{"id":20329820,"url":"https://github.com/f5devcentral/terraform-xc-aws-cloud-credentials","last_synced_at":"2025-09-09T11:44:34.077Z","repository":{"id":205346947,"uuid":"713555244","full_name":"f5devcentral/terraform-xc-aws-cloud-credentials","owner":"f5devcentral","description":"Terraform module which creates AWS Cloud Credentials for F5 Distributed Cloud (XC)","archived":false,"fork":false,"pushed_at":"2023-11-02T19:04:45.000Z","size":10,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-01-14T15:18:27.094Z","etag":null,"topics":["aws-vpc-site","f5-aws","f5-distributed-cloud","f5-xc","f5-xc-cloud","f5xc","terraform"],"latest_commit_sha":null,"homepage":"https://registry.terraform.io/modules/f5devcentral/aws-cloud-credentials/xc/latest","language":"HCL","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/f5devcentral.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2023-11-02T18:58:03.000Z","updated_at":"2023-11-03T20:28:05.000Z","dependencies_parsed_at":null,"dependency_job_id":"bce20772-2a55-4cc8-b4b2-8641e9cc5041","html_url":"https://github.com/f5devcentral/terraform-xc-aws-cloud-credentials","commit_stats":null,"previous_names":["f5devcentral/terraform-xc-aws-cloud-credentials"],"tags_count":1,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/f5devcentral%2Fterraform-xc-aws-cloud-credentials","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/f5devcentral%2Fterraform-xc-aws-cloud-credentials/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/f5devcentral%2Fterraform-xc-aws-cloud-credentials/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/f5devcentral%2Fterraform-xc-aws-cloud-credentials/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/f5devcentral","download_url":"https://codeload.github.com/f5devcentral/terraform-xc-aws-cloud-credentials/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":241844785,"owners_count":20029720,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aws-vpc-site","f5-aws","f5-distributed-cloud","f5-xc","f5-xc-cloud","f5xc","terraform"],"created_at":"2024-11-14T20:13:39.793Z","updated_at":"2025-09-09T11:44:34.055Z","avatar_url":"https://github.com/f5devcentral.png","language":"HCL","funding_links":[],"categories":[],"sub_categories":[],"readme":"# AWS Cloud Credentials for F5 Distributed Cloud (XC) Terraform Module\r\n\r\nThis Terraform module creates and manages AWS Cloud Credentials in F5 Distributed Cloud (XC). The module can either create new AWS IAM resources (user, policies, access keys) or use existing AWS credentials to establish cloud credentials in XC.\r\n\r\n\u003e **Note**: This module is developed and maintained by the [F5 DevCentral](https://github.com/f5devcentral) community. You can use this module as an example for your own development projects.\r\n\r\n## Features\r\n\r\n- **Flexible credential management**: Use existing AWS credentials or create new IAM user automatically\r\n- **Configurable IAM permissions**: Optional policies for VPC sites, Transit Gateway, and Direct Connect\r\n- **Secure credential handling**: Sensitive values are properly marked and handled\r\n- **Input validation**: Ensures proper naming conventions and parameter validation\r\n- **Comprehensive outputs**: Access to all created resources and their identifiers\r\n\r\n## Requirements\r\n\r\n| Name                                                                             | Version    |\r\n| -------------------------------------------------------------------------------- | ---------- |\r\n| [terraform](https://github.com/hashicorp/terraform)                              | \u003e= 1.3     |\r\n| [aws](https://registry.terraform.io/providers/hashicorp/aws/latest/docs)         | \u003e= 6.9.0   |\r\n| [volterra](https://registry.terraform.io/providers/volterraedge/volterra/latest) | \u003e= 0.11.44 |\r\n\r\n## Usage\r\n\r\n### Using Existing AWS Credentials\r\n\r\nTo use this module with your existing AWS credentials without creating new IAM resources:\r\n\r\n```hcl\r\nmodule \"aws_cloud_credentials\" {\r\n  source = \"f5devcentral/aws-cloud-credentials/volterra\"\r\n\r\n  name           = \"my-aws-creds\"\r\n  aws_access_key = \"AKIA...\"\r\n  aws_secret_key = \"your_secret_key\"\r\n\r\n  tags = {\r\n    Environment = \"production\"\r\n    Project     = \"xc-deployment\"\r\n  }\r\n}\r\n```\r\n\r\n### Creating New IAM User and Credentials\r\n\r\nTo create a new AWS IAM user with the necessary permissions:\r\n\r\n```hcl\r\nmodule \"aws_cloud_credentials\" {\r\n  source = \"f5devcentral/aws-cloud-credentials/volterra\"\r\n\r\n  name = \"xc-aws-auto-created\"\r\n\r\n  # Optional: Enable additional IAM permissions\r\n  create_aws_tgw_iam         = true\r\n  create_direct_connect_iam  = true\r\n\r\n  tags = {\r\n    Environment = \"development\"\r\n    Project     = \"xc-poc\"\r\n  }\r\n}\r\n```\r\n\r\n### Advanced Configuration\r\n\r\n```hcl\r\nmodule \"aws_cloud_credentials\" {\r\n  source = \"f5devcentral/aws-cloud-credentials/volterra\"\r\n\r\n  name = \"enterprise-xc-creds\"\r\n  \r\n  # Enable all optional IAM policies\r\n  create_aws_tgw_iam        = true\r\n  create_direct_connect_iam = true\r\n\r\n  # Custom tags for compliance and cost tracking\r\n  tags = {\r\n    Environment     = \"production\"\r\n    Project         = \"f5-xc-deployment\"\r\n    CostCenter      = \"infrastructure\"\r\n    Owner           = \"platform-team\"\r\n    Compliance      = \"sox\"\r\n  }\r\n}\r\n```\r\n\r\n## Inputs\r\n\r\n| Name                      | Description                                                                     | Type          | Default                                  | Required |\r\n| ------------------------- | ------------------------------------------------------------------------------- | ------------- | ---------------------------------------- | :------: |\r\n| name                      | Cloud Credentials name.                                                         | `string`      | `\"xc-aws\"`                               |    no    |\r\n| aws_access_key            | Existing AWS Access Key ID. If not provided, a new IAM user will be created     | `string`      | `null`                                   |    no    |\r\n| aws_secret_key            | Existing AWS Secret Access Key. If not provided, a new IAM user will be created | `string`      | `null`                                   |    no    |\r\n| create_aws_tgw_iam        | Create IAM permissions for AWS Transit Gateway operations                       | `bool`        | `false`                                  |    no    |\r\n| create_direct_connect_iam | Create IAM permissions for AWS Direct Connect operations                        | `bool`        | `false`                                  |    no    |\r\n| tags                      | A map of tags to add to all AWS resources                                       | `map(string)` | `{\"Environment\"=\"dev\", \"Name\"=\"xc-aws\"}` |    no    |\r\n\r\n## Outputs\r\n\r\n| Name                              | Description                                                                                    |\r\n| --------------------------------- | ---------------------------------------------------------------------------------------------- |\r\n| aws_access_key                    | AWS Access Key (sensitive)                                                                     |\r\n| aws_secret_key                    | AWS Secret Key (sensitive)                                                                     |\r\n| aws_iam_user_name                 | Created AWS IAM User name (sensitive)                                                          |\r\n| aws_iam_user_arn                  | The ARN assigned by AWS for the created IAM User (sensitive)                                   |\r\n| aws_iam_user_id                   | The unique ID assigned by AWS for the created IAM User (sensitive)                             |\r\n| aws_iam_vpc_site_policy_arn       | ARN of the created AWS IAM VPC Site Policy                                                     |\r\n| aws_iam_vpc_site_policy_name      | Name of the created AWS IAM VPC Site Policy                                                    |\r\n| aws_iam_tgw_site_policy_arn       | ARN of the created AWS IAM TGW Site Policy (only if `create_aws_tgw_iam` is true)              |\r\n| aws_iam_tgw_site_policy_name      | Name of the created AWS IAM TGW Site Policy (only if `create_aws_tgw_iam` is true)             |\r\n| aws_iam_directconnect_policy_arn  | ARN of the created AWS IAM DirectConnect Policy (only if `create_direct_connect_iam` is true)  |\r\n| aws_iam_directconnect_policy_name | Name of the created AWS IAM DirectConnect Policy (only if `create_direct_connect_iam` is true) |\r\n| name                              | Created XC Cloud Credentials name                                                              |\r\n| namespace                         | The namespace in which the XC Cloud Credentials is created                                     |\r\n| id                                | ID of the XC Cloud Credentials                                                                 |\r\n\r\n## IAM Permissions\r\n\r\nWhen creating a new IAM user, this module creates the following policies:\r\n\r\n### VPC Site Policy (Always Created)\r\nProvides permissions for:\r\n- EC2 instance management (create, describe, modify, terminate)\r\n- VPC and networking operations (subnets, security groups, route tables)\r\n- Auto Scaling Groups and Launch Templates\r\n- Elastic Load Balancers\r\n- IAM role management for EC2 instances\r\n\r\n### Transit Gateway Policy (Optional - `create_aws_tgw_iam = true`)\r\nProvides permissions for:\r\n- Transit Gateway creation, modification, and deletion\r\n- Transit Gateway attachments and route tables\r\n- Cross-account TGW peering\r\n\r\n### Direct Connect Policy (Optional - `create_direct_connect_iam = true`)\r\nProvides permissions for:\r\n- Direct Connect gateway management\r\n- Virtual interfaces creation and management\r\n- Direct Connect connection operations\r\n\r\n## Examples\r\n\r\nSee the `examples/` directory for complete working examples:\r\n- `examples/aws-existing-account/` - Using existing AWS credentials\r\n- `examples/aws-new-account/` - Creating new IAM user and policies\r\n\r\n## Security Considerations\r\n\r\n- **Credential Storage**: When using existing credentials, ensure they are stored securely (e.g., using Terraform Cloud variables or AWS Secrets Manager)\r\n- **Least Privilege**: Only enable the IAM policies you need (`create_aws_tgw_iam` and `create_direct_connect_iam`)\r\n- **Sensitive Outputs**: Access keys and user information are marked as sensitive and won't appear in logs\r\n- **Input Validation**: The module validates input parameters to prevent common configuration errors\r\n\r\n## Troubleshooting\r\n\r\n### Common Issues\r\n\r\n1. **Validation Errors**: Ensure the `name` variable meets AWS IAM naming requirements (1-64 characters, alphanumeric and `+=,.@-` only)\r\n\r\n2. **Permission Denied**: When using existing credentials, ensure they have sufficient permissions to create the XC Cloud Credentials\r\n\r\n3. **Resource Already Exists**: If you see errors about existing resources, check for naming conflicts with existing IAM users or policies\r\n\r\n## Contributing\r\n\r\nContributions to this module are welcome! Please see the contribution guidelines for more information.\r\n\r\n## License\r\n\r\nThis module is licensed under the Apache 2.0 License.","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ff5devcentral%2Fterraform-xc-aws-cloud-credentials","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ff5devcentral%2Fterraform-xc-aws-cloud-credentials","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ff5devcentral%2Fterraform-xc-aws-cloud-credentials/lists"}