# # DMARC reports service: parsedmarc, OpenSearch and OpenSearch Dashboards on # one VM. # # Sizing and service ports belong to the service, so they have defaults here. # The address on the main private network does not: it is part of the address # plan of the project, and it is passed in by the caller. # variable "dmarc_reports_data" { description = "Instance, volume and ports of the DMARC reports service. m1.large is RAM 8 - VCPUs 4" type = object({ name = optional(string, "opensearch-dmarc") description = optional(string, "DMARC reports: parsedmarc, OpenSearch and OpenSearch Dashboards") flavor = optional(string, "m1.large") boot_vol_size = optional(number, 20) # OpenSearch data directory. SSD, as every volume that holds an index vol_data_name = optional(string, "opensearch-dmarc-data") vol_data_size = optional(number, 50) vol_data_device = optional(string, "/dev/vdb") volume_type = optional(string, "CephSSD") # OpenSearch Dashboards, the only port the load balancers reach. It # terminates TLS itself with the certificate of the internal CA service_ports = optional(list(number), [5601]) }) default = {} } # Part of the address plan of the project: no default on purpose variable "dmarc_reports_main_ip" { type = string description = "Address of the instance on the main private network" } # Data that comes from the network/DNS and project setup workspaces variable "main_private_network_id" { type = string description = "ID of the main private network of the project" } variable "main_private_subnet_id" { type = string description = "ID of the main private subnet of the project" } variable "default_security_group_id" { type = string description = "ID of the 'default_for_all' security group of the project" } variable "haproxy_l7_ip" { type = list(string) description = "Addresses of the L7 HAPROXY load balancers, the only ones allowed to reach the service" } variable "availability_zone" { type = string description = "Availability zone hint of the instance" } variable "image" { description = "Image of the instance: uuid and cloud-init user data file" type = object({ uuid = string user_data_file = string }) } variable "ssh_key_name" { type = string description = "Name of the SSH key pair injected by cloud-init" } # DNS. The A record on the main network address is always created; the public # name is a CNAME of the load balancer that publishes the service variable "dns_zone_id" { type = string description = "ID of the DNS zone of the project" } variable "dns_zone_name" { type = string description = "Name of the DNS zone of the project, with the trailing dot" } variable "dmarc_reports_public_name" { type = string default = "dmarc" description = "Left part of the public name, a CNAME of the load balancer. Empty means no record" } variable "dmarc_reports_cname_target" { type = string default = "" description = "Target of the CNAME, usually the name of the main load balancer, with the trailing dot" }