VPC Networking
One VPC per account with public and private subnets, a NAT gateway, and flow logs.
GovCloudCMKView source
- Module
- networking
- Layer
- Network
- Interface
- 8 inputs, 5 outputs
- Used by
- 5 Kaizen apps
Why it matters
Every other module sits inside this private network. It splits the VPC into public subnets for the load balancer and private subnets for the app and its data, and it records every network connection for 90 days. One VPC serves every app in an account, and later apps look it up by name instead of creating their own.
Use it when
- You set up the first app in a new AWS account. Claim a /16 in the README CIDR table first.
Reach for something else when
- The account already has a shared VPC, such as kaizen-ext or kaizen-int. Look it up with data.aws_vpc by its Name tag and the subnets by tier tag.
- You need a highly available NAT. The module creates a single NAT gateway.
What it creates
aws_vpc(DNS support and hostnames on)aws_internet_gatewayaws_subnet(public, one per CIDR, tagged tier = public)aws_subnet(private, one per CIDR, tagged tier = private)aws_eipand aws_nat_gateway (one, optional)aws_route_tableand aws_route_table_association (public and private)aws_cloudwatch_log_group,aws_iam_role, and aws_flow_log (traffic_type ALL)
Secure by default
- VPC flow logs capture all traffic (traffic_type = ALL) and keep it for 90 days.
- CIDRs have no defaults, so two accounts cannot end up with overlapping ranges by accident.
- App and data modules go in private subnets with no route from the internet.
Commercial and GovCloud
module "networking" {
source = "git::ssh://git@github.com/the-kaizen-labs/terraform-modules.git//networking?ref=v1.7.0"
name = "kaizen-ext"
vpc_cidr = "10.5.0.0/16"
public_subnet_cidrs = ["10.5.1.0/24", "10.5.2.0/24"]
private_subnet_cidrs = ["10.5.10.0/24", "10.5.11.0/24"]
tags = local.tags
}| Setting | Commercial default | Federal setting | Note |
|---|---|---|---|
kms_key_arn | null (AWS managed) | customer managed KMS key ARN | FedRAMP SC-13. Encrypts the flow log group. |
create_nat_gateway | true | false for a fully private VPC | The caller must then add VPC endpoints; the module does not create them. |
flow_log_retention_days | 90 | 90 or more |
How it connects
- To alb: vpc_id, public_subnet_ids
- To ecs-service: vpc_id, private_subnet_ids
- To rds-postgres: vpc_id, private_subnet_ids
- To redis: vpc_id, private_subnet_ids
- To bastion: vpc_id, private_subnet_ids[0] (as private_subnet_id)
- To openobserve: vpc_id, private_subnet_ids
Inputs
| Name | Type | Default | Required | Description |
|---|---|---|---|---|
name | string | yes | Name prefix for VPC and related resources (e.g. "kaizen-int"). This is account-level, not app-level - the VPC is shared by every app in the account. | |
private_subnet_cidrs | list(string) | yes | CIDR blocks for private subnets (one per AZ). These are the CIDRs advertised as Cloudflare tunnel routes, so the bastion and RDS live here. | |
public_subnet_cidrs | list(string) | yes | CIDR blocks for public subnets (one per AZ) | |
vpc_cidr | string | yes | CIDR block for the VPC. Required, and must not overlap another Kaizen account - Cloudflare WARP can only route a given CIDR to one VPC. Take the account's assignment from the table in README. | |
create_nat_gateway | bool | true | no | Create a NAT gateway giving private subnets internet egress. Set to false for fully-private VPCs that egress only via VPC endpoints (federal pattern). |
flow_log_retention_days | number | 90 | no | CloudWatch retention in days for VPC flow logs |
kms_key_arn | string | null | no | KMS key ARN to encrypt the VPC flow log group. Null falls back to AWS-managed encryption. Required for federal posture (FedRAMP SC-13). |
tags | map(string) | {} | no | Tags to apply to all resources |
Outputs
| Name | Description |
|---|---|
nat_gateway_id | Value: var.create_nat_gateway ? aws_nat_gateway.main[0].id : null |
private_subnet_ids | Value: aws_subnet.private[*].id |
public_subnet_ids | Value: aws_subnet.public[*].id |
vpc_cidr_block | Value: aws_vpc.main.cidr_block |
vpc_id | Value: aws_vpc.main.id |
Used by
| App | Pinned ref |
|---|---|
| castle | v1.6.0 |
| ginkgo | v1.3.0 |
| magnolia | v1.1.0 |
| oak | v1.1.0 |
| saplings | v1.3.0 |