New Guides for Terraform Modules
hashicorp.com
hashicorp.com
data "aws_iam_policy_document" "s3_bucket" {
version = "2012-10-17"
statement {
sid = "PublicReadGetObject"
principals {
type = "*"
identifiers = ["*"]
}
actions = [
"s3:GetObject"
]
resources = [
"arn:aws:s3:::${var.bucket_name}/*"
]
}
}
resource "aws_s3_bucket" "s3_bucket" {
bucket = var.bucket_name
acl = "public-read"
policy = data.aws_iam_policy_document.s3_bucket.json
website {
index_document = "index.html"
error_document = "error.html"
}
tags = var.tags
}As much documentation as they have, Hashicorp products can be very confusing.
Also, like, most of their examples ignore this data resource. That specific data resource, with terraform 0.12 makes building IAMs so much nicer, because you can mash a bunch of common ones together with for_each and generate policies in a dynamic way without having to learn dynamic IAM stuff, which is it's own thing entirely.
Terraform is particularly excellent, but everything you produce is carefully designed, well built, and reliable.
So great job, Hashicorp. Keep it up.
0.11->0.12 totally hosed me. Not necessarily because of TF itself, but because of the scaleway provider I was using changed everything around such that coming up with the right state file that didn't destroy all my existing instances, was very difficult. I eventually gave up and found someone to do my hosting for me cause it was just too much work to deal with TF changes over time.
I also feel like the concept of looping is a weird afterthought. I want to create 10 vms of the exact same type. Now I have to build a module for reusability, remember to put count everywhere and use dynamic variables all over the place, after studying all the documentation 1000 times. I wish this had been thought out a bit more.
Then they succumbed to demand with HCL 2. As much as I like Terraform in the general sense, their obsession with this weird DSL bothers me immensely.
Alternatively, I'm really enjoying the AWS CDK and hope Pulumi garners some more traction here.