Resource tags
Every AWS resource in BYM carries a standard set of tags. The tags tell you which team owns a resource, which application and environment it belongs to, and which folder in which repository created it. Cost reports, security findings, and the Byks adoption metrics all rely on these tags.
You don't add the tags to each resource yourself. The terraform-aws-tags module builds the tag map once, and the AWS provider in environment.tf applies it to every resource Terraform creates through that provider. See Terraform Infrastruktur-repos for where environment.tf sits in the repository layout.
Tags
The module outputs one map, tags, with these keys:
| Tag | Value |
|---|---|
Terraformed |
Always True. |
Environment |
The environment input. |
Application |
The application input. |
Section |
The section input. |
Team |
The team input. |
Git |
A link to the folder that ran Terraform, in the form github.com/bym-ikt/<repo>/tree/<branch>/<folder>/, with the repository part in lowercase. The module reads the repository URL and folder from your local Git checkout, so Terraform must run inside a clone of the Terraform Infrastruktur-repo. |
Terraform configuration
Call the module once per environment folder and pass its output to default_tags on each AWS provider. The Byks module and every other BYM module then inherit the tags without any extra configuration.
module "tags" {
source = "git@github.com:BYM-IKT/terraform-aws-tags.git?ref=v3"
environment = var.environment
section = var.section
team = var.team
application = var.application_name
# options go here
}
provider "aws" {
region = var.region
profile = var.aws_profile
default_tags {
tags = module.tags.tags
}
}
Options
| Option | Type | Default | Description |
|---|---|---|---|
environment |
string |
required | Environment name, for example test or prod. Becomes the Environment tag. |
section |
string |
required | The BYM section that owns the application, for example DP or DTI. Becomes the Section tag. |
team |
string |
required | Team responsible for the application, for example team-katt. Becomes the Team tag. |
application |
string |
required | Name of the application, for example kattehotell. Becomes the Application tag. Version 3 renamed this input from service, and the tag from Service to Application. |
override_git_branch |
string |
"master" |
Branch name used in the Git tag. The tag always uses this value, not the branch you have checked out, so pull request plans don't show a tag change on every resource. Passing null also gives master. |
Resources
-
AWS documentation
Official AWS documentation for tagging resources