Enterprise Infrastructure Lab

Interactive terraform planning, cost estimation, and security validation.

bash - terraform plan
Terraform will perform the following actions:

  # aws_vpc.lakshay_portfolio_vpc will be created
  + resource "aws_vpc" "lakshay_portfolio_vpc" {
      + cidr_block           = "10.0.0.0/16"
      + enable_dns_hostnames = true
      + tags                 = { Name = "lakshay-walia-cloud-vpc" }
    }

  # aws_security_group.k3s_cluster_sg will be created
  + resource "aws_security_group" "k3s_cluster_sg" {
      + name = "k3s-cluster-hardened-sg"
      + ingress: 443/tcp from 0.0.0.0/0
      + ingress: 80/tcp from 0.0.0.0/0
      + ingress: 22/tcp from 10.0.0.0/16 (VPC only)
    }

  # aws_s3_bucket.educenter_backups will be created
  + resource "aws_s3_bucket" "educenter_backups" { ... }

  # aws_subnet.public will be created
  # aws_subnet.private will be created
  # aws_internet_gateway.igw will be created
  # aws_nat_gateway.nat will be created
  # aws_instance.k3s_master will be created
  # aws_instance.k3s_worker will be created

Plan: 9 to add, 0 to change, 0 to destroy.
☁️
lakshay_portfolio_vpc
aws_vpc
🚪
igw
aws_internet_gateway
🌐
public_subnet
aws_subnet
🔒
private_subnet
aws_subnet
🔄
nat_gw
aws_nat_gateway
🖥️
k3s_master
aws_instance
🪣
educenter_backups
aws_s3_bucket

Resource Config

Click a node to view HCL...
Compute Resources
Number of Instances 1
Storage & Data
EBS Storage (GB) ($0.10/GB/mo) 20
S3 Storage (GB) ($0.023/GB/mo) 10
Data Transfer Out (GB) ($0.09/GB) 5
Networking Add-ons
Elastic IP (Unattached)
$3.60/mo
NAT Gateway
$32/mo + $0.045/GB

Estimated AWS Cost

$0.00
Annual: $0.00
Compute (EC2) $0.00
Storage (EBS+S3) $0.00
Networking (NAT+EIP) $0.00
Data Transfer $0.00
Security Score: 78/100
Based on CIS AWS Foundations

Inbound Rules Analysis

Port/Protocol Source Description Status
TCP 22 (SSH) 10.0.0.0/16 Admin access from internal VPC ✓ Good
TCP 443 (HTTPS) 0.0.0.0/0 Public web traffic ✓ Good
TCP 80 (HTTP) 0.0.0.0/0 Public web traffic ⚠️ Warning
ALL (Egress) 0.0.0.0/0 Unrestricted outbound traffic ⚠️ Warning

CIS Benchmark Compliance

Ensure no security groups allow ingress from 0.0.0.0/0 to port 22
Ensure no security groups allow ingress from 0.0.0.0/0 to port 3389
Ensure VPC flow logging is enabled in all VPCs
Ensure the default security group of every VPC restricts all traffic
Ensure routing tables do not route VPC peering traffic to IGW
Ensure unrestricted egress is minimized
1 Select Operating System
2 Select Node Role
3 Security Hardening
4 Additional Tools
# Click 'Generate Bootstrap Script' to create your custom provisioning script.
# The script will appear here.