Repository navigation
Expand file tree
/
Copy pathtls.tf
More file actions
69 lines (58 loc) · 2.47 KB
/
Copy pathtls.tf
File metadata and controls
69 lines (58 loc) · 2.47 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
# =============================================================================
# TLS certificates for demo.nhp (signed by custom CA)
# =============================================================================
# The CA root certificate and private key are stored in AWS Secrets Manager
# (opennhp/demo) under keys: stealth_ca_cert, stealth_ca_key
#
# This generates a server certificate for demo.nhp signed by that CA.
#
# PREREQUISITE: STEALTH_CA_CERT and STEALTH_CA_KEY must be configured in GitHub
# Secrets and synced to AWS Secrets Manager via the infra-demo workflow before
# these resources can be created. If the secrets are not present, these
# resources are skipped (count = 0) to allow terraform plan/apply to succeed.
# =============================================================================
locals {
# Check if stealth CA is configured. If either cert or key is missing/empty,
# skip creating the demo.nhp certificate resources.
stealth_ca_enabled = (
lookup(local.secrets, "stealth_ca_cert", "") != "" &&
lookup(local.secrets, "stealth_ca_key", "") != ""
)
}
# Generate a new private key for demo.nhp server certificate
resource "tls_private_key" "demo_nhp" {
# Intentionally tie the server keypair lifecycle to stealth_ca_enabled:
# removing and later restoring the CA secrets regenerates demo.nhp.
count = local.stealth_ca_enabled ? 1 : 0
algorithm = "RSA"
rsa_bits = 2048
}
# Create a certificate signing request
resource "tls_cert_request" "demo_nhp" {
count = local.stealth_ca_enabled ? 1 : 0
private_key_pem = tls_private_key.demo_nhp[0].private_key_pem
subject {
common_name = "demo.nhp"
organization = "OpenNHP"
}
dns_names = ["demo.nhp"]
}
# Sign the certificate with our CA
resource "tls_locally_signed_cert" "demo_nhp" {
count = local.stealth_ca_enabled ? 1 : 0
cert_request_pem = tls_cert_request.demo_nhp[0].cert_request_pem
ca_private_key_pem = local.secrets["stealth_ca_key"]
ca_cert_pem = local.secrets["stealth_ca_cert"]
# 2 years validity with automatic renewal 60 days before expiry.
# Shorter validity limits blast radius if state leaks and ensures
# regular key rotation. A 60-day window gives the monthly renewal
# workflow two scheduled chances to renew before expiry.
validity_period_hours = 17520 # 2 years (365 * 2 * 24)
early_renewal_hours = 1440 # 60 days (60 * 24)
set_subject_key_id = true
allowed_uses = [
"key_encipherment",
"digital_signature",
"server_auth",
]
}