Files
terraform-aws-observability…/modules/eks-monitoring/add-ons/external-secrets
Rodrigue Koffi fa38a90efc Move all dashboards to GitOps (#175)
* Typo

* Remove Grafana provider

* Temp: move dashbaords to gitOps

* Move external labels to resource attributes

* Avoid DDoS with using 0.0.0.0

* Pre-commit

* Transition in two steps

Will need to remove provider in a separate version to provide a transition path as removing this will break terraform and leave orphans in the state

* Move patterns' dashboards creation to gitOps

Standardize config objects for patterns as well

* Pre-commit

* Create AMP dashboard from external source with Grafana provider

* Fix deprecated option

* Fix Flux requirements

* Run pre-commit

* Update example with operator

* Cleanup examples

* Update multicluster example

* Update multicluster example

* Drop dead variable

* Update docs

* Change GitOps branch name

* Update docs

* Replacing Secrets Manager to SSM to store Grafana API Key (#178)

* Fixing SSM

* Fixing SSM

* Replacing Secrets Manager with SSM

* Replacing Secrets Manager with SSM

* Update architecture diagram

* Update architecture diagram

* Update README.md

* Update index.md

* Fixing Grafana Operator Version

* Fix multicluster example

* Update docs

---------

Co-authored-by: Ela AWS <51791117+elamaran11@users.noreply.github.com>
Co-authored-by: Elamaran Shanmugam <elamaran.shan@gmail.com>
2023-06-12 18:00:42 +02:00
..
2023-06-12 18:00:42 +02:00
2023-06-12 18:00:42 +02:00

External Secrets Operator Kubernetes addon

This deploys an EKS Cluster with the External Secrets Operator. The cluster is populated with a ClusterSecretStore and ExternalSecret using Grafana API Key secret from AWS Secret Manager. A secret store for each AWS Secret Manager is created. Store use IRSA (IAM Roles For Service Account) to retrieve the secret values from AWS.

Requirements

Name Version
terraform >= 1.0.0
aws >= 3.72
kubectl >= 1.14
kubernetes >= 2.10

Providers

Name Version
aws >= 3.72
kubectl >= 1.14

Modules

Name Source Version
cluster_secretstore_role github.com/aws-ia/terraform-aws-eks-blueprints//modules/irsa v4.32.0
external_secrets github.com/aws-ia/terraform-aws-eks-blueprints//modules/kubernetes-addons/external-secrets v4.32.0

Resources

Name Type
aws_iam_policy.cluster_secretstore resource
aws_kms_key.secrets resource
aws_ssm_parameter.secret resource
kubectl_manifest.cluster_secretstore resource
kubectl_manifest.secret resource
aws_region.current data source

Inputs

Name Description Type Default Required
addon_context Input configuration for the addon
object({
aws_caller_identity_account_id = string
aws_caller_identity_arn = string
aws_eks_cluster_endpoint = string
aws_partition_id = string
aws_region_name = string
eks_cluster_id = string
eks_oidc_issuer_url = string
eks_oidc_provider_arn = string
irsa_iam_role_path = string
irsa_iam_permissions_boundary = string
tags = map(string)
})
n/a yes
enable_external_secrets Enable external-secrets bool true no
grafana_api_key Grafana API key for the Amazon Managed Grafana workspace string n/a yes
helm_config Helm provider config for external secrets any {} no
target_secret_name Name to store the secret for Grafana API Key string n/a yes
target_secret_namespace Namespace to store the secret for Grafana API Key string n/a yes

Outputs

No outputs.