summaryrefslogtreecommitdiff
path: root/infrastructure/s3.tf
diff options
context:
space:
mode:
authorJoe Carstairs <65492573+joeacarstairs@users.noreply.github.com>2024-05-05 21:00:40 +0100
committerGitHub <noreply@github.com>2024-05-05 21:00:40 +0100
commit86450b3dd8bec3b76e2b2a03b8cdc8a708c5f3bc (patch)
tree7576d8863193369adc87dd80d91a3d5d3f58ede1 /infrastructure/s3.tf
parent579e12cfebce9a70ab2adf5842e2673673a707d2 (diff)
Infrastructure as code (#3)
* Moves website to website/ * Adds terraform gitignores * Terraform with AWS provider * Initialises Terraform * Locals and variables for provider * Fetches SSL certificate from ACM * S3 static website bucket * CloudFront distribution * Route53 records * Deployment workflow uses secret S3 bucket suffix * Adds README --------- Co-authored-by: Joe Carstairs <65492573+Sycamost@users.noreply.github.com>
Diffstat (limited to 'infrastructure/s3.tf')
-rw-r--r--infrastructure/s3.tf78
1 files changed, 78 insertions, 0 deletions
diff --git a/infrastructure/s3.tf b/infrastructure/s3.tf
new file mode 100644
index 0000000..7b116a7
--- /dev/null
+++ b/infrastructure/s3.tf
@@ -0,0 +1,78 @@
+resource "aws_s3_bucket" "website" {
+ bucket = local.bucket_name
+}
+
+locals {
+ bucket_name = "${local.domain}-${var.secret_s3_bucket_suffix}"
+}
+
+resource "aws_s3_bucket_website_configuration" "website" {
+ bucket = aws_s3_bucket.website.id
+
+ index_document {
+ suffix = "index.html"
+ }
+
+ error_document {
+ key = "error/index.html"
+ }
+}
+
+resource "aws_s3_bucket_ownership_controls" "website" {
+ bucket = aws_s3_bucket.website.id
+
+ rule {
+ object_ownership = "BucketOwnerPreferred"
+ }
+
+ depends_on = [aws_s3_bucket_public_access_block.website]
+}
+
+resource "aws_s3_bucket_public_access_block" "website" {
+ bucket = aws_s3_bucket.website.id
+
+ block_public_acls = false
+ block_public_policy = false
+ ignore_public_acls = false
+ restrict_public_buckets = false
+}
+
+resource "aws_s3_bucket_acl" "website" {
+ bucket = aws_s3_bucket.website.id
+
+ acl = "public-read"
+
+ depends_on = [aws_s3_bucket_ownership_controls.website]
+}
+
+resource "aws_s3_bucket_versioning" "website" {
+ bucket = aws_s3_bucket.website.id
+
+ versioning_configuration {
+ status = "Disabled"
+ }
+}
+
+resource "aws_s3_bucket_policy" "website" {
+ bucket = aws_s3_bucket.website.id
+ policy = data.aws_iam_policy_document.website.json
+}
+
+# TODO: can we restrict access to just from the CloudFront distro?
+data "aws_iam_policy_document" "website" {
+ statement {
+ sid = "AllowPublicRead"
+ effect = "Allow"
+ resources = [
+ "arn:aws:s3:::${local.bucket_name}",
+ "arn:aws:s3:::${local.bucket_name}/*",
+ ]
+ actions = ["S3:GetObject"]
+ principals {
+ type = "*"
+ identifiers = ["*"]
+ }
+ }
+
+ depends_on = [aws_s3_bucket_public_access_block.website, aws_s3_bucket.website]
+}