Repository navigation
Expand file tree
/
Copy pathvariables.tf
More file actions
130 lines (114 loc) · 3.77 KB
/
Copy pathvariables.tf
File metadata and controls
130 lines (114 loc) · 3.77 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
variable "bucket_name" {
description = "The name to use for the encrypted S3 bucket."
type = string
}
variable "source_policy_document" {
description = "A source policy for the bucket, additional statements to enable encryption will be added to the policy."
type = string
default = ""
}
variable "acl" {
description = "The canned ACL to apply. Defaults to \"private\"."
type = string
default = "private"
}
variable "tags" {
description = "A map of additional tags to set on the bucket."
type = map(string)
default = {}
}
variable "kms_key_arn" {
description = "If provided, \"aws:kms\" encryption will be enforced using the KMS key with the provided ARN. By default, \"AES-256\" encryption is used."
type = string
default = ""
}
variable "access_log_bucket_name" {
description = "The name of the bucket to use for access logging, required when enable_access_logging is \"yes\"."
type = string
default = ""
}
variable "access_log_object_key_prefix" {
description = "The key prefix to use for log objects for access logging. Defaults to \"\"."
type = string
default = ""
}
variable "public_access_block" {
description = "If provided, will configure block public access settings for the bucket."
type = object({
block_public_acls = bool
block_public_policy = bool
ignore_public_acls = bool
restrict_public_buckets = bool
})
default = {
block_public_acls = false
block_public_policy = false
ignore_public_acls = false
restrict_public_buckets = false
}
}
variable "include_deny_unencrypted_inflight_operations_statement" {
description = "Whether or not to include a bucket policy statement to deny unencrypted inflight operations. Defaults to `true`."
type = bool
default = true
}
variable "include_deny_encryption_using_incorrect_algorithm_statement" {
description = "Whether or not to include a bucket policy statement to deny encryption using the incorrect algorithm. Defaults to `true`."
type = bool
default = true
}
variable "include_deny_encryption_using_incorrect_key_statement" {
description = "Whether or not to include a bucket policy statement to deny encryption using the incorrect key. Defaults to `true`."
type = bool
default = true
}
variable "enable_mfa_delete" {
description = "Whether or not to enable MFA delete on the bucket. Defaults to `false`."
type = bool
default = false
}
variable "enable_versioning" {
description = "Whether or not to enable versioning on the bucket. Defaults to `true`."
type = bool
default = true
}
variable "enable_access_logging" {
description = "Whether or not to enable access logging on the bucket. Defaults to `false`."
type = bool
default = false
}
variable "enable_bucket_key" {
description = "Whether or not to use an Amazon S3 Bucket Key for SSE-KMS. Defaults to `false`."
type = bool
default = false
}
variable "enable_object_lock" {
description = "Whether or not to enable object lock on the bucket. Defaults to `false`."
type = bool
default = false
}
variable "allow_destroy_when_objects_present" {
description = "Whether or not to allow the bucket to be destroyed if it still contains objects. Defaults to `false`."
type = bool
default = false
}
variable "object_lock_configuration" {
description = "If provided, will configure object lock configuration rule for the bucket."
type = object({
mode = string
days = number
years = number
})
default = null
}
variable "cors_rules" {
description = "If provided, will create a cors rule configuration with the given rules."
type = list(object({
allowed_methods = list(string)
allowed_origins = list(string)
allowed_headers = optional(list(string))
expose_headers = optional(list(string))
max_age_seconds = optional(number)
}))
default = null
}