Skip to content

Commit 6303fa2

Browse files
authored
Merge pull request #56 from worldcoin/mtls-variable
fix(mTLS): add variable mtls_enabled to module eks
2 parents f61226c + 2a9653f commit 6303fa2

File tree

2 files changed

+9
-1
lines changed

2 files changed

+9
-1
lines changed

kubernetes-traefik-external.tf

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -118,6 +118,8 @@ module "alb" {
118118
drop_invalid_header_fields = var.drop_invalid_header_fields
119119
acm_extra_arns = var.acm_extra_arns
120120

121-
mtls_enabled = !var.open_to_all
121+
# if open_to_all is true, mtls_enabled must be false
122+
# if open_to_all is false, mtls_enabled can be true or false based on var.mtls_enabled
123+
mtls_enabled = var.open_to_all ? false : var.mtls_enabled
122124
mtls_s3_bucket = format("wld-mtls-ca-%s", var.region)
123125
}

variables.tf

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -723,3 +723,9 @@ variable "on_demand_percentage_above_base_capacity" {
723723
type = number
724724
default = 50
725725
}
726+
727+
variable "mtls_enabled" {
728+
description = "Enable mutual TLS (mTLS) on the ALB TLS listener"
729+
type = bool
730+
default = true
731+
}

0 commit comments

Comments
 (0)