diff --git a/aws/platform/main.tf b/aws/platform/main.tf index ea4ccce0..9afad7c2 100644 --- a/aws/platform/main.tf +++ b/aws/platform/main.tf @@ -69,14 +69,15 @@ module "common_platform" { module "aws_load_balancer_controller" { source = "./modules/load-balancer-controller" - aws_namespace = [module.cluster_name.full] - aws_tags = var.aws_tags - chart_values = var.aws_load_balancer_controller_values - chart_version = var.aws_load_balancer_controller_version - cluster_full_name = module.cluster_name.full - k8s_namespace = var.k8s_namespace - oidc_issuer = data.aws_ssm_parameter.oidc_issuer.value - vpc_cidr_block = module.network.vpc.cidr_block + aws_namespace = [module.cluster_name.full] + aws_tags = var.aws_tags + chart_values = var.aws_load_balancer_controller_values + chart_version = var.aws_load_balancer_controller_version + cluster_full_name = module.cluster_name.full + default_ssl_policy = var.default_ssl_policy + k8s_namespace = var.k8s_namespace + oidc_issuer = data.aws_ssm_parameter.oidc_issuer.value + vpc_cidr_block = module.network.vpc.cidr_block depends_on = [module.common_platform] } diff --git a/aws/platform/modules/load-balancer-controller/main.tf b/aws/platform/modules/load-balancer-controller/main.tf index 77b69937..03c14251 100644 --- a/aws/platform/modules/load-balancer-controller/main.tf +++ b/aws/platform/modules/load-balancer-controller/main.tf @@ -90,6 +90,8 @@ locals { "eks.amazonaws.com/role-arn" = module.service_account_role.arn } } + + defaultSSLPolicy = coalesce(var.default_ssl_policy, "ELBSecurityPolicy-TLS13-1-2-2021-06") }) ] } diff --git a/aws/platform/modules/load-balancer-controller/variables.tf b/aws/platform/modules/load-balancer-controller/variables.tf index 2a6e9402..e81765a4 100644 --- a/aws/platform/modules/load-balancer-controller/variables.tf +++ b/aws/platform/modules/load-balancer-controller/variables.tf @@ -66,3 +66,8 @@ variable "vpc_cidr_block" { type = string description = "CIDR block for the AWS VPC in which the load balancer runs" } + +variable "default_ssl_policy" { + type = string + description = "The default SSL policy to use for the load balancer" +} \ No newline at end of file diff --git a/aws/platform/variables.tf b/aws/platform/variables.tf index 943b7b47..fdd3f2fe 100644 --- a/aws/platform/variables.tf +++ b/aws/platform/variables.tf @@ -74,6 +74,12 @@ variable "custom_roles" { default = {} } +variable "default_ssl_policy" { + type = string + description = "The default SSL policy to use for the load balancer" + default = null +} + variable "domain_names" { type = list(string) default = []