Skip to content

Commit d265fed

Browse files
authored
Merge pull request #7 from yaradigitallabs/DE-3650/redis-enable-encryption-at-rest
DE-3650 Enabling encryption at rest parameter for redis
2 parents e37b5e1 + 9931da0 commit d265fed

File tree

2 files changed

+7
-0
lines changed

2 files changed

+7
-0
lines changed

main.tf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,7 @@ resource "aws_elasticache_replication_group" "redis" {
2323
snapshot_retention_limit = var.redis_snapshot_retention_limit
2424
tags = merge({ "Name" = format("tf-elasticache-%s", var.name) }, var.tags)
2525
transit_encryption_enabled = var.transit_encryption_enabled
26+
at_rest_encryption_enabled = var.at_rest_encryption_enabled
2627
auth_token = var.transit_encryption_enabled ? var.auth_token : null
2728
}
2829

variables.tf

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -128,6 +128,12 @@ variable "transit_encryption_enabled" {
128128
description = "Enable TLS"
129129
}
130130

131+
variable "at_rest_encryption_enabled" {
132+
type = bool
133+
default = true
134+
description = "Enable encryption at rest"
135+
}
136+
131137
variable "auth_token" {
132138
type = string
133139
description = "token for password protecting redis, transit_encryption_enabled must`` be set to `true`. Password must be longer than 16 chars"

0 commit comments

Comments
 (0)