diff --git a/.github/workflows/linkcheck.json b/.github/workflows/linkcheck.json new file mode 100644 index 0000000..dba668f --- /dev/null +++ b/.github/workflows/linkcheck.json @@ -0,0 +1,27 @@ +{ + "timeout": "5s", + "retryOn429": true, + "retryCount": 5, + "fallbackRetryDelay": "30s", + "aliveStatusCodes": [200, 206], + "httpHeaders": [ + { + "urls": ["https://help.github.com/"], + "headers": { + "Accept-Encoding": "zstd, br, gzip, deflate" + } + } + ], + "ignorePatterns": [ + { + "pattern": [ + "localhost" + ] + }, + { + "pattern": [ + "127.0.0.1" + ] + } + ] +} diff --git a/.github/workflows/markdown-link-check.yaml b/.github/workflows/markdown-link-check.yaml new file mode 100644 index 0000000..ddaec1e --- /dev/null +++ b/.github/workflows/markdown-link-check.yaml @@ -0,0 +1,29 @@ +name: Check Markdown links + +on: + push: + branches: + - main + paths: + - "**/*.md" + + pull_request: + branches: + - main + paths: + - "**/*.md" + +jobs: + markdown-link-check: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v3 + - uses: actions/setup-node@v3 + with: + node-version: '16.x' + - name: install markdown-link-check + run: npm install -g markdown-link-check@3.10.2 + - name: markdown-link-check version + run: npm list -g markdown-link-check + - name: Run markdown-link-check on MD files + run: find docs -name "*.md" | xargs -n 1 markdown-link-check -q -c .github/workflows/linkcheck.json diff --git a/.github/workflows/pre-commit.yaml b/.github/workflows/pre-commit.yaml new file mode 100644 index 0000000..3166e08 --- /dev/null +++ b/.github/workflows/pre-commit.yaml @@ -0,0 +1,134 @@ +name: pre-commit + +on: + pull_request: + branches: + - main + paths: + - '**.tf' + - '**.yml' + - '**.yaml' + +env: + TERRAFORM_DOCS_VERSION: v0.16.0 + TFSEC_VERSION: v1.22.0 + TF_PLUGIN_CACHE_DIR: ${{ github.workspace }}/.terraform.d/plugin-cache + TFLINT_VERSION: v0.38.1 + +concurrency: + group: '${{ github.workflow }} @ ${{ github.event.pull_request.head.label || github.head_ref || github.ref }}' + cancel-in-progress: true + +jobs: + collectInputs: + name: Collect workflow inputs + runs-on: ubuntu-latest + outputs: + directories: ${{ steps.dirs.outputs.directories }} + steps: + - name: Checkout + uses: actions/checkout@v3 + + - name: Get root directories + id: dirs + uses: clowdhaus/terraform-composite-actions/directories@v1.4.1 + + preCommitMinVersions: + name: Min TF pre-commit + needs: collectInputs + runs-on: ubuntu-latest + strategy: + matrix: + directory: ${{ fromJson(needs.collectInputs.outputs.directories) }} + steps: + - name: Checkout + uses: actions/checkout@v3 + + - uses: dorny/paths-filter@v2 + id: changes + with: + # We only need to check Terraform files for the current directory + # because the `preCommitMaxVersion` job will run the full, + # exhaustive checks (always) + filters: | + src: + - '${{ matrix.directory }}/*.tf' + + - name: Config Terraform plugin cache + if: steps.changes.outputs.src== 'true' + run: mkdir --parents ${{ env.TERRAFORM_DOCS_VERSION }} + + - name: Cache Terraform + uses: actions/cache@v3 + if: steps.changes.outputs.src== 'true' + with: + path: ${{ env.TERRAFORM_DOCS_VERSION }} + key: ${{ runner.os }}-terraform-${{ hashFiles('**/.terraform.lock.hcl') }} + restore-keys: ${{ runner.os }}-terraform- + + - name: Terraform min/max versions + uses: clowdhaus/terraform-min-max@v1.0.7 + if: steps.changes.outputs.src== 'true' + id: minMax + with: + directory: ${{ matrix.directory }} + + - name: Pre-commit Terraform ${{ steps.minMax.outputs.minVersion }} + uses: clowdhaus/terraform-composite-actions/pre-commit@v1.6.0 + # Run only validate pre-commit check on min version supported + if: ${{ matrix.directory != '.' && steps.changes.outputs.src== 'true' }} + with: + terraform-version: ${{ steps.minMax.outputs.minVersion }} + args: 'terraform_validate --color=always --show-diff-on-failure --files ${{ matrix.directory }}/*' + + - name: Pre-commit Terraform ${{ steps.minMax.outputs.minVersion }} + uses: clowdhaus/terraform-composite-actions/pre-commit@v1.6.0 + # Run only validate pre-commit check on min version supported + if: ${{ matrix.directory == '.' && steps.changes.outputs.src== 'true' }} + with: + terraform-version: ${{ steps.minMax.outputs.minVersion }} + args: 'terraform_validate --color=always --show-diff-on-failure --files $(ls *.tf)' + + preCommitMaxVersion: + name: Max TF pre-commit + runs-on: ubuntu-latest + needs: collectInputs + steps: + - name: Checkout + uses: actions/checkout@v3 + + - uses: dorny/paths-filter@v2 + id: changes + with: + filters: | + src: + - '**/*.tf' + + - name: Config Terraform plugin cache + if: steps.changes.outputs.src== 'true' + run: mkdir --parents ${{ env.TERRAFORM_DOCS_VERSION }} + + - name: Cache Terraform + uses: actions/cache@v3 + if: steps.changes.outputs.src== 'true' + with: + path: ${{ env.TF_PLUGIN_CACHE_DIR }} + key: ${{ runner.os }}-terraform-${{ hashFiles('**/.terraform.lock.hcl') }} + restore-keys: ${{ runner.os }}-terraform- + + - name: Install tfsec + if: steps.changes.outputs.src== 'true' + run: curl -sSLo ./tfsec https://github.com/aquasecurity/tfsec/releases/download/${{ env.TFSEC_VERSION }}/tfsec-$(uname)-amd64 && chmod +x tfsec && sudo mv tfsec /usr/bin/ + + - name: Terraform min/max versions + id: minMax + uses: clowdhaus/terraform-min-max@v1.0.7 + if: steps.changes.outputs.src== 'true' + + - name: Pre-commit Terraform ${{ steps.minMax.outputs.maxVersion }} + uses: clowdhaus/terraform-composite-actions/pre-commit@v1.6.0 + if: steps.changes.outputs.src== 'true' + with: + terraform-version: ${{ steps.minMax.outputs.maxVersion }} + terraform-docs-version: ${{ env.TERRAFORM_DOCS_VERSION }} + tflint-version: ${{ env.TFLINT_VERSION }} diff --git a/README.md b/README.md index 30d2bc6..2d39a4e 100644 --- a/README.md +++ b/README.md @@ -1,5 +1,7 @@ # AWS Observability Accelerator for Terraform +[![pre-commit](https://github.com/aws-observability/terraform-aws-observability-accelerator/actions/workflows/pre-commit.yaml/badge.svg)](https://github.com/aws-observability/terraform-aws-observability-accelerator/actions/workflows/pre-commit.yaml) + Welcome to the AWS Observability Accelerator for Terraform! The AWS Observability accelerator for Terraform is a set of modules to help you diff --git a/examples/eks-cluster-with-vpc/versions.tf b/examples/eks-cluster-with-vpc/versions.tf index 7bec64c..5c7948b 100644 --- a/examples/eks-cluster-with-vpc/versions.tf +++ b/examples/eks-cluster-with-vpc/versions.tf @@ -23,4 +23,11 @@ terraform { version = ">= 1.25.0" } } + + # ## Used for end-to-end testing on project; update to suit your needs + # backend "s3" { + # bucket = "observability-accelerator-terraform-states" + # region = "us-west-2" + # key = "e2e/eks-cluster-with-vpc/terraform.tfstate" + # } } diff --git a/examples/existing-cluster-with-base-and-infra/versions.tf b/examples/existing-cluster-with-base-and-infra/versions.tf index 3a4f278..9a03294 100644 --- a/examples/existing-cluster-with-base-and-infra/versions.tf +++ b/examples/existing-cluster-with-base-and-infra/versions.tf @@ -22,4 +22,12 @@ terraform { version = ">= 1.25.0" } } + + # ## Used for end-to-end testing on project; update to suit your needs + # backend "s3" { + # bucket = "observability-accelerator-terraform-states" + # region = "us-west-2" + # key = "e2e/existing-cluster-with-base-and-infra/terraform.tfstate" + # } + } diff --git a/modules/workloads/haproxy/main.tf b/modules/workloads/haproxy/main.tf deleted file mode 100644 index b81151e..0000000 --- a/modules/workloads/haproxy/main.tf +++ /dev/null @@ -1,171 +0,0 @@ - -#--------------------------------------------------------------- -# Observability Resources -#--------------------------------------------------------------- - -module "managed_grafana" { - source = "terraform-aws-modules/managed-service-grafana/aws" - version = "~> 1.3" - - # Workspace - name = local.name - stack_set_name = local.name - data_sources = ["PROMETHEUS"] - associate_license = false - - # # Role associations - # Pending https://github.com/hashicorp/terraform-provider-aws/issues/24166 - # role_associations = { - # "ADMIN" = { - # "group_ids" = [] - # "user_ids" = [] - # } - # "EDITOR" = { - # "group_ids" = [] - # "user_ids" = [] - # } - # } - - tags = local.tags -} - -resource "grafana_data_source" "prometheus" { - type = "prometheus" - name = "amp" - is_default = true - url = module.managed_prometheus.workspace_prometheus_endpoint - - json_data { - http_method = "GET" - sigv4_auth = true - sigv4_auth_type = "workspace-iam-role" - sigv4_region = local.region - } -} - -resource "grafana_folder" "this" { - title = "Observability" -} - -resource "grafana_dashboard" "this" { - folder = grafana_folder.this.id - config_json = file("${path.module}/dashboards/default.json") -} - -module "managed_prometheus" { - source = "terraform-aws-modules/managed-service-prometheus/aws" - version = "~> 2.1" - - workspace_alias = local.name - - alert_manager_definition = <<-EOT - alertmanager_config: | - route: - receiver: 'default' - receivers: - - name: 'default' - EOT - - rule_group_namespaces = { - haproxy = { - name = "haproxy_rules" - data = <<-EOT - groups: - - name: obsa-haproxy-down-alert - rules: - - alert: HA_proxy_down - expr: haproxy_up == 0 - for: 0m - labels: - severity: critical - annotations: - summary: HAProxy down (instance {{ $labels.instance }}) - description: "HAProxy down\n VALUE = {{ $value }}\n LABELS = {{ $labels }}" - - name: obsa-haproxy-http4xx-error-alert - rules: - - alert: Ha_proxy_High_Http4xx_ErrorRate_Backend - expr: sum by (backend) (rate(haproxy_server_http_responses_total{code="4xx"}[1m])) / sum by (backend) (rate(haproxy_server_http_responses_total[1m]) * 100) > 5 - for: 1m - labels: - severity: critical - annotations: - summary: HAProxy high HTTP 4xx error rate backend (instance {{ $labels.instance }}) - description: "Too many HTTP requests with status 4xx (> 5%) on backend {{ $labels.fqdn }}/{{ $labels.backend }}\n VALUE = {{ $value }}\n LABELS = {{ $labels }}" - - name: obsa-haproxy-http5xx-error-alert - rules: - - alert: Ha_proxy_High_Http5xx_ErrorRate_Backend - expr: sum by (backend) (rate(haproxy_server_http_responses_total{code="5xx"}[1m])) / sum by (backend) (rate(haproxy_server_http_responses_total[1m]) * 100) > 5 - for: 1m - labels: - severity: critical - annotations: - summary: HAProxy high HTTP 5xx error rate backend (instance {{ $labels.instance }}) - description: "Too many HTTP requests with status 5xx (> 5%) on backend {{ $labels.fqdn }}/{{ $labels.backend }}\n VALUE = {{ $value }}\n LABELS = {{ $labels }}" - - name: obsa-haproxy-Http4xx-ErrorRate-Server-alert - rules: - - alert: Ha_proxy_High_Http4xx_ErrorRate_Server - expr: sum by (server) (rate(haproxy_server_http_responses_total{code="4xx"}[1m])) / sum by (server) (rate(haproxy_server_http_responses_total[1m]) * 100) > 5 - for: 1m - labels: - severity: critical - annotations: - summary: HAProxy high HTTP 4xx error rate server (instance {{ $labels.instance }}) - description: "Too many HTTP requests with status 4xx (> 5%) on server {{ $labels.server }}\n VALUE = {{ $value }}\n LABELS = {{ $labels }}" - - name: obsa-haproxy-Http5xx-ErrorRate-Server-alert - rules: - - alert: Ha_proxy_High_Http5xx_ErrorRate_Server - expr: sum by (server) (rate(haproxy_server_http_responses_total{code="5xx"}[1m])) / sum by (server) (rate(haproxy_server_http_responses_total[1m]) * 100) > 5 - for: 1m - labels: - severity: critical - annotations: - summary: HAProxy high HTTP 5xx error rate server (instance {{ $labels.instance }}) - description: "Too many HTTP requests with status 5xx (> 5%) on server {{ $labels.server }}\n VALUE = {{ $value }}\n LABELS = {{ $labels }}" - EOT - } - } - - tags = local.tags -} - -#--------------------------------------------------------------- -# Sample Application -#--------------------------------------------------------------- - -# https://github.com/haproxy-ingress/charts/tree/master/haproxy-ingress -resource "helm_release" "haproxy_ingress" { - namespace = "haproxy-ingress" - create_namespace = true - - name = "haproxy-ingress" - repository = "https://haproxy-ingress.github.io/charts" - chart = "haproxy-ingress" - version = "0.13.7" - - set { - name = "defaultBackend.enabled" - value = true - } - - set { - name = "controller.stats.enabled" - value = true - } - - set { - name = "controller.metrics.enabled" - value = true - } - - set { - name = "controller.metrics.service.annotations.prometheus\\.io/port" - value = 9101 - type = "string" - } - - set { - name = "controller.metrics.service.annotations.prometheus\\.io/scrape" - value = true - type = "string" - } -}