-
Notifications
You must be signed in to change notification settings - Fork 3
/
compute.tf
107 lines (98 loc) · 3.07 KB
/
compute.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
# -----------------------------------------------------------------------------------
# Kali Linux VM
resource "google_compute_instance" "kali" {
name = "${local.prefix}-kali"
machine_type = "n1-standard-1"
zone = data.google_compute_zones.main.names[0]
tags = ["kali"]
boot_disk {
initialize_params {
image = var.image_kali
}
}
network_interface {
subnetwork = module.vpc_trust.subnet_self_link["${var.region}-trust-subnet"]
network_ip = var.ip_kali
}
service_account {
scopes = var.service_scopes
}
}
# -----------------------------------------------------------------------------------
# Jenkins VM
resource "google_compute_instance" "jenkins" {
name = "${local.prefix}-jenkins"
machine_type = "n1-standard-1"
zone = data.google_compute_zones.main.names[0]
tags = ["jenkins"]
boot_disk {
initialize_params {
image = var.image_jenkins
}
}
network_interface {
subnetwork = module.vpc_trust.subnet_self_link["${var.region}-trust-subnet"]
network_ip = var.ip_jenkins
}
service_account {
scopes = var.service_scopes
}
}
# -----------------------------------------------------------------------------------
# Juice Shop VM
resource "google_compute_instance" "juice_shop" {
name = "${local.prefix}-juice-shop"
machine_type = "n1-standard-1"
zone = data.google_compute_zones.main.names[0]
tags = ["juice-shop"]
boot_disk {
initialize_params {
image = var.image_juice
}
}
network_interface {
subnetwork = module.vpc_trust.subnet_self_link["${var.region}-trust-subnet"]
network_ip = var.ip_juice
}
service_account {
scopes = var.service_scopes
}
}
# -----------------------------------------------------------------------------------
# Create bootstrap bucket for VM-Series and create VM-Series firewalls. \
module "vmseries" {
source = "./modules/vmseries/"
image_prefix_uri = var.vmseries_image_url
image_name = var.vmseries_image_name
machine_type = var.vmseries_machine_type
create_instance_group = true
#project = var.project_id
#ssh_key = fileexists(var.public_key_path) ? "admin:${file(var.public_key_path)}" : ""
instances = {
vmseries01 = {
name = "${local.prefix}-vmseries01"
zone = data.google_compute_zones.main.names[0]
bootstrap_bucket = "" #var.vmseries_bootstrap_bucket
network_interfaces = [
{
subnetwork = module.vpc_untrust.subnet_self_link["${var.region}-untrust-subnet"]
public_nat = true
},
{
subnetwork = module.vpc_mgmt.subnet_self_link["${var.region}-mgmt-subnet"]
public_nat = true
},
{
subnetwork = module.vpc_trust.subnet_self_link["${var.region}-trust-subnet"]
public_nat = false
network_ip = var.ip_vmseries
}
]
}
}
depends_on = [
google_compute_instance.kali,
google_compute_instance.juice_shop,
google_compute_instance.jenkins
]
}