Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

🔧 Move Lambda to VPC #5535

Merged
merged 9 commits into from
Apr 3, 2024
Merged

🔧 Move Lambda to VPC #5535

merged 9 commits into from
Apr 3, 2024

Conversation

Gary-H9
Copy link
Contributor

@Gary-H9 Gary-H9 commented Apr 2, 2024

This pull request:

  • Moves Lambda functions into VPC
  • Creates and attaches security groups to Lambda functions
  • Allows access to S3 gateway
  • Adds a VPC interface for Secrets Manager

@github-actions github-actions bot added the environments-repository Used to exclude PRs from this repo in our Slack PR update label Apr 2, 2024
Copy link
Contributor

github-actions bot commented Apr 2, 2024

TFSEC Scan Success

Show Output ```hcl

TFSEC will check the following folders:

</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>

```hcl

*****************************

Checkov will check the following folders:

CTFLint Scan Success

Show Output
*****************************

Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version: 0.5.0)
tflint will check the following folders:

Trivy Scan

Show Output

@Gary-H9 Gary-H9 temporarily deployed to analytical-platform-ingestion-development April 2, 2024 15:41 — with GitHub Actions Inactive
Copy link
Contributor

github-actions bot commented Apr 2, 2024

TFSEC Scan Success

Show Output ```hcl

TFSEC will check the following folders:

</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>

```hcl

*****************************

Checkov will check the following folders:

CTFLint Scan Success

Show Output
*****************************

Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version: 0.5.0)
tflint will check the following folders:

Trivy Scan

Show Output

@Gary-H9 Gary-H9 had a problem deploying to analytical-platform-ingestion-development April 2, 2024 15:58 — with GitHub Actions Failure
Copy link
Contributor

github-actions bot commented Apr 2, 2024

TFSEC Scan Success

Show Output ```hcl

TFSEC will check the following folders:

</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>

```hcl

*****************************

Checkov will check the following folders:

CTFLint Scan Success

Show Output
*****************************

Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version: 0.5.0)
tflint will check the following folders:

Trivy Scan

Show Output

@Gary-H9 Gary-H9 temporarily deployed to analytical-platform-ingestion-development April 2, 2024 16:02 — with GitHub Actions Inactive
Copy link
Contributor

github-actions bot commented Apr 2, 2024

TFSEC Scan Success

Show Output ```hcl

TFSEC will check the following folders:

</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>

```hcl

*****************************

Checkov will check the following folders:

CTFLint Scan Success

Show Output
*****************************

Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version: 0.5.0)
tflint will check the following folders:

Trivy Scan

Show Output

@Gary-H9 Gary-H9 had a problem deploying to analytical-platform-ingestion-development April 2, 2024 16:03 — with GitHub Actions Failure
Copy link
Contributor

github-actions bot commented Apr 2, 2024

TFSEC Scan Success

Show Output ```hcl

TFSEC will check the following folders:

</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>

```hcl

*****************************

Checkov will check the following folders:

CTFLint Scan Success

Show Output
*****************************

Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version: 0.5.0)
tflint will check the following folders:

Trivy Scan

Show Output

@Gary-H9 Gary-H9 temporarily deployed to analytical-platform-ingestion-development April 2, 2024 16:35 — with GitHub Actions Inactive
Copy link
Contributor

github-actions bot commented Apr 2, 2024

TFSEC Scan Success

Show Output ```hcl

TFSEC will check the following folders:

</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>

```hcl

*****************************

Checkov will check the following folders:

CTFLint Scan Success

Show Output
*****************************

Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version: 0.5.0)
tflint will check the following folders:

Trivy Scan

Show Output

@Gary-H9 Gary-H9 marked this pull request as ready for review April 2, 2024 16:39
@Gary-H9 Gary-H9 requested review from a team as code owners April 2, 2024 16:39
@modernisation-platform-ci
Copy link
Contributor

@Gary-H9 Terraform plan evalaution detected changes to resources that require approval from a member of @ministryofjustice/modernisation-platform

1 similar comment
@modernisation-platform-ci
Copy link
Contributor

@Gary-H9 Terraform plan evalaution detected changes to resources that require approval from a member of @ministryofjustice/modernisation-platform

Copy link
Contributor

github-actions bot commented Apr 2, 2024

TFSEC Scan Success

Show Output ```hcl

TFSEC will check the following folders:

</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>

```hcl

*****************************

Checkov will check the following folders:

CTFLint Scan Success

Show Output
*****************************

Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version: 0.5.0)
tflint will check the following folders:

Trivy Scan

Show Output

@modernisation-platform-ci
Copy link
Contributor

@jacobwoffenden Terraform plan evalaution detected changes to resources that require approval from a member of @ministryofjustice/modernisation-platform

1 similar comment
@modernisation-platform-ci
Copy link
Contributor

@jacobwoffenden Terraform plan evalaution detected changes to resources that require approval from a member of @ministryofjustice/modernisation-platform

@modernisation-platform-ci
Copy link
Contributor

@Gary-H9 Terraform plan evalaution detected changes to resources that require approval from a member of @ministryofjustice/modernisation-platform

@modernisation-platform-ci
Copy link
Contributor

@Gary-H9 Terraform plan evalaution detected changes to resources that require approval from a member of @ministryofjustice/modernisation-platform

Copy link
Contributor

github-actions bot commented Apr 3, 2024

TFSEC Scan Success

Show Output ```hcl

TFSEC will check the following folders:

</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>

```hcl

*****************************

Checkov will check the following folders:

CTFLint Scan Success

Show Output
*****************************

Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version: 0.5.0)
tflint will check the following folders:

Trivy Scan

Show Output

SteveLinden
SteveLinden previously approved these changes Apr 3, 2024
@Gary-H9 Gary-H9 temporarily deployed to analytical-platform-ingestion-development April 3, 2024 07:57 — with GitHub Actions Inactive
Signed-off-by: Jacob Woffenden <[email protected]>
@modernisation-platform-ci
Copy link
Contributor

@jacobwoffenden Terraform plan evalaution detected changes to resources that require approval from a member of @ministryofjustice/modernisation-platform

@jacobwoffenden jacobwoffenden temporarily deployed to analytical-platform-ingestion-development April 3, 2024 10:45 — with GitHub Actions Inactive
Copy link
Contributor

github-actions bot commented Apr 3, 2024

TFSEC Scan Success

Show Output ```hcl

TFSEC will check the following folders:

</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>

```hcl

*****************************

Checkov will check the following folders:

CTFLint Scan Success

Show Output
*****************************

Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version: 0.5.0)
tflint will check the following folders:

Trivy Scan

Show Output

@Gary-H9 Gary-H9 merged commit 532a4f5 into main Apr 3, 2024
11 of 12 checks passed
@Gary-H9 Gary-H9 deleted the lambda-move branch April 3, 2024 12:21
madhu-k-sr2 pushed a commit that referenced this pull request Apr 3, 2024
* 🔧 Move Lambda to VPC

* 🔧 Add security groups

* 🎨 Update names and descriptions

* 🔧 Update Lambdas to use specific security groups

* WIP

* Correct typo

* 🔧 Add Secrets Manager VPC Endpoint

* Update terraform/environments/analytical-platform-ingestion/lambda-functions.tf

Co-authored-by: Jacob Woffenden <[email protected]>

* Update all egress ranges

Signed-off-by: Jacob Woffenden <[email protected]>

---------

Signed-off-by: Jacob Woffenden <[email protected]>
Co-authored-by: Jacob Woffenden <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
environments-repository Used to exclude PRs from this repo in our Slack PR update
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants