docs: add Terraform certification notes and tasks

This commit is contained in:
2026-08-04 23:18:47 +02:00
parent 91a1849009
commit 758182a700
53 changed files with 4588 additions and 0 deletions

125
terraform/task-39.md Normal file
View File

@@ -0,0 +1,125 @@
# Assignment
The Nautilus DevOps team is automating IAM role creation using Terraform to streamline permissions management. As part of this task, they need to create an IAM role with specific requirements.
For this task, create an AWS IAM role using Terraform with the following requirements:
The IAM role name iamrole_rose should be stored in a variable named KKE_iamrole.
Note:
1. The configuration values should be stored in a variables.tf file.
2. The Terraform script should be structured with a main.tf file referencing variables.tf.
The Terraform working directory is /home/bob/terraform.
Right-click under the EXPLORER section in VS Code and select Open in Integrated Terminal to launch the terminal.
# Solution
# IAM Role with Variables — `iamrole_rose` (`KKE_iamrole`)
Two-file structure: `variables.tf` holds the config, `main.tf` references it. The IAM
role name must be stored in a variable named exactly `KKE_iamrole`.
## `variables.tf`
```hcl
variable "KKE_iamrole" {
description = "Name of the IAM role"
type = string
default = "iamrole_rose"
}
```
## `main.tf`
```hcl
terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 6.0"
}
}
}
provider "aws" {
region = "us-east-1"
}
resource "aws_iam_role" "rose" {
name = var.KKE_iamrole
assume_role_policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Effect = "Allow"
Principal = {
Service = "ec2.amazonaws.com"
}
Action = "sts:AssumeRole"
}
]
})
tags = {
Name = var.KKE_iamrole
}
}
```
## How to run
```bash
cd /home/bob/terraform
terraform init
terraform apply -auto-approve
```
## How it works
### Splitting config from logic
Terraform merges every `.tf` file in the directory into one configuration, so
`variables.tf` and `main.tf` act as a single unit — no imports. `variables.tf` declares
inputs; `main.tf` declares resources that consume them via `var.<name>`.
### The variable
- **`variable "KKE_iamrole"`** — holds the IAM role name, exactly as required. The
`default` of `iamrole_rose` lets `terraform apply` run without prompting.
- **`type = string`** validates the input type at plan time.
### The IAM role
- **`name = var.KKE_iamrole`** — resolves to `iamrole_rose` via the `var.` prefix.
- **`assume_role_policy` is mandatory.** Unlike a user or group, an IAM role
**requires** a trust policy at creation — it defines *who* (which principal) is
allowed to assume the role. Terraform's `aws_iam_role` will error without it. This
one trusts the EC2 service (`ec2.amazonaws.com`) to assume the role via
`sts:AssumeRole`, which is the standard trust for a role you'd attach to EC2
instances. Any valid trust works; EC2 is a sensible, common default.
- **`jsonencode({...})`** builds the trust-policy JSON from an HCL object, keeping it
readable and correctly escaped rather than hand-writing a raw JSON string.
- **No permission policies attached.** The trust policy governs *who can assume* the
role; it grants no AWS permissions itself. The task only asks for the role to exist,
so no `aws_iam_role_policy_attachment` is added — which also keeps the config within
the sandbox's IAM restrictions (attaching a broad policy could trigger
`AccessDenied`).
- **IAM is global.** The provider `region` is only for auth; the role is account-wide.
## Verify
```bash
aws iam get-role --role-name iamrole_rose \
--query 'Role.{Name:RoleName,Id:RoleId,Arn:Arn,Trust:AssumeRolePolicyDocument}'
```
Expected — the role name, a unique ID, an ARN of the form
`arn:aws:iam::<account-id>:role/iamrole_rose`, and the trust policy allowing
`ec2.amazonaws.com` to assume it.