No requirements.
Basic usage of this module is as follows:
module "ec2" {
source = "../module"
domain_name = "example.com"
vpc_id = "vpc-abcdef123456"
subnet_id = "subnet-abcdef123"
allow_ingress_ip = "0.0.0.0/0"
create_iam_instance_profile = true
# Architecture: "x86_64" (default) or "arm64" (Graviton).
# instance_type is resolved automatically unless overridden:
# x86_64 → t3.medium, arm64 → t4g.medium
architecture = "arm64"
# instance_type = "t3.medium" # uncomment to override the auto-resolved type
# Web framework: "php" (default), "nodejs", or "static"
web_framework = "php"
php_version = "8.4"
# Node.js options — only used when web_framework = "nodejs"
# web_framework = "nodejs"
# nodejs_version = "20"
# upstream_port = 3000
# MySQL: set install_mysql = false to skip MySQL entirely.
# mysql_databases defines which databases and users to create.
# A random password is generated for each user.
install_mysql = true
mysql_databases = [
{ name = "appdb", user = "appuser" },
{ name = "testdb", user = "testuser" },
]
ubuntu_lts_version = "24.04"
root_block_device = ({
encrypted = true
volume_type = "gp3"
throughput = 200
volume_size = 50
})
}This project provisions an EC2 instance with Nginx, PHP-FPM or Node.js, MySQL, and automated backups in about 5 minutes. You need Terraform installed to use it.
A full working example is in terraform/example.com/. Adjust main.tf and backend.tf, then run:
terraform init
terraform applyAfter apply, an SSH key pair is saved in the current directory. Connect to your instance with:
ssh <server_ip> -l ubuntu -i example.com.pemThe instance configures itself on first boot via an Ansible playbook delivered through EC2 user data.
- Supported PHP versions:
8.3,8.4,8.5(installed from theondrej/phpPPA). php.iniis hardened: uploads enabled, errors hidden, dangerous functions disabled.- PHP-FPM socket is configured as the Nginx FastCGI upstream.
- Node.js is installed via nvm. The version is controlled by
nodejs_version(default:"20"). - Nginx is configured as a reverse proxy forwarding requests to
127.0.0.1:<upstream_port>(default:3000).
- Nginx serves static files directly from
/var/www/vhosts/<domain_name>/. - No application runtime is installed.
- Installed when
install_mysql = true(default). - Root password is auto-generated and saved to
/root/.my.cnf. - Per-database user passwords are saved to
/var/www/vhosts/<dbname>/.db_credentials. - A read-only backup user is created automatically.
- A backup script is placed at
/root/bin/mysql-maint.shand scheduled as a midnight cron job.
- Virtual host config is written to
/etc/nginx/conf.d/<domain_name>.conf. - Web root is
/var/www/vhosts/<domain_name>/. - Security headers, static asset caching, and WordPress hardening rules are included by default.
- After setup, point your DNS to the instance IP and run
certbot --nginxto issue TLS certificates.
If provisioning fails, review the cloud-init log:
cat /var/log/cloud-init-output.logNo resources.
No inputs.
No outputs.