From df2d01d33f700eec24f5ccc721d655c82997b72c Mon Sep 17 00:00:00 2001 From: badra001 Date: Mon, 10 May 2021 14:17:27 -0400 Subject: [PATCH] add additional rules --- common/defaults.tf | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/common/defaults.tf b/common/defaults.tf index 9f6ec12..2078a4b 100644 --- a/common/defaults.tf +++ b/common/defaults.tf @@ -25,12 +25,15 @@ locals { # basic outbounds ephemeral_outbound = [1024, 65535, true, "tcp", "allow", "ephemeral-outbound"] all_outbound = [0, 0, true, "all", "allow", "all-outbound"] + http_outbound = [80, 80, true, "tcp", "allow", "http-outbound"] + https_outbound = [443, 443, true, "tcp", "allow", "https-outbound"] # basic inbounds - all_inbound = [0, 0, false, "all", "allow", "all-inbound"] - http_inbound = [80, 80, false, "tcp", "allow", "http-inbound"] - https_inbound = [443, 443, false, "tcp", "allow", "https-inbound"] - ssh_inbound = [22, 22, false, "tcp", "allow", "https-inbound"] + ephemeral_inbound = [1024, 65535, false, "tcp", "allow", "ephemeral-inbound"] + all_inbound = [0, 0, false, "all", "allow", "all-inbound"] + http_inbound = [80, 80, false, "tcp", "allow", "http-inbound"] + https_inbound = [443, 443, false, "tcp", "allow", "https-inbound"] + ssh_inbound = [22, 22, false, "tcp", "allow", "https-inbound"] } #--- # vpc varies by specific VPC cidr block, this will be merged with the actual vpc CIDR