/
main.tf
51 lines (46 loc) · 3.08 KB
/
main.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
resource "azurerm_resource_group" "nsg" {
name = "${var.resource_group_name}"
location = "${var.location}"
}
resource "azurerm_network_security_group" "nsg" {
name = "${var.security_group_name}"
location = "${var.location}"
resource_group_name = "${azurerm_resource_group.nsg.name}"
tags = "${var.tags}"
}
#############################
# Simple security rules #
#############################
resource "azurerm_network_security_rule" "predefined_rules" {
count = "${length(var.predefined_rules)}"
name = "${lookup(var.predefined_rules[count.index], "name")}"
priority = "${lookup(var.predefined_rules[count.index], "priority", "${4096 - length(var.predefined_rules) + count.index }" )}"
direction = "${element(var.rules["${lookup(var.predefined_rules[count.index], "name")}"], 0)}"
access = "${element(var.rules["${lookup(var.predefined_rules[count.index], "name")}"], 1)}"
protocol = "${element(var.rules["${lookup(var.predefined_rules[count.index], "name")}"], 2)}"
source_port_range = "${var.source_port_range}"
destination_port_range = "${element(var.rules["${lookup(var.predefined_rules[count.index], "name")}"], 4)}"
description = "${element(var.rules["${lookup(var.predefined_rules[count.index], "name")}"], 5)}"
source_address_prefix = "${join(",", var.source_address_prefix)}"
destination_address_prefix = "${join(",", var.destination_address_prefix)}"
resource_group_name = "${azurerm_resource_group.nsg.name}"
network_security_group_name = "${azurerm_network_security_group.nsg.name}"
}
#############################
# Detailed security rules #
#############################
resource "azurerm_network_security_rule" "custom_rules" {
count = "${length(var.custom_rules)}"
name = "${lookup(var.custom_rules[count.index], "name", "default_rule_name")}"
priority = "${lookup(var.custom_rules[count.index], "priority")}"
direction = "${lookup(var.custom_rules[count.index], "direction", "Any")}"
access = "${lookup(var.custom_rules[count.index], "access", "Allow")}"
protocol = "${lookup(var.custom_rules[count.index], "protocol", "*")}"
source_port_range = "${var.source_port_range}"
destination_port_range = "${lookup(var.custom_rules[count.index], "destination_port_range", "*")}"
source_address_prefix = "${lookup(var.custom_rules[count.index], "source_address_prefix", "*")}"
destination_address_prefix = "${lookup(var.custom_rules[count.index], "destination_address_prefix", "*")}"
description = "${lookup(var.custom_rules[count.index], "description", "Security rule for ${lookup(var.custom_rules[count.index], "name", "default_rule_name")}")}"
resource_group_name = "${azurerm_resource_group.nsg.name}"
network_security_group_name = "${azurerm_network_security_group.nsg.name}"
}