diff --git a/modules/transit_gateway/README.md b/modules/transit_gateway/README.md index f5002687..92720e48 100644 --- a/modules/transit_gateway/README.md +++ b/modules/transit_gateway/README.md @@ -54,6 +54,7 @@ No modules. | [route\_tables](#input\_route\_tables) | n/a | `map` | `{}` | no | | [shared\_principals](#input\_shared\_principals) | n/a | `map` | `{}` | no | | [tags](#input\_tags) | Optional Map of arbitrary tags to apply to all resources | `map(string)` | `{}` | no | +| [transit\_gateway\_cidr\_blocks](#input\_transit\_gateway\_cidr\_blocks) | One or more IPv4 or IPv6 CIDR blocks for the transit gateway. Must be a size /24 CIDR block or larger for IPv4, or a size /64 CIDR block or larger for IPv6. | `set(string)` | `[]` | no | | [vpn\_ecmp\_support](#input\_vpn\_ecmp\_support) | See the [provider documentation](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ec2_transit_gateway). | `string` | `null` | no | ### Outputs diff --git a/modules/transit_gateway/main.tf b/modules/transit_gateway/main.tf index 0531c11e..258f6e56 100644 --- a/modules/transit_gateway/main.tf +++ b/modules/transit_gateway/main.tf @@ -19,6 +19,7 @@ resource "aws_ec2_transit_gateway" "this" { auto_accept_shared_attachments = var.auto_accept_shared_attachments default_route_table_association = "disable" default_route_table_propagation = "disable" + transit_gateway_cidr_blocks = var.transit_gateway_cidr_blocks dns_support = var.dns_support vpn_ecmp_support = var.vpn_ecmp_support tags = merge(var.tags, { Name = var.name }) diff --git a/modules/transit_gateway/variables.tf b/modules/transit_gateway/variables.tf index b6481b8d..f41a925d 100644 --- a/modules/transit_gateway/variables.tf +++ b/modules/transit_gateway/variables.tf @@ -51,6 +51,16 @@ variable "shared_principals" { default = {} } +variable "transit_gateway_cidr_blocks" { + description = "One or more IPv4 or IPv6 CIDR blocks for the transit gateway. Must be a size /24 CIDR block or larger for IPv4, or a size /64 CIDR block or larger for IPv6." + default = [] + type = set(string) + validation { + condition = alltrue([for cidr in var.transit_gateway_cidr_blocks : can(cidrsubnet(cidr, 0, 0))]) + error_message = "Transit gateway CIDR blocks must contain valid IPv4 or IPv6 CIDR." + } +} + variable "tags" { description = "Optional Map of arbitrary tags to apply to all resources" type = map(string)