Terraform AWS Secure Baseline

Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.

Blockchain & Cloud ComputingHCLMIT

Abstract

Terraform AWS Secure Baseline is an open-source Blockchain & Cloud Computing project. Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices. A terraform module to set up your AWS account with the reasonably secure configuration baseline. Most configurations are based on [CIS Amazon Web Services Foundations v1.4.0] and [AWS Foundational Security Best Practices v1.0.0]. It is built using HCL, Terraform, AWS. Key capabilities include: alarm-baseline; analyzer-baseline; cloudtrail-baseline. The complete source code is publicly available on GitHub under the MIT License, making it a useful reference for students building a Blockchain & Cloud Computing mini project or final-year project.

1. Introduction

A terraform module to set up your AWS account with the reasonably secure configuration baseline. Most configurations are based on [CIS Amazon Web Services Foundations v1.4.0] and [AWS Foundational Security Best Practices v1.0.0].

See Benchmark Compliance to check which items in various benchmarks are covered.

2. Objective

Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.

This project demonstrates how HCL, Terraform, AWS can be applied to a real-world Blockchain & Cloud Computing problem.

3. Key Features / Modules

  • alarm-baseline
  • analyzer-baseline
  • cloudtrail-baseline
  • config-baseline
  • ebs-baseline
  • guardduty-baseline
  • iam-baseline
  • s3-baseline
  • secure-bucket
  • securityhub-baseline

4. Technology Stack

HCLTerraformAWS

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Terraform CLI
  • Cloud provider account (e.g. AWS) with CLI configured
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/nozaq/terraform-aws-secure-baseline.git
cd terraform-aws-secure-baseline
data "aws_caller_identity" "current" {}
data "aws_region" "current" {}

module "secure_baseline" {
  source = "nozaq/secure-baseline/aws"

  audit_log_bucket_name           = "YOUR_BUCKET_NAME"
  aws_account_id                  = data.aws_caller_identity.current.account_id
  region                          = data.aws_region.current.name
  support_iam_role_principal_arns = ["YOUR_IAM_USER"]

  providers = {
    aws                = aws
    aws.ap-northeast-1 = aws.ap-northeast-1
    aws.ap-northeast-2 = aws.ap-northeast-2
    aws.ap-northeast-3 = aws.ap-northeast-3
    aws.ap-south-1     = aws.ap-south-1
    aws.ap-southeast-1 = aws.ap-southeast-1
    aws.ap-southeast-2 = aws.ap-southeast-2
    aws.ca-central-1   = aws.ca-central-1
    aws.eu-central-1   = aws.eu-central-1
    aws.eu-north-1     = aws.eu-north-1
    aws.eu-west-1      = aws.eu-west-1
    aws.eu-west-2      = aws.eu-west-2
    aws.eu-west-3      = aws.eu-west-3
    aws.sa-east-1      = aws.sa-east-1
    aws.us-east-1      = aws.us-east-1
    aws.us-east-2      = aws.us-east-2
    aws.us-west-1      = aws.us-west-1
    aws.us-west-2      = aws.us-west-2
  }
}

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add a CI/CD pipeline with GitHub Actions
  • Deploy to a public test network or cloud free tier
  • Add monitoring and cost alerts

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Why does this problem need a blockchain or cloud-native design?
  2. Explain the smart contract / infrastructure components and how they interact.
  3. How are gas costs or cloud costs kept under control?
  4. How is the system secured (keys, IAM, access control)?
  5. How would the solution scale to many more users?

9. Source Code & License

This project is developed by nozaq and published on GitHub under the MIT License. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Blockchain & Cloud Computing project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Blockchain & Cloud Computing Internship