Skip to content

Commit

Permalink
r/aws_vpc_endpoint_private_dns: new resource (#37628)
Browse files Browse the repository at this point in the history
This resource will allow practitioners to enable and disable private DNS for a VPC endpoint.

This allows private DNS to be enabled on the VPC endpoint distinctly from the initial create operation, supporting use cases where additional actions must be taken between creation of the endpoint and enabling of private DNS.

```terraform
resource "aws_vpc_endpoint" "test" {
  vpc_id            = aws_vpc.test.id
  service_name      = "producer service name"
  vpc_endpoint_type = "Interface"
}

resource "aws_vpc_endpoint_connection_accepter" "test" {
  vpc_endpoint_service_id = "producer service id"
  vpc_endpoint_id         = aws_vpc_endpoint.test.id
}

resource "aws_vpc_endpoint_private_dns" "test" {
  depends_on = [aws_vpc_endpoint_connection_accepter.test]

  vpc_endpoint_id     = aws_vpc_endpoint.test.id
  private_dns_enabled = true
}
```

```console
% make testacc PKG=ec2 TESTS="TestAccVPCEndpointPrivateDNS_"
==> Checking that code complies with gofmt requirements...
TF_ACC=1 go1.22.2 test ./internal/service/ec2/... -v -count 1 -parallel 20 -run='TestAccVPCEndpointPrivateDNS_'  -timeout 360m

--- PASS: TestAccVPCEndpointPrivateDNS_disappears_Endpoint (127.05s)
--- PASS: TestAccVPCEndpointPrivateDNS_basic (167.16s)
--- PASS: TestAccVPCEndpointPrivateDNS_update (167.83s)
PASS
ok      github.com/hashicorp/terraform-provider-aws/internal/service/ec2        172.994s
```
  • Loading branch information
jar-b authored May 23, 2024
1 parent 999610a commit 27f7195
Show file tree
Hide file tree
Showing 6 changed files with 464 additions and 3 deletions.
3 changes: 3 additions & 0 deletions .changelog/37628.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:new-resource
aws_vpc_endpoint_private_dns
```
4 changes: 4 additions & 0 deletions internal/service/ec2/service_package_gen.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

9 changes: 6 additions & 3 deletions internal/service/ec2/vpc_endpoint.go
Original file line number Diff line number Diff line change
Expand Up @@ -135,7 +135,7 @@ func ResourceVPCEndpoint() *schema.Resource {
"private_dns_enabled": {
Type: schema.TypeBool,
Optional: true,
Default: false,
Computed: true,
},
"requester_managed": {
Type: schema.TypeBool,
Expand Down Expand Up @@ -202,7 +202,6 @@ func resourceVPCEndpointCreate(ctx context.Context, d *schema.ResourceData, meta
serviceName := d.Get(names.AttrServiceName).(string)
input := &ec2.CreateVpcEndpointInput{
ClientToken: aws.String(id.UniqueId()),
PrivateDnsEnabled: aws.Bool(d.Get("private_dns_enabled").(bool)),
ServiceName: aws.String(serviceName),
TagSpecifications: getTagSpecificationsInV2(ctx, awstypes.ResourceTypeVpcEndpoint),
VpcEndpointType: awstypes.VpcEndpointType(d.Get("vpc_endpoint_type").(string)),
Expand Down Expand Up @@ -233,6 +232,10 @@ func resourceVPCEndpointCreate(ctx context.Context, d *schema.ResourceData, meta
input.PolicyDocument = aws.String(policy)
}

if v, ok := d.GetOk("private_dns_enabled"); ok {
input.PrivateDnsEnabled = aws.Bool(v.(bool))
}

if v, ok := d.GetOk("route_table_ids"); ok && v.(*schema.Set).Len() > 0 {
input.RouteTableIds = flex.ExpandStringValueSet(v.(*schema.Set))
}
Expand Down Expand Up @@ -381,7 +384,6 @@ func resourceVPCEndpointUpdate(ctx context.Context, d *schema.ResourceData, meta
}

if d.HasChanges("dns_options", names.AttrIPAddressType, names.AttrPolicy, "private_dns_enabled", names.AttrSecurityGroupIDs, "route_table_ids", names.AttrSubnetIDs) {
privateDNSEnabled := d.Get("private_dns_enabled").(bool)
input := &ec2.ModifyVpcEndpointInput{
VpcEndpointId: aws.String(d.Id()),
}
Expand All @@ -403,6 +405,7 @@ func resourceVPCEndpointUpdate(ctx context.Context, d *schema.ResourceData, meta
input.IpAddressType = awstypes.IpAddressType(d.Get(names.AttrIPAddressType).(string))
}

privateDNSEnabled := d.Get("private_dns_enabled").(bool)
if d.HasChange("private_dns_enabled") {
input.PrivateDnsEnabled = aws.Bool(privateDNSEnabled)
}
Expand Down
162 changes: 162 additions & 0 deletions internal/service/ec2/vpc_endpoint_private_dns.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,162 @@
// Copyright (c) HashiCorp, Inc.
// SPDX-License-Identifier: MPL-2.0

package ec2

import (
"context"
"errors"

"github.com/aws/aws-sdk-go-v2/aws"
"github.com/aws/aws-sdk-go-v2/service/ec2"
"github.com/hashicorp/terraform-plugin-framework/path"
"github.com/hashicorp/terraform-plugin-framework/resource"
"github.com/hashicorp/terraform-plugin-framework/resource/schema"
"github.com/hashicorp/terraform-plugin-framework/resource/schema/planmodifier"
"github.com/hashicorp/terraform-plugin-framework/resource/schema/stringplanmodifier"
"github.com/hashicorp/terraform-plugin-framework/types"
"github.com/hashicorp/terraform-provider-aws/internal/create"
"github.com/hashicorp/terraform-provider-aws/internal/framework"
"github.com/hashicorp/terraform-provider-aws/internal/framework/flex"
"github.com/hashicorp/terraform-provider-aws/internal/tfresource"
"github.com/hashicorp/terraform-provider-aws/names"
)

// @FrameworkResource("aws_vpc_endpoint_private_dns", name="Endpoint Private DNS")
func newResourceEndpointPrivateDNS(_ context.Context) (resource.ResourceWithConfigure, error) {
return &resourceEndpointPrivateDNS{}, nil
}

const (
ResNameEndpointPrivateDNS = "Endpoint Private DNS"
)

type resourceEndpointPrivateDNS struct {
framework.ResourceWithConfigure
framework.WithNoOpDelete
}

func (r *resourceEndpointPrivateDNS) Metadata(_ context.Context, req resource.MetadataRequest, resp *resource.MetadataResponse) {
resp.TypeName = "aws_vpc_endpoint_private_dns"
}

func (r *resourceEndpointPrivateDNS) Schema(ctx context.Context, req resource.SchemaRequest, resp *resource.SchemaResponse) {
resp.Schema = schema.Schema{
Attributes: map[string]schema.Attribute{
"private_dns_enabled": schema.BoolAttribute{
Required: true,
},
names.AttrVPCEndpointID: schema.StringAttribute{
Required: true,
PlanModifiers: []planmodifier.String{
stringplanmodifier.RequiresReplace(),
},
},
},
}
}

func (r *resourceEndpointPrivateDNS) Create(ctx context.Context, req resource.CreateRequest, resp *resource.CreateResponse) {
conn := r.Meta().EC2Client(ctx)

var plan resourceEndpointPrivateDNSData
resp.Diagnostics.Append(req.Plan.Get(ctx, &plan)...)
if resp.Diagnostics.HasError() {
return
}

in := &ec2.ModifyVpcEndpointInput{
VpcEndpointId: aws.String(plan.VpcEndpointID.ValueString()),
PrivateDnsEnabled: aws.Bool(plan.PrivateDNSEnabled.ValueBool()),
}

out, err := conn.ModifyVpcEndpoint(ctx, in)
if err != nil {
resp.Diagnostics.AddError(
create.ProblemStandardMessage(names.EC2, create.ErrActionCreating, ResNameEndpointPrivateDNS, plan.VpcEndpointID.String(), err),
err.Error(),
)
return
}
if out == nil {
resp.Diagnostics.AddError(
create.ProblemStandardMessage(names.EC2, create.ErrActionCreating, ResNameEndpointPrivateDNS, plan.VpcEndpointID.String(), nil),
errors.New("empty output").Error(),
)
return
}

resp.Diagnostics.Append(resp.State.Set(ctx, plan)...)
}

func (r *resourceEndpointPrivateDNS) Read(ctx context.Context, req resource.ReadRequest, resp *resource.ReadResponse) {
conn := r.Meta().EC2Client(ctx)

var state resourceEndpointPrivateDNSData
resp.Diagnostics.Append(req.State.Get(ctx, &state)...)
if resp.Diagnostics.HasError() {
return
}

out, err := findVPCEndpointByIDV2(ctx, conn, state.VpcEndpointID.ValueString())
if tfresource.NotFound(err) {
resp.State.RemoveResource(ctx)
return
}
if err != nil {
resp.Diagnostics.AddError(
create.ProblemStandardMessage(names.EC2, create.ErrActionReading, ResNameEndpointPrivateDNS, state.VpcEndpointID.String(), err),
err.Error(),
)
return
}

state.PrivateDNSEnabled = flex.BoolToFramework(ctx, out.PrivateDnsEnabled)

resp.Diagnostics.Append(resp.State.Set(ctx, &state)...)
}

func (r *resourceEndpointPrivateDNS) Update(ctx context.Context, req resource.UpdateRequest, resp *resource.UpdateResponse) {
conn := r.Meta().EC2Client(ctx)

var plan, state resourceEndpointPrivateDNSData
resp.Diagnostics.Append(req.Plan.Get(ctx, &plan)...)
resp.Diagnostics.Append(req.State.Get(ctx, &state)...)
if resp.Diagnostics.HasError() {
return
}

if !plan.PrivateDNSEnabled.Equal(state.PrivateDNSEnabled) {
in := &ec2.ModifyVpcEndpointInput{
VpcEndpointId: aws.String(plan.VpcEndpointID.ValueString()),
PrivateDnsEnabled: aws.Bool(plan.PrivateDNSEnabled.ValueBool()),
}

out, err := conn.ModifyVpcEndpoint(ctx, in)
if err != nil {
resp.Diagnostics.AddError(
create.ProblemStandardMessage(names.EC2, create.ErrActionCreating, ResNameEndpointPrivateDNS, plan.VpcEndpointID.String(), err),
err.Error(),
)
return
}
if out == nil {
resp.Diagnostics.AddError(
create.ProblemStandardMessage(names.EC2, create.ErrActionCreating, ResNameEndpointPrivateDNS, plan.VpcEndpointID.String(), nil),
errors.New("empty output").Error(),
)
return
}
}

resp.Diagnostics.Append(resp.State.Set(ctx, &plan)...)
}

func (r *resourceEndpointPrivateDNS) ImportState(ctx context.Context, req resource.ImportStateRequest, resp *resource.ImportStateResponse) {
resource.ImportStatePassthroughID(ctx, path.Root(names.AttrVPCEndpointID), req, resp)
}

type resourceEndpointPrivateDNSData struct {
VpcEndpointID types.String `tfsdk:"vpc_endpoint_id"`
PrivateDNSEnabled types.Bool `tfsdk:"private_dns_enabled"`
}
Loading

0 comments on commit 27f7195

Please sign in to comment.