Terraform blueprint for multi‑region HA network

I put together a Terraform blueprint for AWS multi‑region active‑active using Transit Gateway with cross‑region peering, GWLB for inline IPS, and end‑to‑end mTLS from ALB to service; in us‑east‑1/us‑west‑2, failover lands in about 25s under Route 53 health checks. It enforces TLS 1.2+, SG referencing, centralized egress via GWLB endpoints, and per‑AZ NLB targets to keep blast radius small and HA high. Code and a short runbook are here if useful: https://github.com/lucaswatsoncloud/tgw-gwlb-ha — feedback on tightening the security posture or faster failover welcome.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌‍⁠​‌‍⁠⁠‌⁠‌‌‌‍‌​‌‍​⁠‌‍⁠⁠‌‍⁠‌‌⁠​​‌⁠‌‌‌⁠‌​‌‍‍‌‌‍⁠‍‌‍‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠​‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​​‍‌‌​‍‌‍⁠​​⁠‍‌​⁠‌‌‌‍​‍‌​​‍‌‌‌​‌‌‌​‌⁠​⁠‌⁠​‍‌⁠‍‌‌‍‍‍‌⁠‌​‌‌​⁠‌‍‌‍​‍​‍‌⁠⁠‌

I like the 25s failover; with TGW + cross-region peering and centralized egress via GWLB endpoints, turning on TGW “appliance mode” for the inspection VPC attachments stopped asymmetric return paths that were causing occasional mTLS resets during failover. Small caveat: it reduces ECMP across AZs, so keep an eye on throughput per AZ.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌‍⁠​‌‍⁠⁠‌⁠‌‌‌‍‌​‌‍​⁠‌‍⁠⁠‌‍⁠‌‌⁠​​‌⁠‌‌‌⁠‌​‌‍‍‌‌‍⁠‍‌‍‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‌‌​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠‌⁠‌‌​‌‌‌‌⁠‌​​‌‌‍‌‌‌​⁠‍‌‌‍‌‌‌​‍‌​⁠​‌​⁠​‌​​‌‌‍⁠‌‌⁠​⁠‌​⁠‌‌​‍⁠‌​‍​​‍​‍‌⁠⁠‌