mirror of
https://github.com/storytold/terraform-aws-observability-accelerator.git
synced 2026-10-09 00:09:43 +00:00
d7daeb8c22
* Added example for multi-cluster eks-monitoring and made changes to eks-monitoring module to allow cross-cluster IRSA * Updated eks-monitoring module's README to add the variable description * Hard-coded grafana license type in eks-cross-cluster-with-amp/main.tf * Added README page for eks-cross-account-with-central-amp * Extracted out the eks/amg creation and modified it to use existing resources * Update README.md to add multiaccount dashboard png * Updated README.md and multiaccount.md to add eks multiaccount png * Updated eks-cross-cluster-with-amp example to disable dashboard creation for cluster 2 * Pre commit changed committed * Fixed cross-account-observability docs and README.md and added variable for amp_workpace_alias * Removed extra spacing in multiaccount.md and added precommit suggested changes * Modified cross-account-observability example to change cross-account-amp-role to snake_case * Capitalized Terraform string in multiaccount.md and converted iam-role-attach to snake_case --------- Co-authored-by: Rodrigue Koffi <bonclay7@users.noreply.github.com>
96 lines
3.0 KiB
Terraform
96 lines
3.0 KiB
Terraform
###### AWS Providers ######
|
|
|
|
provider "aws" {
|
|
region = var.cluster_one.region
|
|
alias = "eks_cluster_one"
|
|
assume_role {
|
|
role_arn = var.cluster_one.tf_role
|
|
}
|
|
}
|
|
|
|
provider "aws" {
|
|
region = var.cluster_two.region
|
|
alias = "eks_cluster_two"
|
|
assume_role {
|
|
role_arn = var.cluster_two.tf_role
|
|
}
|
|
}
|
|
|
|
provider "aws" {
|
|
region = var.monitoring.region
|
|
alias = "central_monitoring"
|
|
assume_role {
|
|
role_arn = var.monitoring.tf_role
|
|
}
|
|
}
|
|
|
|
###### Helm Providers ######
|
|
|
|
provider "helm" {
|
|
alias = "eks_cluster_one"
|
|
kubernetes {
|
|
host = data.aws_eks_cluster.eks_one.endpoint
|
|
cluster_ca_certificate = base64decode(data.aws_eks_cluster.eks_one.certificate_authority[0].data)
|
|
exec {
|
|
api_version = "client.authentication.k8s.io/v1beta1"
|
|
args = ["eks", "get-token", "--role-arn", var.cluster_one.tf_role, "--cluster-name", var.cluster_one.name]
|
|
command = "aws"
|
|
}
|
|
}
|
|
}
|
|
|
|
provider "helm" {
|
|
alias = "eks_cluster_two"
|
|
kubernetes {
|
|
host = data.aws_eks_cluster.eks_two.endpoint
|
|
cluster_ca_certificate = base64decode(data.aws_eks_cluster.eks_two.certificate_authority[0].data)
|
|
exec {
|
|
api_version = "client.authentication.k8s.io/v1beta1"
|
|
args = ["eks", "get-token", "--role-arn", var.cluster_two.tf_role, "--cluster-name", var.cluster_two.name]
|
|
command = "aws"
|
|
}
|
|
}
|
|
}
|
|
|
|
###### Kubernetes Providers ######
|
|
|
|
provider "kubernetes" {
|
|
alias = "eks_cluster_one"
|
|
host = data.aws_eks_cluster.eks_one.endpoint
|
|
cluster_ca_certificate = base64decode(data.aws_eks_cluster.eks_one.certificate_authority[0].data)
|
|
exec {
|
|
api_version = "client.authentication.k8s.io/v1beta1"
|
|
args = ["eks", "get-token", "--role-arn", var.cluster_one.tf_role, "--cluster-name", var.cluster_one.name]
|
|
command = "aws"
|
|
}
|
|
}
|
|
|
|
provider "kubernetes" {
|
|
alias = "eks_cluster_two"
|
|
host = data.aws_eks_cluster.eks_two.endpoint
|
|
cluster_ca_certificate = base64decode(data.aws_eks_cluster.eks_two.certificate_authority[0].data)
|
|
exec {
|
|
api_version = "client.authentication.k8s.io/v1beta1"
|
|
args = ["eks", "get-token", "--role-arn", var.cluster_two.tf_role, "--cluster-name", var.cluster_two.name]
|
|
command = "aws"
|
|
}
|
|
}
|
|
|
|
provider "kubectl" {
|
|
alias = "eks_cluster_one"
|
|
apply_retry_count = 30
|
|
host = data.aws_eks_cluster.eks_one.endpoint
|
|
cluster_ca_certificate = base64decode(data.aws_eks_cluster.eks_one.certificate_authority[0].data)
|
|
load_config_file = false
|
|
token = data.aws_eks_cluster_auth.eks_one.token
|
|
}
|
|
|
|
provider "kubectl" {
|
|
alias = "eks_cluster_two"
|
|
apply_retry_count = 30
|
|
host = data.aws_eks_cluster.eks_two.endpoint
|
|
cluster_ca_certificate = base64decode(data.aws_eks_cluster.eks_two.certificate_authority[0].data)
|
|
load_config_file = false
|
|
token = data.aws_eks_cluster_auth.eks_two.token
|
|
}
|