diff --git a/README.md b/README.md index 23b293a..7544718 100644 --- a/README.md +++ b/README.md @@ -1,24 +1,20 @@ - -[![README Header][readme_header_img]][readme_header_link] - -[![Cloud Posse][logo]](https://cpco.io/homepage) - -# terraform-aws-tfstate-backend [![Latest Release](https://img.shields.io/github/release/cloudposse/terraform-aws-tfstate-backend.svg)](https://github.com/cloudposse/terraform-aws-tfstate-backend/releases/latest) [![Slack Community](https://slack.cloudposse.com/badge.svg)](https://slack.cloudposse.com) - +--> Terraform module to provision an S3 bucket to store `terraform.tfstate` file and a DynamoDB table to lock the state file to prevent concurrent modifications and state corruption. @@ -65,7 +45,7 @@ __NOTE:__ This module cannot be used to apply changes to the `mfa_delete` featur --- -This project is part of our comprehensive ["SweetOps"](https://cpco.io/sweetops) approach towards DevOps. +This project is part of our comprehensive ["SweetOps"](https://cpco.io/sweetops) approach towards DevOps. [][share_email] [][share_googleplus] [][share_facebook] @@ -86,7 +66,7 @@ It's 100% Open Source and licensed under the [APACHE2](LICENSE). -We literally have [*hundreds of terraform modules*][terraform_modules] that are Open Source and well-maintained. Check them out! +We literally have [*hundreds of terraform modules*][terraform_modules] that are Open Source and well-maintained. Check them out! @@ -199,8 +179,9 @@ Follow this procedure to delete your deployment. + ## Makefile Targets -``` +```text Available targets: help Help screen @@ -209,6 +190,7 @@ Available targets: lint Lint terraform code ``` + ## Requirements | Name | Version | @@ -235,6 +217,7 @@ Available targets: | additional\_tag\_map | Additional tags for appending to each tag map | `map(string)` | `{}` | no | | arn\_format | ARN format to be used. May be changed to support deployment in GovCloud/China regions. | `string` | `"arn:aws"` | no | | attributes | Additional attributes (e.g. `state`) | `list(string)` |
[
"state"
]
| no | +| backend\_config\_file\_overwrite\_enabled | If false, the backend config file will not be overwritten if it exists. | `bool` | `true` | no | | billing\_mode | DynamoDB billing mode | `string` | `"PROVISIONED"` | no | | block\_public\_acls | Whether Amazon S3 should block public ACLs for this bucket | `bool` | `true` | no | | block\_public\_policy | Whether Amazon S3 should block public bucket policies for this bucket | `bool` | `true` | no | @@ -282,9 +265,9 @@ Available targets: -## Share the Love +## Share the Love -Like this project? Please give it a ★ on [our GitHub](https://github.com/cloudposse/terraform-aws-tfstate-backend)! (it helps us **a lot**) +Like this project? Please give it a ★ on [our GitHub](https://github.com/cloudposse/terraform-aws-tfstate-backend)! (it helps us **a lot**) Are you using this project or any of our other projects? Consider [leaving a testimonial][testimonial]. =) @@ -300,7 +283,7 @@ Check out these related projects. ## Help -**Got a question?** We got answers. +**Got a question?** We got answers. File a GitHub [issue](https://github.com/cloudposse/terraform-aws-tfstate-backend/issues), send us an [email][email] or join our [Slack Community][slack]. @@ -309,7 +292,7 @@ File a GitHub [issue](https://github.com/cloudposse/terraform-aws-tfstate-backen ## DevOps Accelerator for Startups -We are a [**DevOps Accelerator**][commercial_support]. We'll help you build your cloud infrastructure from the ground up so you can own it. Then we'll show you how to operate it and stick around for as long as you need us. +We are a [**DevOps Accelerator**][commercial_support]. We'll help you build your cloud infrastructure from the ground up so you can own it. Then we'll show you how to operate it and stick around for as long as you need us. [![Learn More](https://img.shields.io/badge/learn%20more-success.svg?style=for-the-badge)][commercial_support] @@ -338,11 +321,11 @@ Participate in our [Discourse Forums][discourse]. Here you'll find answers to co ## Newsletter -Sign up for [our newsletter][newsletter] that covers everything on our technology radar. Receive updates on what we're up to on GitHub as well as awesome new projects we discover. +Sign up for [our newsletter][newsletter] that covers everything on our technology radar. Receive updates on what we're up to on GitHub as well as awesome new projects we discover. ## Office Hours -[Join us every Wednesday via Zoom][office_hours] for our weekly "Lunch & Learn" sessions. It's **FREE** for everyone! +[Join us every Wednesday via Zoom][office_hours] for our weekly "Lunch & Learn" sessions. It's **FREE** for everyone! [![zoom](https://img.cloudposse.com/fit-in/200x200/https://cloudposse.com/wp-content/uploads/2019/08/Powered-by-Zoom.png")][office_hours] @@ -373,28 +356,30 @@ Copyright © 2017-2020 [Cloud Posse, LLC](https://cpco.io/copyright) -## License +## License -[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0) +[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0) See [LICENSE](LICENSE) for full details. - Licensed to the Apache Software Foundation (ASF) under one - or more contributor license agreements. See the NOTICE file - distributed with this work for additional information - regarding copyright ownership. The ASF licenses this file - to you under the Apache License, Version 2.0 (the - "License"); you may not use this file except in compliance - with the License. You may obtain a copy of the License at - - https://www.apache.org/licenses/LICENSE-2.0 - - Unless required by applicable law or agreed to in writing, - software distributed under the License is distributed on an - "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY - KIND, either express or implied. See the License for the - specific language governing permissions and limitations - under the License. +```text +Licensed to the Apache Software Foundation (ASF) under one +or more contributor license agreements. See the NOTICE file +distributed with this work for additional information +regarding copyright ownership. The ASF licenses this file +to you under the Apache License, Version 2.0 (the +"License"); you may not use this file except in compliance +with the License. You may obtain a copy of the License at + + https://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, +software distributed under the License is distributed on an +"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +KIND, either express or implied. See the License for the +specific language governing permissions and limitations +under the License. +``` @@ -416,7 +401,7 @@ This project is maintained and funded by [Cloud Posse, LLC][website]. Like it? P We're a [DevOps Professional Services][hire] company based in Los Angeles, CA. We ❤️ [Open Source Software][we_love_open_source]. -We offer [paid support][commercial_support] on all of our projects. +We offer [paid support][commercial_support] on all of our projects. Check out [our other projects][github], [follow us on twitter][twitter], [apply for a job][jobs], or [hire us][hire] to help with your cloud strategy and implementation. diff --git a/docs/targets.md b/docs/targets.md index 3d4be2a..3dce8b3 100644 --- a/docs/targets.md +++ b/docs/targets.md @@ -1,5 +1,6 @@ + ## Makefile Targets -``` +```text Available targets: help Help screen @@ -8,3 +9,4 @@ Available targets: lint Lint terraform code ``` + diff --git a/docs/terraform.md b/docs/terraform.md index 4e0582e..bbc8545 100644 --- a/docs/terraform.md +++ b/docs/terraform.md @@ -24,6 +24,7 @@ | additional\_tag\_map | Additional tags for appending to each tag map | `map(string)` | `{}` | no | | arn\_format | ARN format to be used. May be changed to support deployment in GovCloud/China regions. | `string` | `"arn:aws"` | no | | attributes | Additional attributes (e.g. `state`) | `list(string)` |
[
"state"
]
| no | +| backend\_config\_file\_overwrite\_enabled | If false, the backend config file will not be overwritten if it exists. | `bool` | `true` | no | | billing\_mode | DynamoDB billing mode | `string` | `"PROVISIONED"` | no | | block\_public\_acls | Whether Amazon S3 should block public ACLs for this bucket | `bool` | `true` | no | | block\_public\_policy | Whether Amazon S3 should block public bucket policies for this bucket | `bool` | `true` | no | diff --git a/main.tf b/main.tf index 186b151..6b09ab6 100644 --- a/main.tf +++ b/main.tf @@ -14,6 +14,10 @@ locals { terraform_backend_config_template_file = var.terraform_backend_config_template_file != "" ? var.terraform_backend_config_template_file : "${path.module}/templates/terraform.tf.tpl" + terraform_backend_config_file_exists = fileexists(local.terraform_backend_config_file) + + overwrite_backend_config_file = (! local.terraform_backend_config_file_exists || var.backend_config_file_overwrite_enabled) && var.terraform_backend_config_file_path != "" + bucket_name = var.s3_bucket_name != "" ? var.s3_bucket_name : module.s3_bucket_label.id } @@ -246,8 +250,11 @@ data "template_file" "terraform_backend_config" { } } +# We only write the backend config file if: +# 1. The file doesn't exist and the module was given `terraform_backend_config_file_path` +# 2. The file does exist, `backend_config_file_overwrite_enabled` is `true`, and the module was given `terraform_backend_config_file_path` resource "local_file" "terraform_backend_config" { - count = var.terraform_backend_config_file_path != "" ? 1 : 0 + count = local.overwrite_backend_config_file ? 1 : 0 content = data.template_file.terraform_backend_config.rendered filename = local.terraform_backend_config_file } diff --git a/variables.tf b/variables.tf index cc1f91f..5a9fd7e 100644 --- a/variables.tf +++ b/variables.tf @@ -221,6 +221,12 @@ variable "terraform_state_file" { description = "The path to the state file inside the bucket" } +variable "backend_config_file_overwrite_enabled" { + type = bool + default = true + description = "If false, the backend config file will not be overwritten if it exists." +} + variable "s3_bucket_name" { type = string default = ""