Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JonasNyquist
Contributor
Contributor

Terraform updates - Versions and modules

Hi fellow engineers and architects and all other roles here!

I don't have coding/programming background, but I DO have a fair amount of knowledge and experience of Check Point gateways and management (and all....), so when we decided to implement Public Cloud gateways, and Terraform was the way to do it, I had to take on the task to learn how all THAT works, and at the time I had a colleague who had a bit of a coding background, so he took leed of the coding, and I assisted mostly with settings and knowledge around how and where to deploy these gateways, how to manage them etc and everything worked out pretty good.

Now, this was a few years back, and at the time I want to claim that the Check Point Terraform were not "official" and registered at terraform.io.
Also, since then, my colleague has left our company, so at the moment I'm in sole responsibility for this deployment, and I need to keep it current and accurate, so I have started to go back through the code, got some understanding of how my colleague "built" his own terraform code "tree", using the Check Point terraform modules that were at the time only available in the GitHub repo.
He built an execution that when launched, it creates a Gateway Load Balancer, an AutoScaling Group with Gateways and an Endpoint Service to connect GWLB Endpoints to the "Egress VPC" to "intercept" the Internet bound traffic for security filtering.

Right now, I need to maintain this current code, but I also want to rebuild the code so that instead of using local modules, I want to refer to the "official" ones, in the Terraform repo, so that when updates to the official code happens, I can just change a version number to start running the "latest" modules.
At least, that's my understanding of the most efficient way to utilize the modules, if anyone have a different opinion, please comment and motivate.

Anyway, right now, these are my questions that I hope that I can some help, advice and guidance about:


########################################
So, we implemented the AWS Terraform modules a couple of years back, before they were "officially" part of "Terraform Registry" with versioning and stuff.
So we kind of built our own module using the local code references, and so now when I need to update "our" module, so what modules in "your" code tree needs to be replaced, and CAN they be just "drop-in" replaced?
I have been updating the "version_license" module (I also replaced the "amis" module, although I'm pretty sure that module is "never" changed/updated) to be able to update to newer versions.

Is there anything else that I MUST update/replace. How can I/Can I control exactly which version of the ami I want to install, or will for example "R82-BYOL" ALLWAYS give me the latest ami version available at the execution of the code?

Is the webpage https://cgi-cfts.s3.amazonaws.com/utils/amis.yaml in the ultimately what controls the image installed, what ami version is installed, for a Gateway, would be the Regional ami for the "attribute" R82BYOLGW on that URL?

I'm planning on updating our code to reflect the new "structure" when I have time, but for now I just need to maintain so we can update properly.

Kind regards,

Jonas

 

0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events