Skip to content

Commit 185ca42

Browse files
authored
chore(iac/aws/networking): remove redundant Secrets Manager VPC endpoint (#915)
* chore(iac/aws/networking): remove redundant Secrets Manager VPC endpoint The interface endpoint was unconditional and redundant: every env runs fck-NAT (enable_nat_gateway = true), so in-VPC Secrets Manager consumers (main Lambda, cleanup Lambda, Fargate) will reach SM over NAT regardless. Removes: - aws_vpc_endpoint.secretsmanager (~$14/mo across 2 AZs) - aws_security_group.vpc_endpoints (the endpoint was its sole consumer) - the three matching outputs (vpc_endpoints_security_group_id, secretsmanager_endpoint_id, secretsmanager_endpoint_dns -- grep confirmed no consumers) Header comment updated to reflect actual topology (NAT present, per-service interface endpoints removed). Precondition for safety: enable_nat_gateway must remain true in every environment. If a future change turns NAT off, this endpoint (and likely the ECR ones too) needs to be reintroduced first. * fix(iac/networking): enforce NAT-or-IPv4-endpoint precondition (CR on #915) Add lifecycle.precondition to aws_subnet.private that fails at plan time when enable_nat_gateway is false. Without NAT, module-created private subnets have no IPv4 path to AWS services (Secrets Manager, ECR, etc.) and the module previously planned successfully in this broken configuration. Addresses CodeRabbit Major finding on PR #915. * fix(iac/aws/networking): address CR + pre-commit on SM endpoint removal (#915) - Remove unused data "aws_region" "current" (the SM endpoint was its sole consumer; tflint flagged it as unused). - Restore trailing newline on outputs.tf. - Add lifecycle.precondition on aws_vpc.main that fails the plan when enable_nat_gateway is false: in-VPC workloads (Lambda, Fargate) need NAT for AWS API egress now that per-service interface endpoints are gone. Fails fast instead of relying on doc-only safety as flagged by CodeRabbit. * fix(iac/aws/networking): drop duplicate NAT precondition on aws_vpc.main Commit e395c03 already adds the same precondition on aws_subnet.private, which is the more accurate trigger (it fires only when private subnets are actually being created). Keeping both checked the same variable twice and emitted redundant errors. Drop the one on aws_vpc.main.
1 parent d29a3e0 commit 185ca42

2 files changed

Lines changed: 10 additions & 90 deletions

File tree

‎terraform/modules/networking/aws/main.tf‎

Lines changed: 10 additions & 74 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
# AWS VPC Module with IPv6
2-
# Creates VPC with IPv6 support - no NAT Gateway or VPC Endpoints needed
3-
# Cost savings: ~$54/month (NAT Gateway + VPC Endpoints eliminated)
2+
# Creates VPC with IPv6 support. NAT (fck-nat) handles egress for ECR pulls
3+
# and any AWS APIs that lack IPv6, so we no longer need per-service VPC
4+
# interface endpoints.
45
# Supports: new VPC, existing VPC, or default VPC
56

67
terraform {
@@ -405,6 +406,13 @@ resource "aws_subnet" "private" {
405406
Name = "${var.stack_name}-private-${data.aws_availability_zones.available.names[count.index]}"
406407
Type = "private"
407408
})
409+
410+
lifecycle {
411+
precondition {
412+
condition = var.enable_nat_gateway
413+
error_message = "enable_nat_gateway must be true when creating private subnets: without it, module-created private subnets have no IPv4 path to AWS services (Secrets Manager, ECR, etc.). Enable the fck-nat instance or use an existing VPC with its own egress."
414+
}
415+
}
408416
}
409417

410418
# ==============================================
@@ -683,75 +691,3 @@ resource "aws_iam_role_policy" "flow_logs" {
683691
]
684692
})
685693
}
686-
687-
# ==============================================
688-
# VPC Endpoints (for services without IPv6 support)
689-
# ==============================================
690-
691-
# Security group for VPC endpoints
692-
resource "aws_security_group" "vpc_endpoints" {
693-
name_prefix = "${var.stack_name}-vpc-endpoints-"
694-
description = "Security group for VPC endpoints"
695-
vpc_id = local.vpc_id
696-
697-
# HTTPS from VPC (IPv4)
698-
ingress {
699-
description = "HTTPS from VPC (IPv4)"
700-
from_port = 443
701-
to_port = 443
702-
protocol = "tcp"
703-
cidr_blocks = [local.vpc_cidr]
704-
}
705-
706-
# HTTPS from VPC (IPv6)
707-
ingress {
708-
description = "HTTPS from VPC (IPv6)"
709-
from_port = 443
710-
to_port = 443
711-
protocol = "tcp"
712-
ipv6_cidr_blocks = var.enable_ipv6 ? [local.vpc_ipv6_cidr] : []
713-
}
714-
715-
# Allow all outbound (IPv4)
716-
egress {
717-
description = "Allow all outbound (IPv4)"
718-
from_port = 0
719-
to_port = 0
720-
protocol = "-1"
721-
cidr_blocks = ["0.0.0.0/0"]
722-
}
723-
724-
# Allow all outbound (IPv6)
725-
egress {
726-
description = "Allow all outbound (IPv6)"
727-
from_port = 0
728-
to_port = 0
729-
protocol = "-1"
730-
ipv6_cidr_blocks = ["::/0"]
731-
}
732-
733-
tags = merge(var.tags, {
734-
Name = "${var.stack_name}-vpc-endpoints-sg"
735-
})
736-
737-
lifecycle {
738-
create_before_destroy = true
739-
}
740-
}
741-
742-
# Secrets Manager VPC Endpoint (required - no IPv6 support)
743-
resource "aws_vpc_endpoint" "secretsmanager" {
744-
vpc_id = local.vpc_id
745-
service_name = "com.amazonaws.${data.aws_region.current.name}.secretsmanager"
746-
vpc_endpoint_type = "Interface"
747-
subnet_ids = local.private_subnet_ids
748-
security_group_ids = [aws_security_group.vpc_endpoints.id]
749-
private_dns_enabled = true
750-
751-
tags = merge(var.tags, {
752-
Name = "${var.stack_name}-secretsmanager-endpoint"
753-
})
754-
}
755-
756-
# Data source for current region
757-
data "aws_region" "current" {}

‎terraform/modules/networking/aws/outputs.tf‎

Lines changed: 0 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -98,19 +98,3 @@ output "database_vpc_config" {
9898
security_group_id = aws_security_group.database.id
9999
}
100100
}
101-
102-
# VPC Endpoints
103-
output "vpc_endpoints_security_group_id" {
104-
description = "Security group ID for VPC endpoints"
105-
value = aws_security_group.vpc_endpoints.id
106-
}
107-
108-
output "secretsmanager_endpoint_id" {
109-
description = "Secrets Manager VPC endpoint ID"
110-
value = aws_vpc_endpoint.secretsmanager.id
111-
}
112-
113-
output "secretsmanager_endpoint_dns" {
114-
description = "Secrets Manager VPC endpoint DNS names"
115-
value = aws_vpc_endpoint.secretsmanager.dns_entry
116-
}

0 commit comments

Comments
 (0)