Appendix F: Ivanti Connect Secure Terraform Template for GCP
Terraform is an open source tool to easily define, preview, and deploy cloud infrastructure on GCP Cloud. Ivanti provides sample Terraform template files for 2 NICs and 3 NICs to deploy the Ivanti Connect Secure Virtual Appliance on GCP Cloud. Users can modify this to make it suitable for their need. To download the Cloud Templates, see product-downloads.
Base Setup
##############################################################################################################################
# This terraform script is used to setup common infra in Google Cloud Platform(GCP) such as the following:
# VPC Network
# Sub-Networks for ICS internal, external and management ports within VPC Network
# Firewall for ICS internal, external and management ports
#
# REQUIRED :
# * Terraform : v0.13 or later
# * Terraform Google Provider : 3.5.0 or later
# > Run " terraform init -upgrade " if version is older
#
##############################################################################################################################
terraform {
required_version = ">= 0.13"
required_providers {
google = {
source = "hashicorp/google"
version = ">= 3.5.0"
}
}
}##########################################################################################
provider "google" {
credentials = file("*****.json")
project = var.project_id
region = var.region
zone = var.zone
}##########################################################################################
#Create a VPC for Management Network
resource "google_compute_network" "vpc_network_mgmt" {
name = var.vpc_map["mgmt_network"]
auto_create_subnetworks = false
#cidr_block = "$cidr_block" #not applicable to GCP
}
#Create a VPC for Private Network
resource "google_compute_network" "vpc_network_private" {
name = var.vpc_map["private_network"]
auto_create_subnetworks = false
#cidr_block = "$cidr_block" #not applicable to GCP
}
#Create a VPC for Public Network
resource "google_compute_network" "vpc_network_public" {
name = var.vpc_map["public_network"]
auto_create_subnetworks = false
#cidr_block = "$cidr_block" #not applicable to GCP
}##########################################################################################
#create vSwitch for zone-1
#for ics internal port
resource "google_compute_subnetwork" "vsw-zone-1-ics-int-port-subnet" {
name = var.vswitch_map[var.zone_1]["ics_int_port"]["name"]
ip_cidr_range = var.vswitch_map[var.zone_1]["ics_int_port"]["cidr"]
region = var.region
network = google_compute_network.vpc_network_private.self_link
}
#for ics external port
resource "google_compute_subnetwork" "vsw-zone-1-ics-ext-port-subnet" {
name = var.vswitch_map[var.zone_1]["ics_ext_port"]["name"]
ip_cidr_range = var.vswitch_map[var.zone_1]["ics_ext_port"]["cidr"]
region = var.region
network = google_compute_network.vpc_network_public.self_link
}
#for ics management port
resource "google_compute_subnetwork" "vsw-zone-1-ics-mgmt-port-subnet" {
name = var.vswitch_map[var.zone_1]["ics_mgmt_port"]["name"]
ip_cidr_range = var.vswitch_map[var.zone_1]["ics_mgmt_port"]["cidr"]
region = var.region
network = google_compute_network.vpc_network_mgmt.self_link
}
#for ics tunnel subnet
#resource "google_compute_subnetwork" "vsw-zone-1-ics-tunnel-subnet" {
# name = var.vswitch_map[var.zone_1]["ics_tunnel_subnet"]["name"]
# ip_cidr_range = var.vswitch_map[var.zone_1]["ics_tunnel_subnet"]["cidr"]
# region = var.region
# network = google_compute_network.vpc_network_private.self_link
#}##########################################################################################
#create vSwitch for zone-2
#for ics internal port
resource "google_compute_subnetwork" "vsw-zone-2-ics-int-port-subnet" {
name = var.vswitch_map[var.zone_2]["ics_int_port"]["name"]
ip_cidr_range = var.vswitch_map[var.zone_2]["ics_int_port"]["cidr"]
region = var.region
network = google_compute_network.vpc_network_private.self_link
}
#for ics external port
resource "google_compute_subnetwork" "vsw-zone-2-ics-ext-port-subnet" {
name = var.vswitch_map[var.zone_2]["ics_ext_port"]["name"]
ip_cidr_range = var.vswitch_map[var.zone_2]["ics_ext_port"]["cidr"]
region = var.region
network = google_compute_network.vpc_network_public.self_link
}
#for ics management port
resource "google_compute_subnetwork" "vsw-zone-2-ics-mgmt-port-subnet" {
name = var.vswitch_map[var.zone_2]["ics_mgmt_port"]["name"]
ip_cidr_range = var.vswitch_map[var.zone_2]["ics_mgmt_port"]["cidr"]
region = var.region
network = google_compute_network.vpc_network_mgmt.self_link
}
#for ics tunnel subnet
#resource "google_compute_subnetwork" "vsw-zone-2-ics-tunnel-subnet" {
# name = var.vswitch_map[var.zone_2]["ics_tunnel_subnet"]["name"]
# ip_cidr_range = var.vswitch_map[var.zone_2]["ics_tunnel_subnet"]["cidr"]
# region = var.region
# network = google_compute_network.vpc_network_private.self_link
#}##########################################################################################
#create firewall with rules for ics internal port
resource "google_compute_firewall" "fw_ics_int_port" {
name = var.firewall_map["ics_int_port"]
#network = google_compute_network.vpc_network_private.name
network = google_compute_network.vpc_network_private.self_link
allow {
protocol = "icmp"
}
allow {
protocol = "tcp"
ports = ["443", "11000-11099", "4808-4809", "4900-4910"]
}
allow {
protocol = "udp"
ports = ["4803-4804", "4500"]
}
source_ranges = ["0.0.0.0/0"]}
##########################################################################################
#create firewall with rules for ics external port
resource "google_compute_firewall" "fw_ics_ext_port" {
name = var.firewall_map["ics_ext_port"]
#network = google_compute_network.vpc_network_public.name
network = google_compute_network.vpc_network_public.self_link
allow {
protocol = "icmp"
}
allow {
protocol = "tcp"
ports = ["443"]
}
allow {
protocol = "udp"
ports = ["4500"]
}
source_ranges = ["0.0.0.0/0"]
}##########################################################################################
#create firewall with rules for ics management port
resource "google_compute_firewall" "fw_ics_mgmt_port" {
name = var.firewall_map["ics_mgmt_port"]
#network = google_compute_network.vpc_network_mgmt.name
network = google_compute_network.vpc_network_mgmt.self_link
allow {
protocol = "icmp"
}
allow {
protocol = "tcp"
ports = ["443"]
}
source_ranges = ["0.0.0.0/0"]
}##########################################################################################
#create firewall with rules for backend server
resource "google_compute_firewall" "fw_backend_svr" {
name = var.firewall_map["backend_svr"]
#network = google_compute_network.vpc_network_private.name
network = google_compute_network.vpc_network_private.self_link
allow {
protocol = "icmp"
}
allow {
protocol = "tcp"
ports = ["443", "22"]
}
source_ranges = ["0.0.0.0/0"]
}ICS with 2 NICs
##############################################################################################################################
# This terraform script is used to deploy a ICS instance with 2-nics on Google Cloud Platform(GCP)
#
# REQUIRED :
# * Terraform : v0.13 or later
# * Terraform Google Provider : 3.5.0 or later
# > Run " terraform init -upgrade " if version is older
#
##############################################################################################################################
terraform {
required_version = ">= 0.13"
required_providers {
google = {
source = "hashicorp/google"
version = ">= 3.5.0"
}
}
}##########################################################################################
provider "google" {
credentials = file("*****.json")
project = var.project_id
region = var.region
zone = var.zone
}##########################################################################################
#Data sources
#Image
data "google_compute_image" "ics_image" {
name = var.image_name
#family = "debian-9"
#project = "debian-cloud"
}
#VPCs
data "google_compute_network" "vpc_network_mgmt" {
name = var.vpc_map["mgmt_network"]
}
data "google_compute_network" "vpc_network_private" {
name = var.vpc_map["private_network"]
}
data "google_compute_network" "vpc_network_public" {
name = var.vpc_map["public_network"]
}##########################################################################################
#local variables
locals {
region = var.region
zone = var.zone
zone_1 = var.zone_1
zone_2 = var.zone_2
}##########################################################################################
#Create an ICS instance on Google Cloud Platform(GCP)
resource "google_compute_instance" "ics_instance" {
name = var.instance_name
machine_type = var.instance_type_map["2_nics"]
zone = var.zone
boot_disk {
initialize_params {
#image = "debian-cloud/debian-9"
#image = "centos-7-v20191210"
image = data.google_compute_image.ics_image.self_link
type = "hyperdisk-balanced"
}
}
# --- SECURE BOOT CONFIGURATION ---
shielded_instance_config {
enable_secure_boot = true
enable_vtpm = true
enable_integrity_monitoring = false
}#disable strict ip address check, else GCP will not allow VMs to send packets with source IP belonging to some other device
#this is needed for pulse client use case, where the ICS has to send packets with different IP than its own
can_ip_forward = true#attach interface for internal port of ics
network_interface {
#name = "ics-int-port"
#network = var.vpc
subnetwork = var.vswitch_map[var.zone]["ics_int_port"]["name"]
access_config {
#if this block is present, then GCP assigns a public IP to this interface
#network_tier = "STANDARD" #other supported value is PREMIUM
}
}
#attach interface for external port of ics
network_interface {
#name = "ics-ext-port"
subnetwork = var.vswitch_map[var.zone]["ics_ext_port"]["name"]
access_config {
#if this block is present, then GCP assigns a public IP to this interface
#network_tier = "STANDARD" #other supported value is PREMIUM
}
}#attach metadata to the instance
metadata = {
pulse-config = "<pulse-config><primary-dns>8.8.8.8</primary-dns><secondary-dns>8.8.8.9</secondary-dns><wins-server>1.1.1.1</wins-server><dns-domain>company.domain.com</dns-domain><admin-username>admindb</admin-username><admin-password>xxxxxx</admin-password><cert-common-name>cloud-ics.company.com</cert-common-name><cert-random-text>fdsfpisonvsfnms</cert-random-text><cert-organisation>CompanyName</cert-organisation><config-download-url></config-download-url><config-data></config-data><auth-code-license></auth-code-license><enable-license-server>n</enable-license-server><accept-license-agreement>y</accept-license-agreement><registration-code></registration-code><registration-fqdn></registration-fqdn><enable-proxy>n</enable-proxy><proxy-host>1.2.3.4</proxy-host><proxy-port>3128</proxy-port><proxy-username>username</proxy-username><proxy-password>password</proxy-password><register-network-interface></register-network-interface></pulse-config>"
}##########################################################################################
#Output
#output "vswitch_id_map" {
# value = local.vswitch_id_map
#}
#output "security_group_id_map" {
# value = local.security_group_id_map
#}
#output "instance_info" {
# value = alicloud_instance.ics_instance
#}
#output "vpc_id" {
# value = [ local.vpc_id ]
#}
output "region" {
value = var.region
}
output "instance_id" {
value = google_compute_instance.ics_instance.id
}
output "ics_int_port_private_ip" {
value = google_compute_instance.ics_instance.network_interface.0.network_ip
}
#output "ics_int_port_eip_allocation_id" {
# value = alicloud_eip.ics_int_port_eip.id
#}
output "ics_int_port_elastic_ip" {
value = google_compute_instance.ics_instance.network_interface.0.access_config.0.nat_ip
}
output "ics_ext_port_private_ip" {
value = google_compute_instance.ics_instance.network_interface.1.network_ip
}
#output "ics_ext_port_eip_allocation_id" {
# value = alicloud_eip.ics_ext_port_eip.id
#}
output "ics_ext_port_elastic_ip" {
value = google_compute_instance.ics_instance.network_interface.1.access_config.0.nat_ip
}##################################################################################################################
# This terraform script is used to store the common variables used by main terraform template
#
# REQUIRED :
# * Terraform : v0.13
# * provider.gcp: version = "~> 3.5.0"
# > Run " terraform init -upgrade " if version is older
# Purpose : To store the common variables used by the main terraform script
#
##################################################################################################################
variable project_id {
default = "project_id"
}
variable region {
default = "us-south1"
}
variable zone {
default = "us-south1-a"
}
variable zone_1 {
default = "us-south1-a"
}
variable zone_2 {
default = "us-south1-b"
}
variable vpc {
default = "vpc_us_south1"
}
variable vpc_map {
type = map
default = {
"mgmt_network" = "prefix-vpc-network-mgmt",
"private_network" = "prefix-vpc-network-private",
"public_network" = "prefix-vpc-network-public",
}
}
variable vswitch_map {
type = map
default = {
"us-south1-a" = {
"ics_int_port" = {
"name" = "prefix-vsw-us-south1-a-zone-ics-int-port",
"cidr" = "11.200.36.0/26",
}
"ics_ext_port" = {
"name" = "prefix-vsw-us-south1-a-zone-ics-ext-port",
"cidr" = "11.200.36.64/26",
}
"ics_mgmt_port" = {
"name" = "prefix-vsw-us-south1-a-zone-ics-mgmt-port",
"cidr" = "11.200.36.128/26",
}
#"ics_tunnel_subnet" = {
# "name" = "VSW_ZONE_1_ICS_TUNNEL_SUBNET",
# "cidr" = "11.100.50.16/28",
#}
}
"us-south1-b" = {
"ics_int_port" = {
"name" = "prefix-vsw-us-south1-b-zone-ics-int-port",
"cidr" = "11.100.40.64/28",
}
"ics_ext_port" = {
"name" = "prefix-vsw-us-south1-b-zone-ics-ext-port",
"cidr" = "172.16.100.128/26",
}
"ics_mgmt_port" = {
"name" = "prefix-vsw-us-south1-b-zone-ics-mgmt-port",
"cidr" = "192.168.100.128/26",
}
#"ics_tunnel_subnet" = {
# "name" = "VSW_ZONE_2_ICS_TUNNEL_SUBNET",
# "cidr" = "11.100.50.64/28",
#}
}
}
}
variable firewall_map {
type = map
default = {
"ics_int_port" = "prefix-fw-ics-int-port",
"ics_ext_port" = "prefix-fw-ics-ext-port",
"ics_mgmt_port" = "prefix-fw-ics-mgmt-port",
"backend_svr" = "prefix-fw-backend-svr",
}
}
variable image_name {
default = "image_name"
}
variable image_from {
default = "self"
#default = "marketplace"
}
variable instance_type_map {
description = "The instance types that should be assigned to 2 nics or 3 nics"
type = map
default = {
"2_nics" = "n4-standard-4",
"3_nics" = "n4-standard-4",
}
}
variable instance_type {
default = "n4-standard-4"
}
variable instance_name {
default = "prefix-ics1-on-gcp"
}
variable instance_name_1 {
default = "prefix-ics1-node-1-on-gcp"
}
variable instance_name_2 {
default = "prefix-ics1-node-2-on-gcp"
}
variable cpu_core_count {
default = "4"
}
variable memory_size {
default = "8"
}
variable eni_amount {
default = "2"
}
variable gcp_bucket {
default = "bucket-california-3"
}
variable instance_charge_type {
default = "PostPaid"
}ICS with 3 NICs
##############################################################################################################################
# This terraform script is used to deploy a ICS instance with 3-nics on Google Cloud Platform(GCP)
#
# REQUIRED :
# * Terraform : v0.13 or later
# * Terraform Google Provider : 3.5.0 or later
# > Run " terraform init -upgrade " if version is older
#
##############################################################################################################################
terraform {
required_version = ">= 0.13"
required_providers {
google = {
source = "hashicorp/google"
version = ">= 3.5.0"
}
}
}##########################################################################################
provider "google" {
credentials = file("*****.json")
project = var.project_id
region = var.region
zone = var.zone
}##########################################################################################
#Data sources
#Image
data "google_compute_image" "ics_image" {
name = var.image_name
#family = "debian-9"
#project = "debian-cloud"
}
#VPCs
data "google_compute_network" "vpc_network_mgmt" {
name = var.vpc_map["mgmt_network"]
}
data "google_compute_network" "vpc_network_private" {
name = var.vpc_map["private_network"]
}
data "google_compute_network" "vpc_network_public" {
name = var.vpc_map["public_network"]
}##########################################################################################
#local variables
locals {
region = var.region
zone = var.zone
zone_1 = var.zone_1
zone_2 = var.zone_2
}##########################################################################################
#Create a ICS instance on Google Cloud Platform(GCP)
resource "google_compute_instance" "ics_instance" {
name = var.instance_name
machine_type = var.instance_type_map["3_nics"]
zone = var.zone
boot_disk {
initialize_params {
#image = "debian-cloud/debian-9"
#image = "centos-7-v20191210"
image = data.google_compute_image.ics_image.self_link
type = "hyperdisk-balanced"
}
}
# --- SECURE BOOT CONFIGURATION ---
shielded_instance_config {
enable_secure_boot = true
enable_vtpm = true
enable_integrity_monitoring = false
}#disable strict ip address check, else GCP will not allow VMs to send packets with source IP belonging to some other device
#this is needed for pulse client use case, where the ICS has to send packets with different IP than its own
can_ip_forward = true#attach interface for internal port of ics
network_interface {
#name = "ics-int-port"
#network = var.vpc
subnetwork = var.vswitch_map[var.zone]["ics_int_port"]["name"]
access_config {
#if this block is present, then GCP assigns a public IP to this interface
#network_tier = "STANDARD" #other supported value is PREMIUM
}
}#attach interface for external port of ics
network_interface {
#name = "ics-ext-port"
subnetwork = var.vswitch_map[var.zone]["ics_ext_port"]["name"]
access_config {
#if this block is present, then GCP assigns a public IP to this interface
#network_tier = "STANDARD" #other supported value is PREMIUM
}
}#attach interface for management port of ics
network_interface {
#name = "ics_mgmt_port"
subnetwork = var.vswitch_map[var.zone]["ics_mgmt_port"]["name"]
access_config {
#if this block is present, then GCP assigns a public IP to this interface
#network_tier = "STANDARD" #other supported value is PREMIUM
}
}#attach metadata to the instance
metadata = {
pulse-config = "<pulse-config><primary-dns>8.8.8.8</primary-dns><secondary-dns>8.8.8.9</secondary-dns><wins-server>1.1.1.1</wins-server><dns-domain>company.domain.com</dns-domain><admin-username>admindb</admin-username><admin-password>xxxxxx</admin-password><cert-common-name>cloud-ics.company.com</cert-common-name><cert-random-text>fdsfpisonvsfnms</cert-random-text><cert-organisation>CompanyName</cert-organisation><config-download-url></config-download-url><config-data></config-data><auth-code-license></auth-code-license><enable-license-server>n</enable-license-server><accept-license-agreement>y</accept-license-agreement><registration-code></registration-code><registration-fqdn></registration-fqdn><enable-proxy>n</enable-proxy><proxy-host>1.2.3.4</proxy-host><proxy-port>3128</proxy-port><proxy-username>username</proxy-username><proxy-password>password</proxy-password><register-network-interface></register-network-interface></pulse-config>"
}
}##########################################################################################
#Output
#output "vswitch_id_map" {
#value = local.vswitch_id_map
#}
#output "security_group_id_map" {
#value = local.security_group_id_map
#}
#output "instance_info" {
#value = alicloud_instance.ics_instance
#}
#output "vpc_id" {
#value = [ local.vpc_id ]
#}
output "region" {
value = var.region
}
output "instance_id" {
value = google_compute_instance.ics_instance.id
}
output "ics_int_port_private_ip" {
value = google_compute_instance.ics_instance.network_interface.0.network_ip
}
#output "ics_int_port_eip_allocation_id" {
#value = alicloud_eip.ics_int_port_eip.id
#}
output "ics_int_port_elastic_ip" {
value = google_compute_instance.ics_instance.network_interface.0.access_config.0.nat_ip
}
output "ics_ext_port_private_ip" {
value = google_compute_instance.ics_instance.network_interface.1.network_ip
}
#output "ics_ext_port_eip_allocation_id" {
#value = alicloud_eip.ics_ext_port_eip.id
#}
output "ics_ext_port_elastic_ip" {
value = google_compute_instance.ics_instance.network_interface.1.access_config.0.nat_ip
}
output "ics_mgmt_port_private_ip" {
value = google_compute_instance.ics_instance.network_interface.2.network_ip
}
#output "ics_mgmt_port_eip_allocation_id" {
#value = alicloud_eip.ics_mgmt_port_eip.id
#}
output "ics_mgmt_port_elastic_ip" {
value = google_compute_instance.ics_instance.network_interface.2.access_config.0.nat_ip
}##################################################################################################################
#This terraform script is used to store the common variables used by main terraform template
#
#REQUIRED:
# * Terraform : v0.13
# * provider.gcp: version = "~> 3.5.0"
#> Run " terraform init -upgrade " if version is older
#Purpose : To store the common variables used by the main terraform script
#
##################################################################################################################
variable project_id {
default = "project_id"
}
variable region {
default = "us-south1"
}
variable zone {
default = "us-south1-a"
}
variable zone_1 {
default = "us-south1-a"
}
variable zone_2 {
default = "us-south1-b"
}
variable vpc {
default = "vpc_us_south1"
}
variable vpc_map {
type = map
default = {
"mgmt_network" = "prefix-vpc-network-mgmt",
"private_network" = "prefix-vpc-network-private",
"public_network" = "prefix-vpc-network-public",
}
}
variable vswitch_map {
type = map
default = {
"us-south1-a" = {
"ics_int_port" = {
"name" = "prefix-vsw-us-south1-a-zone-ics-int-port",
"cidr" = "11.200.36.0/26",
}
"ics_ext_port" = {
"name" = "prefix-vsw-us-south1-a-zone-ics-ext-port",
"cidr" = "11.200.36.64/26",
}
"ics_mgmt_port" = {
"name" = "prefix-vsw-us-south1-a-zone-ics-mgmt-port",
"cidr" = "11.200.36.128/26",
}
#"ics_tunnel_subnet" = {
#"name" = "VSW_ZONE_1_ICS_TUNNEL_SUBNET",
#"cidr" = "11.100.50.16/28",
#}
}
"us-south1-b" = {
"ics_int_port" = {
"name" = "prefix-vsw-us-south1-b-zone-ics-int-port",
"cidr" = "11.100.40.64/28",
}
"ics_ext_port" = {
"name" = "prefix-vsw-us-south1-b-zone-ics-ext-port",
"cidr" = "172.16.100.128/26",
}
"ics_mgmt_port" = {
"name" = "prefix-vsw-us-south1-b-zone-ics-mgmt-port",
"cidr" = "192.168.100.128/26",
}
#"ics_tunnel_subnet" = {
#"name" = "VSW_ZONE_2_ICS_TUNNEL_SUBNET",
#"cidr" = "11.100.50.64/28",
#}
}
}
}
variable firewall_map {
type = map
default = {
"ics_int_port" = "prefix-fw-ics-int-port",
"ics_ext_port" = "prefix-fw-ics-ext-port",
"ics_mgmt_port" = "prefix-fw-ics-mgmt-port",
"backend_svr" = "prefix-fw-backend-svr",
}
}
variable image_name {
default = "image_name"
}
variable image_from {
default = "self"
#default = "marketplace"
}
variable instance_type_map {
description = "The instance types that should be assigned to 2 nics or 3 nics"
type = map
default = {
"2_nics" = "n4-standard-4",
"3_nics" = "n4-standard-4",
}
}
variable instance_type {
default = "n4-standard-4"
}
variable instance_name {
default = "prefix-ics1-on-gcp"
}
variable instance_name_1 {
default = "prefix-ics1-node-1-on-gcp"
}
variable instance_name_2 {
default = "prefix-ics1-node-2-on-gcp"
}
variable cpu_core_count {
default = "4"
}
variable memory_size {
default = "8"
}
variable eni_amount {
default = "2"
}
variable gcp_bucket {
default = "bucket-california-3"
}
variable instance_charge_type {
default = "PostPaid"
}Image Creation
##############################################################################################################################
# This terraform script is used to deploy a ICS instance with 2-nics on Google Cloud Platform(GCP)
#
# REQUIRED :
# * Terraform : v0.13 or later
# * Terraform Google Provider : 3.5.0 or later
# > Run " terraform init -upgrade " if version is older
#
##############################################################################################################################
terraform {
required_version = ">= 0.13"
required_providers {
google = {
source = "hashicorp/google"
version = ">= 3.5.0"
}
}
}##########################################################################################
provider "google" {
credentials = file("*****.json")
project = var.project_id
region = var.region
zone = var.zone
}##########################################################################################
resource "google_compute_image" "custom_image" {
name = var.image_name
raw_disk {
source = "https://storage.googleapis.com/${var.bucket_name}/${var.image_file}"
}
guest_os_features {
type = "UEFI_COMPATIBLE"
}
guest_os_features {
type = "GVNIC"
}
guest_os_features {
type = "MULTI_IP_SUBNET"
}
shielded_instance_initial_state {
dbs {
content = filebase64(var.signature_db)
file_type = "X509"
}
}
}##################################################################################################################
# This terraform script is used to store the common variables used by main terraform template
#
# REQUIRED :
# * Terraform : v0.13
# * provider.gcp: version = "~> 3.5.0"
# > Run " terraform init -upgrade " if version is older
# Purpose : To store the common variables used by the main terraform script
#
##################################################################################################################
variable project_id {
default = "project_id"
}
variable region {
default = "us-south1"
}
variable zone {
default = "us-south1-a"
}
variable zone_1 {
default = "us-south1-a"
}
variable zone_2 {
default = "us-south1-b"
}
variable image_name {
default = "image_name"
}
variable bucket_name {
default = "bucket-california-3"
}
variable image_file {
default = "image_file.tar.gz"
}
variable signature_db {
default = "db.der"
}Variables
##################################################################################################################
# This terraform script is used to store the common variables used by main terraform template
#
# REQUIRED :
# * Terraform : v0.13
# * provider.gcp: version = "~> 3.5.0"
# > Run " terraform init -upgrade " if version is older
# Purpose : To store the common variables used by the main terraform script
#
##################################################################################################################
variable project_id {
default = "project_id"
}
variable region {
default = "us-south1"
}
variable zone {
default = "us-south1-a"
}
variable zone_1 {
default = "us-south1-a"
}
variable zone_2 {
default = "us-south1-b"
}
variable vpc {
default = "vpc_us_south1"
}
variable vpc_map {
type = map
default = {
"mgmt_network" = "prefix-vpc-network-mgmt",
"private_network" = "prefix-vpc-network-private",
"public_network" = "prefix-vpc-network-public",
}
}
variable vswitch_map {
type = map
default = {
"us-south1-a" = {
"ics_int_port" = {
"name" = "prefix-vsw-us-south1-a-zone-ics-int-port",
"cidr" = "11.200.36.0/26",
}
"ics_ext_port" = {
"name" = "prefix-vsw-us-south1-a-zone-ics-ext-port",
"cidr" = "11.200.36.64/26",
}
"ics_mgmt_port" = {
"name" = "prefix-vsw-us-south1-a-zone-ics-mgmt-port",
"cidr" = "11.200.36.128/26",
}
#"ics_tunnel_subnet" = {
#"name" = "VSW_ZONE_1_ICS_TUNNEL_SUBNET",
#"cidr" = "11.100.50.16/28",
#}
}
"us-south1-b" = {
"ics_int_port" = {
"name" = "prefix-vsw-us-south1-b-zone-ics-int-port",
"cidr" = "11.100.40.64/28",
}
"ics_ext_port" = {
"name" = "prefix-vsw-us-south1-b-zone-ics-ext-port",
"cidr" = "172.16.100.128/26",
}
"ics_mgmt_port" = {
"name" = "prefix-vsw-us-south1-b-zone-ics-mgmt-port",
"cidr" = "192.168.100.128/26",
}
#"ics_tunnel_subnet" = {
#"name" = "VSW_ZONE_2_ICS_TUNNEL_SUBNET",
#"cidr" = "11.100.50.64/28",
#}
}
}
}
variable firewall_map {
type = map
default = {
"ics_int_port" = "prefix-fw-ics-int-port",
"ics_ext_port" = "prefix-fw-ics-ext-port",
"ics_mgmt_port" = "prefix-fw-ics-mgmt-port",
"backend_svr" = "prefix-fw-backend-svr",
}
}
variable image_name {
default = "image_name"
}
variable image_from {
default = "self"
#default = "marketplace"
}
variable instance_type_map {
description = "The instance types that should be assigned to 2 nics or 3 nics"
type = map
default = {
"2_nics" = "n4-standard-4",
"3_nics" = "n4-standard-4",
}
}
variable instance_type {
default = "n4-standard-4"
}
variable instance_name {
default = "prefix-ics1-on-gcp"
}
variable instance_name_1 {
default = "prefix-ics1-node-1-on-gcp"
}
variable instance_name_2 {
default = "prefix-ics1-node-2-on-gcp"
}
variable cpu_core_count {
default = "4"
}
variable memory_size {
default = "8"
}
variable eni_amount {
default = "2"
}
variable gcp_bucket {
default = "bucket-california-3"
}
variable instance_charge_type {
default = "PostPaid"
}