commit
64be99308b
53 files changed
+1983
No files matched your search
Generated
+65
@@ -0,0 +1,65 @@
|
||||
# This file is maintained automatically by "terraform init".
|
||||
# Manual edits may be lost in future updates.
|
||||
|
||||
provider "registry.terraform.io/cyrilgdn/postgresql" {
|
||||
version = "1.27.0"
|
||||
constraints = "1.27.0"
|
||||
hashes = [
|
||||
"h1:OLbc15TOdKw2afn+M5H8MjQQRbYbEpiWDSj7yHg6iEw=",
|
||||
"zh:0d6fa6f12393f19b95652932c1a53984096bca2dfe27ce8c50f2f7881bae1b75",
|
||||
"zh:1c962ce9e73d96b368354607fd30dc55313c39f03f7ca5f3dea64e143b4f7c06",
|
||||
"zh:289b4a93b310d698914025bd0990f5c7e1eef21ce1db171ae3bd2970e69ea302",
|
||||
"zh:36960ffa44073d0fd71ed37d0d5e65e981d9ac009e69791c874a8903f06d7cfc",
|
||||
"zh:3936aa067c45bf8c2867bd5753f918c64b4d4214d29c999422343a8848ef25df",
|
||||
"zh:69c15b2dfa6e013fd9317a6edb3e5fa85f5bd32d581174ff8c6ec9ebbb88a31e",
|
||||
"zh:74b990f51f92035a6a5cd5f1ba8a427c5781bd5d2531f5dffb704325364459a2",
|
||||
"zh:91d45dbd0593a1f53c4cf4198a999545961937893cf16e2347b4e64bccbb626a",
|
||||
"zh:a50ed48b61d1745f9c185174a56c849c88413ea1adc7409d07947853468d8663",
|
||||
"zh:bc7cbe107bfcf9b57ba3f2ef5e64b205117d09b50528834250772b8c548fdfe3",
|
||||
"zh:c91ee6aa986bb89f69737354ea422292d39fd18410da92ba951e1203fbd9c3ef",
|
||||
"zh:f8cfdb72240d759d7a20f05cd098edbdd44f3b97a6067d7ea2ce29910356d27a",
|
||||
"zh:fa08178b78d23158945483fbdadee90aab7a741089600de27ec19b457d8c6928",
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/hashicorp/random" {
|
||||
version = "3.9.1"
|
||||
constraints = "3.9.1"
|
||||
hashes = [
|
||||
"h1:g40qr7yDmIpaur4SsK5BcOda3HSo1RJ6zHVMqN4EJ+0=",
|
||||
"zh:05f4734c1f0be840b711b3eff259ebc5fca436784c728955b1678078466f48d7",
|
||||
"zh:0b91bf19371d012434eba1deeb6aab77158def9b39601dcbd94450b3974a2a26",
|
||||
"zh:0ee6eacd47ec00183d55d726a4b6c4ce951a199f944bf22f1aa58392ebdfa7a2",
|
||||
"zh:19388a4074b76a89a43a6c8328d7ae8ee2e7de3d346af51e80d3e6d3d12925f1",
|
||||
"zh:23e74d48c5e2ac2e823fd527f49fee9db37d32a1990c9e3bf126ead697b843eb",
|
||||
"zh:3cabf7fbd096c520064aae3aba61aba670af83ab91291a71fa1b1332929c2b7f",
|
||||
"zh:5c0a3b8af0be60be4eca12ddee385cfa8babc1ec8e98cdf9de2f2274c73eabfa",
|
||||
"zh:60b4f8a8ef18f52bf8e19215229dae408bee732825964092db7c989fd2de4097",
|
||||
"zh:7359015acfedcbd6366f2329c854cf8d3c8ca5cd0faa89d2d37db358d6eba6c5",
|
||||
"zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3",
|
||||
"zh:7b38758402f0e13a1071162da28994023cd2ac676e54af350c9ffd8dfa73fa7b",
|
||||
"zh:7c7fbb8895eb75bb4de1f933e98553bd99c8d048c89a925ddba490aa5a67f7dc",
|
||||
"zh:8c2b8c6a7ccdec16b73e2fb9f3700ea097f58c592571e4c5de60c93d2301732c",
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.terraform.io/hashicorp/vault" {
|
||||
version = "5.12.0"
|
||||
constraints = "5.12.0"
|
||||
hashes = [
|
||||
"h1:NXnrOFre4t8nj7+ZQ3MKIECpDohjMBtHWm2aen75nfU=",
|
||||
"zh:0683ab1870c6ffe78463465fc0954ff18fbbfe16d79dc121e20efb27cd2be850",
|
||||
"zh:0ade50207774b544995066be02cf7e108abe828e089eb646da4c04863cbee702",
|
||||
"zh:2b3360bec8d457a7d19df86bf4576711035785928a9fa307affce10cbeae89fd",
|
||||
"zh:5317888b0e3547341b8434f42bbb8df2d30bdd95cc1bde9a4c7a80d266fe9f6b",
|
||||
"zh:6c0271736ceb08774bebedf424735d92c4fe33b8e4db371cc027cbded0439a2e",
|
||||
"zh:70bb990d22d1ce1ceac2209aee025e0f7deab48d95002aa2b8360d9c86343ea8",
|
||||
"zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3",
|
||||
"zh:7f33d7bbf145e15542cfc6b1dbeed639d08204802c239c098770c5f507d1e59c",
|
||||
"zh:8ae8ca31d3c9e4b530c80eed12d8debe6fc46b407acb469b33247227aaafbf51",
|
||||
"zh:c61fcc4d714cefee0696e2f8bf715b5826099e405f66acc859e496de688b6a8e",
|
||||
"zh:ceca8db980ae3bd986142903487d75d143edfc5c7cf467da38f3698f717db046",
|
||||
"zh:e1bba3cb6a728e9bf2951139f1e7bae5bec37a37cd4bfebe282e306212a62c4c",
|
||||
"zh:f9765b4aa90e9e4eae03626ebfdfeda54954ec2552267aedce1fb2643f6eb2de",
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
locals {
|
||||
config = yamldecode(file("${path.root}/../config.yaml"))
|
||||
}
|
||||
|
||||
module "config" {
|
||||
source = "../modules/config"
|
||||
infra = local.config.infra
|
||||
services = local.config.services
|
||||
}
|
||||
|
||||
locals {
|
||||
databases = { for name, svc in module.config.services : name => svc.postgres if svc.postgres != null }
|
||||
}
|
||||
@@ -0,0 +1,73 @@
|
||||
module "app_database" {
|
||||
source = "../modules/app-database"
|
||||
for_each = local.databases
|
||||
service = { name = each.key, database = each.value }
|
||||
}
|
||||
|
||||
resource "vault_kv_secret_v2" "postgres" {
|
||||
for_each = local.databases
|
||||
mount = module.config.vault.mount
|
||||
name = "${each.key}/postgres"
|
||||
delete_all_versions = true
|
||||
data_json = jsonencode(merge(module.app_database[each.key].credentials, {
|
||||
host = module.config.postgres.internal_host
|
||||
port = module.config.postgres.internal_port
|
||||
sslmode = each.value.sslmode
|
||||
}))
|
||||
}
|
||||
|
||||
resource "random_password" "vault" {
|
||||
length = 32
|
||||
special = false
|
||||
}
|
||||
|
||||
resource "postgresql_role" "vault" {
|
||||
name = "vault"
|
||||
login = true
|
||||
create_role = true
|
||||
password = random_password.vault.result
|
||||
|
||||
lifecycle {
|
||||
ignore_changes = [roles]
|
||||
}
|
||||
}
|
||||
|
||||
resource "postgresql_grant_role" "vault" {
|
||||
for_each = local.databases
|
||||
role = postgresql_role.vault.name
|
||||
grant_role = each.value.username
|
||||
with_admin_option = true
|
||||
|
||||
depends_on = [module.app_database]
|
||||
}
|
||||
|
||||
resource "vault_database_secrets_mount" "postgres" {
|
||||
path = module.config.vault.database_mount
|
||||
|
||||
postgresql {
|
||||
name = "postgres"
|
||||
connection_url = "postgresql://{{username}}:{{password}}@${module.config.postgres.internal_host}:${module.config.postgres.internal_port}/postgres?sslmode=disable"
|
||||
username = postgresql_role.vault.name
|
||||
password = random_password.vault.result
|
||||
allowed_roles = keys(local.databases)
|
||||
}
|
||||
}
|
||||
|
||||
resource "vault_database_secret_backend_role" "service" {
|
||||
for_each = local.databases
|
||||
backend = vault_database_secrets_mount.postgres.path
|
||||
name = each.key
|
||||
db_name = vault_database_secrets_mount.postgres.postgresql[0].name
|
||||
|
||||
creation_statements = [
|
||||
"CREATE ROLE \"{{name}}\" WITH LOGIN PASSWORD '{{password}}' VALID UNTIL '{{expiration}}' IN ROLE \"${each.value.username}\";",
|
||||
"ALTER ROLE \"{{name}}\" SET role = \"${each.value.username}\";",
|
||||
]
|
||||
revocation_statements = [
|
||||
"DROP ROLE IF EXISTS \"{{name}}\";",
|
||||
]
|
||||
default_ttl = 3600
|
||||
max_ttl = 86400
|
||||
|
||||
depends_on = [postgresql_grant_role.vault]
|
||||
}
|
||||
@@ -0,0 +1,4 @@
|
||||
output "vault_secrets" {
|
||||
value = { for name, secret in vault_kv_secret_v2.postgres : name => secret.path }
|
||||
description = "vault paths of the postgres credentials of the services"
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
provider "vault" {
|
||||
address = module.config.vault.address
|
||||
token = var.vault_token
|
||||
}
|
||||
|
||||
provider "postgresql" {
|
||||
host = module.config.postgres.host
|
||||
port = module.config.postgres.port
|
||||
username = module.config.postgres.admin_user
|
||||
password = var.postgres_password
|
||||
sslmode = "disable"
|
||||
connect_timeout = 15
|
||||
}
|
||||
@@ -0,0 +1,11 @@
|
||||
variable "postgres_password" {
|
||||
description = "password of the postgres administrator"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
variable "vault_token" {
|
||||
description = "vault token"
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
@@ -0,0 +1,19 @@
|
||||
terraform {
|
||||
required_providers {
|
||||
postgresql = {
|
||||
source = "cyrilgdn/postgresql"
|
||||
version = "1.27.0"
|
||||
}
|
||||
random = {
|
||||
source = "hashicorp/random"
|
||||
version = "3.9.1"
|
||||
}
|
||||
vault = {
|
||||
source = "hashicorp/vault"
|
||||
version = "5.12.0"
|
||||
}
|
||||
}
|
||||
backend "s3" {
|
||||
key = "database/terraform.tfstate"
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user