Skip to content

CloudNationHQ/terraform-azure-sa

Repository files navigation

Storage Account

This terraform module simplifies the process of creating and managing storage accounts on azure with customizable options and features, offering a flexible and powerful solution for managing azure storage through code.

Goals

The main objective is to create a more logic data structure, achieved by combining and grouping related resources together in a complex object.

The structure of the module promotes reusability. It's intended to be a repeatable component, simplifying the process of building diverse workloads and platform accelerators consistently.

A primary goal is to utilize keys and values in the object that correspond to the REST API's structure. This enables us to carry out iterations, increasing its practical value as time goes on.

A last key goal is to separate logic from configuration in the module, thereby enhancing its scalability, ease of customization, and manageability.

Features

  • offers support for shares, tables, containers, and queues.
  • employs management policies using a variety of rules.
  • provides advanced threat protection capabilities.
  • utilization of terratest for robust validation.
  • facilitates cors to securely control access to assets across different domains.
  • supports optional active directory authentication for enhanced security in azure file shares.
  • integrates seamlessly with private endpoint capabilities for direct and secure connectivity.

Requirements

Name Version
terraform ~> 1.0
azurerm ~> 3.61

Providers

Name Version
azurerm ~> 3.61

Resources

Name Type
azurerm_storage_account resource
azurerm_storage_container resource
azurerm_storage_queue resource
azurerm_storage_share resource
azurerm_storage_table resource
azurerm_storage_management_policy resource
azurerm_advanced_threat_protection resource
azurerm_subscription data source
azurerm_user_assigned_identity resource
azurerm_role_assignment resource

Inputs

Name Description Type Required
storage describes storage related configuration object yes
naming contains naming convention string yes

Outputs

Name Description
account storage account details
subscriptionId contains the current subscription id
containers container configuration specifics
shares shares configuration specifics
queues queues configuration specifics
tables table configuration specifics

Testing

As a prerequirement, please ensure that both go and terraform are properly installed on your system.

The Makefile includes two distinct variations of tests. The first one is designed to deploy different usage scenarios of the module. These tests are executed by specifying the TF_PATH environment variable, which determines the different usages located in the example directory.

To execute this test, input the command make test TF_PATH=default, substituting default with the specific usage you wish to test.

The second variation is known as a extended test. This one performs additional checks and can be executed without specifying any parameters, using the command make test_extended.

Both are designed to be executed locally and are also integrated into the github workflow.

Each of these tests contributes to the robustness and resilience of the module. They ensure the module performs consistently and accurately under different scenarios and configurations.

Notes

Using a dedicated module, we've developed a naming convention for resources that's based on specific regular expressions for each type, ensuring correct abbreviations and offering flexibility with multiple prefixes and suffixes.

Full examples detailing all usages, along with integrations with dependency modules, are located in the examples directory.

To streamline integration with the enterprise scale module, private endpoints can also make use of existing zones.

Authors

Module is maintained by these awesome contributors.

License

MIT Licensed. See LICENSE for full details.

References