diff options
| author | Joe Carstairs <65492573+joeacarstairs@users.noreply.github.com> | 2024-05-05 21:00:40 +0100 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2024-05-05 21:00:40 +0100 |
| commit | 86450b3dd8bec3b76e2b2a03b8cdc8a708c5f3bc (patch) | |
| tree | 7576d8863193369adc87dd80d91a3d5d3f58ede1 /infrastructure/variables.tf | |
| parent | 579e12cfebce9a70ab2adf5842e2673673a707d2 (diff) | |
Infrastructure as code (#3)
* Moves website to website/
* Adds terraform gitignores
* Terraform with AWS provider
* Initialises Terraform
* Locals and variables for provider
* Fetches SSL certificate from ACM
* S3 static website bucket
* CloudFront distribution
* Route53 records
* Deployment workflow uses secret S3 bucket suffix
* Adds README
---------
Co-authored-by: Joe Carstairs <65492573+Sycamost@users.noreply.github.com>
Diffstat (limited to 'infrastructure/variables.tf')
| -rw-r--r-- | infrastructure/variables.tf | 28 |
1 files changed, 28 insertions, 0 deletions
diff --git a/infrastructure/variables.tf b/infrastructure/variables.tf new file mode 100644 index 0000000..224ada4 --- /dev/null +++ b/infrastructure/variables.tf @@ -0,0 +1,28 @@ +variable "aws_access_key" { + type = string + sensitive = true + description = "An AWS access key with permission to provision all relevant resources" +} + +variable "aws_secret_key" { + type = string + sensitive = true + description = "The secret corresponding to the provided AWS access key" +} + +variable "secret_s3_bucket_suffix" { + type = string + sensitive = true + description = "This string should be a long string of up to 54 random characters. It will be appended to the S3 bucket name to mitigate the risk of DDoS attacks." + nullable = false + + validation { + condition = length(var.secret_s3_bucket_suffix) > 12 + error_message = "This string should be at least 12 characters" + } + + validation { + condition = length(var.secret_s3_bucket_suffix) <= 54 + error_message = "This string should be no more than 54 characters long" + } +} |
