Chapter 12: Terraform Introduction
12.4 Minimal resource — security group lab (preferred small)
A safe first resource: an AWS security group with a clear name tag for badge API labs. Adjust VPC ID if you are not on the account default VPC — look up the ID (aws ec2 describe-vpcs) rather than inventing networking theory here.
# main.tf — minimal SG example
resource "aws_security_group" "badge-api_lab" {
name = "badge-api-lab-sg"
description = "Lab SG for Instagram-style badge API learning"
vpc_id = var.vpc_id # set via tfvars; use your real VPC id
ingress {
description = "SSH from my IP only — replace cidr"
from_port = 22
to_port = 22
protocol = "tcp"
cidr_blocks = [var.my_ip_cidr]
}
egress {
from_port = 0
to_port = 0
protocol = "-1"
cidr_blocks = ["0.0.0.0/0"]
}
tags = {
Name = "badge-api-lab-sg"
Project = "badge API"
Purpose = "learning"
}
}
# variables.tf
variable "aws_region" {
type = string
default = "ap-south-1"
}
variable "vpc_id" {
type = string
description = "Existing VPC ID from your account (do not invent networking here)"
}
variable "my_ip_cidr" {
type = string
description = "Your public IP as x.x.x.x/32 for lab SSH"
}
# outputs.tf
output "badge-api_lab_sg_id" {
value = aws_security_group.badge-api_lab.id
}
Optional tiny EC2: only if you already understand launch/SG from the AWS course. Reuse an existing subnet ID via variable; do not paste a full VPC module into this beginner chapter. Prefer stopping at the security group if you want lower blast radius.
No invented prices
Cloud bills depend on account, region and usage. Stop idle labs; always destroy when finished. We do not quote fake free-tier numbers here.