* Update with doc site * Use full link * Fix dead links
4.2 KiB
Concepts
Prerequisites
All examples in this repository require the following tools installed
Minimum IAM Policy
To run the examples, you need a set of AWS IAM permissions. You can find an example of minimum permissions required in this file.
Note
: The policy resource is set as
*to allow all resources, this is not a recommended practice. You should restrict instead to the ARNs when applicable.
Terraform states and variables
By default, our examples are using local Terraform states. If you need your Terraform states to be saved remotely, on Amazon S3, visit the terraform remote states documentation.
For simplicity, we use Terraform supported environment variables.
You can also edit the terraform.tfvars files directly and deploy
with terraform apply -var-file=terraform.tfvars. Terraform tfvars file can be useful if
you need to track changes as part of a Git repository or CI/CD pipeline.
Note: When using
tfvarsfiles, always be careful to not store and commit any secrets (keys, passwords, ...)
Base module
The base module allows you to configure the AWS Observability services for your cluster and the AWS Distro for OpenTelemetry (ADOT) Operator as the signals collection mechanism.
Here is the minimum configuration to have a new Managed Grafana Workspace, Amazon Managed Service for Prometheus Workspace, ADOT Operator deployed for you and ready to receive your data.
module "eks_observability_accelerator" {
source = "aws-observability/terraform-aws-observability-accelerator"
aws_region = "eu-west-1"
eks_cluster_id = "my-eks-cluster"
}
You can optionally reuse existing Workspaces to dissociate their lifecycle from the Terraform state.
module "eks_observability_accelerator" {
source = "aws-observability/terraform-aws-observability-accelerator"
aws_region = "eu-west-1"
eks_cluster_id = "my-eks-cluster"
# prevents creation of a new Amazon Managed Prometheus workspace
enable_managed_prometheus = false
# reusing existing Amazon Managed Prometheus Workspace
managed_prometheus_workspace_id = "ws-abcd123..."
# prevents creation of a new Amazon Managed Grafana workspace
enable_managed_grafana = false
managed_grafana_workspace_id = "g-abcdef123"
grafana_api_key = var.grafana_api_key
}
View all the configuration options in the module's documentation
Workload modules
Workloads modules are focused Terraform modules provided in this repository. They essentially provide curated metrics collection, alerts and Grafana dashboards according to the use case. Most of those modules require the base module.
You can check the full workload modules list and their documentation here.
All the modules come with end-to-end deployable examples.
Examples
Examples put modules together in a ready to deploy terraform configuration as a starting point. With little to no configuration, you can run terraform apply and use the deployed resources on your AWS Account.
You can find workload examples like Amazon EKS infrstructure monitoring or monitoring your Amazon Managed Service for Prometheus workspace and more.
Getting started with AWS Observability services
If you are new to AWS Observability services, or want to dive deeper into them, check our One Observability Workshop for a hands-on experience in a self-paced environement or at an AWS venue.