Skip to content

Commit f63ce2d

Browse files
committed
cosmetic formatting, replaced « with double quotes
1 parent 03fa1ff commit f63ce2d

File tree

6 files changed

+27
-25
lines changed

6 files changed

+27
-25
lines changed

docs/terraformoptions.adoc

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -86,6 +86,11 @@ tags = {
8686
|true/false
8787
|false
8888

89+
|`lockdown_default_seclist`
90+
|whether to remove all default security rules from the VCN Default Security List
91+
|true/false
92+
|true
93+
8994
|`nat_gateway_enabled`
9095
|Whether to create a NAT gateway.
9196
|true/false
@@ -111,9 +116,4 @@ tags = {
111116
|
112117
|
113118

114-
|`lockdown_default_seclist`
115-
|whether to remove all default security rules from the VCN Default Security List
116-
|true/false
117-
|true
118-
119119
|===

examples/README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,7 +78,7 @@ module "vcn" {
7878
vcn_cidr = var.vcn_cidr
7979
vcn_dns_label = var.vcn_dns_label
8080
vcn_name = var.vcn_name
81-
lockdown_default_seclist = var.lockdown_default_seclist
81+
lockdown_default_seclist = var.lockdown_default_seclist
8282
}
8383
```
8484

examples/main.tf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,8 @@ module "vcn" {
1515
# vcn parameters
1616
internet_gateway_enabled = false
1717

18+
lockdown_default_seclist = true
19+
1820
nat_gateway_enabled = false
1921

2022
service_gateway_enabled = false
@@ -25,8 +27,6 @@ module "vcn" {
2527

2628
vcn_name = "vcn"
2729

28-
lockdown_default_seclist = true
29-
3030
tags = {
3131
environment = "dev"
3232
lob = "finance"

variables.tf

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,12 @@ variable "internet_gateway_enabled" {
3030
type = bool
3131
}
3232

33+
variable "lockdown_default_seclist" {
34+
description = "whether to remove all default security rules from the VCN Default Security List"
35+
default = true
36+
type = bool
37+
}
38+
3339
variable "nat_gateway_enabled" {
3440
description = "whether to create a nat gateway in the vcn"
3541
default = false
@@ -65,9 +71,3 @@ variable "vcn_name" {
6571
description = "user-friendly name of to use for the vcn to be appended to the label_prefix"
6672
type = string
6773
}
68-
69-
variable "lockdown_default_seclist" {
70-
description = "whether to remove all default security rules from the VCN Default Security List"
71-
default = true
72-
type = bool
73-
}

vcn_defaultresources.tf

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,13 @@
55
// See Issue #22 for the reasoning
66
resource "oci_core_default_security_list" "lockdown" {
77
// If variable is true, removes all rules from default security list
8-
count = var.lockdown_default_seclist == true ? 1 : 0
98
manage_default_resource_id = oci_core_vcn.vcn.default_security_list_id
9+
10+
count = var.lockdown_default_seclist == true ? 1 : 0
1011
}
1112

1213
resource "oci_core_default_security_list" "restore_default" {
1314
// If variable is false, restore all default rules to default security list
14-
count = var.lockdown_default_seclist == false ? 1 : 0
1515
manage_default_resource_id = oci_core_vcn.vcn.default_security_list_id
1616

1717
egress_security_rules {
@@ -21,7 +21,7 @@ resource "oci_core_default_security_list" "restore_default" {
2121
}
2222

2323
ingress_security_rules {
24-
// SSH for all
24+
// allow all SSH
2525
protocol = "6"
2626
source = "0.0.0.0/0"
2727
tcp_options {
@@ -31,7 +31,7 @@ resource "oci_core_default_security_list" "restore_default" {
3131
}
3232

3333
ingress_security_rules {
34-
// ICMP for all type 3 code 4
34+
// allow ICMP for all type 3 code 4
3535
protocol = "1"
3636
source = "0.0.0.0/0"
3737

@@ -42,12 +42,14 @@ resource "oci_core_default_security_list" "restore_default" {
4242
}
4343

4444
ingress_security_rules {
45-
//ICMP for VCN
45+
//allow all ICMP from VCN
4646
protocol = "1"
4747
source = var.vcn_cidr
4848

4949
icmp_options {
5050
type = "3"
5151
}
5252
}
53+
54+
count = var.lockdown_default_seclist == false ? 1 : 0
5355
}

vcn_gateways.tf

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
# Copyright (c) 2019, 2021, Oracle Corporation and/or affiliates.
22
# Licensed under the Universal Permissive License v 1.0 as shown at https://oss.oracle.com/licenses/upl/
33

4-
resource « oci_core_internet_gateway » « ig » {
4+
resource oci_core_internet_gateway "ig" {
55
compartment_id = var.compartment_id
6-
display_name = var.label_prefix == « none » ? « internet-gateway » : « ${var.label_prefix}-internet-gateway »
6+
display_name = var.label_prefix == "none" ? "internet-gateway" : "${var.label_prefix}-internet-gateway"
77

88
freeform_tags = var.tags
99

@@ -12,9 +12,9 @@ resource « oci_core_internet_gateway » « ig » {
1212
count = var.internet_gateway_enabled == true ? 1 : 0
1313
}
1414

15-
resource « oci_core_route_table » « ig » {
15+
resource "oci_core_route_table" "ig" {
1616
compartment_id = var.compartment_id
17-
display_name = var.label_prefix == « none » ? « internet-route » : « ${var.label_prefix}-internet-route »
17+
display_name = var.label_prefix == "none" ? "internet-route" : "${var.label_prefix}-internet-route"
1818

1919
freeform_tags = var.tags
2020

@@ -52,9 +52,9 @@ resource "oci_core_service_gateway" "service_gateway" {
5252
count = var.service_gateway_enabled == true ? 1 : 0
5353
}
5454

55-
resource « oci_core_nat_gateway » « nat_gateway » {
55+
resource "oci_core_nat_gateway" "nat_gateway" {
5656
compartment_id = var.compartment_id
57-
display_name = var.label_prefix == « none » ? « nat-gateway » : « ${var.label_prefix}-nat-gateway »
57+
display_name = var.label_prefix == "none" ? "nat-gateway" : "${var.label_prefix}-nat-gateway"
5858

5959
freeform_tags = var.tags
6060

0 commit comments

Comments
 (0)