From 3613c8d3c513a45833b3997b509d231c9fa02110 Mon Sep 17 00:00:00 2001 From: briskt <3172830+briskt@users.noreply.github.com> Date: Thu, 12 Sep 2024 22:19:23 +0800 Subject: [PATCH] rename cloudflare security group rule to account for ipv6 --- aws/cloudflare-sg/main.tf | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/aws/cloudflare-sg/main.tf b/aws/cloudflare-sg/main.tf index 33fe40d..8ca6579 100644 --- a/aws/cloudflare-sg/main.tf +++ b/aws/cloudflare-sg/main.tf @@ -5,7 +5,7 @@ resource "aws_security_group" "cloudflare_https" { vpc_id = var.vpc_id } -resource "aws_security_group_rule" "cloudflare_ipv4" { +resource "aws_security_group_rule" "cloudflare" { type = "ingress" from_port = 443 to_port = 443 @@ -15,6 +15,11 @@ resource "aws_security_group_rule" "cloudflare_ipv4" { ipv6_cidr_blocks = split("\n", trimspace(data.http.cloudflare_ipv6.response_body)) } +moved { + from = aws_security_group_rule.cloudflare_ipv4 + to = aws_security_group_rule.cloudflare +} + data "http" "cloudflare_ipv4" { url = "https://www.cloudflare.com/ips-v4" }