Skip to main content

Discover AWS Resources in a Single Account

Report an Issue

This page lists the configuration fields in a usage example of the teleport-discovery-aws Terraform module: single-account.

Teleport AWS Account Discovery Example​

Configuration in this directory creates AWS and Teleport resources necessary for Teleport to discover EC2 and EKS resources in a single AWS account.

Requirements​

NameVersion
terraform>= 1.0
aws>= 5.0
teleport>= 18.5.1
tls>= 4.0

Providers​

No providers.

Modules​

NameSourceVersion
aws_discovery../..n/a

Resources​

No resources.

Inputs​

No inputs.

Outputs​

NameDescription
aws_discoveryn/a

Source Code​

View the single-account example source code for the teleport-discovery-aws module on GitHub.

################################################################################
# teleport/discovery/aws/examples/single-account/main.tf
################################################################################

module "aws_discovery" {
  source  = "terraform.releases.teleport.dev/teleport/discovery/aws"
  version = "~> 18.0"

  teleport_proxy_public_addr    = "example.teleport.sh:443"
  teleport_discovery_group_name = "cloud-discovery-group"

  # Discover EC2 instances and EKS clusters with separate matching rules.
  # Both types accept "*" to discover across all enabled regions. The module
  # adds account:ListRegions to the IAM policy automatically when "*" is used.
  aws_matchers = [
    {
      types   = ["ec2"]
      regions = ["*"]
      tags = {
        env = ["prod"]
      }
    },
    {
      types   = ["eks"]
      regions = ["*"]
      tags = {
        team = ["platform"]
      }
      # Teleport's Kubernetes App Discovery will automatically identify and enroll HTTP applications running inside a Kubernetes cluster.
      kube_app_discovery = true
    }
  ]

  # Apply the additional Teleport label "origin=example" to all Teleport resources created by this module
  apply_teleport_resource_labels = { origin = "example" }
  # Apply the additional AWS tag "origin=example" to all AWS resources created by this module
  apply_aws_tags = { origin = "example" }
}

################################################################################
# teleport/discovery/aws/examples/single-account/outputs.tf
################################################################################

output "aws_discovery" {
  value = module.aws_discovery
}

################################################################################
# teleport/discovery/aws/examples/single-account/versions.tf
################################################################################

terraform {
  required_version = ">= 1.0"

  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = ">= 5.0"
    }
    tls = {
      source  = "hashicorp/tls"
      version = ">= 4.0"
    }
    teleport = {
      source  = "terraform.releases.teleport.dev/gravitational/teleport"
      version = ">= 18.5.1"
    }
  }
}