{"repo":"cloudposse/terraform-aws-vpc-flow-logs-s3-bucket","free":true,"listed":false,"github":"https://github.com/cloudposse/terraform-aws-vpc-flow-logs-s3-bucket","clone":"git clone https://github.com/cloudposse/terraform-aws-vpc-flow-logs-s3-bucket.git","description":"Terraform module to provision s3-backed flow logs for VPC and subnets","language":"HCL","stars":27,"topics":["vpc","flowlogs","logging","s3","s3-bucket","subnets","hcl2"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Terraform module to create AWS VPC Flow logs backed by S3. [!TIP] #### 👽 Use Atmos with Terraform Cloud Posse uses atmos to easily orchestrate multiple environments using Terraform. Works with Github Actions, Atlantis, or Spacelift. Watch demo of using Atmos with Terraform Example of running atmos to manage infrastructure from our Quick Start tutorial. Introduction The module will create: S3 bucket with server side encryption KMS key to encrypt flow logs files in the bucket Optional VPC Flow Log backed by the S3 bucket (this can be disabled, e.g. in multi-account environments if you want to create an S3 bucket in one account and VPC Flow Logs in different accounts) Cross-account / multi-account delivery : When centralizing VPC Flow Logs from multiple AWS accounts into a single Log Archive account, set either flow logs source org id (to authorize all accounts in an AWS Organization) or flow logs source account ids (to list individual accounts). These add aws:SourceOrgID / aws:SourceAccount + aws:SourceArn conditions to the bucket delivery policy for confused-deputy protection. The KMS key policy is scoped with the same aws:SourceOrgID / aws:SourceAccount conditions so cross-account key usage is equally protected. BucketOwnerEnforced compatibility : When s3 object ownership is BucketOwnerEnforced (the recommended setting, and the default when null is passed), the module omits the s3:x-amz-acl condition from the AWSLogDeliveryWrite policy statement. With ACLs disabled, the deli","default_branch":null,"files":null,"tree":[],"storefront":"/r/cloudposse","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/cloudposse/terraform-aws-vpc-flow-logs-s3-bucket/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}