1 parent
64be99308b
commit
5cba142003
38 files changed
+565
-353
No files matched your search
+5
-7
@@ -3,11 +3,9 @@ locals {
|
||||
}
|
||||
|
||||
module "config" {
|
||||
source = "../modules/config"
|
||||
infra = local.config.infra
|
||||
services = local.config.services
|
||||
}
|
||||
|
||||
locals {
|
||||
databases = { for name, svc in module.config.services : name => svc.postgres if svc.postgres != null }
|
||||
source = "../modules/config"
|
||||
infra = local.config.infra
|
||||
buckets = try(local.config.buckets, {})
|
||||
databases = try(local.config.databases, {})
|
||||
services = try(local.config.services, {})
|
||||
}
|
||||
+30
-20
@@ -1,19 +1,31 @@
|
||||
module "app_database" {
|
||||
source = "../modules/app-database"
|
||||
for_each = local.databases
|
||||
service = { name = each.key, database = each.value }
|
||||
module "database" {
|
||||
source = "../modules/database"
|
||||
for_each = module.config.databases
|
||||
name = each.key
|
||||
owner = each.value.owner
|
||||
pgvector = each.value.pgvector
|
||||
}
|
||||
|
||||
module "database_access" {
|
||||
source = "../modules/database-access"
|
||||
for_each = module.config.service_databases
|
||||
role = each.value.role
|
||||
owner = module.database[each.value.database].owner
|
||||
}
|
||||
|
||||
resource "vault_kv_secret_v2" "postgres" {
|
||||
for_each = local.databases
|
||||
for_each = module.config.service_databases
|
||||
mount = module.config.vault.mount
|
||||
name = "${each.key}/postgres"
|
||||
name = "${each.value.service}/postgres/${each.value.database}"
|
||||
delete_all_versions = true
|
||||
data_json = jsonencode(merge(module.app_database[each.key].credentials, {
|
||||
host = module.config.postgres.internal_host
|
||||
port = module.config.postgres.internal_port
|
||||
sslmode = each.value.sslmode
|
||||
}))
|
||||
data_json = jsonencode({
|
||||
host = module.config.postgres.internal_host
|
||||
port = module.config.postgres.internal_port
|
||||
database = module.database[each.value.database].name
|
||||
username = module.database_access[each.key].username
|
||||
password = module.database_access[each.key].password
|
||||
sslmode = module.config.postgres.sslmode
|
||||
})
|
||||
}
|
||||
|
||||
resource "random_password" "vault" {
|
||||
@@ -33,12 +45,10 @@ resource "postgresql_role" "vault" {
|
||||
}
|
||||
|
||||
resource "postgresql_grant_role" "vault" {
|
||||
for_each = local.databases
|
||||
for_each = module.database
|
||||
role = postgresql_role.vault.name
|
||||
grant_role = each.value.username
|
||||
grant_role = each.value.owner
|
||||
with_admin_option = true
|
||||
|
||||
depends_on = [module.app_database]
|
||||
}
|
||||
|
||||
resource "vault_database_secrets_mount" "postgres" {
|
||||
@@ -46,22 +56,22 @@ resource "vault_database_secrets_mount" "postgres" {
|
||||
|
||||
postgresql {
|
||||
name = "postgres"
|
||||
connection_url = "postgresql://{{username}}:{{password}}@${module.config.postgres.internal_host}:${module.config.postgres.internal_port}/postgres?sslmode=disable"
|
||||
connection_url = "postgresql://{{username}}:{{password}}@${module.config.postgres.internal_host}:${module.config.postgres.internal_port}/postgres?sslmode=${module.config.postgres.sslmode}"
|
||||
username = postgresql_role.vault.name
|
||||
password = random_password.vault.result
|
||||
allowed_roles = keys(local.databases)
|
||||
allowed_roles = keys(module.config.service_databases)
|
||||
}
|
||||
}
|
||||
|
||||
resource "vault_database_secret_backend_role" "service" {
|
||||
for_each = local.databases
|
||||
for_each = module.config.service_databases
|
||||
backend = vault_database_secrets_mount.postgres.path
|
||||
name = each.key
|
||||
db_name = vault_database_secrets_mount.postgres.postgresql[0].name
|
||||
|
||||
creation_statements = [
|
||||
"CREATE ROLE \"{{name}}\" WITH LOGIN PASSWORD '{{password}}' VALID UNTIL '{{expiration}}' IN ROLE \"${each.value.username}\";",
|
||||
"ALTER ROLE \"{{name}}\" SET role = \"${each.value.username}\";",
|
||||
"CREATE ROLE \"{{name}}\" WITH LOGIN PASSWORD '{{password}}' VALID UNTIL '{{expiration}}' IN ROLE \"${each.value.owner}\";",
|
||||
"ALTER ROLE \"{{name}}\" SET role = \"${each.value.owner}\";",
|
||||
]
|
||||
revocation_statements = [
|
||||
"DROP ROLE IF EXISTS \"{{name}}\";",
|
||||
|
||||
@@ -8,6 +8,6 @@ provider "postgresql" {
|
||||
port = module.config.postgres.port
|
||||
username = module.config.postgres.admin_user
|
||||
password = var.postgres_password
|
||||
sslmode = "disable"
|
||||
sslmode = module.config.postgres.sslmode
|
||||
connect_timeout = 15
|
||||
}
|
||||
Reference in new issue
Block a user