{"repo":"alpersonalwebsite/cloudformation","free":true,"listed":false,"github":"https://github.com/alpersonalwebsite/cloudformation","clone":"git clone https://github.com/alpersonalwebsite/cloudformation.git","description":"CloudFormation templates for common AWS setups: networking, highly available web apps with and without a bastion host, highly available RDS, Aurora Serverless PostgreSQL, Fargate, IAM and StackSets.","language":null,"stars":114,"topics":["cfn-templates","cfn","cloudformation","aws","aws-cloudformation","aurora-serverless","fargate","high-availability","iam","infrastructure-as-code"],"license":null,"category":"deployment-docker-iac","readme_excerpt":"CloudFormation templates A set of small, self-contained CloudFormation stacks, each one a worked example of a single piece of AWS infrastructure. Clone it, read the template, deploy it, delete it. Every directory has its own README with the exact aws cloudformation commands and a matching -parameters.json . The committed parameter files are meant to deploy as they are, apart from the handful of values called out under Secrets below. Directory What it builds --- --- network/ The smallest useful template in the repo: one AWS::EC2::VPC ec2-instance-with-cfinit.yml A single EC2 instance that installs Apache and PHP through cfn-init highly-available-web-app/ Autoscaling web tier in private subnets behind an Application Load Balancer highly-available-web-app-with-bastion-host/ The same, with a bastion host as the only SSH entry point fargate/ ECS on Fargate: network, task execution role, cluster with a load balancer, service aurora-serverless-postgresql/ An Aurora Serverless PostgreSQL cluster, plus an EC2 client to reach it highly-available-RDS/ A StackSet-deployed VPC in two regions, a MySQL primary and a cross-region read replica IAM/ A user, a group, and a self-service policy for access keys and MFA StackSets/ The administration and execution roles StackSets needs Conventions shared across the templates Secrets No template takes a password as a parameter. Passwords are read at deploy time from Secrets Manager with a dynamic reference: That matters more than NoEcho does. A NoEch","default_branch":null,"files":null,"tree":[],"storefront":"/r/alpersonalwebsite","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/alpersonalwebsite/cloudformation/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}