]
41+ }
3542}
3643
3744data "aws_iam_policy_document" "send_letter_proof" {
You can’t perform that action at this time.
0 commit comments