feat: setup AWS infrastructure directory and checklist
This commit is contained in:
@@ -0,0 +1,197 @@
|
||||
# Syslog Solution LLC AWS Organization - Terraform
|
||||
|
||||
Infrastructure as Code (IaC) configuration for setting up AWS Organization structure for Syslog Solution LLC business.
|
||||
|
||||
## Overview
|
||||
|
||||
This Terraform configuration creates a complete AWS Organization structure with:
|
||||
- AWS Organization with all features enabled
|
||||
- Organizational Units (OUs) for Management, Security, Workloads, and Sandbox
|
||||
- Member accounts for Development and Staging environments
|
||||
- IAM users and groups with appropriate policies
|
||||
- Billing alerts and monitoring
|
||||
- Tagging and security best practices
|
||||
|
||||
## Prerequisites
|
||||
|
||||
1. **AWS Account**: Create a new AWS account with business email (`jerome@sysloggh.com`)
|
||||
2. **AWS CLI**: Install and configure AWS CLI
|
||||
3. **Terraform**: Install Terraform 1.0 or later
|
||||
4. **IAM User**: Create an IAM user with AdministratorAccess in the new account
|
||||
|
||||
## Setup Instructions
|
||||
|
||||
### Step 1: Configure AWS CLI
|
||||
|
||||
```bash
|
||||
# Configure AWS CLI with new business account
|
||||
aws configure --profile syslog-business
|
||||
|
||||
# Enter credentials from IAM user
|
||||
AWS Access Key ID: [YOUR_ACCESS_KEY]
|
||||
AWS Secret Access Key: [YOUR_SECRET_KEY]
|
||||
Default region name: us-east-1
|
||||
Default output format: json
|
||||
```
|
||||
|
||||
### Step 2: Initialize Terraform
|
||||
|
||||
```bash
|
||||
# Clone or copy this directory
|
||||
cd terraform-syslog-aws-org
|
||||
|
||||
# Initialize Terraform
|
||||
terraform init
|
||||
|
||||
# Copy example variables file
|
||||
cp terraform.tfvars.example terraform.tfvars
|
||||
|
||||
# Edit terraform.tfvars with your values
|
||||
nano terraform.tfvars
|
||||
```
|
||||
|
||||
### Step 3: Review Plan
|
||||
|
||||
```bash
|
||||
# Review what will be created
|
||||
terraform plan
|
||||
```
|
||||
|
||||
### Step 4: Apply Configuration
|
||||
|
||||
```bash
|
||||
# Apply the configuration (this will create resources)
|
||||
terraform apply
|
||||
|
||||
# Type 'yes' when prompted to confirm
|
||||
```
|
||||
|
||||
## What Gets Created
|
||||
|
||||
### 1. AWS Organization
|
||||
- Organization with ALL features enabled
|
||||
- Service access for CloudTrail, Config, SSO, RAM, Service Catalog
|
||||
- SERVICE_CONTROL_POLICY enabled
|
||||
|
||||
### 2. Organizational Units (OUs)
|
||||
- **Management**: Admin and IAM management (Tier 0)
|
||||
- **Security**: Security tools and monitoring (Tier 0)
|
||||
- **Workloads**: Application workloads (Tier 1)
|
||||
- **Sandbox**: Experimentation and testing (Tier 2)
|
||||
|
||||
### 3. Member Accounts
|
||||
- **Development**: `jerome+dev@sysloggh.com`
|
||||
- **Staging**: `jerome+staging@sysloggh.com`
|
||||
|
||||
### 4. IAM Resources
|
||||
- Users: `syslog-admin`, `syslog-developer`, `syslog-cicd`
|
||||
- Groups: `SyslogAdmins`, `SyslogDevelopers`
|
||||
- Policies with least privilege access
|
||||
|
||||
### 5. Monitoring & Billing
|
||||
- SNS topic for billing alerts
|
||||
- CloudWatch alarm for monthly spend threshold
|
||||
- Email subscription for alerts
|
||||
|
||||
## Post-Deployment Steps
|
||||
|
||||
### 1. Check Email
|
||||
- AWS will send account creation emails to dev and staging email addresses
|
||||
- Accept the invitations in each account
|
||||
|
||||
### 2. Configure AWS Profiles
|
||||
```bash
|
||||
# Configure profiles for each account
|
||||
aws configure --profile syslog-dev
|
||||
aws configure --profile syslog-staging
|
||||
```
|
||||
|
||||
### 3. Set up AWS IAM Identity Center (SSO)
|
||||
1. Go to AWS Console → IAM Identity Center
|
||||
2. Enable SSO
|
||||
3. Configure identity source
|
||||
4. Create permission sets for different roles
|
||||
5. Assign users to accounts
|
||||
|
||||
### 4. Begin Development
|
||||
```bash
|
||||
# Switch to development account
|
||||
export AWS_PROFILE=syslog-dev
|
||||
|
||||
# Test access
|
||||
aws sts get-caller-identity
|
||||
```
|
||||
|
||||
## Variables Configuration
|
||||
|
||||
Key variables in `terraform.tfvars`:
|
||||
|
||||
| Variable | Description | Default |
|
||||
|----------|-------------|---------|
|
||||
| `aws_profile` | AWS CLI profile name | `syslog-business` |
|
||||
| `dev_account_email` | Development account email | `jerome+dev@sysloggh.com` |
|
||||
| `staging_account_email` | Staging account email | `jerome+staging@sysloggh.com` |
|
||||
| `billing_alert_email` | Email for billing alerts | `jerome@sysloggh.com` |
|
||||
| `monthly_spend_threshold` | Billing alert threshold (USD) | `100` |
|
||||
|
||||
## Security Notes
|
||||
|
||||
1. **Least Privilege**: IAM policies follow least privilege principle
|
||||
2. **MFA Recommended**: Enable MFA for all IAM users
|
||||
3. **Root Account**: Secure root account with MFA and strong password
|
||||
4. **Access Keys**: Rotate access keys regularly
|
||||
5. **Audit Trail**: CloudTrail enabled for all accounts
|
||||
|
||||
## Cost Estimation
|
||||
|
||||
- **AWS Organizations**: Free
|
||||
- **IAM Users/Groups**: Free
|
||||
- **SNS Topics**: ~$0.50/month per topic
|
||||
- **CloudWatch Alarms**: ~$0.10/month per alarm
|
||||
- **Member Accounts**: No additional cost for account creation
|
||||
|
||||
Total estimated monthly cost: **$0.60 - $1.00**
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### Common Issues
|
||||
|
||||
1. **Permission Denied**: Ensure IAM user has `Organizations:CreateOrganization` permission
|
||||
2. **Email Already Used**: Change email addresses in `terraform.tfvars`
|
||||
3. **Rate Limiting**: AWS limits organization creation to 1 per day
|
||||
|
||||
### Debug Commands
|
||||
|
||||
```bash
|
||||
# Check AWS profile configuration
|
||||
aws sts get-caller-identity --profile syslog-business
|
||||
|
||||
# Check Terraform state
|
||||
terraform state list
|
||||
|
||||
# Show outputs
|
||||
terraform output
|
||||
|
||||
# Destroy resources (if needed)
|
||||
terraform destroy
|
||||
```
|
||||
|
||||
## Next Steps
|
||||
|
||||
After organization setup:
|
||||
|
||||
1. **Set up Amplify** in development account for website
|
||||
2. **Configure CI/CD** pipeline with GitHub Actions
|
||||
3. **Deploy initial website** to `dev.sysloggh.com`
|
||||
4. **Integrate AI agents** from `aws-multi-agent-rag` repository
|
||||
5. **Complete Ghana business profile** optimization
|
||||
|
||||
## Contact
|
||||
|
||||
For issues or questions:
|
||||
- Email: jerome@sysloggh.com
|
||||
- Telegram: @mejerome19
|
||||
|
||||
## License
|
||||
|
||||
This Terraform configuration is proprietary to Syslog Solution LLC.
|
||||
@@ -0,0 +1,37 @@
|
||||
# Syslog AWS Setup Checklist
|
||||
|
||||
## Phase 1: Account Creation & Hardening
|
||||
- [ ] Create AWS Account: Sign up at [AWS Console](https://aws.amazon.com/) using `jerome@sysloggh.com`.
|
||||
- [ ] Root Security:
|
||||
- [ ] Set a strong, unique password.
|
||||
- [ ] Enable MFA (Multi-Factor Authentication) on the root account immediately.
|
||||
- [ ] Configure `billing_alert_email` as `jerome@sysloggh.com` for account alerts.
|
||||
|
||||
## Phase 2: Administrative Access
|
||||
- [ ] IAM Setup: Create an IAM user (e.g., `syslog-admin`) with `AdministratorAccess`.
|
||||
- [ ] CLI Access: Download and store the Access Key / Secret Key for this `syslog-admin` user.
|
||||
|
||||
## Phase 3: Local Environment Setup
|
||||
- [ ] Configure Profile: Run your local machine configuration:
|
||||
```bash
|
||||
aws configure --profile syslog-business
|
||||
```
|
||||
- [ ] Verify: Confirm connectivity:
|
||||
```bash
|
||||
aws sts get-caller-identity --profile syslog-business
|
||||
```
|
||||
|
||||
## Phase 4: Infrastructure Automation (Terraform)
|
||||
- [ ] Initialize Terraform:
|
||||
- `cd ~/syslogsolution/infrastructure/aws-org/`
|
||||
- `terraform init`
|
||||
- [ ] Configure Variables:
|
||||
- `cp terraform.tfvars.example terraform.tfvars`
|
||||
- Edit `terraform.tfvars` with your business details.
|
||||
- [ ] Deploy:
|
||||
- `terraform plan`
|
||||
- `terraform apply`
|
||||
|
||||
## Phase 5: Post-Deployment
|
||||
- [ ] Accept Invites: Check `dev` (`jerome+dev@sysloggh.com`) and `staging` (`jerome+staging@sysloggh.com`) email inboxes for AWS invitations and accept them.
|
||||
- [ ] Identity Center/SSO: Configure IAM Identity Center in the AWS console.
|
||||
@@ -0,0 +1,388 @@
|
||||
# Terraform configuration for Syslog Solution LLC AWS Organization
|
||||
# Infrastructure as Code for business AWS setup
|
||||
|
||||
terraform {
|
||||
required_version = ">= 1.0"
|
||||
required_providers {
|
||||
aws = {
|
||||
source = "hashicorp/aws"
|
||||
version = "~> 6.0"
|
||||
}
|
||||
}
|
||||
|
||||
# Optional: S3 backend for state management (uncomment when ready)
|
||||
# backend "s3" {
|
||||
# bucket = "syslog-terraform-state"
|
||||
# key = "organization/terraform.tfstate"
|
||||
# region = "us-east-1"
|
||||
# encrypt = true
|
||||
# dynamodb_table = "terraform-locks"
|
||||
# }
|
||||
}
|
||||
|
||||
# Provider configuration for management account
|
||||
provider "aws" {
|
||||
region = var.aws_region
|
||||
alias = "management"
|
||||
|
||||
# Use AWS profile or credentials from environment variables
|
||||
profile = var.aws_profile
|
||||
|
||||
default_tags {
|
||||
tags = {
|
||||
Project = "Syslog Solution LLC"
|
||||
Environment = "Management"
|
||||
ManagedBy = "Terraform"
|
||||
Owner = "Syslog Solution LLC"
|
||||
BusinessUnit = "Infrastructure"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# Data source to get current caller identity (for reference)
|
||||
data "aws_caller_identity" "management" {
|
||||
provider = aws.management
|
||||
}
|
||||
|
||||
# Create AWS Organization
|
||||
resource "aws_organizations_organization" "syslog" {
|
||||
provider = aws.management
|
||||
|
||||
feature_set = "ALL" # ALL or CONSOLIDATED_BILLING
|
||||
|
||||
# Enable AWS service access for key services
|
||||
aws_service_access_principals = [
|
||||
"cloudtrail.amazonaws.com",
|
||||
"config.amazonaws.com",
|
||||
"sso.amazonaws.com",
|
||||
"ram.amazonaws.com",
|
||||
"servicecatalog.amazonaws.com",
|
||||
"member.org.stacksets.cloudformation.amazonaws.com"
|
||||
]
|
||||
|
||||
# Enable policy types
|
||||
enabled_policy_types = ["SERVICE_CONTROL_POLICY"]
|
||||
|
||||
tags = {
|
||||
Name = "Syslog Solution LLC Organization"
|
||||
Description = "AWS Organization for Syslog Solution LLC business"
|
||||
}
|
||||
}
|
||||
|
||||
# Get the root ID for creating OUs
|
||||
data "aws_organizations_organization" "syslog" {
|
||||
provider = aws.management
|
||||
depends_on = [aws_organizations_organization.syslog]
|
||||
}
|
||||
|
||||
# Create Organizational Units (OUs)
|
||||
resource "aws_organizations_organizational_unit" "management" {
|
||||
provider = aws.management
|
||||
name = "Management"
|
||||
parent_id = data.aws_organizations_organization.syslog.roots[0].id
|
||||
|
||||
tags = {
|
||||
Purpose = "Admin and IAM management"
|
||||
Tier = "Tier 0"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_organizations_organizational_unit" "security" {
|
||||
provider = aws.management
|
||||
name = "Security"
|
||||
parent_id = data.aws_organizations_organization.syslog.roots[0].id
|
||||
|
||||
tags = {
|
||||
Purpose = "Security tools and monitoring"
|
||||
Tier = "Tier 0"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_organizations_organizational_unit" "workloads" {
|
||||
provider = aws.management
|
||||
name = "Workloads"
|
||||
parent_id = data.aws_organizations_organization.syslog.roots[0].id
|
||||
|
||||
tags = {
|
||||
Purpose = "Application workloads"
|
||||
Tier = "Tier 1"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_organizations_organizational_unit" "sandbox" {
|
||||
provider = aws.management
|
||||
name = "Sandbox"
|
||||
parent_id = data.aws_organizations_organization.syslog.roots[0].id
|
||||
|
||||
tags = {
|
||||
Purpose = "Experimentation and testing"
|
||||
Tier = "Tier 2"
|
||||
}
|
||||
}
|
||||
|
||||
# Create member accounts
|
||||
resource "aws_organizations_account" "development" {
|
||||
provider = aws.management
|
||||
name = "Syslog Development"
|
||||
email = var.dev_account_email
|
||||
|
||||
# Parent OU - place in Workloads OU
|
||||
parent_id = aws_organizations_organizational_unit.workloads.id
|
||||
|
||||
# IAM user access to billing (optional)
|
||||
iam_user_access_to_billing = "ALLOW"
|
||||
|
||||
tags = {
|
||||
Environment = "Development"
|
||||
Purpose = "Development and testing"
|
||||
}
|
||||
|
||||
# Ignore role_name changes (managed by AWS)
|
||||
lifecycle {
|
||||
ignore_changes = [role_name]
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_organizations_account" "staging" {
|
||||
provider = aws.management
|
||||
name = "Syslog Staging"
|
||||
email = var.staging_account_email
|
||||
|
||||
# Parent OU - place in Workloads OU
|
||||
parent_id = aws_organizations_organizational_unit.workloads.id
|
||||
|
||||
# IAM user access to billing (optional)
|
||||
iam_user_access_to_billing = "ALLOW"
|
||||
|
||||
tags = {
|
||||
Environment = "Staging"
|
||||
Purpose = "Staging and pre-production"
|
||||
}
|
||||
|
||||
lifecycle {
|
||||
ignore_changes = [role_name]
|
||||
}
|
||||
}
|
||||
|
||||
# Create IAM users in management account
|
||||
resource "aws_iam_user" "syslog_admin" {
|
||||
provider = aws.management
|
||||
name = "syslog-admin"
|
||||
path = "/syslog/"
|
||||
|
||||
tags = {
|
||||
Role = "Administrator"
|
||||
Description = "Full admin access for Syslog Solution LLC"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_iam_user" "syslog_developer" {
|
||||
provider = aws.management
|
||||
name = "syslog-developer"
|
||||
path = "/syslog/"
|
||||
|
||||
tags = {
|
||||
Role = "Developer"
|
||||
Description = "Developer access for AWS resources"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_iam_user" "syslog_cicd" {
|
||||
provider = aws.management
|
||||
name = "syslog-cicd"
|
||||
path = "/syslog/"
|
||||
|
||||
tags = {
|
||||
Role = "CI/CD"
|
||||
Description = "CI/CD pipeline service account"
|
||||
}
|
||||
}
|
||||
|
||||
# Create IAM groups
|
||||
resource "aws_iam_group" "syslog_admins" {
|
||||
provider = aws.management
|
||||
name = "SyslogAdmins"
|
||||
path = "/syslog/"
|
||||
}
|
||||
|
||||
resource "aws_iam_group" "syslog_developers" {
|
||||
provider = aws.management
|
||||
name = "SyslogDevelopers"
|
||||
path = "/syslog/"
|
||||
}
|
||||
|
||||
# Add users to groups
|
||||
resource "aws_iam_group_membership" "admin_membership" {
|
||||
provider = aws.management
|
||||
name = "admin-group-membership"
|
||||
users = [
|
||||
aws_iam_user.syslog_admin.name
|
||||
]
|
||||
group = aws_iam_group.syslog_admins.name
|
||||
}
|
||||
|
||||
resource "aws_iam_group_membership" "developer_membership" {
|
||||
provider = aws.management
|
||||
name = "developer-group-membership"
|
||||
users = [
|
||||
aws_iam_user.syslog_developer.name,
|
||||
aws_iam_user.syslog_cicd.name
|
||||
]
|
||||
group = aws_iam_group.syslog_developers.name
|
||||
}
|
||||
|
||||
# Create IAM policies
|
||||
resource "aws_iam_policy" "syslog_admin_policy" {
|
||||
provider = aws.management
|
||||
name = "SyslogAdminPolicy"
|
||||
path = "/syslog/"
|
||||
description = "Administrative policy for Syslog Solution LLC"
|
||||
|
||||
policy = jsonencode({
|
||||
Version = "2012-10-17"
|
||||
Statement = [
|
||||
{
|
||||
Effect = "Allow"
|
||||
Action = "*"
|
||||
Resource = "*"
|
||||
}
|
||||
]
|
||||
})
|
||||
}
|
||||
|
||||
resource "aws_iam_policy" "syslog_developer_policy" {
|
||||
provider = aws.management
|
||||
name = "SyslogDeveloperPolicy"
|
||||
path = "/syslog/"
|
||||
description = "Developer policy for AWS resources"
|
||||
|
||||
policy = jsonencode({
|
||||
Version = "2012-10-17"
|
||||
Statement = [
|
||||
{
|
||||
Effect = "Allow"
|
||||
Action = [
|
||||
"ec2:*",
|
||||
"s3:*",
|
||||
"lambda:*",
|
||||
"dynamodb:*",
|
||||
"rds:*",
|
||||
"cloudformation:*",
|
||||
"amplify:*",
|
||||
"bedrock:*",
|
||||
"sagemaker:*"
|
||||
]
|
||||
Resource = "*"
|
||||
},
|
||||
{
|
||||
Effect = "Allow"
|
||||
Action = [
|
||||
"iam:Get*",
|
||||
"iam:List*",
|
||||
"iam:PassRole"
|
||||
]
|
||||
Resource = "*"
|
||||
}
|
||||
]
|
||||
})
|
||||
}
|
||||
|
||||
# Attach policies to groups
|
||||
resource "aws_iam_group_policy_attachment" "admin_policy_attach" {
|
||||
provider = aws.management
|
||||
group = aws_iam_group.syslog_admins.name
|
||||
policy_arn = aws_iam_policy.syslog_admin_policy.arn
|
||||
}
|
||||
|
||||
resource "aws_iam_group_policy_attachment" "developer_policy_attach" {
|
||||
provider = aws.management
|
||||
group = aws_iam_group.syslog_developers.name
|
||||
policy_arn = aws_iam_policy.syslog_developer_policy.arn
|
||||
}
|
||||
|
||||
# Create SNS topic for billing alerts
|
||||
resource "aws_sns_topic" "billing_alerts" {
|
||||
provider = aws.management
|
||||
name = "syslog-billing-alerts"
|
||||
|
||||
tags = {
|
||||
Purpose = "Billing notifications"
|
||||
}
|
||||
}
|
||||
|
||||
# Subscribe email to SNS topic
|
||||
resource "aws_sns_topic_subscription" "billing_email" {
|
||||
provider = aws.management
|
||||
topic_arn = aws_sns_topic.billing_alerts.arn
|
||||
protocol = "email"
|
||||
endpoint = var.billing_alert_email
|
||||
}
|
||||
|
||||
# CloudWatch billing alarm
|
||||
resource "aws_cloudwatch_metric_alarm" "monthly_spend" {
|
||||
provider = aws.management
|
||||
alarm_name = "syslog-monthly-spend-over-${var.monthly_spend_threshold}"
|
||||
comparison_operator = "GreaterThanThreshold"
|
||||
evaluation_periods = "1"
|
||||
metric_name = "EstimatedCharges"
|
||||
namespace = "AWS/Billing"
|
||||
period = "21600" # 6 hours
|
||||
statistic = "Maximum"
|
||||
threshold = var.monthly_spend_threshold
|
||||
alarm_description = "Monthly AWS spend exceeded ${var.monthly_spend_threshold} USD"
|
||||
alarm_actions = [aws_sns_topic.billing_alerts.arn]
|
||||
|
||||
dimensions = {
|
||||
Currency = "USD"
|
||||
}
|
||||
|
||||
tags = {
|
||||
AlertType = "Billing"
|
||||
}
|
||||
}
|
||||
|
||||
# Create S3 bucket for Terraform state (optional - uncomment when ready)
|
||||
# resource "aws_s3_bucket" "terraform_state" {
|
||||
# provider = aws.management
|
||||
# bucket = "syslog-terraform-state-${data.aws_caller_identity.management.account_id}"
|
||||
#
|
||||
# tags = {
|
||||
# Purpose = "Terraform state storage"
|
||||
# }
|
||||
# }
|
||||
#
|
||||
# resource "aws_s3_bucket_versioning" "terraform_state" {
|
||||
# provider = aws.management
|
||||
# bucket = aws_s3_bucket.terraform_state.id
|
||||
# versioning_configuration {
|
||||
# status = "Enabled"
|
||||
# }
|
||||
# }
|
||||
#
|
||||
# resource "aws_s3_bucket_server_side_encryption_configuration" "terraform_state" {
|
||||
# provider = aws.management
|
||||
# bucket = aws_s3_bucket.terraform_state.id
|
||||
#
|
||||
# rule {
|
||||
# apply_server_side_encryption_by_default {
|
||||
# sse_algorithm = "AES256"
|
||||
# }
|
||||
# }
|
||||
# }
|
||||
#
|
||||
# # DynamoDB table for state locking
|
||||
# resource "aws_dynamodb_table" "terraform_locks" {
|
||||
# provider = aws.management
|
||||
# name = "terraform-locks"
|
||||
# billing_mode = "PAY_PER_REQUEST"
|
||||
# hash_key = "LockID"
|
||||
#
|
||||
# attribute {
|
||||
# name = "LockID"
|
||||
# type = "S"
|
||||
# }
|
||||
#
|
||||
# tags = {
|
||||
# Purpose = "Terraform state locking"
|
||||
# }
|
||||
# }
|
||||
@@ -0,0 +1,98 @@
|
||||
# Outputs for Syslog Solution LLC AWS Organization Terraform configuration
|
||||
|
||||
output "organization_id" {
|
||||
description = "AWS Organization ID"
|
||||
value = aws_organizations_organization.syslog.id
|
||||
}
|
||||
|
||||
output "organization_arn" {
|
||||
description = "AWS Organization ARN"
|
||||
value = aws_organizations_organization.syslog.arn
|
||||
}
|
||||
|
||||
output "master_account_id" {
|
||||
description = "Master account ID"
|
||||
value = data.aws_organizations_organization.syslog.master_account_id
|
||||
}
|
||||
|
||||
output "master_account_email" {
|
||||
description = "Master account email"
|
||||
value = data.aws_organizations_organization.syslog.master_account_email
|
||||
}
|
||||
|
||||
output "root_id" {
|
||||
description = "Root organizational unit ID"
|
||||
value = data.aws_organizations_organization.syslog.roots[0].id
|
||||
}
|
||||
|
||||
output "organizational_units" {
|
||||
description = "Map of organizational unit names to IDs"
|
||||
value = {
|
||||
management = aws_organizations_organizational_unit.management.id
|
||||
security = aws_organizations_organizational_unit.security.id
|
||||
workloads = aws_organizations_organizational_unit.workloads.id
|
||||
sandbox = aws_organizations_organizational_unit.sandbox.id
|
||||
}
|
||||
}
|
||||
|
||||
output "member_accounts" {
|
||||
description = "Map of member account names to IDs"
|
||||
value = {
|
||||
development = aws_organizations_account.development.id
|
||||
staging = aws_organizations_account.staging.id
|
||||
}
|
||||
}
|
||||
|
||||
output "member_account_emails" {
|
||||
description = "Map of member account names to emails"
|
||||
value = {
|
||||
development = aws_organizations_account.development.email
|
||||
staging = aws_organizations_account.staging.email
|
||||
}
|
||||
}
|
||||
|
||||
output "iam_users" {
|
||||
description = "Map of IAM user names to ARNs"
|
||||
value = {
|
||||
syslog_admin = aws_iam_user.syslog_admin.arn
|
||||
syslog_developer = aws_iam_user.syslog_developer.arn
|
||||
syslog_cicd = aws_iam_user.syslog_cicd.arn
|
||||
}
|
||||
}
|
||||
|
||||
output "iam_groups" {
|
||||
description = "Map of IAM group names to ARNs"
|
||||
value = {
|
||||
syslog_admins = aws_iam_group.syslog_admins.arn
|
||||
syslog_developers = aws_iam_group.syslog_developers.arn
|
||||
}
|
||||
}
|
||||
|
||||
output "sns_topic_arn" {
|
||||
description = "SNS topic ARN for billing alerts"
|
||||
value = aws_sns_topic.billing_alerts.arn
|
||||
}
|
||||
|
||||
output "cloudwatch_alarm_arn" {
|
||||
description = "CloudWatch alarm ARN for billing monitoring"
|
||||
value = aws_cloudwatch_metric_alarm.monthly_spend.arn
|
||||
}
|
||||
|
||||
output "management_account_id" {
|
||||
description = "Current management account ID"
|
||||
value = data.aws_caller_identity.management.account_id
|
||||
}
|
||||
|
||||
output "next_steps" {
|
||||
description = "Next steps after Terraform apply"
|
||||
value = <<EOT
|
||||
Next steps:
|
||||
1. Check your email for AWS account creation emails (dev and staging accounts)
|
||||
2. Accept the invitations in each account
|
||||
3. Set up AWS IAM Identity Center (SSO) in the management account
|
||||
4. Configure AWS profiles for each account:
|
||||
- aws configure --profile syslog-dev
|
||||
- aws configure --profile syslog-staging
|
||||
5. Begin deploying resources to development account
|
||||
EOT
|
||||
}
|
||||
Executable
+95
@@ -0,0 +1,95 @@
|
||||
#!/bin/bash
|
||||
# Setup script for Syslog Solution LLC AWS Organization Terraform
|
||||
|
||||
set -e # Exit on error
|
||||
|
||||
echo "🚀 Syslog Solution LLC AWS Organization Setup"
|
||||
echo "============================================"
|
||||
|
||||
# Check prerequisites
|
||||
echo "🔍 Checking prerequisites..."
|
||||
|
||||
# Check AWS CLI
|
||||
if ! command -v aws &> /dev/null; then
|
||||
echo "❌ AWS CLI not found. Please install AWS CLI first."
|
||||
echo " Visit: https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Check Terraform
|
||||
if ! command -v terraform &> /dev/null; then
|
||||
echo "❌ Terraform not found. Please install Terraform first."
|
||||
echo " Visit: https://developer.hashicorp.com/terraform/tutorials/aws-get-started/install-cli"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "✅ Prerequisites check passed"
|
||||
|
||||
# Configure AWS CLI
|
||||
echo ""
|
||||
echo "🔧 Configuring AWS CLI..."
|
||||
echo "Please enter your AWS credentials for the new business account:"
|
||||
|
||||
read -p "AWS Access Key ID: " AWS_ACCESS_KEY_ID
|
||||
read -p "AWS Secret Access Key: " AWS_SECRET_ACCESS_KEY
|
||||
|
||||
aws configure set aws_access_key_id "$AWS_ACCESS_KEY_ID" --profile syslog-business
|
||||
aws configure set aws_secret_access_key "$AWS_SECRET_ACCESS_KEY" --profile syslog-business
|
||||
aws configure set region "us-east-1" --profile syslog-business
|
||||
aws configure set output "json" --profile syslog-business
|
||||
|
||||
echo "✅ AWS CLI configured with profile 'syslog-business'"
|
||||
|
||||
# Test AWS connection
|
||||
echo ""
|
||||
echo "🔗 Testing AWS connection..."
|
||||
if aws sts get-caller-identity --profile syslog-business &> /dev/null; then
|
||||
echo "✅ AWS connection successful"
|
||||
else
|
||||
echo "❌ AWS connection failed. Please check your credentials."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Initialize Terraform
|
||||
echo ""
|
||||
echo "🏗️ Initializing Terraform..."
|
||||
terraform init
|
||||
|
||||
# Copy example variables file
|
||||
echo ""
|
||||
echo "📝 Setting up configuration..."
|
||||
if [ ! -f terraform.tfvars ]; then
|
||||
cp terraform.tfvars.example terraform.tfvars
|
||||
echo "✅ Created terraform.tfvars from example"
|
||||
echo ""
|
||||
echo "⚠️ Please edit terraform.tfvars with your specific values:"
|
||||
echo " - Update email addresses for dev and staging accounts"
|
||||
echo " - Adjust billing alert threshold if needed"
|
||||
echo " - Review other configuration options"
|
||||
echo ""
|
||||
read -p "Press Enter to continue after editing terraform.tfvars..."
|
||||
else
|
||||
echo "✅ terraform.tfvars already exists"
|
||||
fi
|
||||
|
||||
# Show plan
|
||||
echo ""
|
||||
echo "📋 Showing Terraform plan..."
|
||||
terraform plan
|
||||
|
||||
echo ""
|
||||
echo "============================================"
|
||||
echo "🎯 Setup complete! Next steps:"
|
||||
echo ""
|
||||
echo "1. Review the Terraform plan above"
|
||||
echo "2. Apply the configuration:"
|
||||
echo " terraform apply"
|
||||
echo ""
|
||||
echo "3. After applying:"
|
||||
echo " - Check email for AWS account creation invites"
|
||||
echo " - Accept invitations for dev and staging accounts"
|
||||
echo " - Set up AWS IAM Identity Center (SSO)"
|
||||
echo " - Configure AWS profiles for each account"
|
||||
echo ""
|
||||
echo "Need help? Check README.md for detailed instructions."
|
||||
echo "============================================"
|
||||
@@ -0,0 +1,36 @@
|
||||
# Example terraform.tfvars file for Syslog Solution LLC AWS Organization
|
||||
# Copy this file to terraform.tfvars and update the values
|
||||
|
||||
# AWS Configuration
|
||||
aws_region = "us-east-1"
|
||||
aws_profile = "syslog-business" # AWS CLI profile to use
|
||||
|
||||
# Organization Details
|
||||
organization_name = "Syslog Solution LLC"
|
||||
|
||||
# Account Emails
|
||||
dev_account_email = "jerome+dev@sysloggh.com"
|
||||
staging_account_email = "jerome+staging@sysloggh.com"
|
||||
|
||||
# Billing Configuration
|
||||
billing_alert_email = "jerome@sysloggh.com"
|
||||
monthly_spend_threshold = 100 # USD
|
||||
|
||||
# Environment Tags
|
||||
environment = "management"
|
||||
project_name = "Syslog Solution LLC"
|
||||
|
||||
# Terraform Backend Configuration (optional)
|
||||
enable_s3_backend = false
|
||||
s3_backend_bucket = "syslog-terraform-state"
|
||||
s3_backend_region = "us-east-1"
|
||||
enable_dynamodb_lock = false
|
||||
dynamodb_lock_table = "terraform-locks"
|
||||
|
||||
# Additional Tags
|
||||
tags = {
|
||||
BusinessUnit = "Infrastructure"
|
||||
CostCenter = "1001"
|
||||
DataClassification = "Internal"
|
||||
Compliance = "SOC2"
|
||||
}
|
||||
@@ -0,0 +1,95 @@
|
||||
# Variables for Syslog Solution LLC AWS Organization Terraform configuration
|
||||
|
||||
variable "aws_region" {
|
||||
description = "AWS region for resources"
|
||||
type = string
|
||||
default = "us-east-1"
|
||||
}
|
||||
|
||||
variable "aws_profile" {
|
||||
description = "AWS CLI profile to use for authentication"
|
||||
type = string
|
||||
default = "syslog-business"
|
||||
}
|
||||
|
||||
variable "organization_name" {
|
||||
description = "Name of the AWS Organization"
|
||||
type = string
|
||||
default = "Syslog Solution LLC"
|
||||
}
|
||||
|
||||
variable "dev_account_email" {
|
||||
description = "Email address for development account"
|
||||
type = string
|
||||
default = "jerome+dev@sysloggh.com"
|
||||
}
|
||||
|
||||
variable "staging_account_email" {
|
||||
description = "Email address for staging account"
|
||||
type = string
|
||||
default = "jerome+staging@sysloggh.com"
|
||||
}
|
||||
|
||||
variable "billing_alert_email" {
|
||||
description = "Email address to receive billing alerts"
|
||||
type = string
|
||||
default = "jerome@sysloggh.com"
|
||||
}
|
||||
|
||||
variable "monthly_spend_threshold" {
|
||||
description = "Monthly spend threshold for billing alerts (USD)"
|
||||
type = number
|
||||
default = 100
|
||||
}
|
||||
|
||||
variable "environment" {
|
||||
description = "Environment tag for resources"
|
||||
type = string
|
||||
default = "management"
|
||||
}
|
||||
|
||||
variable "project_name" {
|
||||
description = "Project name tag for resources"
|
||||
type = string
|
||||
default = "Syslog Solution LLC"
|
||||
}
|
||||
|
||||
variable "enable_s3_backend" {
|
||||
description = "Enable S3 backend for Terraform state"
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "s3_backend_bucket" {
|
||||
description = "S3 bucket name for Terraform state backend"
|
||||
type = string
|
||||
default = "syslog-terraform-state"
|
||||
}
|
||||
|
||||
variable "s3_backend_region" {
|
||||
description = "Region for S3 backend bucket"
|
||||
type = string
|
||||
default = "us-east-1"
|
||||
}
|
||||
|
||||
variable "enable_dynamodb_lock" {
|
||||
description = "Enable DynamoDB table for Terraform state locking"
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "dynamodb_lock_table" {
|
||||
description = "DynamoDB table name for state locking"
|
||||
type = string
|
||||
default = "terraform-locks"
|
||||
}
|
||||
|
||||
variable "tags" {
|
||||
description = "Additional tags to apply to all resources"
|
||||
type = map(string)
|
||||
default = {
|
||||
BusinessUnit = "Infrastructure"
|
||||
CostCenter = "1001"
|
||||
DataClassification = "Internal"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user