Merge pull request #4918 from JacobValdemar/patch-1

Contribute terraform file for S3 storage in Techdocs
This commit is contained in:
Patrik Oldsberg
2021-04-27 10:30:43 +02:00
committed by GitHub
3 changed files with 86 additions and 1 deletions
@@ -0,0 +1 @@
This terraform file should create a S3 bucket and setup IAM with a user with an inline policy which gives the user access to the bucket. After you have created the bucket, user and policy you should go to the user in the AWS console and create an access key. This access key should be used as the env variables in step 3a [here](https://backstage.io/docs/features/techdocs/using-cloud-storage#configuring-aws-s3-bucket-with-techdocs).
@@ -0,0 +1,81 @@
#==========================
# Variables
#==========================
variable "backstage-bucket" {
default = "backstage_bucket_for_my_corp"
}
variable "backstage-iam" {
default = "backstage"
}
variable "shared-managed-tag-value" {
default = "terraform_for_my_corp"
}
#==========================
# Bucket
#==========================
resource "aws_s3_bucket" "backstage" {
bucket = var.backstage-bucket
acl = "private"
provider = aws
lifecycle {
prevent_destroy = true
}
server_side_encryption_configuration {
rule {
apply_server_side_encryption_by_default {
sse_algorithm = "AES256"
}
}
}
tags = {
Name = var.backstage-bucket
"Managed By Terraform" = var.shared-managed-tag-value
}
}
resource "aws_s3_bucket_public_access_block" "backstage" {
bucket = aws_s3_bucket.backstage.id
block_public_acls = true
block_public_policy = true
ignore_public_acls = true
restrict_public_buckets = true
}
#==========================
# IAM
#==========================
resource "aws_iam_user" "backstage" {
name = var.backstage-iam
}
resource "aws_iam_user_policy" "backstage" {
name = var.backstage-iam
user = aws_iam_user.backstage.name
policy = data.aws_iam_policy_document.backstage-policy.json
}
data "aws_iam_policy_document" "backstage-policy" {
statement {
actions = [
"s3:PutObject",
"s3:GetObject",
"s3:ListBucket"
]
effect = "Allow"
resources = [
"${aws_s3_bucket.backstage.arn}",
"${aws_s3_bucket.backstage.arn}/*",
]
}
}