mirror of
https://github.com/storytold/terraform-aws-observability-accelerator.git
synced 2026-10-09 00:09:43 +00:00
Adding Module and Example for ECS cluster monitoring with ecs_observer (#211)
* Adding Module and Example for ECS cluster monitoring with ecs_observer * Adding Module and Example for ECS cluster monitoring with ecs_observer * Incorporating PR comments * Restructuring Examples and modules folder for ECS, Added content in main Readme * Fixing path as per PR comments * Parameterzing the config files, incorporated PR review comments * Adding condition for AMP WS and fixing AMP endpoint * Adding Document for ECS Monitoring and parameterized some variables * Added sample dashboard * Adding Document for ECS Monitoring and parameterized some variables * Fixing failures detected by pre-commit * Fixing failures detected by pre-commit * Fixing failures detected by pre-commit * Pre-commit fixes * Fixing failures detected by pre-commit * Fixing failures detected by pre-commit * Pre-commit * Fixing HIGH security alerts detected by pre-commit * Fixing HIGH security alerts detected by pre-commit * Fixing HIGH security alerts detected by pre-commit, 31stOct * Add links after merge * 2ndNov - Added condiotnal creation for Grafana WS and module versions for AMG, AMP --------- Co-authored-by: Rodrigue Koffi <bonclay7@users.noreply.github.com>
This commit is contained in:
@@ -0,0 +1,67 @@
|
||||
# ECS Cluster w/ EC2 Autoscaling
|
||||
|
||||
Configuration in this directory creates:
|
||||
|
||||
- ECS cluster using EC2 autoscaling groups
|
||||
- Autoscaling groups with IAM instance profile to be used by ECS cluster
|
||||
- Example ECS service that utilizes
|
||||
- Mounts a host volume into the container definition
|
||||
- Load balancer target group attachment
|
||||
- Security group for access to the example service
|
||||
|
||||
## Usage
|
||||
|
||||
To run this example you need to execute:
|
||||
|
||||
```bash
|
||||
$ terraform init
|
||||
$ terraform plan
|
||||
$ terraform apply
|
||||
```
|
||||
|
||||
Note that this example may create resources which will incur monetary charges on your AWS bill. Run `terraform destroy` when you no longer need these resources.
|
||||
|
||||
<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
|
||||
## Requirements
|
||||
|
||||
| Name | Version |
|
||||
|------|---------|
|
||||
| <a name="requirement_terraform"></a> [terraform](#requirement\_terraform) | >= 1.0 |
|
||||
| <a name="requirement_aws"></a> [aws](#requirement\_aws) | >= 4.55 |
|
||||
|
||||
## Providers
|
||||
|
||||
| Name | Version |
|
||||
|------|---------|
|
||||
| <a name="provider_aws"></a> [aws](#provider\_aws) | >= 4.55 |
|
||||
|
||||
## Modules
|
||||
|
||||
| Name | Source | Version |
|
||||
|------|--------|---------|
|
||||
| <a name="module_alb_sg"></a> [alb\_sg](#module\_alb\_sg) | terraform-aws-modules/security-group/aws | ~> 5.0 |
|
||||
| <a name="module_autoscaling"></a> [autoscaling](#module\_autoscaling) | terraform-aws-modules/autoscaling/aws | ~> 6.5 |
|
||||
| <a name="module_autoscaling_sg"></a> [autoscaling\_sg](#module\_autoscaling\_sg) | terraform-aws-modules/security-group/aws | ~> 5.0 |
|
||||
| <a name="module_ecs_cluster"></a> [ecs\_cluster](#module\_ecs\_cluster) | terraform-aws-modules/ecs/aws | 5.2.2 |
|
||||
| <a name="module_ecs_monitoring"></a> [ecs\_monitoring](#module\_ecs\_monitoring) | ../../modules/ecs-monitoring | n/a |
|
||||
| <a name="module_vpc"></a> [vpc](#module\_vpc) | terraform-aws-modules/vpc/aws | ~> 5.0 |
|
||||
|
||||
## Resources
|
||||
|
||||
| Name | Type |
|
||||
|------|------|
|
||||
| [aws_availability_zones.available](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/availability_zones) | data source |
|
||||
| [aws_ssm_parameter.ecs_optimized_ami](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/ssm_parameter) | data source |
|
||||
|
||||
## Inputs
|
||||
|
||||
No inputs.
|
||||
|
||||
## Outputs
|
||||
|
||||
No outputs.
|
||||
<!-- END OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
|
||||
|
||||
## License
|
||||
|
||||
Apache-2.0 Licensed. See [LICENSE](https://github.com/terraform-aws-modules/terraform-aws-ecs/blob/master/LICENSE).
|
||||
@@ -0,0 +1,246 @@
|
||||
provider "aws" {
|
||||
region = local.region
|
||||
}
|
||||
|
||||
data "aws_availability_zones" "available" {}
|
||||
|
||||
locals {
|
||||
region = "us-east-1"
|
||||
name = "ex-${basename(path.cwd)}"
|
||||
|
||||
vpc_cidr = "10.0.0.0/16"
|
||||
azs = slice(data.aws_availability_zones.available.names, 0, 3)
|
||||
|
||||
container_name = "ecs-sample"
|
||||
container_port = 80
|
||||
|
||||
tags = {
|
||||
Name = local.name
|
||||
Example = local.name
|
||||
Repository = "https://github.com/terraform-aws-modules/terraform-aws-ecs"
|
||||
}
|
||||
|
||||
network_acls = {
|
||||
public_inbound = [
|
||||
{
|
||||
rule_number = 100
|
||||
rule_action = "allow"
|
||||
from_port = 80
|
||||
to_port = 80
|
||||
protocol = "tcp"
|
||||
cidr_block = "10.0.0.0/16"
|
||||
},
|
||||
{
|
||||
rule_number = 110
|
||||
rule_action = "allow"
|
||||
from_port = 443
|
||||
to_port = 443
|
||||
protocol = "tcp"
|
||||
cidr_block = "10.0.0.0/16"
|
||||
},
|
||||
{
|
||||
rule_number = 120
|
||||
rule_action = "allow"
|
||||
from_port = 22
|
||||
to_port = 22
|
||||
protocol = "tcp"
|
||||
cidr_block = "10.0.0.0/16"
|
||||
}
|
||||
]
|
||||
public_outbound = [
|
||||
{
|
||||
rule_number = 100
|
||||
rule_action = "allow"
|
||||
from_port = 80
|
||||
to_port = 80
|
||||
protocol = "tcp"
|
||||
cidr_block = "10.0.0.0/16"
|
||||
},
|
||||
{
|
||||
rule_number = 110
|
||||
rule_action = "allow"
|
||||
from_port = 443
|
||||
to_port = 443
|
||||
protocol = "tcp"
|
||||
cidr_block = "10.0.0.0/16"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
################################################################################
|
||||
# Cluster
|
||||
################################################################################
|
||||
|
||||
module "ecs_cluster" {
|
||||
source = "terraform-aws-modules/ecs/aws"
|
||||
version = "5.2.2"
|
||||
|
||||
cluster_name = local.name
|
||||
|
||||
# Capacity provider - autoscaling groups
|
||||
default_capacity_provider_use_fargate = false
|
||||
create_task_exec_iam_role = true
|
||||
task_exec_iam_role_name = "ecs_monitor_task_exec_role"
|
||||
task_exec_iam_role_policies = { "module.ecs_cluster.module.cluster.aws_iam_policy.task_exec[0]" : "arn:aws:iam::aws:policy/AmazonPrometheusRemoteWriteAccess" }
|
||||
autoscaling_capacity_providers = {
|
||||
# On-demand instances
|
||||
ex-1 = {
|
||||
auto_scaling_group_arn = module.autoscaling["ex-1"].autoscaling_group_arn
|
||||
managed_termination_protection = "ENABLED"
|
||||
|
||||
managed_scaling = {
|
||||
maximum_scaling_step_size = 5
|
||||
minimum_scaling_step_size = 1
|
||||
status = "ENABLED"
|
||||
target_capacity = 60
|
||||
}
|
||||
|
||||
default_capacity_provider_strategy = {
|
||||
weight = 60
|
||||
base = 20
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
tags = local.tags
|
||||
}
|
||||
|
||||
|
||||
module "autoscaling" {
|
||||
source = "terraform-aws-modules/autoscaling/aws"
|
||||
version = "~> 6.5"
|
||||
|
||||
for_each = {
|
||||
# On-demand instances
|
||||
ex-1 = {
|
||||
instance_type = "t3.large"
|
||||
use_mixed_instances_policy = false
|
||||
mixed_instances_policy = {}
|
||||
user_data = <<-EOT
|
||||
#!/bin/bash
|
||||
cat <<'EOF' >> /etc/ecs/ecs.config
|
||||
ECS_CLUSTER=${local.name}
|
||||
ECS_LOGLEVEL=debug
|
||||
ECS_CONTAINER_INSTANCE_TAGS=${jsonencode(local.tags)}
|
||||
ECS_ENABLE_TASK_IAM_ROLE=true
|
||||
EOF
|
||||
EOT
|
||||
}
|
||||
}
|
||||
|
||||
name = "${local.name}-${each.key}"
|
||||
|
||||
image_id = jsondecode(data.aws_ssm_parameter.ecs_optimized_ami.value)["image_id"]
|
||||
instance_type = each.value.instance_type
|
||||
|
||||
security_groups = [module.autoscaling_sg.security_group_id]
|
||||
user_data = base64encode(each.value.user_data)
|
||||
ignore_desired_capacity_changes = true
|
||||
|
||||
create_iam_instance_profile = true
|
||||
iam_role_name = local.name
|
||||
iam_role_description = "ECS role for ${local.name}"
|
||||
iam_role_policies = {
|
||||
AmazonEC2ContainerServiceforEC2Role = "arn:aws:iam::aws:policy/service-role/AmazonEC2ContainerServiceforEC2Role"
|
||||
AmazonSSMManagedInstanceCore = "arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore"
|
||||
}
|
||||
|
||||
vpc_zone_identifier = module.vpc.private_subnets
|
||||
health_check_type = "EC2"
|
||||
min_size = 1
|
||||
max_size = 5
|
||||
desired_capacity = 2
|
||||
|
||||
# https://github.com/hashicorp/terraform-provider-aws/issues/12582
|
||||
autoscaling_group_tags = {
|
||||
AmazonECSManaged = true
|
||||
}
|
||||
|
||||
# Required for managed_termination_protection = "ENABLED"
|
||||
protect_from_scale_in = true
|
||||
|
||||
# Spot instances
|
||||
use_mixed_instances_policy = each.value.use_mixed_instances_policy
|
||||
mixed_instances_policy = each.value.mixed_instances_policy
|
||||
|
||||
metadata_options = {
|
||||
http_tokens = "required"
|
||||
}
|
||||
|
||||
tags = local.tags
|
||||
}
|
||||
|
||||
module "autoscaling_sg" {
|
||||
source = "terraform-aws-modules/security-group/aws"
|
||||
version = "~> 5.0"
|
||||
|
||||
name = local.name
|
||||
description = "Autoscaling group security group"
|
||||
vpc_id = module.vpc.vpc_id
|
||||
|
||||
computed_ingress_with_source_security_group_id = [
|
||||
{
|
||||
rule = "http-80-tcp"
|
||||
source_security_group_id = module.alb_sg.security_group_id
|
||||
}
|
||||
]
|
||||
number_of_computed_ingress_with_source_security_group_id = 1
|
||||
|
||||
tags = local.tags
|
||||
}
|
||||
|
||||
module "vpc" {
|
||||
source = "terraform-aws-modules/vpc/aws"
|
||||
version = "~> 5.0"
|
||||
|
||||
name = local.name
|
||||
cidr = local.vpc_cidr
|
||||
|
||||
azs = local.azs
|
||||
private_subnets = [for k, v in local.azs : cidrsubnet(local.vpc_cidr, 4, k)]
|
||||
public_subnets = [for k, v in local.azs : cidrsubnet(local.vpc_cidr, 8, k + 48)]
|
||||
|
||||
public_dedicated_network_acl = true
|
||||
public_inbound_acl_rules = local.network_acls["public_inbound"]
|
||||
public_outbound_acl_rules = local.network_acls["public_outbound"]
|
||||
private_dedicated_network_acl = true
|
||||
private_inbound_acl_rules = local.network_acls["public_inbound"]
|
||||
private_outbound_acl_rules = local.network_acls["public_outbound"]
|
||||
|
||||
manage_default_network_acl = true
|
||||
enable_nat_gateway = true
|
||||
single_nat_gateway = true
|
||||
|
||||
tags = local.tags
|
||||
}
|
||||
|
||||
data "aws_ssm_parameter" "ecs_optimized_ami" {
|
||||
name = "/aws/service/ecs/optimized-ami/amazon-linux-2/recommended"
|
||||
}
|
||||
|
||||
module "alb_sg" {
|
||||
source = "terraform-aws-modules/security-group/aws"
|
||||
version = "~> 5.0"
|
||||
|
||||
name = "${local.name}-service"
|
||||
description = "Service security group"
|
||||
vpc_id = module.vpc.vpc_id
|
||||
|
||||
ingress_rules = ["http-80-tcp"]
|
||||
ingress_cidr_blocks = ["10.0.0.0/16"]
|
||||
egress_cidr_blocks = module.vpc.private_subnets_cidr_blocks
|
||||
|
||||
tags = local.tags
|
||||
}
|
||||
|
||||
module "ecs_monitoring" {
|
||||
source = "../../modules/ecs-monitoring"
|
||||
aws_ecs_cluster_name = module.ecs_cluster.cluster_name
|
||||
task_role_arn = module.ecs_cluster.task_exec_iam_role_arn
|
||||
execution_role_arn = module.ecs_cluster.task_exec_iam_role_arn
|
||||
|
||||
depends_on = [
|
||||
module.ecs_cluster
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
terraform {
|
||||
required_version = ">= 1.0"
|
||||
|
||||
required_providers {
|
||||
aws = {
|
||||
source = "hashicorp/aws"
|
||||
version = ">= 4.55"
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user