{"id":19129388,"url":"https://github.com/launchbynttdata/tf-aws-module_primitive-private_ca","last_synced_at":"2026-05-15T12:32:24.190Z","repository":{"id":242969185,"uuid":"795229400","full_name":"launchbynttdata/tf-aws-module_primitive-private_ca","owner":"launchbynttdata","description":null,"archived":false,"fork":false,"pushed_at":"2024-10-21T21:20:40.000Z","size":90,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2025-02-22T16:17:21.954Z","etag":null,"topics":["aws","infrastructure-as-code","platform-automation","primitive","terraform"],"latest_commit_sha":null,"homepage":null,"language":"HCL","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/launchbynttdata.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-05-02T20:56:39.000Z","updated_at":"2025-01-13T15:18:31.000Z","dependencies_parsed_at":"2025-01-03T10:43:25.578Z","dependency_job_id":"dbf8addc-75cb-4e1d-b942-5bb319273938","html_url":"https://github.com/launchbynttdata/tf-aws-module_primitive-private_ca","commit_stats":null,"previous_names":["launchbynttdata/tf-aws-module_primitive-private_ca"],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/launchbynttdata/tf-aws-module_primitive-private_ca","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/launchbynttdata%2Ftf-aws-module_primitive-private_ca","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/launchbynttdata%2Ftf-aws-module_primitive-private_ca/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/launchbynttdata%2Ftf-aws-module_primitive-private_ca/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/launchbynttdata%2Ftf-aws-module_primitive-private_ca/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/launchbynttdata","download_url":"https://codeload.github.com/launchbynttdata/tf-aws-module_primitive-private_ca/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/launchbynttdata%2Ftf-aws-module_primitive-private_ca/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":267072690,"owners_count":24031431,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-07-25T02:00:09.625Z","response_time":70,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aws","infrastructure-as-code","platform-automation","primitive","terraform"],"created_at":"2024-11-09T06:07:20.907Z","updated_at":"2026-05-15T12:32:19.151Z","avatar_url":"https://github.com/launchbynttdata.png","language":"HCL","funding_links":[],"categories":[],"sub_categories":[],"readme":"# tf-aws-module_primitive-private_ca\n\n[![License](https://img.shields.io/badge/License-Apache_2.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n[![License: CC BY-NC-ND 4.0](https://img.shields.io/badge/License-CC_BY--NC--ND_4.0-lightgrey.svg)](https://creativecommons.org/licenses/by-nc-nd/4.0/)\n\n## Overview\n\nThis terraform module creates a Private CA in the AWS account.\n\n## Usage\nA sample variable file `example.tfvars` is available in the root directory which can be used to test this module. User needs to follow the below steps to execute this module\n1. Update the `example.tfvars` to manually enter values for all fields marked within `\u003c\u003e` to make the variable file usable\n2. Create a file `provider.tf` with the below contents\n   ```\n    provider \"aws\" {\n      profile = \"\u003cprofile_name\u003e\"\n      region  = \"\u003cregion_name\u003e\"\n    }\n    ```\n   If using `SSO`, make sure you are logged in `aws sso login --profile \u003cprofile_name\u003e`\n3. Make sure terraform binary is installed on your local. Use command `type terraform` to find the installation location. If you are using `asdf`, you can run `asfd install` and it will install the correct terraform version for you. `.tool-version` contains all the dependencies.\n4. Run the `terraform` to provision infrastructure on AWS\n    ```\n    # Initialize\n    terraform init\n    # Plan\n    terraform plan -var-file example.tfvars\n    # Apply (this is create the actual infrastructure)\n    terraform apply -var-file example.tfvars -auto-approve\n   ```\n## Known Issues\n1. The `Encryption  in transit` functionality is currently not supported by terraform. There is an open issue registered with the provider https://github.com/hashicorp/terraform-provider-aws/issues/26367\n## Pre-Commit hooks\n\n[.pre-commit-config.yaml](.pre-commit-config.yaml) file defines certain `pre-commit` hooks that are relevant to terraform, golang and common linting tasks. There are no custom hooks added.\n\n`commitlint` hook enforces commit message in certain format. The commit contains the following structural elements, to communicate intent to the consumers of your commit messages:\n\n- **fix**: a commit of the type `fix` patches a bug in your codebase (this correlates with PATCH in Semantic Versioning).\n- **feat**: a commit of the type `feat` introduces a new feature to the codebase (this correlates with MINOR in Semantic Versioning).\n- **BREAKING CHANGE**: a commit that has a footer `BREAKING CHANGE:`, or appends a `!` after the type/scope, introduces a breaking API change (correlating with MAJOR in Semantic Versioning). A BREAKING CHANGE can be part of commits of any type.\nfooters other than BREAKING CHANGE: \u003cdescription\u003e may be provided and follow a convention similar to git trailer format.\n- **build**: a commit of the type `build` adds changes that affect the build system or external dependencies (example scopes: gulp, broccoli, npm)\n- **chore**: a commit of the type `chore` adds changes that don't modify src or test files\n- **ci**: a commit of the type `ci` adds changes to our CI configuration files and scripts (example scopes: Travis, Circle, BrowserStack, SauceLabs)\n- **docs**: a commit of the type `docs` adds documentation only changes\n- **perf**: a commit of the type `perf` adds code change that improves performance\n- **refactor**: a commit of the type `refactor` adds code change that neither fixes a bug nor adds a feature\n- **revert**: a commit of the type `revert` reverts a previous commit\n- **style**: a commit of the type `style` adds code changes that do not affect the meaning of the code (white-space, formatting, missing semi-colons, etc)\n- **test**: a commit of the type `test` adds missing tests or correcting existing tests\n\nBase configuration used for this project is [commitlint-config-conventional (based on the Angular convention)](https://github.com/conventional-changelog/commitlint/tree/master/@commitlint/config-conventional#type-enum)\n\nIf you are a developer using vscode, [this](https://marketplace.visualstudio.com/items?itemName=joshbolduc.commitlint) plugin may be helpful.\n\n`detect-secrets-hook` prevents new secrets from being introduced into the baseline. TODO: INSERT DOC LINK ABOUT HOOKS\n\nIn order for `pre-commit` hooks to work properly\n\n- You need to have the pre-commit package manager installed. [Here](https://pre-commit.com/#install) are the installation instructions.\n- `pre-commit` would install all the hooks when commit message is added by default except for `commitlint` hook. `commitlint` hook would need to be installed manually using the command below\n\n```\npre-commit install --hook-type commit-msg\n```\n\n## To test the resource group module locally\n\n1. For development/enhancements to this module locally, you'll need to install all of its components. This is controlled by the `configure` target in the project's [`Makefile`](./Makefile). Before you can run `configure`, familiarize yourself with the variables in the `Makefile` and ensure they're pointing to the right places.\n\n```\nmake configure\n```\n\nThis adds in several files and directories that are ignored by `git`. They expose many new Make targets.\n\n2. The first target you care about is `env`. This is the common interface for setting up environment variables. The values of the environment variables will be used to authenticate with cloud provider from local development workstation.\n\n`make configure` command will bring down `aws_env.sh` file on local workstation. Developer would need to modify this file, replace the environment variable values with relevant values.\n\nThese environment variables are used by `terratest` integration suit.\n\nThen run this make target to set the environment variables on developer workstation.\n\n```\nmake env\n```\n\n3. The first target you care about is `check`.\n\n**Pre-requisites**\nBefore running this target it is important to ensure that, developer has created files mentioned below on local workstation under root directory of git repository that contains code for primitives/segments. Note that these files are `aws` specific. If primitive/segment under development uses any other cloud provider than AWS, this section may not be relevant.\n\n- A file named `provider.tf` with contents below\n\n```\nprovider \"aws\" {\n  profile = \"\u003cprofile_name\u003e\"\n  region  = \"\u003cregion_name\u003e\"\n}\n```\n\n- A file named `terraform.tfvars` which contains key value pair of variables used.\n\nNote that since these files are added in `gitignore` they would not be checked in into primitive/segment's git repo.\n\nAfter creating these files, for running tests associated with the primitive/segment, run\n\n```\nmake check\n```\n\nIf `make check` target is successful, developer is good to commit the code to primitive/segment's git repo.\n\n`make check` target\n\n- runs `terraform commands` to `lint`,`validate` and `plan` terraform code.\n- runs `conftests`. `conftests` make sure `policy` checks are successful.\n- runs `terratest`. This is integration test suit.\n- runs `opa` tests\n\n# Know Issues\nCurrently, the `encrypt at transit` is not supported in terraform. There is an open issue for this logged with Hashicorp - https://github.com/hashicorp/terraform-provider-aws/pull/26987\n\n\u003c!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK --\u003e\n## Requirements\n\n| Name | Version |\n|------|---------|\n| \u003ca name=\"requirement_terraform\"\u003e\u003c/a\u003e [terraform](#requirement\\_terraform) | ~\u003e 1.0 |\n| \u003ca name=\"requirement_aws\"\u003e\u003c/a\u003e [aws](#requirement\\_aws) | ~\u003e 5.0 |\n\n## Providers\n\n| Name | Version |\n|------|---------|\n| \u003ca name=\"provider_aws\"\u003e\u003c/a\u003e [aws](#provider\\_aws) | 5.72.1 |\n\n## Modules\n\n| Name | Source | Version |\n|------|--------|---------|\n| \u003ca name=\"module_resource_names\"\u003e\u003c/a\u003e [resource\\_names](#module\\_resource\\_names) | terraform.registry.launch.nttdata.com/module_library/resource_name/launch | ~\u003e 2.0 |\n\n## Resources\n\n| Name | Type |\n|------|------|\n| [aws_acmpca_certificate.certificate](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/acmpca_certificate) | resource |\n| [aws_acmpca_certificate_authority.private_ca](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/acmpca_certificate_authority) | resource |\n| [aws_acmpca_certificate_authority_certificate.ca_certificate](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/acmpca_certificate_authority_certificate) | resource |\n| [aws_acmpca_permission.ca_permission](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/acmpca_permission) | resource |\n| [aws_partition.current](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/partition) | data source |\n\n## Inputs\n\n| Name | Description | Type | Default | Required |\n|------|-------------|------|---------|:--------:|\n| \u003ca name=\"input_logical_product_family\"\u003e\u003c/a\u003e [logical\\_product\\_family](#input\\_logical\\_product\\_family) | (Required) Name of the product family for which the resource is created.\u003cbr\u003e    Example: org\\_name, department\\_name. | `string` | `\"launch\"` | no |\n| \u003ca name=\"input_logical_product_service\"\u003e\u003c/a\u003e [logical\\_product\\_service](#input\\_logical\\_product\\_service) | (Required) Name of the product service for which the resource is created.\u003cbr\u003e    For example, backend, frontend, middleware etc. | `string` | `\"ecs\"` | no |\n| \u003ca name=\"input_environment\"\u003e\u003c/a\u003e [environment](#input\\_environment) | Environment in which the resource should be provisioned like dev, qa, prod etc. | `string` | `\"dev\"` | no |\n| \u003ca name=\"input_environment_number\"\u003e\u003c/a\u003e [environment\\_number](#input\\_environment\\_number) | The environment count for the respective environment. Defaults to 000. Increments in value of 1 | `string` | `\"000\"` | no |\n| \u003ca name=\"input_resource_number\"\u003e\u003c/a\u003e [resource\\_number](#input\\_resource\\_number) | The resource count for the respective resource. Defaults to 000. Increments in value of 1 | `string` | `\"000\"` | no |\n| \u003ca name=\"input_region\"\u003e\u003c/a\u003e [region](#input\\_region) | AWS Region in which the infra needs to be provisioned | `string` | `\"us-east-2\"` | no |\n| \u003ca name=\"input_key_algorithm\"\u003e\u003c/a\u003e [key\\_algorithm](#input\\_key\\_algorithm) | Type of public key algorithm to use for this CA | `string` | `\"RSA_4096\"` | no |\n| \u003ca name=\"input_signing_algorithm\"\u003e\u003c/a\u003e [signing\\_algorithm](#input\\_signing\\_algorithm) | Name of the algorithm your private CA uses to sign certificate requests. | `string` | `\"SHA512WITHRSA\"` | no |\n| \u003ca name=\"input_subject\"\u003e\u003c/a\u003e [subject](#input\\_subject) | Contains information about the certificate subject. Identifies the entity that owns or controls the public key in the certificate. The entity can be a user, computer, device, or service. | \u003cpre\u003eobject({\u003cbr\u003e    country                      = optional(string)\u003cbr\u003e    distinguished_name_qualifier = optional(string)\u003cbr\u003e    generation_qualifier         = optional(string)\u003cbr\u003e    given_name                   = optional(string)\u003cbr\u003e    initials                     = optional(string)\u003cbr\u003e    locality                     = optional(string)\u003cbr\u003e    organization                 = optional(string)\u003cbr\u003e    organizational_unit          = optional(string)\u003cbr\u003e    state                        = optional(string)\u003cbr\u003e  })\u003c/pre\u003e | \u003cpre\u003e{\u003cbr\u003e  \"country\": \"US\",\u003cbr\u003e  \"organization\": \"Launch by NTT DATA\",\u003cbr\u003e  \"organizational_unit\": \"DSO\",\u003cbr\u003e  \"state\": \"Texas\"\u003cbr\u003e}\u003c/pre\u003e | no |\n| \u003ca name=\"input_permanent_deletion_time_in_days\"\u003e\u003c/a\u003e [permanent\\_deletion\\_time\\_in\\_days](#input\\_permanent\\_deletion\\_time\\_in\\_days) | Number of days to make a CA restorable after it has been deleted,\u003cbr\u003e    must be between 7 to 30 days, with default to 30 days. | `number` | `7` | no |\n| \u003ca name=\"input_usage_mode\"\u003e\u003c/a\u003e [usage\\_mode](#input\\_usage\\_mode) | Specifies whether the CA issues general-purpose certificates that typically require a revocation mechanism,\u003cbr\u003e    or short-lived certificates that may optionally omit revocation because they expire quickly. | `string` | `\"GENERAL_PURPOSE\"` | no |\n| \u003ca name=\"input_enabled\"\u003e\u003c/a\u003e [enabled](#input\\_enabled) | Whether the certificate authority is enabled or disabled. | `bool` | `true` | no |\n| \u003ca name=\"input_type\"\u003e\u003c/a\u003e [type](#input\\_type) | Type of the certificate authority. Defaults to SUBORDINATE. Valid values: ROOT and SUBORDINATE. | `string` | `\"ROOT\"` | no |\n| \u003ca name=\"input_ca_certificate_validity\"\u003e\u003c/a\u003e [ca\\_certificate\\_validity](#input\\_ca\\_certificate\\_validity) | Configures end of the validity period for the CA ROOT certificate. Defaults to 1 year | \u003cpre\u003eobject({\u003cbr\u003e    type  = string\u003cbr\u003e    value = number\u003cbr\u003e  })\u003c/pre\u003e | \u003cpre\u003e{\u003cbr\u003e  \"type\": \"YEARS\",\u003cbr\u003e  \"value\": 10\u003cbr\u003e}\u003c/pre\u003e | no |\n| \u003ca name=\"input_tags\"\u003e\u003c/a\u003e [tags](#input\\_tags) | A map of custom tags to be associated with the cache cluster | `map(string)` | `{}` | no |\n\n## Outputs\n\n| Name | Description |\n|------|-------------|\n| \u003ca name=\"output_resource_name_tag\"\u003e\u003c/a\u003e [resource\\_name\\_tag](#output\\_resource\\_name\\_tag) | n/a |\n| \u003ca name=\"output_private_ca_arn\"\u003e\u003c/a\u003e [private\\_ca\\_arn](#output\\_private\\_ca\\_arn) | ARN of Private CA |\n| \u003ca name=\"output_private_ca_id\"\u003e\u003c/a\u003e [private\\_ca\\_id](#output\\_private\\_ca\\_id) | ID of the private CA |\n| \u003ca name=\"output_private_ca_type\"\u003e\u003c/a\u003e [private\\_ca\\_type](#output\\_private\\_ca\\_type) | Type of the private CA |\n| \u003ca name=\"output_private_ca_usage_mode\"\u003e\u003c/a\u003e [private\\_ca\\_usage\\_mode](#output\\_private\\_ca\\_usage\\_mode) | Usage mode of the private CA |\n| \u003ca name=\"output_private_ca_key_algorithm\"\u003e\u003c/a\u003e [private\\_ca\\_key\\_algorithm](#output\\_private\\_ca\\_key\\_algorithm) | Configuration of the private CA |\n| \u003ca name=\"output_private_ca_signing_algorithm\"\u003e\u003c/a\u003e [private\\_ca\\_signing\\_algorithm](#output\\_private\\_ca\\_signing\\_algorithm) | Configuration of the private CA |\n\u003c!-- END OF PRE-COMMIT-TERRAFORM DOCS HOOK --\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Flaunchbynttdata%2Ftf-aws-module_primitive-private_ca","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Flaunchbynttdata%2Ftf-aws-module_primitive-private_ca","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Flaunchbynttdata%2Ftf-aws-module_primitive-private_ca/lists"}