Skip to content

Commit 644d255

Browse files
authored
feat: Support name_prefix in iam_role.enhanced_monitoring (#418)
1 parent 3cd2c79 commit 644d255

File tree

7 files changed

+31
-11
lines changed

7 files changed

+31
-11
lines changed

README.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -286,6 +286,7 @@ Users have the ability to:
286286
| <a name="input_monitoring_role_arn"></a> [monitoring\_role\_arn](#input\_monitoring\_role\_arn) | The ARN for the IAM role that permits RDS to send enhanced monitoring metrics to CloudWatch Logs. Must be specified if monitoring\_interval is non-zero | `string` | `null` | no |
287287
| <a name="input_monitoring_role_description"></a> [monitoring\_role\_description](#input\_monitoring\_role\_description) | Description of the monitoring IAM role | `string` | `null` | no |
288288
| <a name="input_monitoring_role_name"></a> [monitoring\_role\_name](#input\_monitoring\_role\_name) | Name of the IAM role which will be created when create\_monitoring\_role is enabled | `string` | `"rds-monitoring-role"` | no |
289+
| <a name="input_monitoring_role_use_name_prefix"></a> [monitoring\_role\_use\_name\_prefix](#input\_monitoring\_role\_use\_name\_prefix) | Determines whether to use `monitoring_role_name` as is or create a unique identifier beginning with `monitoring_role_name` as the specified prefix | `bool` | `false` | no |
289290
| <a name="input_multi_az"></a> [multi\_az](#input\_multi\_az) | Specifies if the RDS instance is multi-AZ | `bool` | `false` | no |
290291
| <a name="input_option_group_description"></a> [option\_group\_description](#input\_option\_group\_description) | The description of the option group | `string` | `null` | no |
291292
| <a name="input_option_group_name"></a> [option\_group\_name](#input\_option\_group\_name) | Name of the option group | `string` | `null` | no |

examples/complete-postgres/main.tf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -99,6 +99,7 @@ module "db" {
9999
create_monitoring_role = true
100100
monitoring_interval = 60
101101
monitoring_role_name = "example-monitoring-role-name"
102+
monitoring_role_use_name_prefix = true
102103
monitoring_role_description = "Description for monitoring role"
103104

104105
parameters = [

main.tf

Lines changed: 11 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -115,16 +115,17 @@ module "db_instance" {
115115
performance_insights_retention_period = var.performance_insights_retention_period
116116
performance_insights_kms_key_id = var.performance_insights_enabled ? var.performance_insights_kms_key_id : null
117117

118-
replicate_source_db = var.replicate_source_db
119-
replica_mode = var.replica_mode
120-
backup_retention_period = var.backup_retention_period
121-
backup_window = var.backup_window
122-
max_allocated_storage = var.max_allocated_storage
123-
monitoring_interval = var.monitoring_interval
124-
monitoring_role_arn = var.monitoring_role_arn
125-
monitoring_role_name = var.monitoring_role_name
126-
monitoring_role_description = var.monitoring_role_description
127-
create_monitoring_role = var.create_monitoring_role
118+
replicate_source_db = var.replicate_source_db
119+
replica_mode = var.replica_mode
120+
backup_retention_period = var.backup_retention_period
121+
backup_window = var.backup_window
122+
max_allocated_storage = var.max_allocated_storage
123+
monitoring_interval = var.monitoring_interval
124+
monitoring_role_arn = var.monitoring_role_arn
125+
monitoring_role_name = var.monitoring_role_name
126+
monitoring_role_use_name_prefix = var.monitoring_role_use_name_prefix
127+
monitoring_role_description = var.monitoring_role_description
128+
create_monitoring_role = var.create_monitoring_role
128129

129130
character_set_name = var.character_set_name
130131
timezone = var.timezone

modules/db_instance/README.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -73,6 +73,7 @@ No modules.
7373
| <a name="input_monitoring_role_arn"></a> [monitoring\_role\_arn](#input\_monitoring\_role\_arn) | The ARN for the IAM role that permits RDS to send enhanced monitoring metrics to CloudWatch Logs. Must be specified if monitoring\_interval is non-zero. | `string` | `null` | no |
7474
| <a name="input_monitoring_role_description"></a> [monitoring\_role\_description](#input\_monitoring\_role\_description) | Description of the monitoring IAM role | `string` | `null` | no |
7575
| <a name="input_monitoring_role_name"></a> [monitoring\_role\_name](#input\_monitoring\_role\_name) | Name of the IAM role which will be created when create\_monitoring\_role is enabled. | `string` | `"rds-monitoring-role"` | no |
76+
| <a name="input_monitoring_role_use_name_prefix"></a> [monitoring\_role\_use\_name\_prefix](#input\_monitoring\_role\_use\_name\_prefix) | Determines whether to use `monitoring_role_name` as is or create a unique identifier beginning with `monitoring_role_name` as the specified prefix | `bool` | `false` | no |
7677
| <a name="input_multi_az"></a> [multi\_az](#input\_multi\_az) | Specifies if the RDS instance is multi-AZ | `bool` | `false` | no |
7778
| <a name="input_option_group_name"></a> [option\_group\_name](#input\_option\_group\_name) | Name of the DB option group to associate. | `string` | `null` | no |
7879
| <a name="input_parameter_group_name"></a> [parameter\_group\_name](#input\_parameter\_group\_name) | Name of the DB parameter group to associate | `string` | `null` | no |

modules/db_instance/main.tf

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,9 @@ locals {
66
identifier = var.use_identifier_prefix ? null : var.identifier
77
identifier_prefix = var.use_identifier_prefix ? "${var.identifier}-" : null
88

9+
monitoring_role_name = var.monitoring_role_use_name_prefix ? null : var.monitoring_role_name
10+
monitoring_role_name_prefix = var.monitoring_role_use_name_prefix ? "${var.monitoring_role_name}-" : null
11+
912
# Replicas will use source metadata
1013
username = var.replicate_source_db != null ? null : var.username
1114
password = var.replicate_source_db != null ? null : var.password
@@ -162,7 +165,8 @@ data "aws_iam_policy_document" "enhanced_monitoring" {
162165
resource "aws_iam_role" "enhanced_monitoring" {
163166
count = var.create_monitoring_role ? 1 : 0
164167

165-
name = var.monitoring_role_name
168+
name = local.monitoring_role_name
169+
name_prefix = local.monitoring_role_name_prefix
166170
assume_role_policy = data.aws_iam_policy_document.enhanced_monitoring.json
167171
description = var.monitoring_role_description
168172

modules/db_instance/variables.tf

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -201,6 +201,12 @@ variable "monitoring_role_name" {
201201
default = "rds-monitoring-role"
202202
}
203203

204+
variable "monitoring_role_use_name_prefix" {
205+
description = "Determines whether to use `monitoring_role_name` as is or create a unique identifier beginning with `monitoring_role_name` as the specified prefix"
206+
type = bool
207+
default = false
208+
}
209+
204210
variable "monitoring_role_description" {
205211
description = "Description of the monitoring IAM role"
206212
type = string

variables.tf

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -183,6 +183,12 @@ variable "monitoring_role_name" {
183183
default = "rds-monitoring-role"
184184
}
185185

186+
variable "monitoring_role_use_name_prefix" {
187+
description = "Determines whether to use `monitoring_role_name` as is or create a unique identifier beginning with `monitoring_role_name` as the specified prefix"
188+
type = bool
189+
default = false
190+
}
191+
186192
variable "monitoring_role_description" {
187193
description = "Description of the monitoring IAM role"
188194
type = string

0 commit comments

Comments
 (0)