Skip to content

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Repository files navigation

terraform-google-cas

Description

Tagline

This is an auto-generated module.

Detailed

This module was generated from terraform-google-module-template, which by default generates a module that simply creates a GCS bucket. As the module develops, this README should be updated.

The resources/services/activations/deletions that this module will create/trigger are:

  • Create a GCS bucket with the provided name

PreDeploy

To deploy this blueprint you must have an active billing account and billing permissions.

Architecture

alt text for diagram

  1. Architecture description step no. 1
  2. Architecture description step no. 2
  3. Architecture description step no. N

Documentation

Deployment Duration

Configuration: X mins Deployment: Y mins

Cost

Blueprint cost details

Usage

Basic usage of this module is as follows:

module "cas" {
  source  = "terraform-google-modules/cas/google"
  version = "~> 0.1"

  project_id  = ""
  bucket_name = "gcs-test-bucket"
}

Functional examples are included in the examples directory.

Inputs

Name Description Type Default Required
ca_configs List of configurations for the Certificate Authorities to create.
map(object({
is_ca = optional(bool, true)
deletion_protection = optional(bool, false)
desired_state = optional(string, "ENABLED")
skip_grace_period = optional(bool, true)
ignore_active_certificates_on_deletion = optional(bool, false)
gcs_bucket = optional(string)
labels = optional(map(string), {})
subject = object({
common_name = string
organization = string
country_code = optional(string)
locality = optional(string)
postal_code = optional(string)
province = optional(string)
street_address = optional(string)
organizational_unit = optional(string)
})
subject_alt_name = optional(object({
dns_names = optional(list(string))
email_addresses = optional(list(string))
ip_addresses = optional(list(string))
uris = optional(list(string))
}))
key_usage = object({
cert_sign = optional(bool, true)
crl_sign = optional(bool, true)
server_auth = optional(bool, true)
client_auth = optional(bool, false)
code_signing = optional(bool, false)
content_commitment = optional(bool, false)
data_encipherment = optional(bool, false)
decipher_only = optional(bool, false)
digital_signature = optional(bool, false)
email_protection = optional(bool, false)
encipher_only = optional(bool, false)
key_agreement = optional(bool, false)
key_encipherment = optional(bool, true)
ocsp_signing = optional(bool, false)
time_stamping = optional(bool, false)
})
key_spec = object({
algorithm = optional(string, "RSA_PKCS1_2048_SHA256")
kms_key_id = optional(string)
})
subordinate_config = optional(object({
root_ca_id = string
pem_issuer_certificates = optional(list(string))
}))
}))
{} no
ca_pool_config Configuration for the Certificate Authority pool. Exactly one of 'create_pool' (to create a new pool) or 'use_pool' (to use an existing one) must be provided.
object({
create_pool = optional(object({
name = string
enterprise_tier = optional(bool, false)
}))
use_pool = optional(object({
id = string
}))
})
n/a yes
iam IAM bindings to apply to the CA pool.
map(object({
role = string
member = string
}))
{} no
location The location for the CA pool and certificate authority. string n/a yes
network_security_sa_roles A list of roles to assign to the Network Security service agent. list(string) [] no
project_id The ID of the project in which the resources will be created. string n/a yes

Outputs

Name Description
ca_chains The CA chains in PEM format.
ca_ids The CA ids.
ca_pool The CA pool resource.
ca_pool_id The full resource ID of the CA Pool (e.g., 'projects/my-project/locations/us-central1/caPools/my-subordinate-pool-v1').
ca_pool_name The short, user-defined name of the CA Pool (e.g., 'my-subordinate-pool-v1').
ca_roots The root CA certificates in PEM format, concatenated with newlines.
cas The Certificate Authority resources.

Requirements

These sections describe requirements for using this module.

Software

The following dependencies must be available:

Service Account

A service account with the following roles must be used to provision the resources of this module:

  • Storage Admin: roles/storage.admin

The Project Factory module and the IAM module may be used in combination to provision a service account with the necessary roles applied.

APIs

A project with the following APIs enabled must be used to host the resources of this module:

  • Google Cloud Storage JSON API: storage-api.googleapis.com

The Project Factory module can be used to provision a project with the necessary APIs enabled.

Contributing

Refer to the contribution guidelines for information on contributing to this module.

Security Disclosures

Please see our security disclosure process.

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages