Kaizen

VPC Networking

One VPC per account with public and private subnets, a NAT gateway, and flow logs.

GovCloudCMKView source
Module
networking
Layer
Network
Interface
8 inputs, 5 outputs
Used by
5 Kaizen apps

Why it matters

Every other module sits inside this private network. It splits the VPC into public subnets for the load balancer and private subnets for the app and its data, and it records every network connection for 90 days. One VPC serves every app in an account, and later apps look it up by name instead of creating their own.

Use it when

  • You set up the first app in a new AWS account. Claim a /16 in the README CIDR table first.

Reach for something else when

  • The account already has a shared VPC, such as kaizen-ext or kaizen-int. Look it up with data.aws_vpc by its Name tag and the subnets by tier tag.
  • You need a highly available NAT. The module creates a single NAT gateway.

What it creates

  • aws_vpc (DNS support and hostnames on)
  • aws_internet_gateway
  • aws_subnet (public, one per CIDR, tagged tier = public)
  • aws_subnet (private, one per CIDR, tagged tier = private)
  • aws_eip and aws_nat_gateway (one, optional)
  • aws_route_table and aws_route_table_association (public and private)
  • aws_cloudwatch_log_group, aws_iam_role, and aws_flow_log (traffic_type ALL)

Secure by default

  • VPC flow logs capture all traffic (traffic_type = ALL) and keep it for 90 days.
  • CIDRs have no defaults, so two accounts cannot end up with overlapping ranges by accident.
  • App and data modules go in private subnets with no route from the internet.

Commercial and GovCloud

main.tf
module "networking" {
  source = "git::ssh://git@github.com/the-kaizen-labs/terraform-modules.git//networking?ref=v1.7.0"

  name = "kaizen-ext"

  vpc_cidr             = "10.5.0.0/16"
  public_subnet_cidrs  = ["10.5.1.0/24", "10.5.2.0/24"]
  private_subnet_cidrs = ["10.5.10.0/24", "10.5.11.0/24"]

  tags = local.tags
}
SettingCommercial defaultFederal settingNote
kms_key_arnnull (AWS managed)customer managed KMS key ARNFedRAMP SC-13. Encrypts the flow log group.
create_nat_gatewaytruefalse for a fully private VPCThe caller must then add VPC endpoints; the module does not create them.
flow_log_retention_days9090 or more

How it connects

  • To alb: vpc_id, public_subnet_ids
  • To ecs-service: vpc_id, private_subnet_ids
  • To rds-postgres: vpc_id, private_subnet_ids
  • To redis: vpc_id, private_subnet_ids
  • To bastion: vpc_id, private_subnet_ids[0] (as private_subnet_id)
  • To openobserve: vpc_id, private_subnet_ids

Inputs

NameTypeDefaultRequiredDescription
namestringyesName prefix for VPC and related resources (e.g. "kaizen-int"). This is account-level, not app-level - the VPC is shared by every app in the account.
private_subnet_cidrslist(string)yesCIDR blocks for private subnets (one per AZ). These are the CIDRs advertised as Cloudflare tunnel routes, so the bastion and RDS live here.
public_subnet_cidrslist(string)yesCIDR blocks for public subnets (one per AZ)
vpc_cidrstringyesCIDR block for the VPC. Required, and must not overlap another Kaizen account - Cloudflare WARP can only route a given CIDR to one VPC. Take the account's assignment from the table in README.
create_nat_gatewaybooltruenoCreate a NAT gateway giving private subnets internet egress. Set to false for fully-private VPCs that egress only via VPC endpoints (federal pattern).
flow_log_retention_daysnumber90noCloudWatch retention in days for VPC flow logs
kms_key_arnstringnullnoKMS key ARN to encrypt the VPC flow log group. Null falls back to AWS-managed encryption. Required for federal posture (FedRAMP SC-13).
tagsmap(string){}noTags to apply to all resources

Outputs

NameDescription
nat_gateway_idValue: var.create_nat_gateway ? aws_nat_gateway.main[0].id : null
private_subnet_idsValue: aws_subnet.private[*].id
public_subnet_idsValue: aws_subnet.public[*].id
vpc_cidr_blockValue: aws_vpc.main.cidr_block
vpc_idValue: aws_vpc.main.id

Used by

AppPinned ref
castlev1.6.0
ginkgov1.3.0
magnoliav1.1.0
oakv1.1.0
saplingsv1.3.0

On this page