
244 lines
7.0 KiB
Raw Normal View History

2023-01-16 23:49:04 -08:00
# Copyright 2022 Google LLC
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# See the License for the specific language governing permissions and
# limitations under the License.
# tfdoc:file:description Folder resources.
variable "access_policy" {
description = "Access Policy name, set to null if creating one."
type = string
variable "access_policy_create" {
description = "Access Policy configuration, fill in to create. Parent is in 'organizations/123456' format."
type = object({
parent = string
title = string
2023-01-18 06:50:49 -08:00
scopes = optional(list(string))
2023-01-16 23:49:04 -08:00
default = null
2023-01-20 16:08:51 -08:00
variable "bootstrap_service_account" {
description = "Folder bootstrap service account: owner of the folder."
type = string
2023-01-16 23:49:04 -08:00
variable "data_dir" {
description = "Relative path for the folder storing configuration data."
type = string
default = "data"
2023-01-25 03:32:10 -08:00
variable "enable_features" {
description = "Flag to enable features on the solution."
type = object({
kms = bool
log_sink = bool
default = {
kms = true
log_sink = true
2023-01-16 23:49:04 -08:00
variable "folder_create" {
2023-01-25 03:32:10 -08:00
description = "Provide values if folder creation is needed, uses existing folder if null. Parent is in 'folders/nnn' or 'organizations/nnn' format."
2023-01-16 23:49:04 -08:00
type = object({
display_name = string
parent = string
default = null
variable "folder_id" {
description = "Folder ID in case you use folder_create=null."
type = string
default = null
variable "groups" {
description = "User groups."
type = map(string)
default = {
#TODO data-analysts = "gcp-data-analysts"
data-engineers = "gcp-data-engineers"
2023-01-20 16:08:51 -08:00
data-security = "gcp-data-security"
2023-01-16 23:49:04 -08:00
2023-01-20 16:08:51 -08:00
variable "kms_keys" {
description = "KMS keys to create, keyed by name."
type = map(object({
iam = optional(map(list(string)), {})
labels = optional(map(string), {})
locations = optional(list(string), ["global", "europe", "europe-west1"])
rotation_period = optional(string, "7776000s")
default = {}
variable "log_locations" {
description = "Optional locations for GCS, BigQuery, and logging buckets created here."
type = object({
bq = optional(string, "europe")
2023-01-25 09:22:43 -08:00
storage = optional(string, "europe")
2023-01-20 16:08:51 -08:00
logging = optional(string, "global")
2023-01-25 03:32:10 -08:00
pubsub = optional(string, "global")
2023-01-20 16:08:51 -08:00
default = {
bq = "europe"
2023-01-25 09:22:43 -08:00
storage = "europe"
2023-01-20 16:08:51 -08:00
logging = "global"
2023-01-25 09:22:43 -08:00
pubsub = null
2023-01-20 16:08:51 -08:00
nullable = false
variable "log_sinks" {
description = "Org-level log sinks, in name => {type, filter} format."
type = map(object({
filter = string
type = string
default = {
audit-logs = {
filter = "logName:\"/logs/\" OR logName:\"/logs/\""
type = "bigquery"
vpc-sc = {
filter = "protoPayload.metadata.@type=\"\""
type = "bigquery"
validation {
condition = alltrue([
for k, v in var.log_sinks :
contains(["bigquery", "logging", "pubsub", "storage"], v.type)
error_message = "Type must be one of 'bigquery', 'logging', 'pubsub', 'storage'."
variable "organization" {
description = "Organization details."
type = object({
domain = string
variable "prefix" {
description = "Prefix used for resources that need unique names. Use 9 characters or less."
2023-01-16 23:49:04 -08:00
type = string
2023-01-20 16:08:51 -08:00
validation {
condition = try(length(var.prefix), 0) < 10
error_message = "Use a maximum of 9 characters for prefix."
variable "projects_create" {
description = "Provide values if projects creation is needed, uses existing project if null. Projects will be created in the shielded folder."
type = object({
billing_account_id = string
default = null
variable "projects_id" {
description = "Project id, references existing project if `project_create` is null. Projects will be moved into the shielded folder."
type = map(string)
default = null
2023-01-16 23:49:04 -08:00
variable "vpc_sc_access_levels" {
description = "VPC SC access level definitions."
type = map(object({
combining_function = optional(string)
conditions = optional(list(object({
device_policy = optional(object({
allowed_device_management_levels = optional(list(string))
allowed_encryption_statuses = optional(list(string))
require_admin_approval = bool
require_corp_owned = bool
require_screen_lock = optional(bool)
os_constraints = optional(list(object({
os_type = string
minimum_version = optional(string)
require_verified_chrome_os = optional(bool)
ip_subnetworks = optional(list(string), [])
members = optional(list(string), [])
negate = optional(bool)
regions = optional(list(string), [])
required_access_levels = optional(list(string), [])
})), [])
description = optional(string)
default = {}
nullable = false
variable "vpc_sc_egress_policies" {
description = "VPC SC egress policy defnitions."
type = map(object({
from = object({
identity_type = optional(string, "ANY_IDENTITY")
identities = optional(list(string))
to = object({
operations = optional(list(object({
method_selectors = optional(list(string))
service_name = string
})), [])
resources = optional(list(string))
resource_type_external = optional(bool, false)
default = {}
nullable = false
variable "vpc_sc_ingress_policies" {
description = "VPC SC ingress policy defnitions."
type = map(object({
from = object({
access_levels = optional(list(string), [])
identity_type = optional(string)
identities = optional(list(string))
resources = optional(list(string), [])
to = object({
operations = optional(list(object({
method_selectors = optional(list(string))
service_name = string
})), [])
resources = optional(list(string))
default = {}
nullable = false
variable "vpc_sc_perimeters" {
description = "VPC SC regular perimeter definitions for shielded folder. All projects in the perimeter will be added."
type = object({
access_levels = optional(list(string), [])
egress_policies = optional(list(string), [])
ingress_policies = optional(list(string), [])
default = {}
nullable = false