An opinionated AWS VPC module: 3 subnet tiers across N AZs, optional NAT (per-AZ or single), Gateway + Interface VPC endpoints, VPC Flow Logs to CloudWatch or S3 with a least-privilege IAM role, an emptied default security group, and governance tags enforced by type.
namecidr_blockaz_countsubnet_newbitsenable_public_subnetsmap_public_ip_on_launchenable_database_subnetsdatabase_route_to_natenable_nat_gatewaysingle_nat_gatewayenable_dns_hostnamesinstance_tenancyenable_network_address_usage_metricslock_default_security_groupenable_flow_logsflow_log_destination_typeflow_log_s3_bucket_arnflow_log_traffic_typeflow_log_retention_daysflow_log_kms_key_arnmodule "x" {
source = "./terraform-module-vpc-aws-landing-zone"
}
This page is the working piece. The full pack has everything below.
27 typed inputs, 30 outputs, 29 resources in one module — Flow Logs on by default, the default security group left with zero rules, auto-assign public IP off, database tier with no default r
A competing module on this shelf sells at $3 today (measured on this shelf, 50% of which is paid). What is being bought instead of hand-rolling: the 29 resources, 27 typed and validated inputs, 30 outputs, 2 apply-time preconditio
Send it to me