Files
Venkat Penmetsa d7daeb8c22 EKS Cross Account Observability using central AMP (#213)
* Added example for multi-cluster eks-monitoring and made changes to eks-monitoring module to allow cross-cluster IRSA

* Updated eks-monitoring module's README to add the variable description

* Hard-coded grafana license type in eks-cross-cluster-with-amp/main.tf

* Added README page for eks-cross-account-with-central-amp

* Extracted out the eks/amg creation and modified it to use existing resources

* Update README.md to add multiaccount dashboard png

* Updated README.md and multiaccount.md to add eks multiaccount png

* Updated eks-cross-cluster-with-amp example to disable dashboard creation for cluster 2

* Pre commit changed committed

* Fixed cross-account-observability docs and README.md and added variable for amp_workpace_alias

* Removed extra spacing in multiaccount.md and added precommit suggested changes

* Modified cross-account-observability example to change cross-account-amp-role to snake_case

* Capitalized Terraform string in multiaccount.md and converted iam-role-attach to snake_case

---------

Co-authored-by: Rodrigue Koffi <bonclay7@users.noreply.github.com>
2023-09-01 12:55:44 -04:00

96 lines
3.0 KiB
Terraform

###### AWS Providers ######
provider "aws" {
region = var.cluster_one.region
alias = "eks_cluster_one"
assume_role {
role_arn = var.cluster_one.tf_role
}
}
provider "aws" {
region = var.cluster_two.region
alias = "eks_cluster_two"
assume_role {
role_arn = var.cluster_two.tf_role
}
}
provider "aws" {
region = var.monitoring.region
alias = "central_monitoring"
assume_role {
role_arn = var.monitoring.tf_role
}
}
###### Helm Providers ######
provider "helm" {
alias = "eks_cluster_one"
kubernetes {
host = data.aws_eks_cluster.eks_one.endpoint
cluster_ca_certificate = base64decode(data.aws_eks_cluster.eks_one.certificate_authority[0].data)
exec {
api_version = "client.authentication.k8s.io/v1beta1"
args = ["eks", "get-token", "--role-arn", var.cluster_one.tf_role, "--cluster-name", var.cluster_one.name]
command = "aws"
}
}
}
provider "helm" {
alias = "eks_cluster_two"
kubernetes {
host = data.aws_eks_cluster.eks_two.endpoint
cluster_ca_certificate = base64decode(data.aws_eks_cluster.eks_two.certificate_authority[0].data)
exec {
api_version = "client.authentication.k8s.io/v1beta1"
args = ["eks", "get-token", "--role-arn", var.cluster_two.tf_role, "--cluster-name", var.cluster_two.name]
command = "aws"
}
}
}
###### Kubernetes Providers ######
provider "kubernetes" {
alias = "eks_cluster_one"
host = data.aws_eks_cluster.eks_one.endpoint
cluster_ca_certificate = base64decode(data.aws_eks_cluster.eks_one.certificate_authority[0].data)
exec {
api_version = "client.authentication.k8s.io/v1beta1"
args = ["eks", "get-token", "--role-arn", var.cluster_one.tf_role, "--cluster-name", var.cluster_one.name]
command = "aws"
}
}
provider "kubernetes" {
alias = "eks_cluster_two"
host = data.aws_eks_cluster.eks_two.endpoint
cluster_ca_certificate = base64decode(data.aws_eks_cluster.eks_two.certificate_authority[0].data)
exec {
api_version = "client.authentication.k8s.io/v1beta1"
args = ["eks", "get-token", "--role-arn", var.cluster_two.tf_role, "--cluster-name", var.cluster_two.name]
command = "aws"
}
}
provider "kubectl" {
alias = "eks_cluster_one"
apply_retry_count = 30
host = data.aws_eks_cluster.eks_one.endpoint
cluster_ca_certificate = base64decode(data.aws_eks_cluster.eks_one.certificate_authority[0].data)
load_config_file = false
token = data.aws_eks_cluster_auth.eks_one.token
}
provider "kubectl" {
alias = "eks_cluster_two"
apply_retry_count = 30
host = data.aws_eks_cluster.eks_two.endpoint
cluster_ca_certificate = base64decode(data.aws_eks_cluster.eks_two.certificate_authority[0].data)
load_config_file = false
token = data.aws_eks_cluster_auth.eks_two.token
}