provider "aws" { region = "us-east-1" } locals { name = "demo-localzone" ec2_db_instance_username = "wordpress" ec2_db_instance_password = "wordpress99" } resource "aws_instance" "db_ec2_instnace" { #checkov:skip=CKV_AWS_8: The EBS is encrypted already but the warning still shows #checkov:skip=CKV_AWS_79: Skip requiring IMDSv2 for demo code #checkov:skip=CKV_AWS_126: Skip detailed monitoring for demo instance #checkov:skip=CKV_AWS_135: EBS Optimized is always on for Nitro EC2 instance types instance_type = "t3.xlarge" subnet_id = var.private_subnets_local_zone ami = data.aws_ami.amazon-linux-2.id ebs_block_device { volume_size = 40 volume_type = "gp2" device_name = "/dev/xvda" encrypted = true } vpc_security_group_ids = [aws_security_group.rds_security_group.id] key_name = var.ssh_key_name user_data = <