mirror of
https://github.com/storytold/terraform-aws-observability-accelerator.git
synced 2026-10-09 00:09:43 +00:00
Drop unused module
This commit is contained in:
@@ -1,69 +0,0 @@
|
||||
# Cert Manager Deployment Guide
|
||||
|
||||
## Introduction
|
||||
|
||||
Cert Manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates.
|
||||
|
||||
## Helm Chart
|
||||
|
||||
### Instructions to use the Helm Chart
|
||||
|
||||
See the [cert-manager documentation](https://cert-manager.io/docs/installation/helm/).
|
||||
|
||||
# Docker Image for Cert Manager
|
||||
|
||||
cert-manager docker image is available at this repo:
|
||||
|
||||
<https://quay.io/repository/jetstack/cert-manager-controller?tag=latest&tab=tags>
|
||||
|
||||
<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
|
||||
## Requirements
|
||||
|
||||
| Name | Version |
|
||||
|------|---------|
|
||||
| <a name="requirement_terraform"></a> [terraform](#requirement\_terraform) | >= 1.0.0 |
|
||||
| <a name="requirement_aws"></a> [aws](#requirement\_aws) | >= 4.10 |
|
||||
| <a name="requirement_helm"></a> [helm](#requirement\_helm) | >= 2.4.1 |
|
||||
|
||||
## Providers
|
||||
|
||||
| Name | Version |
|
||||
|------|---------|
|
||||
| <a name="provider_aws"></a> [aws](#provider\_aws) | >= 4.10 |
|
||||
| <a name="provider_helm"></a> [helm](#provider\_helm) | >= 2.4.1 |
|
||||
|
||||
## Modules
|
||||
|
||||
| Name | Source | Version |
|
||||
|------|--------|---------|
|
||||
| <a name="module_helm_addon"></a> [helm\_addon](#module\_helm\_addon) | ../helm-addon | n/a |
|
||||
|
||||
## Resources
|
||||
|
||||
| Name | Type |
|
||||
|------|------|
|
||||
| [aws_iam_policy.cert_manager](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_policy) | resource |
|
||||
| [helm_release.cert_manager_ca](https://registry.terraform.io/providers/hashicorp/helm/latest/docs/resources/release) | resource |
|
||||
| [helm_release.cert_manager_letsencrypt](https://registry.terraform.io/providers/hashicorp/helm/latest/docs/resources/release) | resource |
|
||||
| [aws_iam_policy_document.cert_manager_iam_policy_document](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/iam_policy_document) | data source |
|
||||
| [aws_route53_zone.selected](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/data-sources/route53_zone) | data source |
|
||||
|
||||
## Inputs
|
||||
|
||||
| Name | Description | Type | Default | Required |
|
||||
|------|-------------|------|---------|:--------:|
|
||||
| <a name="input_addon_context"></a> [addon\_context](#input\_addon\_context) | Input configuration for the addon | <pre>object({<br> aws_caller_identity_account_id = string<br> aws_caller_identity_arn = string<br> aws_eks_cluster_endpoint = string<br> aws_partition_id = string<br> aws_region_name = string<br> eks_cluster_id = string<br> eks_oidc_issuer_url = string<br> eks_oidc_provider_arn = string<br> tags = map(string)<br> irsa_iam_role_path = string<br> })</pre> | n/a | yes |
|
||||
| <a name="input_domain_names"></a> [domain\_names](#input\_domain\_names) | Domain names of the Route53 hosted zone to use with cert-manager. | `list(string)` | `[]` | no |
|
||||
| <a name="input_helm_config"></a> [helm\_config](#input\_helm\_config) | cert-manager Helm chart configuration | `any` | `{}` | no |
|
||||
| <a name="input_install_letsencrypt_issuers"></a> [install\_letsencrypt\_issuers](#input\_install\_letsencrypt\_issuers) | Install Let's Encrypt Cluster Issuers. | `bool` | `true` | no |
|
||||
| <a name="input_irsa_policies"></a> [irsa\_policies](#input\_irsa\_policies) | Additional IAM policies used for the add-on service account. | `list(string)` | `[]` | no |
|
||||
| <a name="input_letsencrypt_email"></a> [letsencrypt\_email](#input\_letsencrypt\_email) | Email address for expiration emails from Let's Encrypt. | `string` | `""` | no |
|
||||
| <a name="input_manage_via_gitops"></a> [manage\_via\_gitops](#input\_manage\_via\_gitops) | Determines if the add-on should be managed via GitOps. | `bool` | `false` | no |
|
||||
|
||||
## Outputs
|
||||
|
||||
| Name | Description |
|
||||
|------|-------------|
|
||||
| <a name="output_argocd_gitops_config"></a> [argocd\_gitops\_config](#output\_argocd\_gitops\_config) | Configuration used for managing the add-on with ArgoCD |
|
||||
| <a name="output_eks_cluster_id"></a> [eks\_cluster\_id](#output\_eks\_cluster\_id) | Current AWS EKS Cluster ID |
|
||||
<!-- END OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
|
||||
@@ -1,6 +0,0 @@
|
||||
apiVersion: v2
|
||||
name: cert-manager-ca
|
||||
description: A Helm chart to install a Cert Manager CA
|
||||
type: application
|
||||
version: 0.2.0
|
||||
appVersion: v0.1.0
|
||||
@@ -1,21 +0,0 @@
|
||||
{{- range .Values.clusterIssuers }}
|
||||
{{- if eq .type "CA" }}
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: {{ .name }}
|
||||
namespace: {{ $.Release.Namespace }}
|
||||
spec:
|
||||
isCA: true
|
||||
commonName: {{ .name }}
|
||||
secretName: {{ .secretName }}
|
||||
{{- with .privateKey }}
|
||||
privateKey:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with .issuer }}
|
||||
issuerRef:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -1,14 +0,0 @@
|
||||
{{- range .Values.clusterIssuers }}
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: {{ .name }}
|
||||
spec:
|
||||
{{- if eq .type "selfSigned" }}
|
||||
selfSigned: {}
|
||||
{{- else if eq .type "CA" }}
|
||||
ca:
|
||||
secretName: {{ .secretName }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -1,13 +0,0 @@
|
||||
clusterIssuers:
|
||||
- name: cert-manager-selfsigned
|
||||
type: selfSigned
|
||||
- name: cert-manager-ca
|
||||
type: CA
|
||||
secretName: cert-manager-ca-root
|
||||
privateKey:
|
||||
algorithm: ECDSA
|
||||
size: 256
|
||||
issuer:
|
||||
name: cert-manager-selfsigned
|
||||
kind: ClusterIssuer
|
||||
group: cert-manager.io
|
||||
@@ -1,6 +0,0 @@
|
||||
apiVersion: v2
|
||||
name: cert-manager-letsencrypt
|
||||
description: Cert Manager Cluster Issuers for Let's Encrypt certificates with DNS01 protocol
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: v0.1.0
|
||||
-27
@@ -1,27 +0,0 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: {{ .Release.Name }}-production-route53
|
||||
labels:
|
||||
ca: letsencrypt
|
||||
environment: production
|
||||
solver: dns01
|
||||
provider: route53
|
||||
spec:
|
||||
acme:
|
||||
{{- if .Values.email }}
|
||||
email: {{ .Values.email }}
|
||||
{{- end }}
|
||||
server: https://acme-v02.api.letsencrypt.org/directory
|
||||
preferredChain: ISRG Root X1
|
||||
privateKeySecretRef:
|
||||
name: {{ .Release.Name }}-production-route53
|
||||
solvers:
|
||||
- dns01:
|
||||
route53:
|
||||
region: {{ .Values.region | default "global" }}
|
||||
{{- if .Values.dnsZones }}
|
||||
selector:
|
||||
dnsZones:
|
||||
{{- .Values.dnsZones | toYaml | nindent 12 }}
|
||||
{{- end }}
|
||||
-27
@@ -1,27 +0,0 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: {{ .Release.Name }}-staging-route53
|
||||
labels:
|
||||
ca: letsencrypt
|
||||
environment: staging
|
||||
solver: dns01
|
||||
provider: route53
|
||||
spec:
|
||||
acme:
|
||||
{{- if .Values.email }}
|
||||
email: {{ .Values.email }}
|
||||
{{- end }}
|
||||
server: https://acme-staging-v02.api.letsencrypt.org/directory
|
||||
preferredChain: ISRG Root X1
|
||||
privateKeySecretRef:
|
||||
name: {{ .Release.Name }}-staging-route53
|
||||
solvers:
|
||||
- dns01:
|
||||
route53:
|
||||
region: {{ .Values.region | default "global" }}
|
||||
{{- if .Values.dnsZones }}
|
||||
selector:
|
||||
dnsZones:
|
||||
{{- .Values.dnsZones | toYaml | nindent 12 }}
|
||||
{{- end }}
|
||||
@@ -1,6 +0,0 @@
|
||||
# email: user@example.com
|
||||
|
||||
# region: global
|
||||
|
||||
# dnsZones:
|
||||
# - domain.name
|
||||
@@ -1,32 +0,0 @@
|
||||
data "aws_route53_zone" "selected" {
|
||||
for_each = toset(var.domain_names)
|
||||
|
||||
name = each.key
|
||||
}
|
||||
|
||||
data "aws_iam_policy_document" "cert_manager_iam_policy_document" {
|
||||
statement {
|
||||
effect = "Allow"
|
||||
resources = ["arn:${var.addon_context.aws_partition_id}:route53:::change/*"]
|
||||
actions = ["route53:GetChange"]
|
||||
}
|
||||
|
||||
dynamic "statement" {
|
||||
for_each = { for k, v in toset(var.domain_names) : k => data.aws_route53_zone.selected[k].arn }
|
||||
|
||||
content {
|
||||
effect = "Allow"
|
||||
resources = [statement.value]
|
||||
actions = [
|
||||
"route53:ChangeresourceRecordSets",
|
||||
"route53:ListresourceRecordSets"
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
statement {
|
||||
effect = "Allow"
|
||||
resources = ["*"]
|
||||
actions = ["route53:ListHostedZonesByName"]
|
||||
}
|
||||
}
|
||||
@@ -1,45 +0,0 @@
|
||||
locals {
|
||||
name = "cert-manager"
|
||||
service_account_name = "cert-manager" # AWS PrivateCA is expecting the service account name as `cert-manager`
|
||||
|
||||
default_helm_config = {
|
||||
name = local.name
|
||||
chart = local.name
|
||||
repository = "https://charts.jetstack.io"
|
||||
version = "v1.8.0"
|
||||
namespace = local.name
|
||||
description = "Cert Manager Add-on"
|
||||
values = local.default_helm_values
|
||||
}
|
||||
|
||||
default_helm_values = [templatefile("${path.module}/values.yaml", {})]
|
||||
|
||||
helm_config = merge(
|
||||
local.default_helm_config,
|
||||
var.helm_config
|
||||
)
|
||||
|
||||
set_values = [
|
||||
{
|
||||
name = "serviceAccount.name"
|
||||
value = local.service_account_name
|
||||
},
|
||||
{
|
||||
name = "serviceAccount.create"
|
||||
value = false
|
||||
}
|
||||
]
|
||||
|
||||
irsa_config = {
|
||||
kubernetes_namespace = local.helm_config["namespace"]
|
||||
kubernetes_service_account = local.service_account_name
|
||||
create_kubernetes_namespace = try(local.helm_config["create_namespace"], true)
|
||||
create_kubernetes_service_account = true
|
||||
irsa_iam_policies = concat([aws_iam_policy.cert_manager.arn], var.irsa_policies)
|
||||
}
|
||||
|
||||
argocd_gitops_config = {
|
||||
enable = true
|
||||
serviceAccountName = local.service_account_name
|
||||
}
|
||||
}
|
||||
@@ -1,47 +0,0 @@
|
||||
module "helm_addon" {
|
||||
source = "../helm-addon"
|
||||
manage_via_gitops = var.manage_via_gitops
|
||||
set_values = local.set_values
|
||||
helm_config = local.helm_config
|
||||
irsa_config = local.irsa_config
|
||||
addon_context = var.addon_context
|
||||
}
|
||||
|
||||
resource "helm_release" "cert_manager_ca" {
|
||||
count = var.manage_via_gitops ? 0 : 1
|
||||
name = "cert-manager-ca"
|
||||
chart = "${path.module}/cert-manager-ca"
|
||||
version = "0.2.0"
|
||||
namespace = local.helm_config["namespace"]
|
||||
|
||||
depends_on = [module.helm_addon]
|
||||
}
|
||||
|
||||
resource "helm_release" "cert_manager_letsencrypt" {
|
||||
count = var.manage_via_gitops || !var.install_letsencrypt_issuers ? 0 : 1
|
||||
name = "cert-manager-letsencrypt"
|
||||
chart = "${path.module}/cert-manager-letsencrypt"
|
||||
version = "0.1.0"
|
||||
namespace = local.helm_config["namespace"]
|
||||
|
||||
set {
|
||||
name = "email"
|
||||
value = var.letsencrypt_email
|
||||
type = "string"
|
||||
}
|
||||
|
||||
set {
|
||||
name = "dnsZones"
|
||||
value = "{${join(",", toset(var.domain_names))}}"
|
||||
type = "string"
|
||||
}
|
||||
|
||||
depends_on = [module.helm_addon]
|
||||
}
|
||||
|
||||
resource "aws_iam_policy" "cert_manager" {
|
||||
description = "cert-manager IAM policy."
|
||||
name = "${var.addon_context.eks_cluster_id}-${local.helm_config["name"]}-irsa"
|
||||
path = var.addon_context.irsa_iam_role_path
|
||||
policy = data.aws_iam_policy_document.cert_manager_iam_policy_document.json
|
||||
}
|
||||
@@ -1,9 +0,0 @@
|
||||
output "argocd_gitops_config" {
|
||||
description = "Configuration used for managing the add-on with ArgoCD"
|
||||
value = var.manage_via_gitops ? local.argocd_gitops_config : null
|
||||
}
|
||||
|
||||
output "eks_cluster_id" {
|
||||
description = "Current AWS EKS Cluster ID"
|
||||
value = var.addon_context.eks_cluster_id
|
||||
}
|
||||
@@ -1,8 +0,0 @@
|
||||
extraArgs:
|
||||
- --enable-certificate-owner-ref=true
|
||||
|
||||
installCRDs: true
|
||||
|
||||
securityContext:
|
||||
enabled: true
|
||||
fsGroup: 1001
|
||||
@@ -1,51 +0,0 @@
|
||||
variable "helm_config" {
|
||||
description = "cert-manager Helm chart configuration"
|
||||
type = any
|
||||
default = {}
|
||||
}
|
||||
|
||||
variable "manage_via_gitops" {
|
||||
description = "Determines if the add-on should be managed via GitOps."
|
||||
type = bool
|
||||
default = false
|
||||
}
|
||||
|
||||
variable "irsa_policies" {
|
||||
description = "Additional IAM policies used for the add-on service account."
|
||||
type = list(string)
|
||||
default = []
|
||||
}
|
||||
|
||||
variable "domain_names" {
|
||||
description = "Domain names of the Route53 hosted zone to use with cert-manager."
|
||||
type = list(string)
|
||||
default = []
|
||||
}
|
||||
|
||||
variable "install_letsencrypt_issuers" {
|
||||
description = "Install Let's Encrypt Cluster Issuers."
|
||||
type = bool
|
||||
default = true
|
||||
}
|
||||
|
||||
variable "letsencrypt_email" {
|
||||
description = "Email address for expiration emails from Let's Encrypt."
|
||||
type = string
|
||||
default = ""
|
||||
}
|
||||
|
||||
variable "addon_context" {
|
||||
description = "Input configuration for the addon"
|
||||
type = object({
|
||||
aws_caller_identity_account_id = string
|
||||
aws_caller_identity_arn = string
|
||||
aws_eks_cluster_endpoint = string
|
||||
aws_partition_id = string
|
||||
aws_region_name = string
|
||||
eks_cluster_id = string
|
||||
eks_oidc_issuer_url = string
|
||||
eks_oidc_provider_arn = string
|
||||
tags = map(string)
|
||||
irsa_iam_role_path = string
|
||||
})
|
||||
}
|
||||
@@ -1,14 +0,0 @@
|
||||
terraform {
|
||||
required_version = ">= 1.0.0"
|
||||
|
||||
required_providers {
|
||||
aws = {
|
||||
source = "hashicorp/aws"
|
||||
version = ">= 4.10"
|
||||
}
|
||||
helm = {
|
||||
source = "hashicorp/helm"
|
||||
version = ">= 2.4.1"
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user