diff --git a/.github/ISSUE_TEMPLATE/bug_report.yaml b/.github/ISSUE_TEMPLATE/bug_report.yaml new file mode 100644 index 0000000..ec249f3 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.yaml @@ -0,0 +1,65 @@ +name: 🐞 Bug Report +title: "[Bug]: " +description: Create a report to help us improve +labels: ["bug", "triage"] +body: + - type: markdown + attributes: + value: | + ### How to write a good bug report? + + - Respect the issue template as much as possible. + - The title should be short and descriptive. + - Explain the conditions which led you to report this issue and the context. + - The context should lead to something, an idea or a problem that you’re facing. + - Remain clear and concise. + - Format your messages to help the reader focus on what matters and understand the structure of your message, use [Markdown syntax](https://help.github.com/articles/github-flavored-markdown) + + - type: checkboxes + id: terms + attributes: + label: Welcome to Amazon EKS Blueprints! + options: + - label: Yes, I've searched similar issues on [GitHub](https://github.com/aws-ia/terraform-aws-observability-accelerator/issues) and didn't find any. + required: true + + - type: input + attributes: + label: Amazon EKS Blueprints Release version + description: | + `latest` is not considered as a valid version. + Enter release number! + placeholder: Your version here. + validations: + required: true + + - type: textarea + attributes: + label: What is your environment, configuration and the example used? + description: | + Terraform version, link to example used or your main.tf content etc. + + Use [Markdown syntax](https://help.github.com/articles/github-flavored-markdown) if needed. + placeholder: Add information here. + validations: + required: true + + - type: textarea + attributes: + label: What did you do and What did you see instead? + description: | + Provide error details and the expected details. + + Use [Markdown syntax](https://help.github.com/articles/github-flavored-markdown) if needed. + placeholder: Add information here. + validations: + required: true + + - type: textarea + attributes: + label: Additional Information + description: Use [Markdown syntax](https://help.github.com/articles/github-flavored-markdown) if needed. + placeholder: Add information here. + render: shell + validations: + required: false diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml new file mode 100644 index 0000000..3ba13e0 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -0,0 +1 @@ +blank_issues_enabled: false diff --git a/.github/ISSUE_TEMPLATE/feature_request.md b/.github/ISSUE_TEMPLATE/feature_request.md new file mode 100644 index 0000000..2d26ce4 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/feature_request.md @@ -0,0 +1,23 @@ +--- +name: Feature request +about: Suggest an idea for this project +title: '[FEATURE] <title>' +labels: 'feature-request' +assignees: '' + +--- + +#### Is your feature request related to a problem? Please describe +A clear and concise description of what the problem is. Ex. I'm always frustrated when [...] + + +#### Describe the solution you'd like +A clear and concise description of what you want to happen. + + +#### Describe alternatives you've considered +A clear and concise description of any alternative solutions or features you've considered. + + +#### Additional context +Add any other context or screenshots about the feature request here. diff --git a/.github/ISSUE_TEMPLATE/question.md b/.github/ISSUE_TEMPLATE/question.md new file mode 100644 index 0000000..bc56468 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/question.md @@ -0,0 +1,24 @@ +--- +name: Question +about: I have a Question +title: '[QUESTION] <title>' +labels: 'question' +assignees: '' + +--- + +#### Please describe your question here +<!-- Provide as much information as possible to explain your question --> + + +#### Provide link to the example related to the question +<!-- Please provide the link to the example related to this question from this repo --> + + +#### Additional context +<!-- Add any other context or screenshots about the question here --> + + +#### More + +- [ ] Yes, I have checked the repo for existing issues before raising this question diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md new file mode 100644 index 0000000..282a997 --- /dev/null +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -0,0 +1,28 @@ + +### What does this PR do? + +<!-- A brief description of the change being made with this pull request. --> + + +### Motivation + +<!-- What inspired you to submit this pull request? --> + + +### More + +- [ ] Yes, I have tested the PR using my local account setup (Provide any test evidence report under Additional Notes) +- [ ] Yes, I have added a new example under [examples](https://github.com/aws-ia/terraform-aws-eks-blueprints/tree/main/examples) to support my PR +- [ ] Yes, I have created another PR for add-ons under [add-ons](https://github.com/aws-samples/eks-blueprints-add-ons) repo (if applicable) +- [ ] Yes, I have updated the [docs](https://github.com/aws-ia/terraform-aws-eks-blueprints/tree/main/docs) for this feature +- [ ] Yes, I ran `pre-commit run -a` with this PR + + +**Note**: Not all the PRs required examples and docs except a new pattern or add-on added. + +### For Moderators +- [ ] E2E Test successfully complete before merge? + +### Additional Notes + +<!-- Anything else we should know when reviewing? --> diff --git a/.header.md b/.header.md deleted file mode 100644 index 2d740ef..0000000 --- a/.header.md +++ /dev/null @@ -1,57 +0,0 @@ -# Creating modules for AWS I&A Organization - -This repo template is used to seed Terraform Module templates for the [AWS I&A GitHub organization](https://github.com/aws-ia). Usage of this template is allowed per included license. PRs to this template will be considered but are not guaranteed to be included. Consider creating an issue to discuss a feature you want to include before taking the time to create a PR. -### TL;DR - -1. [install pre-commit](https://pre-commit.com/) -2. configure pre-commit: `pre-commit install` -3. install required tools - - [tflint](https://github.com/terraform-linters/tflint) - - [tfsec](https://aquasecurity.github.io/tfsec/v1.0.11/) - - [terraform-docs](https://github.com/terraform-docs/terraform-docs) - - [golang](https://go.dev/doc/install) (for macos you can use `brew`) - - [coreutils](https://www.gnu.org/software/coreutils/) - -Write code according to [I&A module standards](https://aws-ia.github.io/standards-terraform/) - -## Module Documentation - -**Do not manually update README.md**. `terraform-docs` is used to generate README files. For any instructions an content, please update [.header.md](./.header.md) then simply run `terraform-docs ./` or allow the `pre-commit` to do so. - -## Terratest - -Please include tests to validate your examples/<> root modules, at a minimum. This can be accomplished with usually only slight modifications to the [boilerplate test provided in this template](./test/examples_basic_test.go) - -### Configure and run Terratest - -1. Install - - [golang](https://go.dev/doc/install) (for macos you can use `brew`) -2. Change directory into the test folder. - - `cd test` -3. Initialize your test - - go mod init github.com/[github org]/[repository] - - `go mod init github.com/aws-ia/terraform-aws-vpc` -4. Run tidy - - `git mod tidy` -5. Install Terratest - - `go get github.com/gruntwork-io/terratest/modules/terraform` -6. Run test (You can have multiple test files). - - Run all tests - - `go test` - - Run a specific test with a timeout - - `go test -run examples_basic_test.go -timeout 45m` -## Module Standards - -For best practices and information on developing with Terraform, see the [I&A Module Standards](https://aws-ia.github.io/standards-terraform/) - -## Continuous Integration - -The I&A team uses AWS CodeBuild to perform continuous integration (CI) within the organization. Our CI uses the a repo's `.pre-commit-config.yaml` file as well as some other checks. All PRs with other CI will be rejected. See our [FAQ](https://aws-ia.github.io/standards-terraform/faq/#are-modules-protected-by-ci-automation) for more details. \ No newline at end of file diff --git a/.terraform-docs.yaml b/.terraform-docs.yaml deleted file mode 100644 index 1e310cc..0000000 --- a/.terraform-docs.yaml +++ /dev/null @@ -1,20 +0,0 @@ -formatter: markdown -header-from: .header.md -settings: - anchor: true - color: true - default: true - escape: true - html: true - indent: 2 - required: true - sensitive: true - type: true - -sort: - enabled: true - by: required - -output: - file: README.md - mode: replace diff --git a/ADOPTERS.md b/ADOPTERS.md new file mode 100644 index 0000000..05897a4 --- /dev/null +++ b/ADOPTERS.md @@ -0,0 +1,15 @@ +# Who is using AWS Observability Accelerator for Terraform? + +AWS Observability Accelerator for Terraform has a variety of users and use cases to configure and manage Observability on EKS/ECS clusters. +Many customers want to learn from others who have already implemented AWS Observability Accelerator in their environments. + +The following is a self-reported list of users to help identify adoption and points of contact. + +## Add yourself + +If you are using AWS Observability Accelerator please consider adding yourself as a user by opening a pull request to this file. + +## Adopters (Alphabetical) + +| Organization | Description | Contacts | Link | +| --- | --- | --- | --- | diff --git a/CODEOWNERS b/CODEOWNERS index 1006f66..d3e8e50 100644 --- a/CODEOWNERS +++ b/CODEOWNERS @@ -1 +1,4 @@ -* @aws-ia/aws-ia \ No newline at end of file +# Require approvals from someone in the owner team before merging +# More information here: https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/about-code-owners + +* @aws-ia/aws-observability-accelerator diff --git a/README.md b/README.md index ab3dd0f..2bbe133 100644 --- a/README.md +++ b/README.md @@ -1,63 +1,30 @@ -<!-- BEGIN_TF_DOCS --> -# Creating modules for AWS I&A Organization +# AWS Observability Accelerator for Terraform -This repo template is used to seed Terraform Module templates for the [AWS I&A GitHub organization](https://github.com/aws-ia). Usage of this template is allowed per included license. PRs to this template will be considered but are not guaranteed to be included. Consider creating an issue to discuss a feature you want to include before taking the time to create a PR. -### TL;DR +Welcome to AWS Observability Accelerator for Terraform! -1. [install pre-commit](https://pre-commit.com/) -2. configure pre-commit: `pre-commit install` -3. install required tools - - [tflint](https://github.com/terraform-linters/tflint) - - [tfsec](https://aquasecurity.github.io/tfsec/v1.0.11/) - - [terraform-docs](https://github.com/terraform-docs/terraform-docs) - - [golang](https://go.dev/doc/install) (for macos you can use `brew`) - - [coreutils](https://www.gnu.org/software/coreutils/) +## Getting Started -Write code according to [I&A module standards](https://aws-ia.github.io/standards-terraform/) -## Module Documentation +## Documentation -**Do not manually update README.md**. `terraform-docs` is used to generate README files. For any instructions an content, please update [.header.md](./.header.md) then simply run `terraform-docs ./` or allow the `pre-commit` to do so. -## Terratest +## Examples -Please include tests to validate your examples/<> root modules, at a minimum. This can be accomplished with usually only slight modifications to the [boilerplate test provided in this template](./test/examples\_basic\_test.go) -### Configure and run Terratest +## Usage -1. Install - [golang](https://go.dev/doc/install) (for macos you can use `brew`) -2. Change directory into the test folder. - - `cd test` -3. Initialize your test - - go mod init github.com/[github org]/[repository] +## Submodules - `go mod init github.com/aws-ia/terraform-aws-vpc` -4. Run tidy - `git mod tidy` -5. Install Terratest +## Motivation - `go get github.com/gruntwork-io/terratest/modules/terraform` -6. Run test (You can have multiple test files). - - Run all tests - `go test` - - Run a specific test with a timeout +## Support & Feedback - `go test -run examples_basic_test.go -timeout 45m` - -## Module Standards - -For best practices and information on developing with Terraform, see the [I&A Module Standards](https://aws-ia.github.io/standards-terraform/) - -## Continuous Integration - -The I&A team uses AWS CodeBuild to perform continuous integration (CI) within the organization. Our CI uses the a repo's `.pre-commit-config.yaml` file as well as some other checks. All PRs with other CI will be rejected. See our [FAQ](https://aws-ia.github.io/standards-terraform/faq/#are-modules-protected-by-ci-automation) for more details. +--- +<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK --> ## Requirements | Name | Version | @@ -65,33 +32,79 @@ The I&A team uses AWS CodeBuild to perform continuous integration (CI) within th | <a name="requirement_terraform"></a> [terraform](#requirement\_terraform) | >= 0.14.0 | | <a name="requirement_aws"></a> [aws](#requirement\_aws) | >= 4.0.0, < 5.0.0 | | <a name="requirement_awscc"></a> [awscc](#requirement\_awscc) | >= 0.24.0 | +| <a name="requirement_grafana"></a> [grafana](#requirement\_grafana) | 1.25.0 | ## Providers -No providers. +| Name | Version | +|------|---------| +| <a name="provider_aws"></a> [aws](#provider\_aws) | >= 4.0.0, < 5.0.0 | +| <a name="provider_grafana"></a> [grafana](#provider\_grafana) | 1.25.0 | ## Modules -No modules. +| Name | Source | Version | +|------|--------|---------| +| <a name="module_managed_grafana"></a> [managed\_grafana](#module\_managed\_grafana) | terraform-aws-modules/managed-service-grafana/aws | ~> 1.3 | +| <a name="module_operator"></a> [operator](#module\_operator) | ./modules/add-ons/adot-operator | n/a | ## Resources -No resources. +| Name | Type | +|------|------| +| [aws_prometheus_alert_manager_definition.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_alert_manager_definition) | resource | +| [aws_prometheus_workspace.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_workspace) | resource | +| [grafana_data_source.amp](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/data_source) | resource | +| [grafana_folder.this](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/folder) | resource | +| [aws_caller_identity.current](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/caller_identity) | data source | +| [aws_eks_cluster.eks_cluster](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/eks_cluster) | data source | +| [aws_grafana_workspace.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/grafana_workspace) | data source | +| [aws_partition.current](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/partition) | data source | +| [aws_region.current](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/region) | data source | ## Inputs -No inputs. +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| <a name="input_aws_region"></a> [aws\_region](#input\_aws\_region) | AWS Region | `string` | n/a | yes | +| <a name="input_eks_cluster_id"></a> [eks\_cluster\_id](#input\_eks\_cluster\_id) | EKS Cluster Id | `string` | n/a | yes | +| <a name="input_enable_alertmanager"></a> [enable\_alertmanager](#input\_enable\_alertmanager) | Create AMP AlertManager for all workloads | `bool` | `false` | no | +| <a name="input_enable_amazon_eks_adot"></a> [enable\_amazon\_eks\_adot](#input\_enable\_amazon\_eks\_adot) | n/a | `bool` | `true` | no | +| <a name="input_enable_cert_manager"></a> [enable\_cert\_manager](#input\_enable\_cert\_manager) | Allow reusing an existing installation of cert-manager | `bool` | `true` | no | +| <a name="input_enable_infra_metrics"></a> [enable\_infra\_metrics](#input\_enable\_infra\_metrics) | n/a | `bool` | `false` | no | +| <a name="input_enable_java"></a> [enable\_java](#input\_enable\_java) | Deploys a collector for JAVA/JMX based workloads, dashboards and alerting rules | `bool` | `false` | no | +| <a name="input_enable_java_recording_rules"></a> [enable\_java\_recording\_rules](#input\_enable\_java\_recording\_rules) | Enable AMP recording rules for Java | `bool` | `true` | no | +| <a name="input_enable_managed_grafana"></a> [enable\_managed\_grafana](#input\_enable\_managed\_grafana) | n/a | `bool` | `true` | no | +| <a name="input_enable_managed_prometheus"></a> [enable\_managed\_prometheus](#input\_enable\_managed\_prometheus) | n/a | `bool` | `true` | no | +| <a name="input_enable_opentelemetry_operator"></a> [enable\_opentelemetry\_operator](#input\_enable\_opentelemetry\_operator) | n/a | `bool` | `false` | no | +| <a name="input_grafana_api_key"></a> [grafana\_api\_key](#input\_grafana\_api\_key) | n/a | `string` | `null` | no | +| <a name="input_infra_metrics_config"></a> [infra\_metrics\_config](#input\_infra\_metrics\_config) | n/a | <pre>object({<br> helm_config = map(any)<br><br> enable_kube_state_metrics = bool<br> kms_create_namespace = bool<br> ksm_k8s_namespace = string<br> ksm_helm_chart_name = string<br> ksm_helm_chart_version = string<br> ksm_helm_release_name = string<br> ksm_helm_repo_url = string<br> ksm_helm_settings = map(string)<br> ksm_helm_values = map(any)<br><br> enable_node_exporter = bool<br> ne_create_namespace = bool<br> ne_k8s_namespace = string<br> ne_helm_chart_name = string<br> ne_helm_chart_version = string<br> ne_helm_release_name = string<br> ne_helm_repo_url = string<br> ne_helm_settings = map(string)<br> ne_helm_values = map(any)<br><br> enable_dashboards = bool<br> })</pre> | `null` | no | +| <a name="input_irsa_iam_permissions_boundary"></a> [irsa\_iam\_permissions\_boundary](#input\_irsa\_iam\_permissions\_boundary) | IAM permissions boundary for IRSA roles | `string` | `""` | no | +| <a name="input_irsa_iam_role_path"></a> [irsa\_iam\_role\_path](#input\_irsa\_iam\_role\_path) | IAM role path for IRSA roles | `string` | `"/"` | no | +| <a name="input_managed_grafana_region"></a> [managed\_grafana\_region](#input\_managed\_grafana\_region) | AWS Managed Grafana Workspace Region | `string` | `null` | no | +| <a name="input_managed_grafana_workspace_id"></a> [managed\_grafana\_workspace\_id](#input\_managed\_grafana\_workspace\_id) | n/a | `string` | `""` | no | +| <a name="input_managed_prometheus_workspace_id"></a> [managed\_prometheus\_workspace\_id](#input\_managed\_prometheus\_workspace\_id) | AWS Managed Prometheus Workspace ID | `string` | `""` | no | +| <a name="input_managed_prometheus_workspace_region"></a> [managed\_prometheus\_workspace\_region](#input\_managed\_prometheus\_workspace\_region) | AWS Managed Prometheus Workspace Region | `string` | `null` | no | +| <a name="input_tags"></a> [tags](#input\_tags) | Additional tags (e.g. `map('BusinessUnit`,`XYZ`) | `map(string)` | `{}` | no | ## Outputs -No outputs. -<!-- END_TF_DOCS --> +| Name | Description | +|------|-------------| +| <a name="output_aws_region"></a> [aws\_region](#output\_aws\_region) | EKS Cluster Id | +| <a name="output_eks_cluster_id"></a> [eks\_cluster\_id](#output\_eks\_cluster\_id) | EKS Cluster Id | +| <a name="output_eks_cluster_version"></a> [eks\_cluster\_version](#output\_eks\_cluster\_version) | n/a | +| <a name="output_grafana_dashboards_folder_id"></a> [grafana\_dashboards\_folder\_id](#output\_grafana\_dashboards\_folder\_id) | n/a | +| <a name="output_managed_grafana_workspace_endpoint"></a> [managed\_grafana\_workspace\_endpoint](#output\_managed\_grafana\_workspace\_endpoint) | n/a | +| <a name="output_managed_prometheus_workspace_endpoint"></a> [managed\_prometheus\_workspace\_endpoint](#output\_managed\_prometheus\_workspace\_endpoint) | n/a | +| <a name="output_managed_prometheus_workspace_id"></a> [managed\_prometheus\_workspace\_id](#output\_managed\_prometheus\_workspace\_id) | n/a | +| <a name="output_managed_prometheus_workspace_region"></a> [managed\_prometheus\_workspace\_region](#output\_managed\_prometheus\_workspace\_region) | n/a | +<!-- END OF PRE-COMMIT-TERRAFORM DOCS HOOK --> +## Security +See [CONTRIBUTING](CONTRIBUTING.md#security-issue-notifications) for more information. -### Design Questions +## License -1. fetching EKS auth as config map? and pass to module (version, etc) as object? -2. automatically pass config option as objects? (aws adot add-on: enable cert-manager, cert-manager version?) -3. Test case for every option possible? -4. Need data source for AMP - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_workspace, Bryant's module doesn't seem to support splitting usage (eg. using multiple alerting rules ONLY) +Apache-2.0 Licensed. See [LICENSE](https://github.com/aws-ia/terraform-aws-eks-blueprints/blob/main/LICENSE). diff --git a/docs/index.md b/docs/index.md new file mode 100644 index 0000000..4d71ac8 --- /dev/null +++ b/docs/index.md @@ -0,0 +1,19 @@ +# AWS Observability Accelerator for Terraform + +![GitHub](https://img.shields.io/github/license/aws-ia/terraform-aws-observability-accelerator) + +Welcome to AWS Observability Accelerator for Terraform! + + +## What is AWS Observability Accelerator for Terraform + + +## Examples + + +## Workshop + + +## Motivation + +## What can I do with this Solution? diff --git a/examples/existing-cluster-with-base-and-infra/README.md b/examples/existing-cluster-with-base-and-infra/README.md new file mode 100644 index 0000000..06d064b --- /dev/null +++ b/examples/existing-cluster-with-base-and-infra/README.md @@ -0,0 +1,55 @@ +# Existing Cluster + +--- + +<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK --> +## Requirements + +| Name | Version | +|------|---------| +| <a name="requirement_grafana"></a> [grafana](#requirement\_grafana) | 1.25.0 | + +## Providers + +| Name | Version | +|------|---------| +| <a name="provider_aws"></a> [aws](#provider\_aws) | n/a | + +## Modules + +| Name | Source | Version | +|------|--------|---------| +| <a name="module_eks_observability_accelerator"></a> [eks\_observability\_accelerator](#module\_eks\_observability\_accelerator) | ../../ | n/a | +| <a name="module_workloads_infra"></a> [workloads\_infra](#module\_workloads\_infra) | ../../workloads/infra | n/a | + +## Resources + +| Name | Type | +|------|------| +| [aws_eks_cluster.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/eks_cluster) | data source | +| [aws_eks_cluster_auth.this](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/eks_cluster_auth) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| <a name="input_aws_region"></a> [aws\_region](#input\_aws\_region) | AWS Region | `string` | n/a | yes | +| <a name="input_eks_cluster_id"></a> [eks\_cluster\_id](#input\_eks\_cluster\_id) | EKS Cluster Id | `string` | n/a | yes | +| <a name="input_grafana_api_key"></a> [grafana\_api\_key](#input\_grafana\_api\_key) | API key for authorizing the Grafana provider to make changes to Amazon Managed Grafana | `string` | `""` | no | +| <a name="input_grafana_endpoint"></a> [grafana\_endpoint](#input\_grafana\_endpoint) | Grafana endpoint | `string` | `null` | no | +| <a name="input_java"></a> [java](#input\_java) | n/a | `map` | <pre>{<br> "a": "",<br> "b": ""<br>}</pre> | no | +| <a name="input_managed_grafana_workspace_id"></a> [managed\_grafana\_workspace\_id](#input\_managed\_grafana\_workspace\_id) | n/a | `string` | `""` | no | +| <a name="input_managed_prometheus_endpoint"></a> [managed\_prometheus\_endpoint](#input\_managed\_prometheus\_endpoint) | n/a | `string` | `""` | no | +| <a name="input_managed_prometheus_region"></a> [managed\_prometheus\_region](#input\_managed\_prometheus\_region) | n/a | `string` | `""` | no | +| <a name="input_managed_prometheus_workspace_id"></a> [managed\_prometheus\_workspace\_id](#input\_managed\_prometheus\_workspace\_id) | n/a | `string` | `""` | no | + +## Outputs + +| Name | Description | +|------|-------------| +| <a name="output_aws_region"></a> [aws\_region](#output\_aws\_region) | AWS Region | +| <a name="output_eks_cluster_id"></a> [eks\_cluster\_id](#output\_eks\_cluster\_id) | EKS Cluster Id | +| <a name="output_eks_cluster_version"></a> [eks\_cluster\_version](#output\_eks\_cluster\_version) | n/a | +| <a name="output_prometheus_endpoint"></a> [prometheus\_endpoint](#output\_prometheus\_endpoint) | n/a | +| <a name="output_prometheus_id"></a> [prometheus\_id](#output\_prometheus\_id) | n/a | +<!-- END OF PRE-COMMIT-TERRAFORM DOCS HOOK --> diff --git a/main.tf b/main.tf index 3372ef2..1bfbf6b 100644 --- a/main.tf +++ b/main.tf @@ -1,5 +1,5 @@ module "operator" { - source = "./modules/adot-operator" + source = "./modules/add-ons/adot-operator" enable_cert_manager = var.enable_cert_manager kubernetes_version = local.eks_cluster_version diff --git a/modules/adot-operator/README.md b/modules/add-ons/adot-operator/README.md similarity index 89% rename from modules/adot-operator/README.md rename to modules/add-ons/adot-operator/README.md index 884ffb4..70884c4 100644 --- a/modules/adot-operator/README.md +++ b/modules/add-ons/adot-operator/README.md @@ -41,8 +41,7 @@ the ADOT Operator. | Name | Source | Version | |------|--------|---------| -| <a name="module_cert_manager"></a> [cert\_manager](#module\_cert\_manager) | ../cert-manager | n/a | -| <a name="module_helm_addon"></a> [helm\_addon](#module\_helm\_addon) | ../helm-addon | n/a | +| <a name="module_cert_manager"></a> [cert\_manager](#module\_cert\_manager) | github.com/aws-ia/terraform-aws-eks-blueprints/modules/kubernetes-addons/cert-manager | n/a | ## Resources @@ -62,9 +61,9 @@ the ADOT Operator. |------|-------------|------|---------|:--------:| | <a name="input_addon_config"></a> [addon\_config](#input\_addon\_config) | Amazon EKS Managed CoreDNS Add-on config | `any` | `{}` | no | | <a name="input_addon_context"></a> [addon\_context](#input\_addon\_context) | Input configuration for the addon | <pre>object({<br> aws_caller_identity_account_id = string<br> aws_caller_identity_arn = string<br> aws_eks_cluster_endpoint = string<br> aws_partition_id = string<br> aws_region_name = string<br> eks_cluster_id = string<br> eks_oidc_issuer_url = string<br> eks_oidc_provider_arn = string<br> irsa_iam_role_path = string<br> tags = map(string)<br> })</pre> | n/a | yes | -| <a name="input_enable_amazon_eks_adot"></a> [enable\_amazon\_eks\_adot](#input\_enable\_amazon\_eks\_adot) | Enable Amazon EKS ADOT add-on | `bool` | `true` | no | -| <a name="input_enable_opentelemetry_operator"></a> [enable\_opentelemetry\_operator](#input\_enable\_opentelemetry\_operator) | Enable opentelemetry operator addon | `bool` | `false` | no | +| <a name="input_enable_cert_manager"></a> [enable\_cert\_manager](#input\_enable\_cert\_manager) | n/a | `bool` | `true` | no | | <a name="input_helm_config"></a> [helm\_config](#input\_helm\_config) | Helm provider config for ADOT Operator AddOn | `any` | `{}` | no | +| <a name="input_kubernetes_version"></a> [kubernetes\_version](#input\_kubernetes\_version) | n/a | `string` | n/a | yes | ## Outputs diff --git a/modules/adot-operator/locals.tf b/modules/add-ons/adot-operator/locals.tf similarity index 100% rename from modules/adot-operator/locals.tf rename to modules/add-ons/adot-operator/locals.tf diff --git a/modules/adot-operator/main.tf b/modules/add-ons/adot-operator/main.tf similarity index 100% rename from modules/adot-operator/main.tf rename to modules/add-ons/adot-operator/main.tf diff --git a/modules/adot-operator/outputs.tf b/modules/add-ons/adot-operator/outputs.tf similarity index 100% rename from modules/adot-operator/outputs.tf rename to modules/add-ons/adot-operator/outputs.tf diff --git a/modules/adot-operator/variables.tf b/modules/add-ons/adot-operator/variables.tf similarity index 100% rename from modules/adot-operator/variables.tf rename to modules/add-ons/adot-operator/variables.tf diff --git a/modules/adot-operator/versions.tf b/modules/add-ons/adot-operator/versions.tf similarity index 100% rename from modules/adot-operator/versions.tf rename to modules/add-ons/adot-operator/versions.tf diff --git a/workloads/haproxy/main.tf b/modules/workloads/haproxy/main.tf similarity index 99% rename from workloads/haproxy/main.tf rename to modules/workloads/haproxy/main.tf index 2c413df..b81151e 100644 --- a/workloads/haproxy/main.tf +++ b/modules/workloads/haproxy/main.tf @@ -169,4 +169,3 @@ resource "helm_release" "haproxy_ingress" { type = "string" } } - diff --git a/modules/workloads/infra/README.md b/modules/workloads/infra/README.md new file mode 100644 index 0000000..28193ba --- /dev/null +++ b/modules/workloads/infra/README.md @@ -0,0 +1,96 @@ +# Observability Pattern for Java/JMX + +This module provides an automated experience around Observability for Nginx workloads. +It provides the following resources: + +- AWS Distro For OpenTelemetry Operator and Collector +- AWS Managed Grafana Dashboard and data source +- Alerts and recording rules with AWS Managed Service for Prometheus + +<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK --> +## Requirements + +| Name | Version | +|------|---------| +| <a name="requirement_grafana"></a> [grafana](#requirement\_grafana) | 1.25.0 | + +## Providers + +| Name | Version | +|------|---------| +| <a name="provider_aws"></a> [aws](#provider\_aws) | n/a | +| <a name="provider_grafana"></a> [grafana](#provider\_grafana) | 1.25.0 | +| <a name="provider_helm"></a> [helm](#provider\_helm) | n/a | + +## Modules + +| Name | Source | Version | +|------|--------|---------| +| <a name="module_helm_addon"></a> [helm\_addon](#module\_helm\_addon) | github.com/aws-ia/terraform-aws-eks-blueprints/modules/kubernetes-addons/helm-addon | n/a | + +## Resources + +| Name | Type | +|------|------| +| [aws_prometheus_rule_group_namespace.api-availability](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | +| [aws_prometheus_rule_group_namespace.apibr](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | +| [aws_prometheus_rule_group_namespace.apihg](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | +| [aws_prometheus_rule_group_namespace.kubelet](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | +| [aws_prometheus_rule_group_namespace.kubeprom-recording](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | +| [aws_prometheus_rule_group_namespace.kubepromnr](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | +| [aws_prometheus_rule_group_namespace.kubescheduler](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | +| [aws_prometheus_rule_group_namespace.kubprom](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | +| [aws_prometheus_rule_group_namespace.ne](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | +| [aws_prometheus_rule_group_namespace.noderules](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/prometheus_rule_group_namespace) | resource | +| [grafana_dashboard.alertmanager](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.apis](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.cluster](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.clusternw](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.controller](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.coredns](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.etcd](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.grafana](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.kubelet](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.macos](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.necluster](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.nenode](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.nenodeuse](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.nodes](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.nsnw](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.nsnwworkload](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.nspods](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.nsworkload](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.nwworload](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.podnetwork](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.pods](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.prometheus](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.proxy](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.pv](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.scheduler](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [grafana_dashboard.workloads](https://registry.terraform.io/providers/grafana/grafana/1.25.0/docs/resources/dashboard) | resource | +| [helm_release.kube_state_metrics](https://registry.terraform.io/providers/hashicorp/helm/latest/docs/resources/release) | resource | +| [helm_release.prometheus_node_exporter](https://registry.terraform.io/providers/hashicorp/helm/latest/docs/resources/release) | resource | +| [aws_caller_identity.current](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/caller_identity) | data source | +| [aws_eks_cluster.eks_cluster](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/eks_cluster) | data source | +| [aws_partition.current](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/partition) | data source | +| [aws_region.current](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/region) | data source | + +## Inputs + +| Name | Description | Type | Default | Required | +|------|-------------|------|---------|:--------:| +| <a name="input_config"></a> [config](#input\_config) | n/a | <pre>object({<br> helm_config = map(any)<br><br> enable_kube_state_metrics = bool<br> kms_create_namespace = bool<br> ksm_k8s_namespace = string<br> ksm_helm_chart_name = string<br> ksm_helm_chart_version = string<br> ksm_helm_release_name = string<br> ksm_helm_repo_url = string<br> ksm_helm_settings = map(string)<br> ksm_helm_values = map(any)<br><br> enable_node_exporter = bool<br> ne_create_namespace = bool<br> ne_k8s_namespace = string<br> ne_helm_chart_name = string<br> ne_helm_chart_version = string<br> ne_helm_release_name = string<br> ne_helm_repo_url = string<br> ne_helm_settings = map(string)<br> ne_helm_values = map(any)<br><br> enable_dashboards = bool<br><br> enable_recording_rules = bool<br> })</pre> | <pre>{<br> "enable_dashboards": true,<br> "enable_kube_state_metrics": true,<br> "enable_node_exporter": true,<br> "enable_recording_rules": true,<br> "helm_config": {},<br> "kms_create_namespace": true,<br> "ksm_helm_chart_name": "kube-state-metrics",<br> "ksm_helm_chart_version": "4.9.2",<br> "ksm_helm_release_name": "kube-state-metrics",<br> "ksm_helm_repo_url": "https://prometheus-community.github.io/helm-charts",<br> "ksm_helm_settings": {},<br> "ksm_helm_values": {},<br> "ksm_k8s_namespace": "kube-system",<br> "ne_create_namespace": true,<br> "ne_helm_chart_name": "prometheus-node-exporter",<br> "ne_helm_chart_version": "2.0.3",<br> "ne_helm_release_name": "prometheus-node-exporter",<br> "ne_helm_repo_url": "https://prometheus-community.github.io/helm-charts",<br> "ne_helm_settings": {},<br> "ne_helm_values": {},<br> "ne_k8s_namespace": "prometheus-node-exporter"<br>}</pre> | no | +| <a name="input_dashboards_folder_id"></a> [dashboards\_folder\_id](#input\_dashboards\_folder\_id) | n/a | `string` | n/a | yes | +| <a name="input_eks_cluster_id"></a> [eks\_cluster\_id](#input\_eks\_cluster\_id) | EKS Cluster Id | `string` | n/a | yes | +| <a name="input_helm_config"></a> [helm\_config](#input\_helm\_config) | Helm Config for Prometheus | `any` | `{}` | no | +| <a name="input_irsa_iam_permissions_boundary"></a> [irsa\_iam\_permissions\_boundary](#input\_irsa\_iam\_permissions\_boundary) | IAM permissions boundary for IRSA roles | `string` | `""` | no | +| <a name="input_irsa_iam_role_path"></a> [irsa\_iam\_role\_path](#input\_irsa\_iam\_role\_path) | IAM role path for IRSA roles | `string` | `"/"` | no | +| <a name="input_managed_prometheus_workspace_endpoint"></a> [managed\_prometheus\_workspace\_endpoint](#input\_managed\_prometheus\_workspace\_endpoint) | Amazon Managed Prometheus Workspace Endpoint | `string` | `null` | no | +| <a name="input_managed_prometheus_workspace_id"></a> [managed\_prometheus\_workspace\_id](#input\_managed\_prometheus\_workspace\_id) | Amazon Managed Prometheus Workspace ID | `string` | `null` | no | +| <a name="input_managed_prometheus_workspace_region"></a> [managed\_prometheus\_workspace\_region](#input\_managed\_prometheus\_workspace\_region) | Amazon Managed Prometheus Workspace's Region | `string` | `null` | no | +| <a name="input_tags"></a> [tags](#input\_tags) | Additional tags (e.g. `map('BusinessUnit`,`XYZ`) | `map(string)` | `{}` | no | + +## Outputs + +No outputs. +<!-- END OF PRE-COMMIT-TERRAFORM DOCS HOOK --> diff --git a/workloads/infra/dashboards.tf b/modules/workloads/infra/dashboards.tf similarity index 100% rename from workloads/infra/dashboards.tf rename to modules/workloads/infra/dashboards.tf diff --git a/workloads/infra/dashboards/alertmanager.json b/modules/workloads/infra/dashboards/alertmanager.json similarity index 99% rename from workloads/infra/dashboards/alertmanager.json rename to modules/workloads/infra/dashboards/alertmanager.json index 8a28a32..edce3ac 100644 --- a/workloads/infra/dashboards/alertmanager.json +++ b/modules/workloads/infra/dashboards/alertmanager.json @@ -623,4 +623,4 @@ "uid": "alertmanager-overview", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/apiserver.json b/modules/workloads/infra/dashboards/apiserver.json similarity index 99% rename from workloads/infra/dashboards/apiserver.json rename to modules/workloads/infra/dashboards/apiserver.json index e4754d1..850f68b 100644 --- a/workloads/infra/dashboards/apiserver.json +++ b/modules/workloads/infra/dashboards/apiserver.json @@ -1582,4 +1582,4 @@ "uid": "09ec8aa1e996d6ffcd6817bbaff4db1b", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/cluster-networking.json b/modules/workloads/infra/dashboards/cluster-networking.json similarity index 99% rename from workloads/infra/dashboards/cluster-networking.json rename to modules/workloads/infra/dashboards/cluster-networking.json index 166a7fd..7b16534 100644 --- a/workloads/infra/dashboards/cluster-networking.json +++ b/modules/workloads/infra/dashboards/cluster-networking.json @@ -1742,4 +1742,4 @@ "uid": "ff635a025bcfea7bc3dd4f508990a3e9", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/cluster.json b/modules/workloads/infra/dashboards/cluster.json similarity index 99% rename from workloads/infra/dashboards/cluster.json rename to modules/workloads/infra/dashboards/cluster.json index 6966770..af68103 100644 --- a/workloads/infra/dashboards/cluster.json +++ b/modules/workloads/infra/dashboards/cluster.json @@ -2944,4 +2944,4 @@ "uid": "efa86fd1d0c121a26444b636a3f509a8", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/controller.json b/modules/workloads/infra/dashboards/controller.json similarity index 99% rename from workloads/infra/dashboards/controller.json rename to modules/workloads/infra/dashboards/controller.json index 658e66b..1e11736 100644 --- a/workloads/infra/dashboards/controller.json +++ b/modules/workloads/infra/dashboards/controller.json @@ -1023,4 +1023,4 @@ "uid": "72e0e05bef5099e5f049b05fdc429ed4", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/coredns.json b/modules/workloads/infra/dashboards/coredns.json similarity index 99% rename from workloads/infra/dashboards/coredns.json rename to modules/workloads/infra/dashboards/coredns.json index 58daafb..d26810a 100644 --- a/workloads/infra/dashboards/coredns.json +++ b/modules/workloads/infra/dashboards/coredns.json @@ -1511,4 +1511,4 @@ "uid": "vkQ0UHxik", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/etcd.json b/modules/workloads/infra/dashboards/etcd.json similarity index 99% rename from workloads/infra/dashboards/etcd.json rename to modules/workloads/infra/dashboards/etcd.json index cd6c564..415813b 100644 --- a/workloads/infra/dashboards/etcd.json +++ b/modules/workloads/infra/dashboards/etcd.json @@ -1266,4 +1266,4 @@ "uid": "c2f4e12cdf69feb95caa41a5a1b423d9", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/grafana.json b/modules/workloads/infra/dashboards/grafana.json similarity index 99% rename from workloads/infra/dashboards/grafana.json rename to modules/workloads/infra/dashboards/grafana.json index 7842aaf..33e46a1 100644 --- a/workloads/infra/dashboards/grafana.json +++ b/modules/workloads/infra/dashboards/grafana.json @@ -560,4 +560,4 @@ "uid": "6be0s85Mk", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/kubelet.json b/modules/workloads/infra/dashboards/kubelet.json similarity index 99% rename from workloads/infra/dashboards/kubelet.json rename to modules/workloads/infra/dashboards/kubelet.json index 9677249..5b164ac 100644 --- a/workloads/infra/dashboards/kubelet.json +++ b/modules/workloads/infra/dashboards/kubelet.json @@ -1983,4 +1983,4 @@ "uid": "3138fa155d5915769fbded898ac09fd9", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/macos.json b/modules/workloads/infra/dashboards/macos.json similarity index 99% rename from workloads/infra/dashboards/macos.json rename to modules/workloads/infra/dashboards/macos.json index 6064a2c..6f9d691 100644 --- a/workloads/infra/dashboards/macos.json +++ b/modules/workloads/infra/dashboards/macos.json @@ -1015,4 +1015,4 @@ "uid": "2_yvYJq7k", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/namespace-networking.json b/modules/workloads/infra/dashboards/namespace-networking.json similarity index 99% rename from workloads/infra/dashboards/namespace-networking.json rename to modules/workloads/infra/dashboards/namespace-networking.json index 5d05f33..dd01ee8 100644 --- a/workloads/infra/dashboards/namespace-networking.json +++ b/modules/workloads/infra/dashboards/namespace-networking.json @@ -1398,4 +1398,4 @@ "uid": "8b7a8b326d7a6f1f04244066368c67af", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/namespace-nw-workloads.json b/modules/workloads/infra/dashboards/namespace-nw-workloads.json similarity index 99% rename from workloads/infra/dashboards/namespace-nw-workloads.json rename to modules/workloads/infra/dashboards/namespace-nw-workloads.json index f71d1dd..1c6534b 100644 --- a/workloads/infra/dashboards/namespace-nw-workloads.json +++ b/modules/workloads/infra/dashboards/namespace-nw-workloads.json @@ -1631,4 +1631,4 @@ "uid": "bbb2a765a623ae38130206c7d94a160f", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/namespace-pods.json b/modules/workloads/infra/dashboards/namespace-pods.json similarity index 99% rename from workloads/infra/dashboards/namespace-pods.json rename to modules/workloads/infra/dashboards/namespace-pods.json index 21887bb..9785c7f 100644 --- a/workloads/infra/dashboards/namespace-pods.json +++ b/modules/workloads/infra/dashboards/namespace-pods.json @@ -2718,4 +2718,4 @@ "uid": "85a562078cdf77779eaa1add43ccec1e", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/namespace-workloads.json b/modules/workloads/infra/dashboards/namespace-workloads.json similarity index 99% rename from workloads/infra/dashboards/namespace-workloads.json rename to modules/workloads/infra/dashboards/namespace-workloads.json index 06fef5a..a19b3a8 100644 --- a/workloads/infra/dashboards/namespace-workloads.json +++ b/modules/workloads/infra/dashboards/namespace-workloads.json @@ -2274,4 +2274,4 @@ "uid": "a87fb0d919ec0ea5f6543124e16c42a5", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/networking-workloads.json b/modules/workloads/infra/dashboards/networking-workloads.json similarity index 99% rename from workloads/infra/dashboards/networking-workloads.json rename to modules/workloads/infra/dashboards/networking-workloads.json index 86898a7..05e4efc 100644 --- a/workloads/infra/dashboards/networking-workloads.json +++ b/modules/workloads/infra/dashboards/networking-workloads.json @@ -1351,4 +1351,4 @@ "uid": "728bf77cc1166d2f3133bf25846876cc", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/nodeexporter-nodes.json b/modules/workloads/infra/dashboards/nodeexporter-nodes.json similarity index 99% rename from workloads/infra/dashboards/nodeexporter-nodes.json rename to modules/workloads/infra/dashboards/nodeexporter-nodes.json index 286fe8c..3902fbf 100644 --- a/workloads/infra/dashboards/nodeexporter-nodes.json +++ b/modules/workloads/infra/dashboards/nodeexporter-nodes.json @@ -1004,4 +1004,4 @@ "uid": "v8yDYJqnz", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/nodeexporter-use-node.json b/modules/workloads/infra/dashboards/nodeexporter-use-node.json similarity index 99% rename from workloads/infra/dashboards/nodeexporter-use-node.json rename to modules/workloads/infra/dashboards/nodeexporter-use-node.json index b173d4a..9aa6fec 100644 --- a/workloads/infra/dashboards/nodeexporter-use-node.json +++ b/modules/workloads/infra/dashboards/nodeexporter-use-node.json @@ -1077,4 +1077,4 @@ "uid": "XysDYJ37k", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/nodeexpoter-use-cluster.json b/modules/workloads/infra/dashboards/nodeexpoter-use-cluster.json similarity index 99% rename from workloads/infra/dashboards/nodeexpoter-use-cluster.json rename to modules/workloads/infra/dashboards/nodeexpoter-use-cluster.json index acfbaef..5addb6a 100644 --- a/workloads/infra/dashboards/nodeexpoter-use-cluster.json +++ b/modules/workloads/infra/dashboards/nodeexpoter-use-cluster.json @@ -1075,4 +1075,4 @@ "uid": "h-sDLJ37z", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/nodes.json b/modules/workloads/infra/dashboards/nodes.json similarity index 99% rename from workloads/infra/dashboards/nodes.json rename to modules/workloads/infra/dashboards/nodes.json index c145796..76e78ea 100644 --- a/workloads/infra/dashboards/nodes.json +++ b/modules/workloads/infra/dashboards/nodes.json @@ -1049,4 +1049,4 @@ "uid": "200ac8fdbfbb74b39aff88118e4d1c2c", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/pesistentvolumes.json b/modules/workloads/infra/dashboards/pesistentvolumes.json similarity index 99% rename from workloads/infra/dashboards/pesistentvolumes.json rename to modules/workloads/infra/dashboards/pesistentvolumes.json index 0168891..53f2480 100644 --- a/workloads/infra/dashboards/pesistentvolumes.json +++ b/modules/workloads/infra/dashboards/pesistentvolumes.json @@ -547,4 +547,4 @@ "uid": "919b92a8e8041bd567af9edab12c840c", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/pods-networking.json b/modules/workloads/infra/dashboards/pods-networking.json similarity index 99% rename from workloads/infra/dashboards/pods-networking.json rename to modules/workloads/infra/dashboards/pods-networking.json index d4ecc3b..e0db4c7 100644 --- a/workloads/infra/dashboards/pods-networking.json +++ b/modules/workloads/infra/dashboards/pods-networking.json @@ -1178,4 +1178,4 @@ "uid": "7a18067ce943a40ae25454675c19ff5c", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/pods.json b/modules/workloads/infra/dashboards/pods.json similarity index 99% rename from workloads/infra/dashboards/pods.json rename to modules/workloads/infra/dashboards/pods.json index 23d9f4f..f812c2d 100644 --- a/workloads/infra/dashboards/pods.json +++ b/modules/workloads/infra/dashboards/pods.json @@ -2483,4 +2483,4 @@ "uid": "6581e46e4e5c7ba40a07646395ef7b23", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/prometheus.json b/modules/workloads/infra/dashboards/prometheus.json similarity index 99% rename from workloads/infra/dashboards/prometheus.json rename to modules/workloads/infra/dashboards/prometheus.json index 3f50d22..f3d6eb6 100644 --- a/workloads/infra/dashboards/prometheus.json +++ b/modules/workloads/infra/dashboards/prometheus.json @@ -1272,4 +1272,4 @@ "uid": "XayDYJ3nz", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/proxy.json b/modules/workloads/infra/dashboards/proxy.json similarity index 99% rename from workloads/infra/dashboards/proxy.json rename to modules/workloads/infra/dashboards/proxy.json index 0a9348d..f107a45 100644 --- a/workloads/infra/dashboards/proxy.json +++ b/modules/workloads/infra/dashboards/proxy.json @@ -1126,4 +1126,4 @@ "uid": "632e265de029684c40b21cb76bca4f94", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/scheduler.json b/modules/workloads/infra/dashboards/scheduler.json similarity index 99% rename from workloads/infra/dashboards/scheduler.json rename to modules/workloads/infra/dashboards/scheduler.json index feff65a..852872a 100644 --- a/workloads/infra/dashboards/scheduler.json +++ b/modules/workloads/infra/dashboards/scheduler.json @@ -1035,4 +1035,4 @@ "uid": "2e6b6a3b4bddf1427b3a55aa1311c656", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/dashboards/workloads.json b/modules/workloads/infra/dashboards/workloads.json similarity index 99% rename from workloads/infra/dashboards/workloads.json rename to modules/workloads/infra/dashboards/workloads.json index 9792cdc..477aa08 100644 --- a/workloads/infra/dashboards/workloads.json +++ b/modules/workloads/infra/dashboards/workloads.json @@ -2031,4 +2031,4 @@ "uid": "a164a7f0339f99e89cea5cb47e9be617", "version": 1, "weekStart": "" - } \ No newline at end of file + } diff --git a/workloads/infra/locals.tf b/modules/workloads/infra/locals.tf similarity index 100% rename from workloads/infra/locals.tf rename to modules/workloads/infra/locals.tf diff --git a/workloads/infra/main.tf b/modules/workloads/infra/main.tf similarity index 100% rename from workloads/infra/main.tf rename to modules/workloads/infra/main.tf diff --git a/workloads/infra/otel-config/Chart.yaml b/modules/workloads/infra/otel-config/Chart.yaml similarity index 100% rename from workloads/infra/otel-config/Chart.yaml rename to modules/workloads/infra/otel-config/Chart.yaml diff --git a/workloads/infra/otel-config/templates/clusterrole.yaml b/modules/workloads/infra/otel-config/templates/clusterrole.yaml similarity index 100% rename from workloads/infra/otel-config/templates/clusterrole.yaml rename to modules/workloads/infra/otel-config/templates/clusterrole.yaml diff --git a/workloads/infra/otel-config/templates/clusterrolebinding.yaml b/modules/workloads/infra/otel-config/templates/clusterrolebinding.yaml similarity index 100% rename from workloads/infra/otel-config/templates/clusterrolebinding.yaml rename to modules/workloads/infra/otel-config/templates/clusterrolebinding.yaml diff --git a/workloads/infra/otel-config/templates/opentelemetrycollector.yaml b/modules/workloads/infra/otel-config/templates/opentelemetrycollector.yaml similarity index 98% rename from workloads/infra/otel-config/templates/opentelemetrycollector.yaml rename to modules/workloads/infra/otel-config/templates/opentelemetrycollector.yaml index a18b39a..67447f9 100644 --- a/workloads/infra/otel-config/templates/opentelemetrycollector.yaml +++ b/modules/workloads/infra/otel-config/templates/opentelemetrycollector.yaml @@ -12,7 +12,7 @@ spec: config: global: scrape_interval: {{ .Values.scrapeInterval }} - scrape_timeout: {{ .Values.scrapeTimeout }} + scrape_timeout: {{ .Values.scrapeTimeout }} scrape_configs: - job_name: 'kubernetes-kubelet' scheme: https @@ -48,7 +48,7 @@ spec: - source_labels: [__meta_kubernetes_node_name] regex: (.+) target_label: __metrics_path__ - replacement: /api/v1/nodes/$${1}/proxy/metrics/cadvisor + replacement: /api/v1/nodes/$${1}/proxy/metrics/cadvisor - source_labels: [__metrics_path__] separator: ; regex: (.*) @@ -158,7 +158,7 @@ spec: namespaces: own_namespace: false names: - - default + - default - job_name: serviceMonitor/default/kube-prometheus-stack-prometheus/0 honor_timestamps: true scrape_interval: 30s @@ -261,7 +261,7 @@ spec: namespaces: own_namespace: false names: - - default + - default - job_name: serviceMonitor/default/kube-prometheus-stack-operator/0 honor_labels: true honor_timestamps: true @@ -364,7 +364,7 @@ spec: namespaces: own_namespace: false names: - - default + - default - job_name: serviceMonitor/default/kube-prometheus-stack-kubelet/2 honor_labels: true honor_timestamps: true @@ -481,7 +481,7 @@ spec: namespaces: own_namespace: false names: - - kube-system + - kube-system - job_name: serviceMonitor/default/kube-prometheus-stack-kubelet/1 honor_labels: true honor_timestamps: true @@ -716,7 +716,7 @@ spec: namespaces: own_namespace: false names: - - kube-system + - kube-system - job_name: serviceMonitor/default/kube-prometheus-stack-kube-state-metrics/0 honor_labels: true honor_timestamps: true @@ -821,7 +821,7 @@ spec: namespaces: own_namespace: false names: - - default + - default - job_name: serviceMonitor/default/kube-prometheus-stack-kube-scheduler/0 honor_timestamps: true scrape_interval: 30s @@ -928,7 +928,7 @@ spec: namespaces: own_namespace: false names: - - kube-system + - kube-system - job_name: serviceMonitor/default/kube-prometheus-stack-kube-proxy/0 honor_timestamps: true scrape_interval: 30s @@ -1035,7 +1035,7 @@ spec: namespaces: own_namespace: false names: - - kube-system + - kube-system - job_name: serviceMonitor/default/kube-prometheus-stack-kube-etcd/0 honor_timestamps: true scrape_interval: 30s @@ -1354,7 +1354,7 @@ spec: namespaces: own_namespace: false names: - - kube-system + - kube-system - job_name: serviceMonitor/default/kube-prometheus-stack-apiserver/0 honor_timestamps: true @@ -1367,7 +1367,7 @@ spec: credentials_file: /var/run/secrets/kubernetes.io/serviceaccount/token tls_config: ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt - server_name: kubernetes + server_name: kubernetes follow_redirects: true enable_http2: true relabel_configs: @@ -1439,7 +1439,7 @@ spec: regex: (.*) target_label: endpoint replacement: https - action: replace + action: replace - source_labels: [__address__] separator: ; regex: (.*) @@ -1460,7 +1460,7 @@ spec: namespaces: own_namespace: false names: - - default + - default - job_name: serviceMonitor/default/kube-prometheus-stack-alertmanager/0 honor_timestamps: true scrape_interval: 30s @@ -1563,7 +1563,7 @@ spec: namespaces: own_namespace: false names: - - default + - default - job_name: 'kube-state-metrics' static_configs: - targets: ['kube-state-metrics.kube-system.svc.cluster.local:8080'] diff --git a/workloads/infra/otel-config/values.yaml b/modules/workloads/infra/otel-config/values.yaml similarity index 100% rename from workloads/infra/otel-config/values.yaml rename to modules/workloads/infra/otel-config/values.yaml diff --git a/workloads/infra/outputs.tf b/modules/workloads/infra/outputs.tf similarity index 100% rename from workloads/infra/outputs.tf rename to modules/workloads/infra/outputs.tf diff --git a/workloads/infra/rules.tf b/modules/workloads/infra/rules.tf similarity index 100% rename from workloads/infra/rules.tf rename to modules/workloads/infra/rules.tf diff --git a/workloads/infra/variables.tf b/modules/workloads/infra/variables.tf similarity index 100% rename from workloads/infra/variables.tf rename to modules/workloads/infra/variables.tf diff --git a/workloads/java/dashboards/default.json b/modules/workloads/java/dashboards/default.json similarity index 99% rename from workloads/java/dashboards/default.json rename to modules/workloads/java/dashboards/default.json index ce05f68..21c635f 100644 --- a/workloads/java/dashboards/default.json +++ b/modules/workloads/java/dashboards/default.json @@ -1787,4 +1787,4 @@ "title": "Java/JMX", "uid": "m9mHfAy7ks", "version": 12 -} \ No newline at end of file +} diff --git a/workloads/java/main.tf b/modules/workloads/java/main.tf similarity index 100% rename from workloads/java/main.tf rename to modules/workloads/java/main.tf diff --git a/workloads/java/otel-config/Chart.yaml b/modules/workloads/java/otel-config/Chart.yaml similarity index 100% rename from workloads/java/otel-config/Chart.yaml rename to modules/workloads/java/otel-config/Chart.yaml diff --git a/workloads/java/otel-config/templates/clusterrole.yaml b/modules/workloads/java/otel-config/templates/clusterrole.yaml similarity index 100% rename from workloads/java/otel-config/templates/clusterrole.yaml rename to modules/workloads/java/otel-config/templates/clusterrole.yaml diff --git a/workloads/java/otel-config/templates/clusterrolebinding.yaml b/modules/workloads/java/otel-config/templates/clusterrolebinding.yaml similarity index 100% rename from workloads/java/otel-config/templates/clusterrolebinding.yaml rename to modules/workloads/java/otel-config/templates/clusterrolebinding.yaml diff --git a/workloads/java/otel-config/templates/opentelemetrycollector.yaml b/modules/workloads/java/otel-config/templates/opentelemetrycollector.yaml similarity index 100% rename from workloads/java/otel-config/templates/opentelemetrycollector.yaml rename to modules/workloads/java/otel-config/templates/opentelemetrycollector.yaml diff --git a/workloads/java/otel-config/values.yaml b/modules/workloads/java/otel-config/values.yaml similarity index 100% rename from workloads/java/otel-config/values.yaml rename to modules/workloads/java/otel-config/values.yaml diff --git a/workloads/java/variables.tf b/modules/workloads/java/variables.tf similarity index 100% rename from workloads/java/variables.tf rename to modules/workloads/java/variables.tf diff --git a/tfsec.yaml b/tfsec.yaml new file mode 100644 index 0000000..73b3338 --- /dev/null +++ b/tfsec.yaml @@ -0,0 +1,8 @@ +exclude: + - aws-iam-no-policy-wildcards # Wildcards required in addon IAM policies + - aws-vpc-no-excessive-port-access # VPC settings left up to user implementation for recommended practices + - aws-vpc-no-public-ingress-acl # VPC settings left up to user implementation for recommended practices + - aws-eks-no-public-cluster-access-to-cidr # Public access enabled for better example usability, users are recommended to disable if possible + - aws-eks-no-public-cluster-access # Public access enabled for better example usability, users are recommended to disable if possible + - aws-eks-encrypt-secrets # Module defaults to encrypting secrets with CMK, but this is not hardcoded and therefore a spurious error + - aws-vpc-no-public-egress-sgr # Added in v1.22 diff --git a/workloads/infra/README.md b/workloads/infra/README.md deleted file mode 100644 index 16df589..0000000 --- a/workloads/infra/README.md +++ /dev/null @@ -1,49 +0,0 @@ -# Observability Pattern for Java/JMX - -This module provides an automated experience around Observability for Nginx workloads. -It provides the following resources: - -- AWS Distro For OpenTelemetry Operator and Collector -- AWS Managed Grafana Dashboard and data source -- Alerts and recording rules with AWS Managed Service for Prometheus - -<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK --> -## Requirements - -| Name | Version | -|------|---------| -| <a name="requirement_terraform"></a> [terraform](#requirement\_terraform) | >= 1.0.0 | -| <a name="requirement_aws"></a> [aws](#requirement\_aws) | >= 3.72 | -| <a name="requirement_kubernetes"></a> [kubernetes](#requirement\_kubernetes) | >= 2.10 | - -## Providers - -| Name | Version | -|------|---------| -| <a name="provider_aws"></a> [aws](#provider\_aws) | >= 3.72 | - -## Modules - -| Name | Source | Version | -|------|--------|---------| -| <a name="module_helm_addon"></a> [helm\_addon](#module\_helm\_addon) | ../helm-addon | n/a | - -## Resources - -| Name | Type | -|------|------| -| [aws_partition.current](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/partition) | data source | - -## Inputs - -| Name | Description | Type | Default | Required | -|------|-------------|------|---------|:--------:| -| <a name="input_addon_context"></a> [addon\_context](#input\_addon\_context) | Input configuration for the addon | <pre>object({<br> aws_caller_identity_account_id = string<br> aws_caller_identity_arn = string<br> aws_eks_cluster_endpoint = string<br> aws_partition_id = string<br> aws_region_name = string<br> eks_cluster_id = string<br> eks_oidc_issuer_url = string<br> eks_oidc_provider_arn = string<br> irsa_iam_permissions_boundary = string<br> irsa_iam_role_path = string<br> tags = map(string)<br> })</pre> | n/a | yes | -| <a name="input_amazon_prometheus_workspace_endpoint"></a> [amazon\_prometheus\_workspace\_endpoint](#input\_amazon\_prometheus\_workspace\_endpoint) | Amazon Managed Prometheus Workspace Endpoint | `string` | `null` | no | -| <a name="input_amazon_prometheus_workspace_region"></a> [amazon\_prometheus\_workspace\_region](#input\_amazon\_prometheus\_workspace\_region) | Amazon Managed Prometheus Workspace's Region | `string` | `null` | no | -| <a name="input_helm_config"></a> [helm\_config](#input\_helm\_config) | Helm Config for Prometheus | `any` | `{}` | no | - -## Outputs - -No outputs. -<!-- END OF PRE-COMMIT-TERRAFORM DOCS HOOK -->