EKS container insights (#204)

* adot-container-insight-tf-code by Rajat Omar

* Documentation and naming convention added

* PR review fixes

* PR CI pipeline fixes

* pr ci run fixes

* added the variables mentioned in ci build

* ci variable fixes

* changed the module name

---------

Co-authored-by: Omar <merajat@3c0630162a5a.ant.amazon.com>
This commit is contained in:
Rajat Omar
2023-08-09 21:53:54 +05:30
committed by GitHub
parent 4d88d16cb6
commit 97177eea04
15 changed files with 484 additions and 0 deletions
+78
View File
@@ -0,0 +1,78 @@
data "aws_partition" "current" {}
data "aws_caller_identity" "current" {}
data "aws_region" "current" {}
data "aws_eks_cluster" "eks_cluster" {
name = var.eks_cluster_id
}
data "aws_iam_policy" "irsa" {
arn = "arn:aws:iam::aws:policy/CloudWatchAgentServerPolicy"
}
locals {
name = "adot-exporter-for-eks-on-ec2"
service_account = try(var.helm_config.service_account, "${local.name}-sa")
set_values = [
{
name = "serviceAccount.name"
value = local.service_account
},
{
name = "serviceAccount.create"
value = false
}
]
# https://github.com/aws-observability/aws-otel-helm-charts/tree/main/charts/adot-exporter-for-eks-on-ec2
default_helm_config = {
name = local.name
chart = "adot-exporter-for-eks-on-ec2"
repository = "https://aws-observability.github.io/aws-otel-helm-charts"
version = var.adot_otel_helm_chart_verison
namespace = "amazon-metrics"
values = local.default_helm_values
description = "ADOT Helm Chart Deployment Configuration for Container Insights"
}
helm_config = merge(
local.default_helm_config,
var.helm_config
)
default_helm_values = [templatefile("${path.module}/values.yaml", {
aws_region = local.addon_context.aws_region_name
cluster_name = local.addon_context.eks_cluster_id
service_receivers = format("[\"%s\"]", var.service_receivers)
service_exporters = format("[\"%s\"]", var.service_exporters)
service_account = local.service_account
})]
irsa_config = {
kubernetes_namespace = local.helm_config["namespace"]
kubernetes_service_account = local.service_account
create_kubernetes_namespace = try(local.helm_config["create_namespace"], true)
create_kubernetes_service_account = true
create_service_account_secret_token = try(local.helm_config["create_service_account_secret_token"], false)
irsa_iam_policies = concat([data.aws_iam_policy.irsa.arn], var.irsa_policies)
}
eks_oidc_issuer_url = replace(data.aws_eks_cluster.eks_cluster.identity[0].oidc[0].issuer, "https://", "")
addon_context = {
aws_caller_identity_account_id = data.aws_caller_identity.current.account_id
aws_caller_identity_arn = data.aws_caller_identity.current.arn
aws_eks_cluster_endpoint = data.aws_eks_cluster.eks_cluster.endpoint
aws_partition_id = data.aws_partition.current.partition
aws_region_name = data.aws_region.current.name
eks_cluster_id = var.eks_cluster_id
eks_oidc_issuer_url = replace(data.aws_eks_cluster.eks_cluster.identity[0].oidc[0].issuer, "https://", "")
eks_oidc_provider_arn = "arn:${data.aws_partition.current.partition}:iam::${data.aws_caller_identity.current.account_id}:oidc-provider/${local.eks_oidc_issuer_url}"
tags = var.tags
irsa_iam_role_path = var.irsa_iam_role_path
irsa_iam_permissions_boundary = var.irsa_iam_permissions_boundary
}
}