/terraform-azure-sqlmi

Terraform module which creates sql managed instance resources used by workloads and accelerators.

Primary LanguageHCLMIT LicenseMIT

Sql Managed Instance

This terraform module streamlines the deployment and configuration of azure sql managed instances, offering customizable settings for databases, security policies, and vulnerability assessments.

Goals

The main objective is to create a more logic data structure, achieved by combining and grouping related resources together in a complex object.

The structure of the module promotes reusability. It's intended to be a repeatable component, simplifying the process of building diverse workloads and platform accelerators consistently.

A primary goal is to utilize keys and values in the object that correspond to the REST API's structure. This enables us to carry out iterations, increasing its practical value as time goes on.

A last key goal is to separate logic from configuration in the module, thereby enhancing its scalability, ease of customization, and manageability.

Non-Goals

These modules are not intended to be complete, ready-to-use solutions; they are designed as components for creating your own patterns.

They are not tailored for a single use case but are meant to be versatile and applicable to a range of scenarios.

Security standardization is applied at the pattern level, while the modules include default values based on best practices but do not enforce specific security standards.

End-to-end testing is not conducted on these modules, as they are individual components and do not undergo the extensive testing reserved for complete patterns or solutions.

Features

  • support for multiple database configurations.
  • utilization of terratest for robust validation.
  • integration of vulnerability assessment capabilities.
  • security alert policy support with customizable alert types and email notifications.

Requirements

Name Version
terraform ~> 1.0
azuread ~> 3.0
azurerm ~> 4.0
time ~> 0.12

Providers

Name Version
azuread ~> 3.0
azurerm ~> 4.0
time ~> 0.12

Resources

Name Type
azuread_directory_role.reader resource
azuread_directory_role_assignment.role resource
azurerm_mssql_managed_database.databases resource
azurerm_mssql_managed_instance.sql resource
azurerm_mssql_managed_instance_active_directory_administrator.sql resource
azurerm_mssql_managed_instance_security_alert_policy.policy resource
azurerm_mssql_managed_instance_vulnerability_assessment.assessment resource
time_sleep.wait_after_directory_role_assignment resource
azuread_group.current data source
azuread_service_principal.current data source
azuread_user.current data source
azurerm_client_config.current data source

Inputs

Name Description Type Default Required
config contains the configuration for the sql managed instance any n/a yes
location default azure region to be used. string null no
resource_group default resource group to be used. string null no
tags tags to be added to the resources map(string) {} no

Outputs

Name Description
config contains the configuration for the sql managed instance
databases contains the sql managed instance databases

Testing

For more information, please see our testing guidelines

Notes

Using a dedicated module, we've developed a naming convention for resources that's based on specific regular expressions for each type, ensuring correct abbreviations and offering flexibility with multiple prefixes and suffixes.

Full examples detailing all usages, along with integrations with dependency modules, are located in the examples directory.

To update the module's documentation run make doc

Authors

Module is maintained by these awesome contributors.

Contributing

We welcome contributions from the community! Whether it's reporting a bug, suggesting a new feature, or submitting a pull request, your input is highly valued.

For more information, please see our contribution guidelines

License

MIT Licensed. See LICENSE for full details.

References