Resources and access
terraform / check (push) Waiting to run

This commit is contained in:
stolzor committed 2026-10-11 21:04:27 +03:00
1 parent 64be99308b
commit 5cba142003
38 files changed
+565 -353

No files matched your search

+5 -7
View File
@@ -3,11 +3,9 @@ locals {
}
module "config" {
source = "../modules/config"
infra = local.config.infra
services = local.config.services
}
locals {
services_with_buckets = { for name, svc in module.config.services : name => svc if length(svc.buckets) > 0 }
source = "../modules/config"
infra = local.config.infra
buckets = try(local.config.buckets, {})
databases = try(local.config.databases, {})
services = try(local.config.services, {})
}
+14 -18
View File
@@ -31,29 +31,25 @@ resource "minio_ilm_policy" "admin_policy" {
}
}
resource "minio_s3_bucket" "backups" {
bucket = module.config.silo.backup_bucket
acl = "private"
module "bucket" {
source = "../modules/bucket"
for_each = module.config.buckets
name = each.key
versioning = each.value.versioning
noncurrent_days = each.value.noncurrent_days
expire_days = each.value.expire_days
}
resource "minio_ilm_policy" "backups" {
bucket = minio_s3_bucket.backups.bucket
rule {
id = "expire-old-backups"
status = "Enabled"
expiration = "30d"
}
}
module "app_storage" {
source = "../modules/app-storage"
for_each = local.services_with_buckets
service = { name = each.key, buckets = each.value.buckets }
module "bucket_access" {
source = "../modules/bucket-access"
for_each = module.config.service_buckets
name = each.key
read_write = [for bucket in each.value.read_write : module.bucket[bucket].name]
read_only = [for bucket in each.value.read_only : module.bucket[bucket].name]
}
resource "vault_kv_secret_v2" "s3" {
for_each = module.app_storage
for_each = module.bucket_access
mount = module.config.vault.mount
name = "${each.key}/s3"
delete_all_versions = true