| ami_id |
The AMI ID provided by Corelight |
string |
n/a |
yes |
| aws_key_pair_name |
The name of the AWS key pair that will be used to access the sensor instances in the auto-scale group |
string |
n/a |
yes |
| community_string |
The community string (api password) for sensor management |
string |
n/a |
yes |
| custom_sensor_user_data |
Custom user data for a sensor if the default doesn't apply |
string |
"" |
no |
| deployment_name |
Name prefix for all resources (used to avoid naming conflicts) |
string |
"corelight-sensor" |
no |
| ebs_volume_size |
The size, in GB, of the EBS volume to be attached to the instance. Not recommended to set lower than 500GB |
number |
500 |
no |
| egress_allow_cidrs |
The IP range allowed outbound for both network interfaces. Typically can be left as default |
list(string) |
[ "0.0.0.0/0" ] |
no |
| fleet_http_proxy |
(optional) the proxy URL for HTTP traffic from the fleet |
string |
"" |
no |
| fleet_https_proxy |
(optional) the proxy URL for HTTPS traffic from the fleet |
string |
"" |
no |
| fleet_no_proxy |
(optional) hosts or domains to bypass the proxy for fleet traffic |
string |
"" |
no |
| fleet_server_sslname |
(optional) the SSL hostname for the fleet server |
string |
"1.broala.fleet.product.corelight.io" |
no |
| fleet_token |
(optional) the pairing token from the Fleet UI. Must be set if 'fleet_url' is provided |
string |
"" |
no |
| fleet_url |
(optional) the URL of the fleet instance from the Fleet UI. Must be set if 'fleet_token' is provided |
string |
"" |
no |
| health_check_allow_cidrs |
IP range to allow health checks. Typically the CIDR of the VPC being monitored |
list(string) |
[ "0.0.0.0/0" ] |
no |
| iam_instance_profile_name |
Name of the IAM instance profile that should be attached to the EC2 instance |
string |
"" |
no |
| instance_name |
The name for the sensor EC2 instance (defaults to <deployment_name>-sensor) |
string |
null |
no |
| instance_type |
The type of the EC2 instance |
string |
"c5.2xlarge" |
no |
| license_key_file_path |
The path to your Corelight sensor license key. This must be provided if not licensing through fleet |
string |
"" |
no |
| management_interface_id |
Used in place of the 'management_interface' variable if you would like to provide one |
string |
"" |
no |
| management_interface_name |
The name of the management interface for the sensor (defaults to <deployment_name>-mgmt-nic) |
string |
null |
no |
| management_interface_public_ip |
The flag to determine if the management interface for the sensor should have a publicly assigned IP address |
bool |
false |
no |
| management_interface_subnet_id |
The subnet id of the management interface for the sensor |
string |
"" |
no |
| management_security_group_description |
Description of the management ENI security group |
string |
"Corelight Sensor Managment SG" |
no |
| management_security_group_id |
Used in place of the 'management_security_group' variable if you would like to provide one |
string |
"" |
no |
| management_security_group_name |
Name of the security group the module will provision for the management ENI (defaults to <deployment_name>-mgmt-sg) |
string |
null |
no |
| management_security_group_vpc_id |
Security group VPC ID module will use to provision the management ENI security group |
string |
"" |
no |
| mirror_ingress_allow_cidrs |
IP range to allow EC2 mirroring. Typically the CIDR of the VPC being monitored |
list(string) |
[ "0.0.0.0/0" ] |
no |
| monitoring_interface_id |
The ID of a pre-exiting ENI if you would rather create it outside of the module |
string |
"" |
no |
| monitoring_interface_name |
The name of the monitoring interface for the sensor (defaults to <deployment_name>-mon-nic) |
string |
null |
no |
| monitoring_interface_subnet_id |
Subnet where the monitoring ENI should reside |
string |
"" |
no |
| monitoring_security_group_description |
Description of the monitoring ENI security group |
string |
"Corelight Sensor Monitoring SG" |
no |
| monitoring_security_group_id |
Used in place of the 'monitoring_security_group' variable if you would like to provide one |
string |
"" |
no |
| monitoring_security_group_name |
Name of the security group the module will provision for the monitoring ENI (defaults to <deployment_name>-mon-sg) |
string |
null |
no |
| monitoring_security_group_vpc_id |
Security group VPC ID module will use to provision the monitoring ENI security group |
string |
"" |
no |
| ssh_allow_cidrs |
List of IPs (/32) to grant access to port 22 |
list(string) |
[] |
no |