# main.tf — LOM compliance fixture
# Produces zero LOM policy violations

terraform {
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 5.0"
    }
  }
}

provider "aws" {
  region = "ap-south-1"
}

# LOM-001 + LOM-002 + LOM-003 — Multi-region, validation, KMS encrypted
resource "aws_cloudtrail" "good_trail" {
  name                          = "good-trail"
  s3_bucket_name                = "good-trail-bucket"
  is_multi_region_trail         = true
  include_global_service_events = true
  enable_log_file_validation    = true
  kms_key_id                    = "arn:aws:kms:ap-south-1:123456789012:key/mrk-1234abcd"

  event_selector {
    read_write_type           = "All"
    include_management_events = true
  }
}

# LOM-004 + LOM-005 — KMS encrypted, 365 day retention
resource "aws_cloudwatch_log_group" "good_log_group" {
  name              = "good-log-group"
  kms_key_id        = "arn:aws:kms:ap-south-1:123456789012:key/mrk-1234abcd"
  retention_in_days = 365
}

# LOM-006 — VPC with flow log
resource "aws_vpc" "good_vpc" {
  cidr_block = "10.0.0.0/16"
}

resource "aws_flow_log" "good_flow_log" {
  vpc_id          = aws_vpc.good_vpc.id
  traffic_type    = "ALL"
  iam_role_arn    = "arn:aws:iam::123456789012:role/flow-log-role"
  log_destination = "arn:aws:logs:ap-south-1:123456789012:log-group:vpc-flow-logs"
}

# LOM-007 — ALB with access logging enabled
resource "aws_lb" "good_lb" {
  name               = "good-lb"
  internal           = false
  load_balancer_type = "application"
  subnets            = ["subnet-12345678", "subnet-87654321"]

  access_logs {
    bucket  = "good-lb-logs"
    enabled = true
  }
}

# LOM-008 — RDS with log exports
resource "aws_db_instance" "good_rds" {
  identifier                      = "good-rds"
  engine                          = "mysql"
  engine_version                  = "8.0"
  instance_class                  = "db.t3.micro"
  allocated_storage               = 20
  username                        = "admin"
  password                        = "Goodpassword123"
  skip_final_snapshot             = true
  enabled_cloudwatch_logs_exports = ["audit", "error", "general", "slowquery"]
}

# LOM-009 — Config recorder and delivery channel
resource "aws_config_configuration_recorder" "good_recorder" {
  name     = "good-recorder"
  role_arn = "arn:aws:iam::123456789012:role/config-role"

  recording_group {
    all_supported                 = true
    include_global_resource_types = true
  }
}

resource "aws_config_delivery_channel" "good_channel" {
  name           = "good-channel"
  s3_bucket_name = "good-config-bucket"

  depends_on = [aws_config_configuration_recorder.good_recorder]
}
