2017-03-01 17:25:58 +00:00
|
|
|
terraform {
|
2019-12-12 11:42:33 +00:00
|
|
|
required_version = ">= 0.12.0"
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
provider "aws" {
|
2020-06-05 07:05:43 +00:00
|
|
|
access_key = var.AWS_ACCESS_KEY_ID
|
|
|
|
secret_key = var.AWS_SECRET_ACCESS_KEY
|
|
|
|
region = var.AWS_DEFAULT_REGION
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|
|
|
|
|
2017-11-30 15:27:52 +00:00
|
|
|
data "aws_availability_zones" "available" {}
|
|
|
|
|
2017-03-01 17:25:58 +00:00
|
|
|
/*
|
|
|
|
* Calling modules who create the initial AWS VPC / AWS ELB
|
|
|
|
* and AWS IAM Roles for Kubernetes Deployment
|
|
|
|
*/
|
|
|
|
|
|
|
|
module "aws-vpc" {
|
2019-12-04 15:20:58 +00:00
|
|
|
source = "./modules/vpc"
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
aws_cluster_name = var.aws_cluster_name
|
|
|
|
aws_vpc_cidr_block = var.aws_vpc_cidr_block
|
|
|
|
aws_avail_zones = slice(data.aws_availability_zones.available.names, 0, 2)
|
|
|
|
aws_cidr_subnets_private = var.aws_cidr_subnets_private
|
|
|
|
aws_cidr_subnets_public = var.aws_cidr_subnets_public
|
|
|
|
default_tags = var.default_tags
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
module "aws-elb" {
|
2019-12-04 15:20:58 +00:00
|
|
|
source = "./modules/elb"
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
aws_cluster_name = var.aws_cluster_name
|
|
|
|
aws_vpc_id = module.aws-vpc.aws_vpc_id
|
|
|
|
aws_avail_zones = slice(data.aws_availability_zones.available.names, 0, 2)
|
|
|
|
aws_subnet_ids_public = module.aws-vpc.aws_subnet_ids_public
|
|
|
|
aws_elb_api_port = var.aws_elb_api_port
|
|
|
|
k8s_secure_api_port = var.k8s_secure_api_port
|
|
|
|
default_tags = var.default_tags
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
module "aws-iam" {
|
2019-12-04 15:20:58 +00:00
|
|
|
source = "./modules/iam"
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
aws_cluster_name = var.aws_cluster_name
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Create Bastion Instances in AWS
|
|
|
|
*
|
|
|
|
*/
|
2017-11-30 15:27:52 +00:00
|
|
|
|
2017-03-01 17:25:58 +00:00
|
|
|
resource "aws_instance" "bastion-server" {
|
2020-06-05 07:05:43 +00:00
|
|
|
ami = data.aws_ami.distro.id
|
|
|
|
instance_type = var.aws_bastion_size
|
|
|
|
count = length(var.aws_cidr_subnets_public)
|
2019-04-08 09:22:24 +00:00
|
|
|
associate_public_ip_address = true
|
2020-06-05 07:05:43 +00:00
|
|
|
availability_zone = element(slice(data.aws_availability_zones.available.names, 0, 2), count.index)
|
|
|
|
subnet_id = element(module.aws-vpc.aws_subnet_ids_public, count.index)
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
vpc_security_group_ids = module.aws-vpc.aws_security_group
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
key_name = var.AWS_SSH_KEY_NAME
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
tags = merge(var.default_tags, map(
|
2019-12-04 15:20:58 +00:00
|
|
|
"Name", "kubernetes-${var.aws_cluster_name}-bastion-${count.index}",
|
2020-12-23 13:08:26 +00:00
|
|
|
"Cluster", var.aws_cluster_name,
|
2019-12-04 15:20:58 +00:00
|
|
|
"Role", "bastion-${var.aws_cluster_name}-${count.index}"
|
2020-06-05 07:05:43 +00:00
|
|
|
))
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Create K8s Master and worker nodes and etcd instances
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
|
|
|
resource "aws_instance" "k8s-master" {
|
2020-06-05 07:05:43 +00:00
|
|
|
ami = data.aws_ami.distro.id
|
|
|
|
instance_type = var.aws_kube_master_size
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
count = var.aws_kube_master_num
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
availability_zone = element(slice(data.aws_availability_zones.available.names, 0, 2), count.index)
|
|
|
|
subnet_id = element(module.aws-vpc.aws_subnet_ids_private, count.index)
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
vpc_security_group_ids = module.aws-vpc.aws_security_group
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2021-03-24 00:26:05 +00:00
|
|
|
iam_instance_profile = module.aws-iam.kube_control_plane-profile
|
2020-06-05 07:05:43 +00:00
|
|
|
key_name = var.AWS_SSH_KEY_NAME
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
tags = merge(var.default_tags, map(
|
2019-12-04 15:20:58 +00:00
|
|
|
"Name", "kubernetes-${var.aws_cluster_name}-master${count.index}",
|
|
|
|
"kubernetes.io/cluster/${var.aws_cluster_name}", "member",
|
|
|
|
"Role", "master"
|
2020-06-05 07:05:43 +00:00
|
|
|
))
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
resource "aws_elb_attachment" "attach_master_nodes" {
|
2020-06-05 07:05:43 +00:00
|
|
|
count = var.aws_kube_master_num
|
|
|
|
elb = module.aws-elb.aws_elb_api_id
|
|
|
|
instance = element(aws_instance.k8s-master.*.id, count.index)
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
resource "aws_instance" "k8s-etcd" {
|
2020-06-05 07:05:43 +00:00
|
|
|
ami = data.aws_ami.distro.id
|
|
|
|
instance_type = var.aws_etcd_size
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
count = var.aws_etcd_num
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
availability_zone = element(slice(data.aws_availability_zones.available.names, 0, 2), count.index)
|
|
|
|
subnet_id = element(module.aws-vpc.aws_subnet_ids_private, count.index)
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
vpc_security_group_ids = module.aws-vpc.aws_security_group
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
key_name = var.AWS_SSH_KEY_NAME
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
tags = merge(var.default_tags, map(
|
2019-12-04 15:20:58 +00:00
|
|
|
"Name", "kubernetes-${var.aws_cluster_name}-etcd${count.index}",
|
|
|
|
"kubernetes.io/cluster/${var.aws_cluster_name}", "member",
|
|
|
|
"Role", "etcd"
|
2020-06-05 07:05:43 +00:00
|
|
|
))
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
resource "aws_instance" "k8s-worker" {
|
2020-06-05 07:05:43 +00:00
|
|
|
ami = data.aws_ami.distro.id
|
|
|
|
instance_type = var.aws_kube_worker_size
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
count = var.aws_kube_worker_num
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
availability_zone = element(slice(data.aws_availability_zones.available.names, 0, 2), count.index)
|
|
|
|
subnet_id = element(module.aws-vpc.aws_subnet_ids_private, count.index)
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
vpc_security_group_ids = module.aws-vpc.aws_security_group
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
iam_instance_profile = module.aws-iam.kube-worker-profile
|
|
|
|
key_name = var.AWS_SSH_KEY_NAME
|
2017-03-01 17:25:58 +00:00
|
|
|
|
2020-06-05 07:05:43 +00:00
|
|
|
tags = merge(var.default_tags, map(
|
2019-12-04 15:20:58 +00:00
|
|
|
"Name", "kubernetes-${var.aws_cluster_name}-worker${count.index}",
|
|
|
|
"kubernetes.io/cluster/${var.aws_cluster_name}", "member",
|
|
|
|
"Role", "worker"
|
2020-06-05 07:05:43 +00:00
|
|
|
))
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
2017-06-16 17:25:46 +00:00
|
|
|
* Create Kubespray Inventory File
|
2017-03-01 17:25:58 +00:00
|
|
|
*
|
|
|
|
*/
|
|
|
|
data "template_file" "inventory" {
|
2020-06-05 07:05:43 +00:00
|
|
|
template = file("${path.module}/templates/inventory.tpl")
|
2019-04-08 09:22:24 +00:00
|
|
|
|
2019-12-04 15:20:58 +00:00
|
|
|
vars = {
|
2020-06-05 07:05:43 +00:00
|
|
|
public_ip_address_bastion = join("\n", formatlist("bastion ansible_host=%s", aws_instance.bastion-server.*.public_ip))
|
|
|
|
connection_strings_master = join("\n", formatlist("%s ansible_host=%s", aws_instance.k8s-master.*.private_dns, aws_instance.k8s-master.*.private_ip))
|
|
|
|
connection_strings_node = join("\n", formatlist("%s ansible_host=%s", aws_instance.k8s-worker.*.private_dns, aws_instance.k8s-worker.*.private_ip))
|
|
|
|
connection_strings_etcd = join("\n", formatlist("%s ansible_host=%s", aws_instance.k8s-etcd.*.private_dns, aws_instance.k8s-etcd.*.private_ip))
|
|
|
|
list_master = join("\n", aws_instance.k8s-master.*.private_dns)
|
|
|
|
list_node = join("\n", aws_instance.k8s-worker.*.private_dns)
|
|
|
|
list_etcd = join("\n", aws_instance.k8s-etcd.*.private_dns)
|
2019-04-08 09:22:24 +00:00
|
|
|
elb_api_fqdn = "apiserver_loadbalancer_domain_name=\"${module.aws-elb.aws_elb_api_fqdn}\""
|
|
|
|
}
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
resource "null_resource" "inventories" {
|
|
|
|
provisioner "local-exec" {
|
2019-04-08 09:22:24 +00:00
|
|
|
command = "echo '${data.template_file.inventory.rendered}' > ${var.inventory_file}"
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|
|
|
|
|
2019-12-04 15:20:58 +00:00
|
|
|
triggers = {
|
2020-06-05 07:05:43 +00:00
|
|
|
template = data.template_file.inventory.rendered
|
2017-09-05 11:10:53 +00:00
|
|
|
}
|
2017-03-01 17:25:58 +00:00
|
|
|
}
|