{"_id":"@arkadecx/serverless-vpc-plugin","_rev":"1-ca96ec75c1028d89a47be06e93a291ed","name":"@arkadecx/serverless-vpc-plugin","dist-tags":{"latest":"0.9.6"},"versions":{"0.9.6":{"name":"@arkadecx/serverless-vpc-plugin","version":"0.9.6","engines":{"node":">=8.0"},"description":"Serverless Plugin to generate a VPC","author":{"name":"Smoke Turner, LLC","email":"github@smoketurner.com"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/arkade-digital/serverless-vpc-plugin.git"},"keywords":["serverless","serverless plugin","vpc","lambda","aws","aws lambda","amazon web services","serverless.com"],"main":"src/index.js","scripts":{"test":"SLS_DEBUG=* jest --coverage"},"dependencies":{"cidr-split":"0.1.2"},"devDependencies":{"aws-sdk-mock":"5.1.0","eslint":"6.8.0","eslint-config-airbnb-base":"14.1.0","eslint-config-prettier":"6.10.1","eslint-plugin-import":"2.20.2","eslint-plugin-jest":"23.8.2","eslint-plugin-prettier":"3.1.2","jest":"25.3.0","nock":"12.0.3","prettier":"2.0.4","serverless":"1.67.3"},"bugs":{"url":"https://github.com/arkade-digital/serverless-vpc-plugin/issues"},"homepage":"https://github.com/arkade-digital/serverless-vpc-plugin#readme","directories":{"example":"example"},"gitHead":"6f5c99a5b8384f5ac600c6f0013954539d04fd6c","_id":"@arkadecx/serverless-vpc-plugin@0.9.6","_nodeVersion":"16.14.0","_npmVersion":"8.12.2","dist":{"integrity":"sha512-VfIjrVpkxocmb01zZJKqWhPvzCNeCdDtDkF+3gRI2Hqphq+b7X4FzpeXtaMbyx1/5nAZ3Wx7W3z+28HWcPZ/uQ==","shasum":"d7d1ff3adadf27ca40adc8369ae73f37e0c9eca5","tarball":"https://registry.npmjs.org/@arkadecx/serverless-vpc-plugin/-/serverless-vpc-plugin-0.9.6.tgz","fileCount":23,"unpackedSize":70090,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDSIhNp6G8vEIHfxY0cDjDnVWDW8BnJAVKcQwEdQCuOzAIhALXt1TTlW+9aNvmzou/Yiuf+H4TeJYha5YGvR5ueKbnJ"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjFbdEACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrU4g//ehwMsbWCiLpj3J0/gLBNq4MXBro/ofB6E17m2YvAk8MA5ndO\r\nra/uQshUJOBBxGBxenEB3qt99xJqlJyLKLwPptzkC6gutrtrHHbyLAu8u+Mb\r\nhBmSPLRjepv9029ME4GheUDcSa4tpvImoC7FenNjbhbjZRIV5zODc7nlpZ2N\r\nUDQReq7EyQj/Ht6Zlc5rb9EDORLLIKM90MGRuYvv9jeER7XmRjKB7moiqW6g\r\nEBWQiavniO46lIUuPXAKdbOjkk0FdE+fU/RSkEBiBnKSl1ZSubJTE1yz2pkS\r\nH+1ZLWbJoASuoV02Ixjnbz8LC4KU+WORSNCdxXUJ/FXWRuxUt4Iwv4oieiEz\r\nJIPJIjrvGgoAomCgIN+uT8yRD5mQcbSljtMd3ttN1v8AGZpiPH5QfSokNTHo\r\nC4X6TBN2PSPP35WnNUWyAMTOBZiN78YdxQXiE2VUqt576ajAFMCtnTLmRYeN\r\n+KkoFgeBj058v8I+3IPsFilaGYh8seFw8FJ7hE2VJhudqrUsCymEUxpgLKrI\r\nZnVJA078moRgylTwdDOb9wY8MMBxpbhuvVsxgGzEeCF104GxwxvCpgAg/mJD\r\nRSZC7n0/9HZfN3A5q/NvQq+nFp0qFde+8Avdqd39++/Z7RMUu3GQZzpARRr+\r\nckmGopTKRgpG8V9hNpAo0zoAW0WVCb/DhBU=\r\n=M6Ow\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"kyle-arkade","email":"kyle@arkade.com.au"},"maintainers":[{"name":"fnandogp","email":"fnandogp@gmail.com"},{"name":"yazhizhou","email":"yazhi@arkade.com.au"},{"name":"max.arkade","email":"max@arkade.com.au"},{"name":"kyle-arkade","email":"kyle@arkade.com.au"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/serverless-vpc-plugin_0.9.6_1662367556745_0.13276669098479954"},"_hasShrinkwrap":false}},"time":{"created":"2022-09-05T08:45:56.672Z","0.9.6":"2022-09-05T08:45:56.921Z","modified":"2022-10-18T11:05:03.604Z"},"maintainers":[{"email":"tew@arkade.com.au","name":"tew-arkade"},{"email":"fnandogp@gmail.com","name":"fnandogp"},{"email":"yazhi@arkade.com.au","name":"yazhizhou"},{"email":"max@arkade.com.au","name":"max.arkade"},{"email":"kyle@arkade.com.au","name":"kyle-arkade"}],"description":"Serverless Plugin to generate a VPC","homepage":"https://github.com/arkade-digital/serverless-vpc-plugin#readme","keywords":["serverless","serverless plugin","vpc","lambda","aws","aws lambda","amazon web services","serverless.com"],"repository":{"type":"git","url":"git+https://github.com/arkade-digital/serverless-vpc-plugin.git"},"author":{"name":"Smoke Turner, LLC","email":"github@smoketurner.com"},"bugs":{"url":"https://github.com/arkade-digital/serverless-vpc-plugin/issues"},"license":"MIT","readme":"# serverless-vpc-plugin\n\n[![serverless](http://public.serverless.com/badges/v3.svg)](http://www.serverless.com)\n[![npm version](https://badge.fury.io/js/serverless-vpc-plugin.svg)](https://badge.fury.io/js/serverless-vpc-plugin)\n[![MIT licensed](https://img.shields.io/badge/license-MIT-blue.svg)](https://raw.githubusercontent.com/smoketurner/serverless-vpc-plugin/master/LICENSE)\n[![npm downloads](https://img.shields.io/npm/dt/serverless-vpc-plugin.svg?style=flat)](https://www.npmjs.com/package/serverless-vpc-plugin)\n\nAutomatically creates an AWS Virtual Private Cloud (VPC) using all available Availability Zones (AZ) in a region.\n\nThis plugin provisions the following resources:\n\n- `AWS::EC2::VPC`\n- `AWS::EC2::InternetGateway` (for outbound internet access from \"Public\" subnet)\n- `AWS::EC2::VPCGatewayAttachment` (to attach the `InternetGateway` to the VPC)\n- `AWS::EC2::SecurityGroup` (to execute Lambda functions [`LambdaExecutionSecurityGroup`])\n\nIf the VPC is allocated a /16 subnet, each availability zone within the region will be allocated a /20 subnet. Within each availability zone, this plugin will further divide the subnets:\n\n- `AWS::EC2::Subnet` \"Public\" (/22) - default route set to the `InternetGateway`\n- `AWS::EC2::Subnet` \"Application\" (/21) - no default route set (can be set to either a `NatGateway` or `NatInstance`)\n- `AWS::EC2::Subnet` \"Database\" (/22) - no default route set\n\nThe subnetting layout was heavily inspired by the now shutdown [Skyliner](https://skyliner.io) platform. 😞\n\nOptionally, this plugin can also create `AWS::EC2::NatGateway` instances in each availability zone which requires provisioning `AWS::EC2::EIP` resources (AWS limits you to 5 per VPC, so if you want to provision your VPC across all 6 us-east availability zones, you'll need to request an VPC EIP limit increase from AWS).\n\nInstead of using the managed `AWS::EC2::NatGateway` instances, this plugin can also provision a single `t2.micro` NAT instance in `PublicSubnet1` which will allow HTTP/HTTPS traffic from the \"Application\" subnets to reach the Internet.\n\nLambda functions will execute within the \"Application\" subnet and only be able to access:\n\n- S3 (via an S3 VPC endpoint)\n- DynamoDB (via an DynamoDB VPC endpoint)\n- RDS instances (provisioned within the \"DB\" subnet)\n- ElastiCache instances (provisioned within the \"DB\" subnet)\n- RedShift (provisioned within the \"DB\" subnet),\n- DAX clusters (provisioned within the \"DB\" subnet)\n- Neptune clusters (provisioned with the \"DB\" subnet)\n- Internet Access (if using a `NatGateway` or a `NatInstance`)\n\nIf your Lambda functions need to [access the internet](https://docs.aws.amazon.com/lambda/latest/dg/vpc.html#vpc-internet), then you _MUST_ provision `NatGateway` resources or a NAT instance.\n\nBy default, `AWS::EC2::VPCEndpoint` \"Gateway\" endpoints for S3 and DynamoDB will be provisioned within each availability zone to provide internal access to these services (there is no additional charge for using Gateway Type VPC endpoints). You can selectively control which `AWS::EC2::VPCEndpoint` \"Interface\" endpoints are available within your VPC using the `services` configuration option below. Not all AWS services are available in every region, so the plugin will query AWS to validate the services you have selected and notify you if any changes are required (there is an additional charge for using Interface Type VPC endpoints).\n\nIf you specify more then one availability zone, this plugin will also provision the following database-related resources (controlled using the `subnetGroups` plugin option):\n\n- `AWS::RDS::DBSubnetGroup`\n- `AWS::ElastiCache::SubnetGroup`\n- `AWS::Redshift::ClusterSubnetGroup`\n- `AWS::DAX::SubnetGroup`\n\nto make it easier to create these resources across all of the availability zones.\n\n## Installation\n\n```\n$ npx sls plugin install -n serverless-vpc-plugin\n```\n\n## Configuration\n\n- All `vpcConfig` configuration parameters are optional\n\n```yaml\n# add in your serverless.yml\n\nplugins:\n  - serverless-vpc-plugin\n\nprovider:\n  # you do not need to provide the \"vpc\" section as this plugin will populate it automatically\n  vpc:\n    securityGroupIds:\n      -  # plugin will add LambdaExecutionSecurityGroup to this list\n    subnetIds:\n      -  # plugin will add the \"Application\" subnets to this list\n\ncustom:\n  vpcConfig:\n    cidrBlock: '10.0.0.0/16'\n\n    # if createNatGateway is a boolean \"true\", a NAT Gateway and EIP will be provisioned in each zone\n    # if createNatGateway is a number, that number of NAT Gateways will be provisioned\n    createNatGateway: 2\n\n    # When enabled, the DB subnet will only be accessible from the Application subnet\n    # Both the Public and Application subnets will be accessible from 0.0.0.0/0\n    createNetworkAcl: false\n\n    # Whether to create the DB subnet\n    createDbSubnet: true\n\n    # Whether to enable VPC flow logging to an S3 bucket\n    createFlowLogs: false\n\n    # Whether to create a bastion host\n    createBastionHost: false\n    bastionHostKeyName: MyKey # required if creating a bastion host\n\n    # Whether to create a NAT instance\n    createNatInstance: false\n\n    # Optionally specify AZs (defaults to auto-discover all availabile AZs)\n    zones:\n      - us-east-1a\n      - us-east-1b\n      - us-east-1c\n\n    # By default, S3 and DynamoDB endpoints will be available within the VPC\n    # see https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints.html\n    # for a list of available service endpoints to provision within the VPC\n    # (varies per region)\n    services:\n      - kms\n      - secretsmanager\n\n    # Optionally specify subnet groups to create. If not provided, subnet groups\n    # for RDS, Redshift, ElasticCache and DAX will be provisioned.\n    subnetGroups:\n      - rds\n        \n    # Whether to export stack outputs so it may be consumed by other stacks \n    exportOutputs: false\n```\n\n## CloudFormation Outputs\n\nAfter executing `serverless deploy`, the following CloudFormation Stack Outputs will be provided:\n\n- `VPC`: VPC logical resource ID\n- `LambdaExecutionSecurityGroup`: Security Group logical resource ID that the Lambda functions use when executing within the VPC\n- `BastionSSHUser`: SSH username to access the bastion host, if provisioned\n- `BastionEIP`: Elastic IP address associated to the bastion host, if provisioned\n- `RDSSubnetGroup`: SubnetGroup associated to RDS, if provisioned \n- `ElastiCacheSubnetGroup`: SubnetGroup associated to ElastiCache, if provisioned\n- `RedshiftSubnetGroup`: SubnetGroup associated to Redshift, if provisioned\n- `DAXSubnetGroup`: SubnetGroup associated to DAX, if provisioned\n- `AppSubnet{i}`: Each of the generated \"Application\" Subnets, where i is a 1 based index\n\n### Exporting CloudFormation Outputs\nSetting `exportOutputs: true` will export stack outputs.  \nThe name of the exported value will be prefixed by the cloud formation stack name (`AWS::StackName`).\nFor example, the value of the `VPC` output of a stack named `foo-prod` will be exported as `foo-prod-VPC`. \n","readmeFilename":"README.md"}