-
Notifications
You must be signed in to change notification settings - Fork 4
/
Copy pathmain.tf
127 lines (101 loc) · 3.16 KB
/
main.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
terraform {
required_version = ">= 0.12.6"
}
provider "aws" {
version = ">= 2.28.1"
region = var.region
}
provider "local" {
version = "~> 1.2"
}
provider "null" {
version = "~> 2.1"
}
provider "template" {
version = "~> 2.1"
}
data "aws_eks_cluster" "cluster" {
name = module.eks.cluster_id
}
data "aws_eks_cluster_auth" "cluster" {
name = module.eks.cluster_id
}
provider "kubernetes" {
host = data.aws_eks_cluster.cluster.endpoint
cluster_ca_certificate = base64decode(data.aws_eks_cluster.cluster.certificate_authority.0.data)
token = data.aws_eks_cluster_auth.cluster.token
load_config_file = false
version = "~> 1.10"
}
data "aws_availability_zones" "available" {
}
locals {
cluster_name = var.cluster_name
azs_sliced = slice(data.aws_availability_zones.available.names,0,var.rudder_num_availability_zones == -1 || var.rudder_num_availability_zones > length(data.aws_availability_zones.available.names) ? length(data.aws_availability_zones.available.names) : var.rudder_num_availability_zones)
}
module "vpc" {
source = "terraform-aws-modules/vpc/aws"
version = "~> 2.6"
name = "rudder-vpc"
cidr = var.vpc_cidr_block
azs = local.azs_sliced
private_subnets = [
for i in range(length(local.azs_sliced)):
cidrsubnet(var.vpc_cidr_block, var.vpc_cidr_subnetwork_width_delta, length(local.azs_sliced) + i)
]
public_subnets = [
for i in range(length(local.azs_sliced)):
cidrsubnet(var.vpc_cidr_block, var.vpc_cidr_subnetwork_width_delta, i)
]
enable_nat_gateway = true
single_nat_gateway = true
enable_dns_hostnames = true
tags = {
"kubernetes.io/cluster/${local.cluster_name}" = "shared"
}
public_subnet_tags = {
"kubernetes.io/cluster/${local.cluster_name}" = "shared"
"kubernetes.io/role/elb" = "1"
}
private_subnet_tags = {
"kubernetes.io/cluster/${local.cluster_name}" = "shared"
"kubernetes.io/role/internal-elb" = "1"
}
}
module "eks" {
source = "./modules/eks"
cluster_name = local.cluster_name
subnets = module.vpc.public_subnets
vpc_id = module.vpc.vpc_id
node_groups_defaults = {
ami_type = "AL2_x86_64"
disk_size = var.rudder_disk_size_gb
desired_capacity = 1
max_capacity = 10
min_capacity = 1
instance_type = var.rudder_node_type
}
node_groups = {
for i in range(length(local.azs_sliced)):
format("rudder-%s",element(local.azs_sliced,i)) => {
subnets = [element(module.vpc.public_subnets,i)]
}
}
cluster_enabled_log_types = ["api", "audit", "authenticator", "controllerManager", "scheduler"]
cluster_log_retention_in_days = 7
map_roles = var.map_roles
map_users = var.map_users
map_accounts = var.map_accounts
}
data "template_file" "aws_yml" {
template = file("${path.module}/templates/aws.yml.tpl")
vars = {
aws_region = var.region
vpc_id = module.vpc.vpc_id
cluster_name = local.cluster_name
}
}
resource "local_file" "aws_yml" {
content = data.template_file.aws_yml.rendered
filename = "aws.yml"
}