docs: add Terraform certification notes and tasks

This commit is contained in:
2026-08-04 23:18:47 +02:00
parent 91a1849009
commit 758182a700
53 changed files with 4588 additions and 0 deletions

45
terraform/012/main.tf Normal file
View File

@@ -0,0 +1,45 @@
# terraform {
# required_providers {
# aws = {
# source = "hashicorp/aws"
# version = "~> 6.0"
# }
# }
# }
# provider "aws" {
# region = "us-east-1"
# }
resource "aws_s3_bucket" "datacenter" {
bucket = "datacenter-s3-30377"
}
# Re-enable ACLs (default is BucketOwnerEnforced, which disables them)
resource "aws_s3_bucket_ownership_controls" "datacenter" {
bucket = aws_s3_bucket.datacenter.id
rule {
object_ownership = "BucketOwnerPreferred"
}
}
# Lift the public-access block so a public ACL is allowed
resource "aws_s3_bucket_public_access_block" "datacenter" {
bucket = aws_s3_bucket.datacenter.id
block_public_acls = false
block_public_policy = false
ignore_public_acls = false
restrict_public_buckets = false
}
# Now the public ACL will actually take
resource "aws_s3_bucket_acl" "datacenter" {
bucket = aws_s3_bucket.datacenter.id
acl = "public-read"
depends_on = [
aws_s3_bucket_ownership_controls.datacenter,
aws_s3_bucket_public_access_block.datacenter,
]
}

14
terraform/012/task-12.md Normal file
View File

@@ -0,0 +1,14 @@
As part of the data migration process, the Nautilus DevOps team is actively creating several S3 buckets on AWS. They plan to utilize both private and public S3 buckets to store the relevant data. Given the ongoing migration of other infrastructure to AWS, it is logical to consolidate data storage within the AWS environment as well.
Create a public S3 bucket named datacenter-s3-30377 using Terraform.
Ensure the bucket is accessible publicly once created by setting the proper ACL.
The Terraform working directory is /home/bob/terraform. Create the main.tf file (do not create a different .tf file) to accomplish this task.
Notes:
Create the resources only in the us-east-1 region.
Right-click under the EXPLORER section in VS Code and select Open in Integrated Terminal to launch the terminal.
The name of the S3 bucket should be based on datacenter-s3-30377.
You can use the ACL settings to ensure the bucket is publicly accessible.