From 2a5564607491389ad1a87c16add9542d44d9ac20 Mon Sep 17 00:00:00 2001 From: Rodrigue Koffi Date: Thu, 28 Jul 2022 14:37:55 +0200 Subject: [PATCH] Create a new AMG workspace --- examples/variables.tf | 9 +++++- examples/workloads.tf | 34 +++++++++++----------- locals.tf | 37 +++++++++++++++++++++++- main.tf | 52 +++++++++++++++++++++++----------- modules/workloads/java/main.tf | 9 ++++++ variables.tf | 23 +++++++++++++-- 6 files changed, 125 insertions(+), 39 deletions(-) diff --git a/examples/variables.tf b/examples/variables.tf index 32eccff..4d89e8c 100644 --- a/examples/variables.tf +++ b/examples/variables.tf @@ -14,7 +14,7 @@ variable "aws_region" { description = "AWS Region" type = string } -variable "managed_prometheus_id" { +variable "managed_prometheus_workspace_id" { type = string default = "" } @@ -26,3 +26,10 @@ variable "managed_prometheus_region" { type = string default = "" } + + +variable "managed_grafana_workspace_id" { + type = string + default = "" +} + diff --git a/examples/workloads.tf b/examples/workloads.tf index 2334d02..eb094dc 100644 --- a/examples/workloads.tf +++ b/examples/workloads.tf @@ -7,6 +7,8 @@ module "eks_observability_accelerator" { aws_region = var.aws_region eks_cluster_id = var.eks_cluster_id + # TODO: create also a cluster, VPC -- check if enough VPCs + # deploys AWS Distro for OpenTelemetry operator into the cluster enable_amazon_eks_adot = false @@ -15,20 +17,27 @@ module "eks_observability_accelerator" { # # -- or enable opentelemetry operator enable_opentelemetry_operator = false #-- true doesn't work for me, needs fix - # open_telemetry_operator_config = map() // custom config + #open_telemetry_operator_config = map() // custom config # creates a new AMP workspace, defaults to true - create_managed_prometheus_workspace = false + enable_managed_prometheus = false # reusing existing AMP -- needs data source for alerting rules - managed_prometheus_id = var.managed_prometheus_id - managed_prometheus_region = null # defaults to the current region, useful for cross region scenarios + managed_prometheus_id = var.managed_prometheus_workspace_id + managed_prometheus_region = null # defaults to the current region, useful for cross region scenarios (same account) # sets up the AMP alert manager at the workspace level enable_alertmanager = true + # create a new Grafana workspace + enable_managed_grafana = true + #managed_grafana_workspace_id = "g-9790a4306b" + + + enable_java = true - enable_java_recording_rules = true # defaults to true + enable_java_recording_rules = true + # enable_haproxy = true # haproxy_config = { @@ -42,17 +51,6 @@ module "eks_observability_accelerator" { # grafana_endpoint = "" # } - - - - # # -- or use an existing one - # # seems like https://github.com/terraform-aws-modules/terraform-aws-managed-service-prometheus - # # supports importing - # amp_workspace_alias = var.amp_alias - - # # enable rules and alerts - # enable_alert_manager = true - # # -- or provide custom alerts definition # prometheus_custom_alert_rule = var.prometheus_custom_alert_rule @@ -65,12 +63,12 @@ module "eks_observability_accelerator" { # grafana_permission_role_arn = var.grafana_permission_role_arn // if CUSTOMER_MANAGED # # -- or using existing amg workspace. so we can use API for keys - # managed_grafana_workspace_id = var.managed_grafana_workspace_id + tags = local.tags -} +} # module "amp" { # } diff --git a/locals.tf b/locals.tf index be34fe5..07b77cc 100644 --- a/locals.tf +++ b/locals.tf @@ -8,6 +8,30 @@ data "aws_eks_cluster" "eks_cluster" { name = var.eks_cluster_id } +data "aws_grafana_workspace" "this" { + count = var.managed_grafana_workspace_id == "" ? 0 : 1 + workspace_id = var.managed_grafana_workspace_id +} + +# resource "null_resource" "amg_api_key" { + +# # Bootstrap script can run on any instance of the cluster +# # So we just choose the first in this case +# connection { +# host = element(aws_instance.cluster.*.public_ip, 0) +# } + +# provisioner "remote-exec" { +# # requires aws-cli +# inline = [ +# #"bootstrap-cluster.sh ${join(" ", aws_instance.cluster.*.private_ip)}", +# "aws grafana create-key", +# ] +# } +# } + + + locals { eks_oidc_issuer_url = replace(data.aws_eks_cluster.eks_cluster.identity[0].oidc[0].issuer, "https://", "") eks_cluster_endpoint = data.aws_eks_cluster.eks_cluster.endpoint @@ -15,9 +39,20 @@ locals { # if region is not passed, we assume the current one amp_ws_region = coalesce(var.managed_prometheus_region, data.aws_region.current.name) - amp_ws_id = var.create_managed_prometheus_workspace ? aws_prometheus_workspace.this[0].id : var.managed_prometheus_id + amp_ws_id = var.enable_managed_prometheus ? aws_prometheus_workspace.this[0].id : var.managed_prometheus_id amp_ws_endpoint = "https://aps-workspaces.${local.amp_ws_region}.amazonaws.com/workspaces/${local.amp_ws_id}/" + # if region is not passed, we assume the current one + amg_ws_region = coalesce(var.managed_grafana_region, data.aws_region.current.name) + + # if grafana_workspace_id is supplied, we infer the endpoint from + # computed region, else we create a new workspace + amg_ws_endpoint = var.enable_managed_grafana ? "https://${module.managed_grafana[0].workspace_endpoint}" : "https://${var.managed_grafana_workspace_id}.grafana-workspace.${local.amg_ws_region}.amazonaws.com" + + # TODO when tf resource for AMG api keys are supported + # create a short-lived api key on the fly if api_key is not provided + amg_api_key = var.grafana_api_key + context = { aws_caller_identity_account_id = data.aws_caller_identity.current.account_id aws_caller_identity_arn = data.aws_caller_identity.current.arn diff --git a/main.tf b/main.tf index 962cce6..6eec0c5 100644 --- a/main.tf +++ b/main.tf @@ -1,19 +1,3 @@ - -# DONT create the resources -# VPC and supporting resources -# EKS and Managed node groups - -# locals { -# # if both adot and otel are enabled, just deploys adot -# enable_otel = (var.enable_amazon_eks_adot && var.enable_opentelemetry_operator) ? false : var.enable_opentelemetry_operator - -# # if both adot and otel are disabled, just deploys adot -# enable_adot = (!var.enable_amazon_eks_adot && !var.enable_opentelemetry_operator) ? true : var.enable_amazon_eks_adot - -# #possible side effects? maybe customer wants only dashboards? - -# } - module "operator" { source = "./modules/core/opentelemetry-operator" @@ -27,7 +11,7 @@ module "operator" { } resource "aws_prometheus_workspace" "this" { - count = var.create_managed_prometheus_workspace ? 1 : 0 + count = var.enable_managed_prometheus ? 1 : 0 alias = local.name tags = var.tags @@ -49,6 +33,40 @@ alertmanager_config: | EOF } +module "managed_grafana" { + count = var.enable_managed_grafana ? 1 : 0 + source = "terraform-aws-modules/managed-service-grafana/aws" + version = "~> 1.3" + + # Workspace + name = local.name + stack_set_name = local.name + data_sources = ["PROMETHEUS"] + associate_license = false + + tags = var.tags +} + +# provider "grafana" { +# #url = try(var.grafana_endpoint, "https://${module.managed_grafana.workspace_endpoint}") +# url = local.grafana_endpoint +# auth = local.grafana_api_key +# } + + +# resource "grafana_data_source" "amp" { +# type = "prometheus" +# name = local.name +# is_default = true +# url = local.amp_ws_endpoint +# json_data { +# http_method = "GET" +# sigv4_auth = true +# sigv4_auth_type = "workspace-iam-role" +# sigv4_region = local.amp_ws_region +# } +# } + module "java" { count = var.enable_java ? 1 : 0 source = "./modules/workloads/java" diff --git a/modules/workloads/java/main.tf b/modules/workloads/java/main.tf index 623a147..8c7bc89 100644 --- a/modules/workloads/java/main.tf +++ b/modules/workloads/java/main.tf @@ -91,3 +91,12 @@ EOF } # dashboard + +# resource "grafana_folder" "this" { +# title = "Observability Accelerator - Java" +# } + +# resource "grafana_dashboard" "this" { +# folder = grafana_folder.this.id +# config_json = file("${path.module}/dashboards/default.json") +# } diff --git a/variables.tf b/variables.tf index 01ee50e..0f26a1e 100644 --- a/variables.tf +++ b/variables.tf @@ -27,7 +27,6 @@ variable "irsa_iam_permissions_boundary" { default = "" } - variable "enable_amazon_eks_adot" { type = bool default = true @@ -44,7 +43,7 @@ variable "enable_opentelemetry_operator" { default = false } -variable "create_managed_prometheus_workspace" { +variable "enable_managed_prometheus" { type = bool default = true } @@ -67,6 +66,26 @@ variable "enable_alertmanager" { default = false } +variable "enable_managed_grafana" { + type = bool + default = true +} + + +variable "managed_grafana_region" { + description = "AWS Managed Grafana Workspace Region" + type = string + default = null +} +variable "managed_grafana_workspace_id" { + type = string + default = "" +} +variable "grafana_api_key" { + type = string + default = null +} + variable "enable_java" { description = "Deploys a collector for JAVA/JMX based workloads, dashboards and alerting rules" type = bool