Skip to content

Commit

Permalink
Add support for shared VPC in central project (closes #23)
Browse files Browse the repository at this point in the history
  • Loading branch information
micksatana authored and jbeemster committed Jun 3, 2024
1 parent d949e30 commit 5db75fe
Show file tree
Hide file tree
Showing 3 changed files with 13 additions and 3 deletions.
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -137,6 +137,7 @@ module "iglu_lb" {
| <a name="input_java_opts"></a> [java\_opts](#input\_java\_opts) | Custom JAVA Options | `string` | `"-XX:InitialRAMPercentage=75 -XX:MaxRAMPercentage=75"` | no |
| <a name="input_labels"></a> [labels](#input\_labels) | The labels to append to this resource | `map(string)` | `{}` | no |
| <a name="input_machine_type"></a> [machine\_type](#input\_machine\_type) | The machine type to use | `string` | `"e2-small"` | no |
| <a name="input_network_project_id"></a> [network\_project\_id](#input\_network\_project\_id) | The project ID of the shared VPC in which the stack is being deployed | `string` | `""` | no |
| <a name="input_patches_allowed"></a> [patches\_allowed](#input\_patches\_allowed) | Whether or not patches are allowed for published Iglu Schemas | `bool` | `true` | no |
| <a name="input_ssh_block_project_keys"></a> [ssh\_block\_project\_keys](#input\_ssh\_block\_project\_keys) | Whether to block project wide SSH keys | `bool` | `true` | no |
| <a name="input_ssh_ip_allowlist"></a> [ssh\_ip\_allowlist](#input\_ssh\_ip\_allowlist) | The list of CIDR ranges to allow SSH traffic from | `list(any)` | <pre>[<br> "0.0.0.0/0"<br>]</pre> | no |
Expand Down
9 changes: 6 additions & 3 deletions main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,8 @@ resource "google_project_iam_member" "sa_cloud_sql_client" {
# --- CE: Firewall rules

resource "google_compute_firewall" "ingress_ssh" {
name = "${var.name}-ssh-in"
project = (var.network_project_id != "") ? var.network_project_id : var.project_id
name = "${var.name}-ssh-in"

network = var.network
target_tags = [var.name]
Expand All @@ -76,7 +77,8 @@ resource "google_compute_firewall" "ingress_ssh" {
#
# https://cloud.google.com/load-balancing/docs/health-check-concepts#ip-ranges
resource "google_compute_firewall" "ingress" {
name = "${var.name}-traffic-in"
project = (var.network_project_id != "") ? var.network_project_id : var.project_id
name = "${var.name}-traffic-in"

network = var.network
target_tags = [var.name]
Expand All @@ -90,7 +92,8 @@ resource "google_compute_firewall" "ingress" {
}

resource "google_compute_firewall" "egress" {
name = "${var.name}-traffic-out"
project = (var.network_project_id != "") ? var.network_project_id : var.project_id
name = "${var.name}-traffic-out"

network = var.network
target_tags = [var.name]
Expand Down
6 changes: 6 additions & 0 deletions variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,12 @@ variable "project_id" {
type = string
}

variable "network_project_id" {
description = "The project ID of the shared VPC in which the stack is being deployed"
type = string
default = ""
}

variable "region" {
description = "The name of the region to deploy within"
type = string
Expand Down

0 comments on commit 5db75fe

Please sign in to comment.