Skip to content

Commit f32e2f9

Browse files
Promote network security mirroring resources to GA. (#13322) (#938)
[upstream:6510bb363bd4ccd11d64b42c11c444fb0ddfd5cb] Signed-off-by: Modular Magician <magic-modules@google.com>
1 parent 1efd379 commit f32e2f9

File tree

16 files changed

+525
-0
lines changed

16 files changed

+525
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# This file has some scaffolding to make sure that names are unique and that
2+
# a region and zone are selected when you try to create your Terraform resources.
3+
4+
locals {
5+
name_suffix = "${random_pet.suffix.id}"
6+
}
7+
8+
resource "random_pet" "suffix" {
9+
length = 2
10+
}
11+
12+
provider "google" {
13+
region = "us-central1"
14+
zone = "us-central1-c"
15+
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
resource "google_compute_network" "network" {
2+
name = "example-network-${local.name_suffix}"
3+
auto_create_subnetworks = false
4+
}
5+
6+
resource "google_compute_subnetwork" "subnetwork" {
7+
name = "example-subnet-${local.name_suffix}"
8+
region = "us-central1"
9+
ip_cidr_range = "10.1.0.0/16"
10+
network = google_compute_network.network.name
11+
}
12+
13+
resource "google_compute_region_health_check" "health_check" {
14+
name = "example-hc-${local.name_suffix}"
15+
region = "us-central1"
16+
http_health_check {
17+
port = 80
18+
}
19+
}
20+
21+
resource "google_compute_region_backend_service" "backend_service" {
22+
name = "example-bs-${local.name_suffix}"
23+
region = "us-central1"
24+
health_checks = [google_compute_region_health_check.health_check.id]
25+
protocol = "UDP"
26+
load_balancing_scheme = "INTERNAL"
27+
}
28+
29+
resource "google_compute_forwarding_rule" "forwarding_rule" {
30+
name = "example-fwr-${local.name_suffix}"
31+
region = "us-central1"
32+
network = google_compute_network.network.name
33+
subnetwork = google_compute_subnetwork.subnetwork.name
34+
backend_service = google_compute_region_backend_service.backend_service.id
35+
load_balancing_scheme = "INTERNAL"
36+
ports = [6081]
37+
ip_protocol = "UDP"
38+
is_mirroring_collector = true
39+
}
40+
41+
resource "google_network_security_mirroring_deployment_group" "deployment_group" {
42+
mirroring_deployment_group_id = "example-dg-${local.name_suffix}"
43+
location = "global"
44+
network = google_compute_network.network.id
45+
}
46+
47+
resource "google_network_security_mirroring_deployment" "default" {
48+
mirroring_deployment_id = "example-deployment-${local.name_suffix}"
49+
location = "us-central1-a"
50+
forwarding_rule = google_compute_forwarding_rule.forwarding_rule.id
51+
mirroring_deployment_group = google_network_security_mirroring_deployment_group.deployment_group.id
52+
description = "some description"
53+
labels = {
54+
foo = "bar"
55+
}
56+
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
===
2+
3+
These examples use real resources that will be billed to the
4+
Google Cloud Platform project you use - so make sure that you
5+
run "terraform destroy" before quitting!
6+
7+
===
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,79 @@
1+
# Network Security Mirroring Deployment Basic - Terraform
2+
3+
## Setup
4+
5+
<walkthrough-author name="rileykarson@google.com" analyticsId="UA-125550242-1" tutorialName="network_security_mirroring_deployment_basic" repositoryUrl="https://github.com/terraform-google-modules/docs-examples"></walkthrough-author>
6+
7+
Welcome to Terraform in Google Cloud Shell! We need you to let us know what project you'd like to use with Terraform.
8+
9+
<walkthrough-project-billing-setup></walkthrough-project-billing-setup>
10+
11+
Terraform provisions real GCP resources, so anything you create in this session will be billed against this project.
12+
13+
## Terraforming!
14+
15+
Let's use {{project-id}} with Terraform! Click the Cloud Shell icon below to copy the command
16+
to your shell, and then run it from the shell by pressing Enter/Return. Terraform will pick up
17+
the project name from the environment variable.
18+
19+
```bash
20+
export GOOGLE_CLOUD_PROJECT={{project-id}}
21+
```
22+
23+
After that, let's get Terraform started. Run the following to pull in the providers.
24+
25+
```bash
26+
terraform init
27+
```
28+
29+
With the providers downloaded and a project set, you're ready to use Terraform. Go ahead!
30+
31+
```bash
32+
terraform apply
33+
```
34+
35+
Terraform will show you what it plans to do, and prompt you to accept. Type "yes" to accept the plan.
36+
37+
```bash
38+
yes
39+
```
40+
41+
42+
## Post-Apply
43+
44+
### Editing your config
45+
46+
Now you've provisioned your resources in GCP! If you run a "plan", you should see no changes needed.
47+
48+
```bash
49+
terraform plan
50+
```
51+
52+
So let's make a change! Try editing a number, or appending a value to the name in the editor. Then,
53+
run a 'plan' again.
54+
55+
```bash
56+
terraform plan
57+
```
58+
59+
Afterwards you can run an apply, which implicitly does a plan and shows you the intended changes
60+
at the 'yes' prompt.
61+
62+
```bash
63+
terraform apply
64+
```
65+
66+
```bash
67+
yes
68+
```
69+
70+
## Cleanup
71+
72+
Run the following to remove the resources Terraform provisioned:
73+
74+
```bash
75+
terraform destroy
76+
```
77+
```bash
78+
yes
79+
```
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# This file has some scaffolding to make sure that names are unique and that
2+
# a region and zone are selected when you try to create your Terraform resources.
3+
4+
locals {
5+
name_suffix = "${random_pet.suffix.id}"
6+
}
7+
8+
resource "random_pet" "suffix" {
9+
length = 2
10+
}
11+
12+
provider "google" {
13+
region = "us-central1"
14+
zone = "us-central1-c"
15+
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
resource "google_compute_network" "network" {
2+
name = "example-network-${local.name_suffix}"
3+
auto_create_subnetworks = false
4+
}
5+
6+
resource "google_network_security_mirroring_deployment_group" "default" {
7+
mirroring_deployment_group_id = "example-dg-${local.name_suffix}"
8+
location = "global"
9+
network = google_compute_network.network.id
10+
description = "some description"
11+
labels = {
12+
foo = "bar"
13+
}
14+
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
===
2+
3+
These examples use real resources that will be billed to the
4+
Google Cloud Platform project you use - so make sure that you
5+
run "terraform destroy" before quitting!
6+
7+
===
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,79 @@
1+
# Network Security Mirroring Deployment Group Basic - Terraform
2+
3+
## Setup
4+
5+
<walkthrough-author name="rileykarson@google.com" analyticsId="UA-125550242-1" tutorialName="network_security_mirroring_deployment_group_basic" repositoryUrl="https://github.com/terraform-google-modules/docs-examples"></walkthrough-author>
6+
7+
Welcome to Terraform in Google Cloud Shell! We need you to let us know what project you'd like to use with Terraform.
8+
9+
<walkthrough-project-billing-setup></walkthrough-project-billing-setup>
10+
11+
Terraform provisions real GCP resources, so anything you create in this session will be billed against this project.
12+
13+
## Terraforming!
14+
15+
Let's use {{project-id}} with Terraform! Click the Cloud Shell icon below to copy the command
16+
to your shell, and then run it from the shell by pressing Enter/Return. Terraform will pick up
17+
the project name from the environment variable.
18+
19+
```bash
20+
export GOOGLE_CLOUD_PROJECT={{project-id}}
21+
```
22+
23+
After that, let's get Terraform started. Run the following to pull in the providers.
24+
25+
```bash
26+
terraform init
27+
```
28+
29+
With the providers downloaded and a project set, you're ready to use Terraform. Go ahead!
30+
31+
```bash
32+
terraform apply
33+
```
34+
35+
Terraform will show you what it plans to do, and prompt you to accept. Type "yes" to accept the plan.
36+
37+
```bash
38+
yes
39+
```
40+
41+
42+
## Post-Apply
43+
44+
### Editing your config
45+
46+
Now you've provisioned your resources in GCP! If you run a "plan", you should see no changes needed.
47+
48+
```bash
49+
terraform plan
50+
```
51+
52+
So let's make a change! Try editing a number, or appending a value to the name in the editor. Then,
53+
run a 'plan' again.
54+
55+
```bash
56+
terraform plan
57+
```
58+
59+
Afterwards you can run an apply, which implicitly does a plan and shows you the intended changes
60+
at the 'yes' prompt.
61+
62+
```bash
63+
terraform apply
64+
```
65+
66+
```bash
67+
yes
68+
```
69+
70+
## Cleanup
71+
72+
Run the following to remove the resources Terraform provisioned:
73+
74+
```bash
75+
terraform destroy
76+
```
77+
```bash
78+
yes
79+
```
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# This file has some scaffolding to make sure that names are unique and that
2+
# a region and zone are selected when you try to create your Terraform resources.
3+
4+
locals {
5+
name_suffix = "${random_pet.suffix.id}"
6+
}
7+
8+
resource "random_pet" "suffix" {
9+
length = 2
10+
}
11+
12+
provider "google" {
13+
region = "us-central1"
14+
zone = "us-central1-c"
15+
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
resource "google_compute_network" "producer_network" {
2+
name = "example-prod-network-${local.name_suffix}"
3+
auto_create_subnetworks = false
4+
}
5+
6+
resource "google_compute_network" "consumer_network" {
7+
name = "example-cons-network-${local.name_suffix}"
8+
auto_create_subnetworks = false
9+
}
10+
11+
resource "google_network_security_mirroring_deployment_group" "deployment_group" {
12+
mirroring_deployment_group_id = "example-dg-${local.name_suffix}"
13+
location = "global"
14+
network = google_compute_network.producer_network.id
15+
}
16+
17+
resource "google_network_security_mirroring_endpoint_group" "endpoint_group" {
18+
mirroring_endpoint_group_id = "example-eg-${local.name_suffix}"
19+
location = "global"
20+
mirroring_deployment_group = google_network_security_mirroring_deployment_group.deployment_group.id
21+
}
22+
23+
resource "google_network_security_mirroring_endpoint_group_association" "default" {
24+
mirroring_endpoint_group_association_id = "example-ega-${local.name_suffix}"
25+
location = "global"
26+
network = google_compute_network.consumer_network.id
27+
mirroring_endpoint_group = google_network_security_mirroring_endpoint_group.endpoint_group.id
28+
labels = {
29+
foo = "bar"
30+
}
31+
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
===
2+
3+
These examples use real resources that will be billed to the
4+
Google Cloud Platform project you use - so make sure that you
5+
run "terraform destroy" before quitting!
6+
7+
===

0 commit comments

Comments
 (0)