About this project
This repository provides a minimal but production-oriented Terraform configuration for deploying a single Amazon EC2 instance on AWS. It creates a dedicated VPC, subnet, internet gateway, route table, flow log, security group, Elastic IP, EC2 instance, and generated SSH key pair. It also bootstraps a remote Terraform state backend using S3 buckets with versioning, encryption, and public-access blocking, a DynamoDB lock table, and KMS keys.
The configuration uses flat, numbered .tf files with 18 documented variables and 5 outputs. Provider versions are pinned to exact builds in the lockfile, and CI runs formatting, initialization, validation, and tflint checks. The project includes tests that plan against mocked providers and assert security properties such as KMS key rotation, bucket encryption, and state lock recoverability.
Supply chain practices include Sigstore-signed release archives, SLSA provenance, digest-pinned CI images, and SHA-pinned GitHub Actions. The README also provides a production checklist covering remote state migration, security group narrowing, CI-based planning, and drift detection. Note that default security group rules open SSH and HTTP(S) to the internet, so users should restrict access before real use.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.