diff --git a/CHANGELOG.md b/CHANGELOG.md index 90d3ca09..7cf58eb7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,19 +4,61 @@ All notable changes to this project will be documented in this file. ## [Unreleased] - + + +## [26.0.0] - 2023-09-18 + ### BLUEPRINTS +- [[#1684](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1684)] **incompatible change:** Update resource-level IAM interface for kms and pubsub modules ([juliocc](https://github.com/juliocc)) +- [[#1682](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1682)] GKE cluster modules: add optional kube state metrics ([olliefr](https://github.com/olliefr)) +- [[#1681](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1681)] **incompatible change:** Embed subnet-level IAM in the variables controlling creation of subnets ([juliocc](https://github.com/juliocc)) +- [[#1680](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1680)] Upgrades to `monitoring_config` in `gke-cluster-*`, docs update, and cosmetics fixes to GKE cluster modules ([olliefr](https://github.com/olliefr)) +- [[#1679](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1679)] Add lineage on Minimal Data Platform blueprint ([lcaggio](https://github.com/lcaggio)) +- [[#1678](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1678)] Allow only one of `secondary_range_blocks` or `secondary_range_names` when creating GKE clusters. ([juliocc](https://github.com/juliocc)) +- [[#1671](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1671)] **incompatible change:** Fixed, added back environments to each instance, that way we can also… ([apichick](https://github.com/apichick)) +- [[#1662](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1662)] merge labels from data_merges in project factory ([Tutuchan](https://github.com/Tutuchan)) +- [[#1651](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1651)] add AIRFLOW_VAR_ prefix to environment variables in data-platform blueprints ([Tutuchan](https://github.com/Tutuchan)) +- [[#1642](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1642)] New phpIPAM serverless third parties solution in blueprints ([simonebruzzechesse](https://github.com/simonebruzzechesse)) +- [[#1654](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1654)] Fix project factory blueprint and fast stage ([LucaPrete](https://github.com/LucaPrete)) +- [[#1647](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1647)] Bump provider version to 4.80.0 ([juliocc](https://github.com/juliocc)) +- [[#1638](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1638)] gke-cluster-standard: change logging configuration ([olliefr](https://github.com/olliefr)) +- [[#1636](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1636)] Delete api gateway blueprint ([juliodiez](https://github.com/juliodiez)) +- [[#1607](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1607)] Trap requests timeout error in quota sync ([ludoo](https://github.com/ludoo)) - [[#1595](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1595)] **incompatible change:** IAM interface refactor ([ludoo](https://github.com/ludoo)) - [[#1601](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1601)] [Data Platform] Update README.md ([lcaggio](https://github.com/lcaggio)) ### DOCUMENTATION +- [[#1687](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1687)] Add IAM variables template to ADR ([juliocc](https://github.com/juliocc)) +- [[#1686](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1686)] CONTRIBUTING guide: fix broken links and update "running tests for specific examples" section ([olliefr](https://github.com/olliefr)) +- [[#1658](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1658)] **incompatible change:** Change type of `iam_bindings` variable to allow multiple conditional bindings ([ludoo](https://github.com/ludoo)) +- [[#1642](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1642)] New phpIPAM serverless third parties solution in blueprints ([simonebruzzechesse](https://github.com/simonebruzzechesse)) +- [[#1640](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1640)] Simplify linting output in workflow ([juliocc](https://github.com/juliocc)) +- [[#1636](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1636)] Delete api gateway blueprint ([juliodiez](https://github.com/juliodiez)) - [[#1595](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1595)] **incompatible change:** IAM interface refactor ([ludoo](https://github.com/ludoo)) ### FAST +- [[#1684](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1684)] **incompatible change:** Update resource-level IAM interface for kms and pubsub modules ([juliocc](https://github.com/juliocc)) +- [[#1685](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1685)] Fix psa routing variable in FAST net stages ([ludoo](https://github.com/ludoo)) +- [[#1682](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1682)] GKE cluster modules: add optional kube state metrics ([olliefr](https://github.com/olliefr)) +- [[#1681](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1681)] **incompatible change:** Embed subnet-level IAM in the variables controlling creation of subnets ([juliocc](https://github.com/juliocc)) +- [[#1680](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1680)] Upgrades to `monitoring_config` in `gke-cluster-*`, docs update, and cosmetics fixes to GKE cluster modules ([olliefr](https://github.com/olliefr)) +- [[#1678](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1678)] Allow only one of `secondary_range_blocks` or `secondary_range_names` when creating GKE clusters. ([juliocc](https://github.com/juliocc)) +- [[#1664](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1664)] Align pf stage sample data to new format ([ludoo](https://github.com/ludoo)) +- [[#1663](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1663)] [#1661] Make FAST stage 1 resman tf destroy more reliable ([LucaPrete](https://github.com/LucaPrete)) +- [[#1659](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1659)] Link project factory documentation from FAST stage ([ludoo](https://github.com/ludoo)) +- [[#1658](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1658)] **incompatible change:** Change type of `iam_bindings` variable to allow multiple conditional bindings ([ludoo](https://github.com/ludoo)) +- [[#1654](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1654)] Fix project factory blueprint and fast stage ([LucaPrete](https://github.com/LucaPrete)) +- [[#1638](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1638)] gke-cluster-standard: change logging configuration ([olliefr](https://github.com/olliefr)) +- [[#1634](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1634)] [revert(revert(patch))] Remove unused ASN numbers for CloudNAT in FAST ([LucaPrete](https://github.com/LucaPrete)) +- [[#1631](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1631)] Allow single hfw policy association in folder and organization modules ([juliocc](https://github.com/juliocc)) +- [[#1626](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1626)] Revert "Remove unused ASN numbers from CloudNAT to avoid provider errors" ([LucaPrete](https://github.com/LucaPrete)) +- [[#1623](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1623)] Fix role name for delegated grants in FAST bootstrap ([juliocc](https://github.com/juliocc)) +- [[#1612](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1612)] Fix: align stage-2-e-nva-bgp to the latest APIs ([LucaPrete](https://github.com/LucaPrete)) +- [[#1610](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1610)] Fix: use existing variable to optionally name fw policies ([LucaPrete](https://github.com/LucaPrete)) - [[#1595](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1595)] **incompatible change:** IAM interface refactor ([ludoo](https://github.com/ludoo)) - [[#1597](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1597)] fix null object exception in bootstrap output when using cloudsource ([sm3142](https://github.com/sm3142)) - [[#1593](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1593)] Fix FAST CI/CD for Gitlab ([ludoo](https://github.com/ludoo)) @@ -24,6 +66,41 @@ All notable changes to this project will be documented in this file. ### MODULES +- [[#1684](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1684)] **incompatible change:** Update resource-level IAM interface for kms and pubsub modules ([juliocc](https://github.com/juliocc)) +- [[#1683](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1683)] Fix subnet iam_bindings to use arbitrary keys ([juliocc](https://github.com/juliocc)) +- [[#1682](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1682)] GKE cluster modules: add optional kube state metrics ([olliefr](https://github.com/olliefr)) +- [[#1681](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1681)] **incompatible change:** Embed subnet-level IAM in the variables controlling creation of subnets ([juliocc](https://github.com/juliocc)) +- [[#1680](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1680)] Upgrades to `monitoring_config` in `gke-cluster-*`, docs update, and cosmetics fixes to GKE cluster modules ([olliefr](https://github.com/olliefr)) +- [[#1678](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1678)] Allow only one of `secondary_range_blocks` or `secondary_range_names` when creating GKE clusters. ([juliocc](https://github.com/juliocc)) +- [[#1675](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1675)] GKE Autopilot module: add network tags ([olliefr](https://github.com/olliefr)) +- [[#1676](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1676)] fixed up nit from PR 1666 ([dgulli](https://github.com/dgulli)) +- [[#1672](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1672)] Added possibility to use gcs push endpoint on pubsub subscription ([luigi-bitonti](https://github.com/luigi-bitonti)) +- [[#1671](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1671)] **incompatible change:** Fixed, added back environments to each instance, that way we can also… ([apichick](https://github.com/apichick)) +- [[#1666](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1666)] added support for global proxy only subnets ([dgulli](https://github.com/dgulli)) +- [[#1669](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1669)] Fix for partner interconnect ([apichick](https://github.com/apichick)) +- [[#1668](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1668)] fix(compute-mig): add correct type optionality for metrics in autosca… ([NotArpit](https://github.com/NotArpit)) +- [[#1667](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1667)] fix(compute-mig): add mode property to compute_region_autoscaler ([NotArpit](https://github.com/NotArpit)) +- [[#1658](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1658)] **incompatible change:** Change type of `iam_bindings` variable to allow multiple conditional bindings ([ludoo](https://github.com/ludoo)) +- [[#1653](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1653)] Fixes to the apigee module ([juliocc](https://github.com/juliocc)) +- [[#1642](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1642)] New phpIPAM serverless third parties solution in blueprints ([simonebruzzechesse](https://github.com/simonebruzzechesse)) +- [[#1650](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1650)] Make net-vpc variables non-nullable ([juliocc](https://github.com/juliocc)) +- [[#1647](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1647)] Bump provider version to 4.80.0 ([juliocc](https://github.com/juliocc)) +- [[#1646](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1646)] gke-cluster-autopilot: add monitoring configuration ([olliefr](https://github.com/olliefr)) +- [[#1645](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1645)] gke-cluster-autopilot: add validation for release_channel input variable ([olliefr](https://github.com/olliefr)) +- [[#1638](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1638)] gke-cluster-standard: change logging configuration ([olliefr](https://github.com/olliefr)) +- [[#1625](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1625)] gke-cluster-autopilot: add logging configuration ([olliefr](https://github.com/olliefr)) +- [[#1637](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1637)] GRPC variable is misnamed "GRCP" in `modules/cloud-run/variables.tf`, causing liveness probe and startup probe to fail ([zacharysmithdatatonic](https://github.com/zacharysmithdatatonic)) +- [[#1632](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1632)] Vpc sc allow null for identity type ([LudovicEmo](https://github.com/LudovicEmo)) +- [[#1633](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1633)] Do not set default ASN number ([LucaPrete](https://github.com/LucaPrete)) +- [[#1631](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1631)] Allow single hfw policy association in folder and organization modules ([juliocc](https://github.com/juliocc)) +- [[#1630](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1630)] [Fix] Add explicit dependency between CR peers and NCC RA spoke creation ([LucaPrete](https://github.com/LucaPrete)) +- [[#1613](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1613)] Cloud SQL activation policy selectable ([cmvalla](https://github.com/cmvalla)) +- [[#1619](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1619)] Adding support for NAT in Apigee ([billabongrob](https://github.com/billabongrob)) +- [[#1620](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1620)] Remove net-firewall-policy match variable validation ([richard-olson](https://github.com/richard-olson)) +- [[#1614](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1614)] Fix net-firewall-policy factory name and action ([richard-olson](https://github.com/richard-olson)) +- [[#1584](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1584)] add support for object upload to gcs module ([ehorning](https://github.com/ehorning)) +- [[#1609](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1609)] **incompatible change:** Use cloud run bindings for cf v2 invoker role, refactor iam handling in cf v2 and cloud run ([ludoo](https://github.com/ludoo)) +- [[#1590](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1590)] GCVE module first release ([eliamaldini](https://github.com/eliamaldini)) - [[#1595](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1595)] **incompatible change:** IAM interface refactor ([ludoo](https://github.com/ludoo)) - [[#1600](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1600)] fix(cloud-run): move cpu boost annotation to revision ([LiuVII](https://github.com/LiuVII)) - [[#1599](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1599)] Fixing some typos ([bluPhy](https://github.com/bluPhy)) @@ -38,6 +115,9 @@ All notable changes to this project will be documented in this file. ### TOOLS +- [[#1641](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1641)] Lint script ([juliocc](https://github.com/juliocc)) +- [[#1640](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1640)] Simplify linting output in workflow ([juliocc](https://github.com/juliocc)) +- [[#1635](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1635)] Silence FAST tests warnings ([juliocc](https://github.com/juliocc)) - [[#1595](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1595)] **incompatible change:** IAM interface refactor ([ludoo](https://github.com/ludoo)) - [[#1585](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1585)] Print inventory path when a test fails ([juliocc](https://github.com/juliocc)) @@ -1483,7 +1563,8 @@ All notable changes to this project will be documented in this file. - merge development branch with suite of new modules and end-to-end examples -[Unreleased]: https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/compare/v25.0.0...HEAD +[Unreleased]: https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/compare/v26.0.0...HEAD +[26.0.0]: https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/compare/v25.0.0...v26.0.0 [25.0.0]: https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/compare/v24.0.0...v25.0.0 [24.0.0]: https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/compare/v23.0.0...v24.0.0 [23.0.0]: https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/compare/v22.0.0...v23.0.0 diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 3d997e94..1e12acf7 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -686,8 +686,8 @@ Writing `pytest` unit tests to check plan results is really easy, but since wrap In the following sections we describe the three testing approaches we currently have: - [Example-based tests](#testing-via-readmemd-example-blocks): this is perhaps the easiest and most common way to test either a module or a blueprint. You simply have to provide an example call to your module and a few metadata values in the module's README.md. -- [tfvars-based tests](#testing-via-tfvars-and-yaml): allows you to test a module or blueprint by providing variables via tfvar files and an expected plan result in form of an inventory. This type of test is useful, for example, for FAST stages that don't have any examples within their READMEs. -- [Python-based (legacy) tests](#writing-tests-in-python--legacy-approach-): in some situations you might still want to interact directly with `tftest` via Python, if that's the case, use this method to write custom Python logic to test your module in any way you see fit. +- [tfvars-based tests](#testing-via-tfvars-and-yaml-aka-tftest-based-tests): allows you to test a module or blueprint by providing variables via tfvar files and an expected plan result in form of an inventory. This type of test is useful, for example, for FAST stages that don't have any examples within their READMEs. +- [Python-based (legacy) tests](#writing-tests-in-python-legacy-approach): in some situations you might still want to interact directly with `tftest` via Python, if that's the case, use this method to write custom Python logic to test your module in any way you see fit. ### Testing via README.md example blocks @@ -818,27 +818,47 @@ Example-based test are named based on the section within the README.md that cont Here we show a few commonly used selection commands: - Run all examples: - - `pytest tests/examples/` -- Run all examples for modules: - - `pytest -k modules/ tests/examples` + - `pytest tests/examples` +- Run all examples for blueprints only: + - `pytest -k blueprints tests/examples` +- Run all examples for modules only: + - `pytest -k modules tests/examples` - Run all examples for the `net-vpc` module: - - `pytest -k 'net and vpc' tests/examples` -- Run a specific example in module `net-vpc`: - - `pytest -k 'modules and dns and private'` - - `pytest -v 'tests/examples/test_plan.py::test_example[modules/dns:Private Zone]'` + - `pytest -k 'modules and net-vpc:' tests/examples` +- Run a specific example (identified by a substring match on its name) from the `net-vpc` module: + - `pytest -k 'modules and net-vpc: and ipv6' tests/examples` +- Run a specific example (identified by its full name) from the `net-vpc` module: + - `pytest -v 'tests/examples/test_plan.py::test_example[modules/net-vpc:IPv6:1]'` - Run tests for all blueprints except those under the gke directory: - - `pytest -k 'blueprints and not gke'` + - `pytest -k 'blueprints and not gke' tests/examples` -Tip: you can use `pytest --collect-only` to fine tune your selection query without actually running the tests. Once you find the expression matching your desired tests, remove the `collect-only` flag. +> [!NOTE] +> The colon symbol (`:`) in `pytest` keyword expression `'modules and net-vpc:'` makes sure that `net-vpc` is matched but `net-vpc-firewall` or `net-vpc-peering` are not. + +Tip: to list all tests matched by your keyword expression (`-k ...`) without actually running them, you can use the `--collect-only` flag. + +The following command executes a dry run that *lists* all example-based tests for the `gke-cluster-autopilot` module: + +```bash +pytest -k 'modules and gke-cluster-autopilot:' tests/examples --collect-only +``` + +Once you find the expression matching your desired test(s), remove the `--collect-only` flag. + +The next command executes an example-based test found in the *Monitoring Configuration* section of the README file for the `gke-cluster-autopilot` module. That section actually has two tests, so the `:2` part selects the second test only: + +```bash +pytest -k 'modules and gke-cluster-autopilot: and monitoring and :2' tests/examples +``` #### Generating the inventory automatically Building an inventory file by hand is difficult. To simplify this task, the default test runner for examples prints the inventory for the full plan if it succeeds. Therefore, you can start without an inventory and then run a test to get the full plan and extract the pieces you want to build the inventory file. -Suppose you want to generate the inventory for the last DNS example above (the one creating the recordsets from a YAML file). Assuming that example is under the "Private Zone" section in the README for the `dns`, you can run the following command to build the inventory: +Suppose you want to generate the inventory for the last DNS example above (the one creating the recordsets from a YAML file). Assuming that example is the first code block under the "Private Zone" section in the README for the `dns` module, you can run the following command to build the inventory: ```bash -pytest -s 'tests/examples/test_plan.py::test_example[modules/dns:Private Zone]' +pytest -s 'tests/examples/test_plan.py::test_example[modules/dns:Private Zone:1]' ``` which will generate a output similar to this: diff --git a/blueprints/apigee/bigquery-analytics/README.md b/blueprints/apigee/bigquery-analytics/README.md index 5261f72e..3eeeaaf7 100644 --- a/blueprints/apigee/bigquery-analytics/README.md +++ b/blueprints/apigee/bigquery-analytics/README.md @@ -53,14 +53,13 @@ Do the following to verify that everything works as expected. 4. At 4am (UTC) every day the Cloud Scheduler will run and will export the analytics to the BigQuery table. Double-check they are there. - ## Variables | name | description | type | required | default | |---|---|:---:|:---:|:---:| | [envgroups](variables.tf#L24) | Environment groups (NAME => [HOSTNAMES]). | map(list(string)) | ✓ | | -| [environments](variables.tf#L30) | Environments. | map(object({…})) | ✓ | | -| [instances](variables.tf#L46) | Instance. | map(object({…})) | ✓ | | +| [environments](variables.tf#L30) | Environments. | map(object({…})) | ✓ | | +| [instances](variables.tf#L45) | Instance. | map(object({…})) | ✓ | | | [project_id](variables.tf#L91) | Project ID. | string | ✓ | | | [psc_config](variables.tf#L97) | PSC configuration. | map(string) | ✓ | | | [datastore_name](variables.tf#L17) | Datastore. | string | | "gcs" | @@ -74,7 +73,6 @@ Do the following to verify that everything works as expected. | name | description | sensitive | |---|---|:---:| | [ip_address](outputs.tf#L17) | IP address. | | - ## Test @@ -92,13 +90,13 @@ module "test" { environments = { apis-test = { envgroups = ["test"] - regions = ["europe-west1"] } } instances = { europe-west1 = { runtime_ip_cidr_range = "10.0.4.0/22" troubleshooting_ip_cidr_range = "10.1.0.0/28" + environments = ["apis-test"] } } psc_config = { diff --git a/blueprints/apigee/bigquery-analytics/variables.tf b/blueprints/apigee/bigquery-analytics/variables.tf index 53f329b0..3552d58e 100644 --- a/blueprints/apigee/bigquery-analytics/variables.tf +++ b/blueprints/apigee/bigquery-analytics/variables.tf @@ -38,7 +38,6 @@ variable "environments" { })) iam = optional(map(list(string))) envgroups = optional(list(string)) - regions = optional(list(string)) })) nullable = false } @@ -52,6 +51,7 @@ variable "instances" { troubleshooting_ip_cidr_range = string disk_encryption_key = optional(string) consumer_accept_list = optional(list(string)) + environments = optional(list(string)) })) nullable = false } diff --git a/blueprints/apigee/bigquery-analytics/versions.tf b/blueprints/apigee/bigquery-analytics/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/apigee/bigquery-analytics/versions.tf +++ b/blueprints/apigee/bigquery-analytics/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/apigee/hybrid-gke/gke.tf b/blueprints/apigee/hybrid-gke/gke.tf index 6ae38433..701384b9 100644 --- a/blueprints/apigee/hybrid-gke/gke.tf +++ b/blueprints/apigee/hybrid-gke/gke.tf @@ -20,12 +20,9 @@ module "cluster" { name = "cluster" location = var.region vpc_config = { - network = module.vpc.self_link - subnetwork = module.vpc.subnet_self_links["${var.region}/subnet-apigee"] - secondary_range_names = { - pods = "pods" - services = "services" - } + network = module.vpc.self_link + subnetwork = module.vpc.subnet_self_links["${var.region}/subnet-apigee"] + secondary_range_names = {} master_authorized_ranges = var.cluster_network_config.master_authorized_cidr_blocks master_ipv4_cidr_block = var.cluster_network_config.master_cidr_block } @@ -79,4 +76,4 @@ module "apigee-runtime-nodepool" { create = true } tags = ["node"] -} \ No newline at end of file +} diff --git a/blueprints/apigee/network-patterns/nb-glb-psc-neg-sb-psc-ilbl7-hybrid-neg/apigee.tf b/blueprints/apigee/network-patterns/nb-glb-psc-neg-sb-psc-ilbl7-hybrid-neg/apigee.tf index 2923f1f6..afad0f0d 100644 --- a/blueprints/apigee/network-patterns/nb-glb-psc-neg-sb-psc-ilbl7-hybrid-neg/apigee.tf +++ b/blueprints/apigee/network-patterns/nb-glb-psc-neg-sb-psc-ilbl7-hybrid-neg/apigee.tf @@ -76,11 +76,11 @@ module "apigee" { environments = { (local.environment) = { envgroups = [local.envgroup] - regions = [var.region] } } instances = { (var.region) = { + environments = [local.environment] runtime_ip_cidr_range = var.apigee_runtime_ip_cidr_range troubleshooting_ip_cidr_range = var.apigee_troubleshooting_ip_cidr_range } diff --git a/blueprints/apigee/network-patterns/nb-glb-psc-neg-sb-psc-ilbl7-hybrid-neg/versions.tf b/blueprints/apigee/network-patterns/nb-glb-psc-neg-sb-psc-ilbl7-hybrid-neg/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/apigee/network-patterns/nb-glb-psc-neg-sb-psc-ilbl7-hybrid-neg/versions.tf +++ b/blueprints/apigee/network-patterns/nb-glb-psc-neg-sb-psc-ilbl7-hybrid-neg/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/cloud-operations/adfs/versions.tf b/blueprints/cloud-operations/adfs/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/cloud-operations/adfs/versions.tf +++ b/blueprints/cloud-operations/adfs/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/cloud-operations/asset-inventory-feed-remediation/main.tf b/blueprints/cloud-operations/asset-inventory-feed-remediation/main.tf index e4082f69..e396364e 100644 --- a/blueprints/cloud-operations/asset-inventory-feed-remediation/main.tf +++ b/blueprints/cloud-operations/asset-inventory-feed-remediation/main.tf @@ -55,10 +55,12 @@ module "vpc" { } module "pubsub" { - source = "../../../modules/pubsub" - project_id = module.project.project_id - name = var.name - subscriptions = { "${var.name}-default" = null } + source = "../../../modules/pubsub" + project_id = module.project.project_id + name = var.name + subscriptions = { + "${var.name}-default" = {} + } iam = { "roles/pubsub.publisher" = [ "serviceAccount:${module.project.service_accounts.robots.cloudasset}" diff --git a/blueprints/cloud-operations/asset-inventory-feed-remediation/versions.tf b/blueprints/cloud-operations/asset-inventory-feed-remediation/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/cloud-operations/asset-inventory-feed-remediation/versions.tf +++ b/blueprints/cloud-operations/asset-inventory-feed-remediation/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/cloud-operations/dns-fine-grained-iam/versions.tf b/blueprints/cloud-operations/dns-fine-grained-iam/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/cloud-operations/dns-fine-grained-iam/versions.tf +++ b/blueprints/cloud-operations/dns-fine-grained-iam/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/cloud-operations/dns-shared-vpc/versions.tf b/blueprints/cloud-operations/dns-shared-vpc/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/cloud-operations/dns-shared-vpc/versions.tf +++ b/blueprints/cloud-operations/dns-shared-vpc/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/cloud-operations/iam-delegated-role-grants/versions.tf b/blueprints/cloud-operations/iam-delegated-role-grants/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/cloud-operations/iam-delegated-role-grants/versions.tf +++ b/blueprints/cloud-operations/iam-delegated-role-grants/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/cloud-operations/onprem-sa-key-management/versions.tf b/blueprints/cloud-operations/onprem-sa-key-management/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/cloud-operations/onprem-sa-key-management/versions.tf +++ b/blueprints/cloud-operations/onprem-sa-key-management/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/cloud-operations/packer-image-builder/versions.tf b/blueprints/cloud-operations/packer-image-builder/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/cloud-operations/packer-image-builder/versions.tf +++ b/blueprints/cloud-operations/packer-image-builder/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/cloud-operations/quota-monitoring/main.tf b/blueprints/cloud-operations/quota-monitoring/main.tf index f644c8fb..a49891c0 100644 --- a/blueprints/cloud-operations/quota-monitoring/main.tf +++ b/blueprints/cloud-operations/quota-monitoring/main.tf @@ -39,7 +39,7 @@ module "pubsub" { project_id = module.project.project_id name = var.name subscriptions = { - "${var.name}-default" = null + "${var.name}-default" = {} } # the Cloud Scheduler robot service account already has pubsub.topics.publish # at the project level via roles/cloudscheduler.serviceAgent diff --git a/blueprints/cloud-operations/quota-monitoring/versions.tf b/blueprints/cloud-operations/quota-monitoring/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/cloud-operations/quota-monitoring/versions.tf +++ b/blueprints/cloud-operations/quota-monitoring/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/cloud-operations/scheduled-asset-inventory-export-bq/main.tf b/blueprints/cloud-operations/scheduled-asset-inventory-export-bq/main.tf index c10c0b6b..6460384e 100644 --- a/blueprints/cloud-operations/scheduled-asset-inventory-export-bq/main.tf +++ b/blueprints/cloud-operations/scheduled-asset-inventory-export-bq/main.tf @@ -63,7 +63,7 @@ module "pubsub" { project_id = module.project.project_id name = var.name subscriptions = { - "${var.name}-default" = null + "${var.name}-default" = {} } # the Cloud Scheduler robot service account already has pubsub.topics.publish # at the project level via roles/cloudscheduler.serviceAgent @@ -74,7 +74,7 @@ module "pubsub_file" { project_id = module.project.project_id name = var.name_cffile subscriptions = { - "${var.name_cffile}-default" = null + "${var.name_cffile}-default" = {} } # the Cloud Scheduler robot service account already has pubsub.topics.publish # at the project level via roles/cloudscheduler.serviceAgent diff --git a/blueprints/cloud-operations/scheduled-asset-inventory-export-bq/versions.tf b/blueprints/cloud-operations/scheduled-asset-inventory-export-bq/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/cloud-operations/scheduled-asset-inventory-export-bq/versions.tf +++ b/blueprints/cloud-operations/scheduled-asset-inventory-export-bq/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/data-solutions/bq-ml/versions.tf b/blueprints/data-solutions/bq-ml/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/data-solutions/bq-ml/versions.tf +++ b/blueprints/data-solutions/bq-ml/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/data-solutions/cloudsql-multiregion/README.md b/blueprints/data-solutions/cloudsql-multiregion/README.md index 85f2594c..def4d3f1 100644 --- a/blueprints/data-solutions/cloudsql-multiregion/README.md +++ b/blueprints/data-solutions/cloudsql-multiregion/README.md @@ -179,5 +179,5 @@ module "test" { } prefix = "prefix" } -# tftest modules=9 resources=43 +# tftest modules=9 resources=44 ``` diff --git a/blueprints/data-solutions/cmek-via-centralized-kms/main.tf b/blueprints/data-solutions/cmek-via-centralized-kms/main.tf index 27fbe99b..fb446e71 100644 --- a/blueprints/data-solutions/cmek-via-centralized-kms/main.tf +++ b/blueprints/data-solutions/cmek-via-centralized-kms/main.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -106,7 +106,10 @@ module "kms" { name = "${var.prefix}-${var.region}", location = var.region } - keys = { key-gce = null, key-gcs = null } + keys = { + key-gce = {} + key-gcs = {} + } } ############################################################################### diff --git a/blueprints/data-solutions/cmek-via-centralized-kms/versions.tf b/blueprints/data-solutions/cmek-via-centralized-kms/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/data-solutions/cmek-via-centralized-kms/versions.tf +++ b/blueprints/data-solutions/cmek-via-centralized-kms/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/data-solutions/composer-2/README.md b/blueprints/data-solutions/composer-2/README.md index c43590e7..6cf927b7 100644 --- a/blueprints/data-solutions/composer-2/README.md +++ b/blueprints/data-solutions/composer-2/README.md @@ -139,5 +139,5 @@ module "test" { } prefix = "prefix" } -# tftest modules=5 resources=28 +# tftest modules=5 resources=29 ``` diff --git a/blueprints/data-solutions/data-platform-foundations/03-composer.tf b/blueprints/data-solutions/data-platform-foundations/03-composer.tf index f806f0e5..8c803e4b 100644 --- a/blueprints/data-solutions/data-platform-foundations/03-composer.tf +++ b/blueprints/data-solutions/data-platform-foundations/03-composer.tf @@ -15,7 +15,7 @@ # tfdoc:file:description Orchestration Cloud Composer definition. locals { - env_variables = { + _env_variables = { BQ_LOCATION = var.location DATA_CAT_TAGS = try(jsonencode(module.common-datacatalog.tags), "{}") DF_KMS_KEY = try(var.service_encryption_keys.dataflow, "") @@ -48,6 +48,12 @@ locals { TRF_SA_DF = module.transf-sa-df-0.email TRF_SA_BQ = module.transf-sa-bq-0.email } + env_variables = { + for k, v in merge( + try(var.composer_config.software_config.env_variables, null), + local._env_variables + ) : "AIRFLOW_VAR_${k}" => v + } } module "orch-sa-cmp-0" { source = "../../../modules/iam-service-account" @@ -70,7 +76,7 @@ resource "google_composer_environment" "orch-cmp-0" { software_config { airflow_config_overrides = try(var.composer_config.software_config.airflow_config_overrides, null) pypi_packages = try(var.composer_config.software_config.pypi_packages, null) - env_variables = merge(try(var.composer_config.software_config.env_variables, null), local.env_variables) + env_variables = local.env_variables image_version = try(var.composer_config.software_config.image_version, null) } dynamic "workloads_config" { diff --git a/blueprints/data-solutions/data-platform-foundations/demo/datapipeline.py b/blueprints/data-solutions/data-platform-foundations/demo/datapipeline.py index a682d346..45b71b30 100644 --- a/blueprints/data-solutions/data-platform-foundations/demo/datapipeline.py +++ b/blueprints/data-solutions/data-platform-foundations/demo/datapipeline.py @@ -16,57 +16,52 @@ # Load The Dependencies # -------------------------------------------------------------------------------- -import csv import datetime -import io -import json -import logging -import os from airflow import models +from airflow.models.variable import Variable from airflow.providers.google.cloud.operators.dataflow import DataflowTemplatedJobStartOperator -from airflow.operators import dummy -from airflow.providers.google.cloud.operators.bigquery import BigQueryInsertJobOperator, BigQueryUpsertTableOperator, BigQueryUpdateTableSchemaOperator -from airflow.utils.task_group import TaskGroup +from airflow.operators import empty +from airflow.providers.google.cloud.operators.bigquery import BigQueryInsertJobOperator # -------------------------------------------------------------------------------- # Set variables - Needed for the DEMO # -------------------------------------------------------------------------------- -BQ_LOCATION = os.environ.get("BQ_LOCATION") -DATA_CAT_TAGS = json.loads(os.environ.get("DATA_CAT_TAGS")) -DWH_LAND_PRJ = os.environ.get("DWH_LAND_PRJ") -DWH_LAND_BQ_DATASET = os.environ.get("DWH_LAND_BQ_DATASET") -DWH_LAND_GCS = os.environ.get("DWH_LAND_GCS") -DWH_CURATED_PRJ = os.environ.get("DWH_CURATED_PRJ") -DWH_CURATED_BQ_DATASET = os.environ.get("DWH_CURATED_BQ_DATASET") -DWH_CURATED_GCS = os.environ.get("DWH_CURATED_GCS") -DWH_CONFIDENTIAL_PRJ = os.environ.get("DWH_CONFIDENTIAL_PRJ") -DWH_CONFIDENTIAL_BQ_DATASET = os.environ.get("DWH_CONFIDENTIAL_BQ_DATASET") -DWH_CONFIDENTIAL_GCS = os.environ.get("DWH_CONFIDENTIAL_GCS") -DWH_PLG_PRJ = os.environ.get("DWH_PLG_PRJ") -DWH_PLG_BQ_DATASET = os.environ.get("DWH_PLG_BQ_DATASET") -DWH_PLG_GCS = os.environ.get("DWH_PLG_GCS") -GCP_REGION = os.environ.get("GCP_REGION") -DRP_PRJ = os.environ.get("DRP_PRJ") -DRP_BQ = os.environ.get("DRP_BQ") -DRP_GCS = os.environ.get("DRP_GCS") -DRP_PS = os.environ.get("DRP_PS") -LOD_PRJ = os.environ.get("LOD_PRJ") -LOD_GCS_STAGING = os.environ.get("LOD_GCS_STAGING") -LOD_NET_VPC = os.environ.get("LOD_NET_VPC") -LOD_NET_SUBNET = os.environ.get("LOD_NET_SUBNET") -LOD_SA_DF = os.environ.get("LOD_SA_DF") -ORC_PRJ = os.environ.get("ORC_PRJ") -ORC_GCS = os.environ.get("ORC_GCS") -TRF_PRJ = os.environ.get("TRF_PRJ") -TRF_GCS_STAGING = os.environ.get("TRF_GCS_STAGING") -TRF_NET_VPC = os.environ.get("TRF_NET_VPC") -TRF_NET_SUBNET = os.environ.get("TRF_NET_SUBNET") -TRF_SA_DF = os.environ.get("TRF_SA_DF") -TRF_SA_BQ = os.environ.get("TRF_SA_BQ") -DF_KMS_KEY = os.environ.get("DF_KMS_KEY", "") -DF_REGION = os.environ.get("GCP_REGION") -DF_ZONE = os.environ.get("GCP_REGION") + "-b" +BQ_LOCATION = Variable.get("BQ_LOCATION") +DATA_CAT_TAGS = Variable.get("DATA_CAT_TAGS", deserialize_json=True) +DWH_LAND_PRJ = Variable.get("DWH_LAND_PRJ") +DWH_LAND_BQ_DATASET = Variable.get("DWH_LAND_BQ_DATASET") +DWH_LAND_GCS = Variable.get("DWH_LAND_GCS") +DWH_CURATED_PRJ = Variable.get("DWH_CURATED_PRJ") +DWH_CURATED_BQ_DATASET = Variable.get("DWH_CURATED_BQ_DATASET") +DWH_CURATED_GCS = Variable.get("DWH_CURATED_GCS") +DWH_CONFIDENTIAL_PRJ = Variable.get("DWH_CONFIDENTIAL_PRJ") +DWH_CONFIDENTIAL_BQ_DATASET = Variable.get("DWH_CONFIDENTIAL_BQ_DATASET") +DWH_CONFIDENTIAL_GCS = Variable.get("DWH_CONFIDENTIAL_GCS") +DWH_PLG_PRJ = Variable.get("DWH_PLG_PRJ") +DWH_PLG_BQ_DATASET = Variable.get("DWH_PLG_BQ_DATASET") +DWH_PLG_GCS = Variable.get("DWH_PLG_GCS") +GCP_REGION = Variable.get("GCP_REGION") +DRP_PRJ = Variable.get("DRP_PRJ") +DRP_BQ = Variable.get("DRP_BQ") +DRP_GCS = Variable.get("DRP_GCS") +DRP_PS = Variable.get("DRP_PS") +LOD_PRJ = Variable.get("LOD_PRJ") +LOD_GCS_STAGING = Variable.get("LOD_GCS_STAGING") +LOD_NET_VPC = Variable.get("LOD_NET_VPC") +LOD_NET_SUBNET = Variable.get("LOD_NET_SUBNET") +LOD_SA_DF = Variable.get("LOD_SA_DF") +ORC_PRJ = Variable.get("ORC_PRJ") +ORC_GCS = Variable.get("ORC_GCS") +TRF_PRJ = Variable.get("TRF_PRJ") +TRF_GCS_STAGING = Variable.get("TRF_GCS_STAGING") +TRF_NET_VPC = Variable.get("TRF_NET_VPC") +TRF_NET_SUBNET = Variable.get("TRF_NET_SUBNET") +TRF_SA_DF = Variable.get("TRF_SA_DF") +TRF_SA_BQ = Variable.get("TRF_SA_BQ") +DF_KMS_KEY = Variable.get("DF_KMS_KEY", "") +DF_REGION = Variable.get("GCP_REGION") +DF_ZONE = Variable.get("GCP_REGION") + "-b" # -------------------------------------------------------------------------------- # Set default arguments @@ -106,12 +101,12 @@ with models.DAG( 'data_pipeline_dag', default_args=default_args, schedule_interval=None) as dag: - start = dummy.DummyOperator( + start = empty.EmptyOperator( task_id='start', trigger_rule='all_success' ) - end = dummy.DummyOperator( + end = empty.EmptyOperator( task_id='end', trigger_rule='all_success' ) diff --git a/blueprints/data-solutions/data-platform-foundations/demo/datapipeline_dc_tags.py b/blueprints/data-solutions/data-platform-foundations/demo/datapipeline_dc_tags.py index 56e62897..5e86472a 100644 --- a/blueprints/data-solutions/data-platform-foundations/demo/datapipeline_dc_tags.py +++ b/blueprints/data-solutions/data-platform-foundations/demo/datapipeline_dc_tags.py @@ -16,57 +16,53 @@ # Load The Dependencies # -------------------------------------------------------------------------------- -import csv import datetime -import io -import json -import logging -import os from airflow import models +from airflow.models.variable import Variable from airflow.providers.google.cloud.operators.dataflow import DataflowTemplatedJobStartOperator -from airflow.operators import dummy +from airflow.operators import empty from airflow.providers.google.cloud.operators.bigquery import BigQueryInsertJobOperator, BigQueryUpsertTableOperator, BigQueryUpdateTableSchemaOperator from airflow.utils.task_group import TaskGroup # -------------------------------------------------------------------------------- # Set variables - Needed for the DEMO # -------------------------------------------------------------------------------- -BQ_LOCATION = os.environ.get("BQ_LOCATION") -DATA_CAT_TAGS = json.loads(os.environ.get("DATA_CAT_TAGS")) -DWH_LAND_PRJ = os.environ.get("DWH_LAND_PRJ") -DWH_LAND_BQ_DATASET = os.environ.get("DWH_LAND_BQ_DATASET") -DWH_LAND_GCS = os.environ.get("DWH_LAND_GCS") -DWH_CURATED_PRJ = os.environ.get("DWH_CURATED_PRJ") -DWH_CURATED_BQ_DATASET = os.environ.get("DWH_CURATED_BQ_DATASET") -DWH_CURATED_GCS = os.environ.get("DWH_CURATED_GCS") -DWH_CONFIDENTIAL_PRJ = os.environ.get("DWH_CONFIDENTIAL_PRJ") -DWH_CONFIDENTIAL_BQ_DATASET = os.environ.get("DWH_CONFIDENTIAL_BQ_DATASET") -DWH_CONFIDENTIAL_GCS = os.environ.get("DWH_CONFIDENTIAL_GCS") -DWH_PLG_PRJ = os.environ.get("DWH_PLG_PRJ") -DWH_PLG_BQ_DATASET = os.environ.get("DWH_PLG_BQ_DATASET") -DWH_PLG_GCS = os.environ.get("DWH_PLG_GCS") -GCP_REGION = os.environ.get("GCP_REGION") -DRP_PRJ = os.environ.get("DRP_PRJ") -DRP_BQ = os.environ.get("DRP_BQ") -DRP_GCS = os.environ.get("DRP_GCS") -DRP_PS = os.environ.get("DRP_PS") -LOD_PRJ = os.environ.get("LOD_PRJ") -LOD_GCS_STAGING = os.environ.get("LOD_GCS_STAGING") -LOD_NET_VPC = os.environ.get("LOD_NET_VPC") -LOD_NET_SUBNET = os.environ.get("LOD_NET_SUBNET") -LOD_SA_DF = os.environ.get("LOD_SA_DF") -ORC_PRJ = os.environ.get("ORC_PRJ") -ORC_GCS = os.environ.get("ORC_GCS") -TRF_PRJ = os.environ.get("TRF_PRJ") -TRF_GCS_STAGING = os.environ.get("TRF_GCS_STAGING") -TRF_NET_VPC = os.environ.get("TRF_NET_VPC") -TRF_NET_SUBNET = os.environ.get("TRF_NET_SUBNET") -TRF_SA_DF = os.environ.get("TRF_SA_DF") -TRF_SA_BQ = os.environ.get("TRF_SA_BQ") -DF_KMS_KEY = os.environ.get("DF_KMS_KEY", "") -DF_REGION = os.environ.get("GCP_REGION") -DF_ZONE = os.environ.get("GCP_REGION") + "-b" +BQ_LOCATION = Variable.get("BQ_LOCATION") +DATA_CAT_TAGS = Variable.get("DATA_CAT_TAGS", deserialize_json=True) +DWH_LAND_PRJ = Variable.get("DWH_LAND_PRJ") +DWH_LAND_BQ_DATASET = Variable.get("DWH_LAND_BQ_DATASET") +DWH_LAND_GCS = Variable.get("DWH_LAND_GCS") +DWH_CURATED_PRJ = Variable.get("DWH_CURATED_PRJ") +DWH_CURATED_BQ_DATASET = Variable.get("DWH_CURATED_BQ_DATASET") +DWH_CURATED_GCS = Variable.get("DWH_CURATED_GCS") +DWH_CONFIDENTIAL_PRJ = Variable.get("DWH_CONFIDENTIAL_PRJ") +DWH_CONFIDENTIAL_BQ_DATASET = Variable.get("DWH_CONFIDENTIAL_BQ_DATASET") +DWH_CONFIDENTIAL_GCS = Variable.get("DWH_CONFIDENTIAL_GCS") +DWH_PLG_PRJ = Variable.get("DWH_PLG_PRJ") +DWH_PLG_BQ_DATASET = Variable.get("DWH_PLG_BQ_DATASET") +DWH_PLG_GCS = Variable.get("DWH_PLG_GCS") +GCP_REGION = Variable.get("GCP_REGION") +DRP_PRJ = Variable.get("DRP_PRJ") +DRP_BQ = Variable.get("DRP_BQ") +DRP_GCS = Variable.get("DRP_GCS") +DRP_PS = Variable.get("DRP_PS") +LOD_PRJ = Variable.get("LOD_PRJ") +LOD_GCS_STAGING = Variable.get("LOD_GCS_STAGING") +LOD_NET_VPC = Variable.get("LOD_NET_VPC") +LOD_NET_SUBNET = Variable.get("LOD_NET_SUBNET") +LOD_SA_DF = Variable.get("LOD_SA_DF") +ORC_PRJ = Variable.get("ORC_PRJ") +ORC_GCS = Variable.get("ORC_GCS") +TRF_PRJ = Variable.get("TRF_PRJ") +TRF_GCS_STAGING = Variable.get("TRF_GCS_STAGING") +TRF_NET_VPC = Variable.get("TRF_NET_VPC") +TRF_NET_SUBNET = Variable.get("TRF_NET_SUBNET") +TRF_SA_DF = Variable.get("TRF_SA_DF") +TRF_SA_BQ = Variable.get("TRF_SA_BQ") +DF_KMS_KEY = Variable.get("DF_KMS_KEY", "") +DF_REGION = Variable.get("GCP_REGION") +DF_ZONE = Variable.get("GCP_REGION") + "-b" # -------------------------------------------------------------------------------- # Set default arguments @@ -106,12 +102,12 @@ with models.DAG( 'data_pipeline_dc_tags_dag', default_args=default_args, schedule_interval=None) as dag: - start = dummy.DummyOperator( + start = empty.EmptyOperator( task_id='start', trigger_rule='all_success' ) - end = dummy.DummyOperator( + end = empty.EmptyOperator( task_id='end', trigger_rule='all_success' ) diff --git a/blueprints/data-solutions/data-platform-foundations/demo/datapipeline_dc_tags_flex.py b/blueprints/data-solutions/data-platform-foundations/demo/datapipeline_dc_tags_flex.py index b6784b9e..7bbf67a1 100644 --- a/blueprints/data-solutions/data-platform-foundations/demo/datapipeline_dc_tags_flex.py +++ b/blueprints/data-solutions/data-platform-foundations/demo/datapipeline_dc_tags_flex.py @@ -17,12 +17,11 @@ # -------------------------------------------------------------------------------- import datetime -import json -import os import time from airflow import models -from airflow.operators import dummy +from airflow.models.variable import Variable +from airflow.operators import empty from airflow.providers.google.cloud.operators.dataflow import DataflowStartFlexTemplateOperator from airflow.providers.google.cloud.operators.bigquery import BigQueryInsertJobOperator, BigQueryUpsertTableOperator, BigQueryUpdateTableSchemaOperator from airflow.utils.task_group import TaskGroup @@ -30,42 +29,42 @@ from airflow.utils.task_group import TaskGroup # -------------------------------------------------------------------------------- # Set variables - Needed for the DEMO # -------------------------------------------------------------------------------- -BQ_LOCATION = os.environ.get("BQ_LOCATION") -DATA_CAT_TAGS = json.loads(os.environ.get("DATA_CAT_TAGS")) -DWH_LAND_PRJ = os.environ.get("DWH_LAND_PRJ") -DWH_LAND_BQ_DATASET = os.environ.get("DWH_LAND_BQ_DATASET") -DWH_LAND_GCS = os.environ.get("DWH_LAND_GCS") -DWH_CURATED_PRJ = os.environ.get("DWH_CURATED_PRJ") -DWH_CURATED_BQ_DATASET = os.environ.get("DWH_CURATED_BQ_DATASET") -DWH_CURATED_GCS = os.environ.get("DWH_CURATED_GCS") -DWH_CONFIDENTIAL_PRJ = os.environ.get("DWH_CONFIDENTIAL_PRJ") -DWH_CONFIDENTIAL_BQ_DATASET = os.environ.get("DWH_CONFIDENTIAL_BQ_DATASET") -DWH_CONFIDENTIAL_GCS = os.environ.get("DWH_CONFIDENTIAL_GCS") -DWH_PLG_PRJ = os.environ.get("DWH_PLG_PRJ") -DWH_PLG_BQ_DATASET = os.environ.get("DWH_PLG_BQ_DATASET") -DWH_PLG_GCS = os.environ.get("DWH_PLG_GCS") -GCP_REGION = os.environ.get("GCP_REGION") -DRP_PRJ = os.environ.get("DRP_PRJ") -DRP_BQ = os.environ.get("DRP_BQ") -DRP_GCS = os.environ.get("DRP_GCS") -DRP_PS = os.environ.get("DRP_PS") -LOD_PRJ = os.environ.get("LOD_PRJ") -LOD_GCS_STAGING = os.environ.get("LOD_GCS_STAGING") -LOD_NET_VPC = os.environ.get("LOD_NET_VPC") -LOD_NET_SUBNET = os.environ.get("LOD_NET_SUBNET") -LOD_SA_DF = os.environ.get("LOD_SA_DF") -ORC_PRJ = os.environ.get("ORC_PRJ") -ORC_GCS = os.environ.get("ORC_GCS") -ORC_GCS_TMP_DF = os.environ.get("ORC_GCS_TMP_DF") -TRF_PRJ = os.environ.get("TRF_PRJ") -TRF_GCS_STAGING = os.environ.get("TRF_GCS_STAGING") -TRF_NET_VPC = os.environ.get("TRF_NET_VPC") -TRF_NET_SUBNET = os.environ.get("TRF_NET_SUBNET") -TRF_SA_DF = os.environ.get("TRF_SA_DF") -TRF_SA_BQ = os.environ.get("TRF_SA_BQ") -DF_KMS_KEY = os.environ.get("DF_KMS_KEY", "") -DF_REGION = os.environ.get("GCP_REGION") -DF_ZONE = os.environ.get("GCP_REGION") + "-b" +BQ_LOCATION = Variable.get("BQ_LOCATION") +DATA_CAT_TAGS = Variable.get("DATA_CAT_TAGS", deserialize_json=True) +DWH_LAND_PRJ = Variable.get("DWH_LAND_PRJ") +DWH_LAND_BQ_DATASET = Variable.get("DWH_LAND_BQ_DATASET") +DWH_LAND_GCS = Variable.get("DWH_LAND_GCS") +DWH_CURATED_PRJ = Variable.get("DWH_CURATED_PRJ") +DWH_CURATED_BQ_DATASET = Variable.get("DWH_CURATED_BQ_DATASET") +DWH_CURATED_GCS = Variable.get("DWH_CURATED_GCS") +DWH_CONFIDENTIAL_PRJ = Variable.get("DWH_CONFIDENTIAL_PRJ") +DWH_CONFIDENTIAL_BQ_DATASET = Variable.get("DWH_CONFIDENTIAL_BQ_DATASET") +DWH_CONFIDENTIAL_GCS = Variable.get("DWH_CONFIDENTIAL_GCS") +DWH_PLG_PRJ = Variable.get("DWH_PLG_PRJ") +DWH_PLG_BQ_DATASET = Variable.get("DWH_PLG_BQ_DATASET") +DWH_PLG_GCS = Variable.get("DWH_PLG_GCS") +GCP_REGION = Variable.get("GCP_REGION") +DRP_PRJ = Variable.get("DRP_PRJ") +DRP_BQ = Variable.get("DRP_BQ") +DRP_GCS = Variable.get("DRP_GCS") +DRP_PS = Variable.get("DRP_PS") +LOD_PRJ = Variable.get("LOD_PRJ") +LOD_GCS_STAGING = Variable.get("LOD_GCS_STAGING") +LOD_NET_VPC = Variable.get("LOD_NET_VPC") +LOD_NET_SUBNET = Variable.get("LOD_NET_SUBNET") +LOD_SA_DF = Variable.get("LOD_SA_DF") +ORC_PRJ = Variable.get("ORC_PRJ") +ORC_GCS = Variable.get("ORC_GCS") +ORC_GCS_TMP_DF = Variable.get("ORC_GCS_TMP_DF") +TRF_PRJ = Variable.get("TRF_PRJ") +TRF_GCS_STAGING = Variable.get("TRF_GCS_STAGING") +TRF_NET_VPC = Variable.get("TRF_NET_VPC") +TRF_NET_SUBNET = Variable.get("TRF_NET_SUBNET") +TRF_SA_DF = Variable.get("TRF_SA_DF") +TRF_SA_BQ = Variable.get("TRF_SA_BQ") +DF_KMS_KEY = Variable.get("DF_KMS_KEY", "") +DF_REGION = Variable.get("GCP_REGION") +DF_ZONE = Variable.get("GCP_REGION") + "-b" # -------------------------------------------------------------------------------- # Set default arguments @@ -104,9 +103,9 @@ dataflow_environment = { with models.DAG('data_pipeline_dc_tags_dag_flex', default_args=default_args, schedule_interval=None) as dag: - start = dummy.DummyOperator(task_id='start', trigger_rule='all_success') + start = empty.EmptyOperator(task_id='start', trigger_rule='all_success') - end = dummy.DummyOperator(task_id='end', trigger_rule='all_success') + end = empty.EmptyOperator(task_id='end', trigger_rule='all_success') # Bigquery Tables created here for demo porpuse. # Consider a dedicated pipeline or tool for a real life scenario. diff --git a/blueprints/data-solutions/data-platform-foundations/demo/datapipeline_flex.py b/blueprints/data-solutions/data-platform-foundations/demo/datapipeline_flex.py index 34ff10cc..5e60c62f 100644 --- a/blueprints/data-solutions/data-platform-foundations/demo/datapipeline_flex.py +++ b/blueprints/data-solutions/data-platform-foundations/demo/datapipeline_flex.py @@ -17,54 +17,53 @@ # -------------------------------------------------------------------------------- import datetime -import json -import os import time from airflow import models +from airflow.models.variable import Variable from airflow.providers.google.cloud.operators.dataflow import DataflowStartFlexTemplateOperator -from airflow.operators import dummy +from airflow.operators import empty from airflow.providers.google.cloud.operators.bigquery import BigQueryInsertJobOperator # -------------------------------------------------------------------------------- # Set variables - Needed for the DEMO # -------------------------------------------------------------------------------- -BQ_LOCATION = os.environ.get("BQ_LOCATION") -DATA_CAT_TAGS = json.loads(os.environ.get("DATA_CAT_TAGS")) -DWH_LAND_PRJ = os.environ.get("DWH_LAND_PRJ") -DWH_LAND_BQ_DATASET = os.environ.get("DWH_LAND_BQ_DATASET") -DWH_LAND_GCS = os.environ.get("DWH_LAND_GCS") -DWH_CURATED_PRJ = os.environ.get("DWH_CURATED_PRJ") -DWH_CURATED_BQ_DATASET = os.environ.get("DWH_CURATED_BQ_DATASET") -DWH_CURATED_GCS = os.environ.get("DWH_CURATED_GCS") -DWH_CONFIDENTIAL_PRJ = os.environ.get("DWH_CONFIDENTIAL_PRJ") -DWH_CONFIDENTIAL_BQ_DATASET = os.environ.get("DWH_CONFIDENTIAL_BQ_DATASET") -DWH_CONFIDENTIAL_GCS = os.environ.get("DWH_CONFIDENTIAL_GCS") -DWH_PLG_PRJ = os.environ.get("DWH_PLG_PRJ") -DWH_PLG_BQ_DATASET = os.environ.get("DWH_PLG_BQ_DATASET") -DWH_PLG_GCS = os.environ.get("DWH_PLG_GCS") -GCP_REGION = os.environ.get("GCP_REGION") -DRP_PRJ = os.environ.get("DRP_PRJ") -DRP_BQ = os.environ.get("DRP_BQ") -DRP_GCS = os.environ.get("DRP_GCS") -DRP_PS = os.environ.get("DRP_PS") -LOD_PRJ = os.environ.get("LOD_PRJ") -LOD_GCS_STAGING = os.environ.get("LOD_GCS_STAGING") -LOD_NET_VPC = os.environ.get("LOD_NET_VPC") -LOD_NET_SUBNET = os.environ.get("LOD_NET_SUBNET") -LOD_SA_DF = os.environ.get("LOD_SA_DF") -ORC_PRJ = os.environ.get("ORC_PRJ") -ORC_GCS = os.environ.get("ORC_GCS") -ORC_GCS_TMP_DF = os.environ.get("ORC_GCS_TMP_DF") -TRF_PRJ = os.environ.get("TRF_PRJ") -TRF_GCS_STAGING = os.environ.get("TRF_GCS_STAGING") -TRF_NET_VPC = os.environ.get("TRF_NET_VPC") -TRF_NET_SUBNET = os.environ.get("TRF_NET_SUBNET") -TRF_SA_DF = os.environ.get("TRF_SA_DF") -TRF_SA_BQ = os.environ.get("TRF_SA_BQ") -DF_KMS_KEY = os.environ.get("DF_KMS_KEY", "") -DF_REGION = os.environ.get("GCP_REGION") -DF_ZONE = os.environ.get("GCP_REGION") + "-b" +BQ_LOCATION = Variable.get("BQ_LOCATION") +DATA_CAT_TAGS = Variable.get("DATA_CAT_TAGS", deserialize_json=True) +DWH_LAND_PRJ = Variable.get("DWH_LAND_PRJ") +DWH_LAND_BQ_DATASET = Variable.get("DWH_LAND_BQ_DATASET") +DWH_LAND_GCS = Variable.get("DWH_LAND_GCS") +DWH_CURATED_PRJ = Variable.get("DWH_CURATED_PRJ") +DWH_CURATED_BQ_DATASET = Variable.get("DWH_CURATED_BQ_DATASET") +DWH_CURATED_GCS = Variable.get("DWH_CURATED_GCS") +DWH_CONFIDENTIAL_PRJ = Variable.get("DWH_CONFIDENTIAL_PRJ") +DWH_CONFIDENTIAL_BQ_DATASET = Variable.get("DWH_CONFIDENTIAL_BQ_DATASET") +DWH_CONFIDENTIAL_GCS = Variable.get("DWH_CONFIDENTIAL_GCS") +DWH_PLG_PRJ = Variable.get("DWH_PLG_PRJ") +DWH_PLG_BQ_DATASET = Variable.get("DWH_PLG_BQ_DATASET") +DWH_PLG_GCS = Variable.get("DWH_PLG_GCS") +GCP_REGION = Variable.get("GCP_REGION") +DRP_PRJ = Variable.get("DRP_PRJ") +DRP_BQ = Variable.get("DRP_BQ") +DRP_GCS = Variable.get("DRP_GCS") +DRP_PS = Variable.get("DRP_PS") +LOD_PRJ = Variable.get("LOD_PRJ") +LOD_GCS_STAGING = Variable.get("LOD_GCS_STAGING") +LOD_NET_VPC = Variable.get("LOD_NET_VPC") +LOD_NET_SUBNET = Variable.get("LOD_NET_SUBNET") +LOD_SA_DF = Variable.get("LOD_SA_DF") +ORC_PRJ = Variable.get("ORC_PRJ") +ORC_GCS = Variable.get("ORC_GCS") +ORC_GCS_TMP_DF = Variable.get("ORC_GCS_TMP_DF") +TRF_PRJ = Variable.get("TRF_PRJ") +TRF_GCS_STAGING = Variable.get("TRF_GCS_STAGING") +TRF_NET_VPC = Variable.get("TRF_NET_VPC") +TRF_NET_SUBNET = Variable.get("TRF_NET_SUBNET") +TRF_SA_DF = Variable.get("TRF_SA_DF") +TRF_SA_BQ = Variable.get("TRF_SA_BQ") +DF_KMS_KEY = Variable.get("DF_KMS_KEY", "") +DF_REGION = Variable.get("GCP_REGION") +DF_ZONE = Variable.get("GCP_REGION") + "-b" # -------------------------------------------------------------------------------- # Set default arguments @@ -104,9 +103,9 @@ with models.DAG('data_pipeline_dag_flex', default_args=default_args, schedule_interval=None) as dag: - start = dummy.DummyOperator(task_id='start', trigger_rule='all_success') + start = empty.EmptyOperator(task_id='start', trigger_rule='all_success') - end = dummy.DummyOperator(task_id='end', trigger_rule='all_success') + end = empty.EmptyOperator(task_id='end', trigger_rule='all_success') # Bigquery Tables automatically created for demo purposes. # Consider a dedicated pipeline or tool for a real life scenario. diff --git a/blueprints/data-solutions/data-platform-foundations/demo/delete_table.py b/blueprints/data-solutions/data-platform-foundations/demo/delete_table.py index bade0388..252400ad 100644 --- a/blueprints/data-solutions/data-platform-foundations/demo/delete_table.py +++ b/blueprints/data-solutions/data-platform-foundations/demo/delete_table.py @@ -24,49 +24,49 @@ import logging import os from airflow import models -from airflow.providers.google.cloud.operators.dataflow import DataflowTemplatedJobStartOperator -from airflow.operators import dummy +from airflow.models.variable import Variable +from airflow.operators import empty from airflow.providers.google.cloud.operators.bigquery import BigQueryDeleteTableOperator from airflow.utils.task_group import TaskGroup # -------------------------------------------------------------------------------- # Set variables - Needed for the DEMO # -------------------------------------------------------------------------------- -BQ_LOCATION = os.environ.get("BQ_LOCATION") -DATA_CAT_TAGS = json.loads(os.environ.get("DATA_CAT_TAGS")) -DWH_LAND_PRJ = os.environ.get("DWH_LAND_PRJ") -DWH_LAND_BQ_DATASET = os.environ.get("DWH_LAND_BQ_DATASET") -DWH_LAND_GCS = os.environ.get("DWH_LAND_GCS") -DWH_CURATED_PRJ = os.environ.get("DWH_CURATED_PRJ") -DWH_CURATED_BQ_DATASET = os.environ.get("DWH_CURATED_BQ_DATASET") -DWH_CURATED_GCS = os.environ.get("DWH_CURATED_GCS") -DWH_CONFIDENTIAL_PRJ = os.environ.get("DWH_CONFIDENTIAL_PRJ") -DWH_CONFIDENTIAL_BQ_DATASET = os.environ.get("DWH_CONFIDENTIAL_BQ_DATASET") -DWH_CONFIDENTIAL_GCS = os.environ.get("DWH_CONFIDENTIAL_GCS") -DWH_PLG_PRJ = os.environ.get("DWH_PLG_PRJ") -DWH_PLG_BQ_DATASET = os.environ.get("DWH_PLG_BQ_DATASET") -DWH_PLG_GCS = os.environ.get("DWH_PLG_GCS") -GCP_REGION = os.environ.get("GCP_REGION") -DRP_PRJ = os.environ.get("DRP_PRJ") -DRP_BQ = os.environ.get("DRP_BQ") -DRP_GCS = os.environ.get("DRP_GCS") -DRP_PS = os.environ.get("DRP_PS") -LOD_PRJ = os.environ.get("LOD_PRJ") -LOD_GCS_STAGING = os.environ.get("LOD_GCS_STAGING") -LOD_NET_VPC = os.environ.get("LOD_NET_VPC") -LOD_NET_SUBNET = os.environ.get("LOD_NET_SUBNET") -LOD_SA_DF = os.environ.get("LOD_SA_DF") -ORC_PRJ = os.environ.get("ORC_PRJ") -ORC_GCS = os.environ.get("ORC_GCS") -TRF_PRJ = os.environ.get("TRF_PRJ") -TRF_GCS_STAGING = os.environ.get("TRF_GCS_STAGING") -TRF_NET_VPC = os.environ.get("TRF_NET_VPC") -TRF_NET_SUBNET = os.environ.get("TRF_NET_SUBNET") -TRF_SA_DF = os.environ.get("TRF_SA_DF") -TRF_SA_BQ = os.environ.get("TRF_SA_BQ") -DF_KMS_KEY = os.environ.get("DF_KMS_KEY", "") -DF_REGION = os.environ.get("GCP_REGION") -DF_ZONE = os.environ.get("GCP_REGION") + "-b" +BQ_LOCATION = Variable.get("BQ_LOCATION") +DATA_CAT_TAGS = Variable.get("DATA_CAT_TAGS", deserialize_json=True) +DWH_LAND_PRJ = Variable.get("DWH_LAND_PRJ") +DWH_LAND_BQ_DATASET = Variable.get("DWH_LAND_BQ_DATASET") +DWH_LAND_GCS = Variable.get("DWH_LAND_GCS") +DWH_CURATED_PRJ = Variable.get("DWH_CURATED_PRJ") +DWH_CURATED_BQ_DATASET = Variable.get("DWH_CURATED_BQ_DATASET") +DWH_CURATED_GCS = Variable.get("DWH_CURATED_GCS") +DWH_CONFIDENTIAL_PRJ = Variable.get("DWH_CONFIDENTIAL_PRJ") +DWH_CONFIDENTIAL_BQ_DATASET = Variable.get("DWH_CONFIDENTIAL_BQ_DATASET") +DWH_CONFIDENTIAL_GCS = Variable.get("DWH_CONFIDENTIAL_GCS") +DWH_PLG_PRJ = Variable.get("DWH_PLG_PRJ") +DWH_PLG_BQ_DATASET = Variable.get("DWH_PLG_BQ_DATASET") +DWH_PLG_GCS = Variable.get("DWH_PLG_GCS") +GCP_REGION = Variable.get("GCP_REGION") +DRP_PRJ = Variable.get("DRP_PRJ") +DRP_BQ = Variable.get("DRP_BQ") +DRP_GCS = Variable.get("DRP_GCS") +DRP_PS = Variable.get("DRP_PS") +LOD_PRJ = Variable.get("LOD_PRJ") +LOD_GCS_STAGING = Variable.get("LOD_GCS_STAGING") +LOD_NET_VPC = Variable.get("LOD_NET_VPC") +LOD_NET_SUBNET = Variable.get("LOD_NET_SUBNET") +LOD_SA_DF = Variable.get("LOD_SA_DF") +ORC_PRJ = Variable.get("ORC_PRJ") +ORC_GCS = Variable.get("ORC_GCS") +TRF_PRJ = Variable.get("TRF_PRJ") +TRF_GCS_STAGING = Variable.get("TRF_GCS_STAGING") +TRF_NET_VPC = Variable.get("TRF_NET_VPC") +TRF_NET_SUBNET = Variable.get("TRF_NET_SUBNET") +TRF_SA_DF = Variable.get("TRF_SA_DF") +TRF_SA_BQ = Variable.get("TRF_SA_BQ") +DF_KMS_KEY = Variable.get("DF_KMS_KEY", "") +DF_REGION = Variable.get("GCP_REGION") +DF_ZONE = Variable.get("GCP_REGION") + "-b" # -------------------------------------------------------------------------------- # Set default arguments @@ -106,19 +106,19 @@ with models.DAG( 'delete_tables_dag', default_args=default_args, schedule_interval=None) as dag: - start = dummy.DummyOperator( + start = empty.EmptyOperator( task_id='start', trigger_rule='all_success' ) - end = dummy.DummyOperator( + end = empty.EmptyOperator( task_id='end', trigger_rule='all_success' ) # Bigquery Tables deleted here for demo porpuse. # Consider a dedicated pipeline or tool for a real life scenario. - with TaskGroup('delete_table') as delte_table: + with TaskGroup('delete_table') as delete_table: delete_table_customers = BigQueryDeleteTableOperator( task_id="delete_table_customers", deletion_dataset_table=DWH_LAND_PRJ+"."+DWH_LAND_BQ_DATASET+".customers", @@ -143,4 +143,4 @@ with models.DAG( impersonation_chain=[TRF_SA_DF] ) - start >> delte_table >> end + start >> delete_table >> end diff --git a/blueprints/data-solutions/data-platform-minimal/01-landing.tf b/blueprints/data-solutions/data-platform-minimal/01-landing.tf index 94ecf5a3..52bf6e8a 100644 --- a/blueprints/data-solutions/data-platform-minimal/01-landing.tf +++ b/blueprints/data-solutions/data-platform-minimal/01-landing.tf @@ -64,6 +64,7 @@ module "land-project" { "bigquerystorage.googleapis.com", "cloudkms.googleapis.com", "cloudresourcemanager.googleapis.com", + "datalineage.googleapis.com", "iam.googleapis.com", "serviceusage.googleapis.com", "stackdriver.googleapis.com", diff --git a/blueprints/data-solutions/data-platform-minimal/02-composer.tf b/blueprints/data-solutions/data-platform-minimal/02-composer.tf index da6fca9a..c250b1fd 100644 --- a/blueprints/data-solutions/data-platform-minimal/02-composer.tf +++ b/blueprints/data-solutions/data-platform-minimal/02-composer.tf @@ -15,7 +15,7 @@ # tfdoc:file:description Cloud Composer resources. locals { - env_variables = { + _env_variables = { BQ_LOCATION = var.location CURATED_BQ_DATASET = module.cur-bq-0.dataset_id CURATED_GCS = module.cur-cs-0.url @@ -31,6 +31,11 @@ locals { PROCESSING_SUBNET = local.processing_subnet PROCESSING_VPC = local.processing_vpc } + env_variables = { + for k, v in merge( + var.composer_config.software_config.env_variables, local._env_variables + ) : "AIRFLOW_VAR_${k}" => v + } } module "processing-sa-cmp-0" { @@ -46,18 +51,20 @@ module "processing-sa-cmp-0" { } resource "google_composer_environment" "processing-cmp-0" { - count = var.enable_services.composer == true ? 1 : 0 - project = module.processing-project.project_id - name = "${var.prefix}-prc-cmp-0" - region = var.region + count = var.enable_services.composer == true ? 1 : 0 + provider = google-beta + project = module.processing-project.project_id + name = "${var.prefix}-prc-cmp-0" + region = var.region config { software_config { airflow_config_overrides = var.composer_config.software_config.airflow_config_overrides pypi_packages = var.composer_config.software_config.pypi_packages - env_variables = merge( - var.composer_config.software_config.env_variables, local.env_variables - ) - image_version = var.composer_config.software_config.image_version + env_variables = local.env_variables + image_version = var.composer_config.software_config.image_version + cloud_data_lineage_integration { + enabled = var.composer_config.software_config.cloud_data_lineage_integration + } } workloads_config { scheduler { diff --git a/blueprints/data-solutions/data-platform-minimal/02-processing.tf b/blueprints/data-solutions/data-platform-minimal/02-processing.tf index 1bba98da..720e2a81 100644 --- a/blueprints/data-solutions/data-platform-minimal/02-processing.tf +++ b/blueprints/data-solutions/data-platform-minimal/02-processing.tf @@ -118,6 +118,7 @@ module "processing-project" { "compute.googleapis.com", "container.googleapis.com", "dataflow.googleapis.com", + "datalineage.googleapis.com", "dataproc.googleapis.com", "iam.googleapis.com", "servicenetworking.googleapis.com", diff --git a/blueprints/data-solutions/data-platform-minimal/03-curated.tf b/blueprints/data-solutions/data-platform-minimal/03-curated.tf index 8bff815f..53a6e7b2 100644 --- a/blueprints/data-solutions/data-platform-minimal/03-curated.tf +++ b/blueprints/data-solutions/data-platform-minimal/03-curated.tf @@ -22,6 +22,7 @@ locals { "cloudkms.googleapis.com", "cloudresourcemanager.googleapis.com", "compute.googleapis.com", + "datalineage.googleapis.com", "iam.googleapis.com", "servicenetworking.googleapis.com", "serviceusage.googleapis.com", diff --git a/blueprints/data-solutions/data-platform-minimal/README.md b/blueprints/data-solutions/data-platform-minimal/README.md index 1f4eb777..62b30acd 100644 --- a/blueprints/data-solutions/data-platform-minimal/README.md +++ b/blueprints/data-solutions/data-platform-minimal/README.md @@ -229,7 +229,7 @@ module "data-platform" { prefix = "myprefix" } -# tftest modules=23 resources=135 +# tftest modules=23 resources=138 ``` ## Customizations @@ -302,19 +302,19 @@ The application layer is out of scope of this script. As a demo purpuse only, on | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [organization_domain](variables.tf#L122) | Organization domain. | string | ✓ | | -| [prefix](variables.tf#L127) | Prefix used for resource names. | string | ✓ | | -| [project_config](variables.tf#L136) | Provide 'billing_account_id' value if project creation is needed, uses existing 'project_ids' if null. Parent is in 'folders/nnn' or 'organizations/nnn' format. | object({…}) | ✓ | | -| [composer_config](variables.tf#L17) | Cloud Composer config. | object({…}) | | {} | -| [data_catalog_tags](variables.tf#L55) | List of Data Catalog Policy tags to be created with optional IAM binging configuration in {tag => {ROLE => [MEMBERS]}} format. | map(object({…})) | | {…} | -| [data_force_destroy](variables.tf#L69) | Flag to set 'force_destroy' on data services like BiguQery or Cloud Storage. | bool | | false | -| [enable_services](variables.tf#L75) | Flag to enable or disable services in the Data Platform. | object({…}) | | {} | -| [groups](variables.tf#L84) | User groups. | map(string) | | {…} | -| [location](variables.tf#L94) | Location used for multi-regional resources. | string | | "eu" | -| [network_config](variables.tf#L100) | Shared VPC network configurations to use. If null networks will be created in projects. | object({…}) | | {} | -| [project_suffix](variables.tf#L160) | Suffix used only for project ids. | string | | null | -| [region](variables.tf#L166) | Region used for regional resources. | string | | "europe-west1" | -| [service_encryption_keys](variables.tf#L172) | Cloud KMS to use to encrypt different services. Key location should match service region. | object({…}) | | {} | +| [organization_domain](variables.tf#L123) | Organization domain. | string | ✓ | | +| [prefix](variables.tf#L128) | Prefix used for resource names. | string | ✓ | | +| [project_config](variables.tf#L137) | Provide 'billing_account_id' value if project creation is needed, uses existing 'project_ids' if null. Parent is in 'folders/nnn' or 'organizations/nnn' format. | object({…}) | ✓ | | +| [composer_config](variables.tf#L17) | Cloud Composer config. | object({…}) | | {} | +| [data_catalog_tags](variables.tf#L56) | List of Data Catalog Policy tags to be created with optional IAM binging configuration in {tag => {ROLE => [MEMBERS]}} format. | map(object({…})) | | {…} | +| [data_force_destroy](variables.tf#L70) | Flag to set 'force_destroy' on data services like BiguQery or Cloud Storage. | bool | | false | +| [enable_services](variables.tf#L76) | Flag to enable or disable services in the Data Platform. | object({…}) | | {} | +| [groups](variables.tf#L85) | User groups. | map(string) | | {…} | +| [location](variables.tf#L95) | Location used for multi-regional resources. | string | | "eu" | +| [network_config](variables.tf#L101) | Shared VPC network configurations to use. If null networks will be created in projects. | object({…}) | | {} | +| [project_suffix](variables.tf#L161) | Suffix used only for project ids. | string | | null | +| [region](variables.tf#L167) | Region used for regional resources. | string | | "europe-west1" | +| [service_encryption_keys](variables.tf#L173) | Cloud KMS to use to encrypt different services. Key location should match service region. | object({…}) | | {} | ## Outputs diff --git a/blueprints/data-solutions/data-platform-minimal/demo/README.md b/blueprints/data-solutions/data-platform-minimal/demo/README.md index b9a24b82..f3c1cbf7 100644 --- a/blueprints/data-solutions/data-platform-minimal/demo/README.md +++ b/blueprints/data-solutions/data-platform-minimal/demo/README.md @@ -54,5 +54,5 @@ source ./env.sh gsutil -i $LND_SA cp demo/data/*.csv gs://$LND_GCS gsutil -i $CMP_SA cp demo/data/*.j* gs://$PRC_GCS gsutil -i $CMP_SA cp demo/pyspark_* gs://$PRC_GCS -gsutil -i $CMP_SA cp demo/dag_*.py $CMP_GCS +gsutil -i $CMP_SA cp demo/dag_*.py gs://$CMP_GCS/dags ``` diff --git a/blueprints/data-solutions/data-platform-minimal/demo/dag_bq_gcs2bq.py b/blueprints/data-solutions/data-platform-minimal/demo/dag_bq_gcs2bq.py index 7abf3691..321071b2 100644 --- a/blueprints/data-solutions/data-platform-minimal/demo/dag_bq_gcs2bq.py +++ b/blueprints/data-solutions/data-platform-minimal/demo/dag_bq_gcs2bq.py @@ -16,34 +16,30 @@ # Load The Dependencies # -------------------------------------------------------------------------------- -import csv import datetime -import io -import json -import logging -import os from airflow import models -from airflow.operators import dummy +from airflow.models.variable import Variable +from airflow.operators import empty from airflow.providers.google.cloud.transfers.gcs_to_bigquery import GCSToBigQueryOperator # -------------------------------------------------------------------------------- # Set variables - Needed for the DEMO # -------------------------------------------------------------------------------- -BQ_LOCATION = os.environ.get("BQ_LOCATION") -CURATED_PRJ = os.environ.get("CURATED_PRJ") -CURATED_BQ_DATASET = os.environ.get("CURATED_BQ_DATASET") -CURATED_GCS = os.environ.get("CURATED_GCS") -LAND_PRJ = os.environ.get("LAND_PRJ") -LAND_GCS = os.environ.get("LAND_GCS") -PROCESSING_GCS = os.environ.get("PROCESSING_GCS") -PROCESSING_SA = os.environ.get("PROCESSING_SA") -PROCESSING_PRJ = os.environ.get("PROCESSING_PRJ") -PROCESSING_SUBNET = os.environ.get("PROCESSING_SUBNET") -PROCESSING_VPC = os.environ.get("PROCESSING_VPC") -DP_KMS_KEY = os.environ.get("DP_KMS_KEY", "") -DP_REGION = os.environ.get("DP_REGION") -DP_ZONE = os.environ.get("DP_REGION") + "-b" +BQ_LOCATION = Variable.get("BQ_LOCATION") +CURATED_PRJ = Variable.get("CURATED_PRJ") +CURATED_BQ_DATASET = Variable.get("CURATED_BQ_DATASET") +CURATED_GCS = Variable.get("CURATED_GCS") +LAND_PRJ = Variable.get("LAND_PRJ") +LAND_GCS = Variable.get("LAND_GCS") +PROCESSING_GCS = Variable.get("PROCESSING_GCS") +PROCESSING_SA = Variable.get("PROCESSING_SA") +PROCESSING_PRJ = Variable.get("PROCESSING_PRJ") +PROCESSING_SUBNET = Variable.get("PROCESSING_SUBNET") +PROCESSING_VPC = Variable.get("PROCESSING_VPC") +DP_KMS_KEY = Variable.get("DP_KMS_KEY", "") +DP_REGION = Variable.get("DP_REGION") +DP_ZONE = Variable.get("DP_REGION") + "-b" # -------------------------------------------------------------------------------- # Set default arguments @@ -73,12 +69,12 @@ with models.DAG( 'bq_gcs2bq', default_args=default_args, schedule_interval=None) as dag: - start = dummy.DummyOperator( + start = empty.EmptyOperator( task_id='start', trigger_rule='all_success' ) - end = dummy.DummyOperator( + end = empty.EmptyOperator( task_id='end', trigger_rule='all_success' ) @@ -96,7 +92,7 @@ with models.DAG( schema_update_options=['ALLOW_FIELD_RELAXATION', 'ALLOW_FIELD_ADDITION'], schema_object="customers.json", schema_object_bucket=PROCESSING_GCS[5:], - project_id=PROCESSING_PRJ, # The process will continue to run on the dataset project until the Apache Airflow bug is fixed. https://github.com/apache/airflow/issues/32106 + project_id=PROCESSING_PRJ, impersonation_chain=[PROCESSING_SA] ) diff --git a/blueprints/data-solutions/data-platform-minimal/demo/dag_dataflow_gcs2bq.py b/blueprints/data-solutions/data-platform-minimal/demo/dag_dataflow_gcs2bq.py index 6556de8f..111efcdc 100644 --- a/blueprints/data-solutions/data-platform-minimal/demo/dag_dataflow_gcs2bq.py +++ b/blueprints/data-solutions/data-platform-minimal/demo/dag_dataflow_gcs2bq.py @@ -16,36 +16,30 @@ # Load The Dependencies # -------------------------------------------------------------------------------- -import csv import datetime -import io -import json -import logging -import os from airflow import models +from airflow.models.variable import Variable +from airflow.operators import empty from airflow.providers.google.cloud.operators.dataflow import DataflowTemplatedJobStartOperator -from airflow.operators import dummy -from airflow.providers.google.cloud.operators.bigquery import BigQueryInsertJobOperator, BigQueryUpsertTableOperator, BigQueryUpdateTableSchemaOperator -from airflow.utils.task_group import TaskGroup # -------------------------------------------------------------------------------- # Set variables - Needed for the DEMO # -------------------------------------------------------------------------------- -BQ_LOCATION = os.environ.get("BQ_LOCATION") -CURATED_PRJ = os.environ.get("CURATED_PRJ") -CURATED_BQ_DATASET = os.environ.get("CURATED_BQ_DATASET") -CURATED_GCS = os.environ.get("CURATED_GCS") -LAND_PRJ = os.environ.get("LAND_PRJ") -LAND_GCS = os.environ.get("LAND_GCS") -PROCESSING_GCS = os.environ.get("PROCESSING_GCS") -PROCESSING_SA = os.environ.get("PROCESSING_SA") -PROCESSING_PRJ = os.environ.get("PROCESSING_PRJ") -PROCESSING_SUBNET = os.environ.get("PROCESSING_SUBNET") -PROCESSING_VPC = os.environ.get("PROCESSING_VPC") -DP_KMS_KEY = os.environ.get("DP_KMS_KEY", "") -DP_REGION = os.environ.get("DP_REGION") -DP_ZONE = os.environ.get("DP_REGION") + "-b" +BQ_LOCATION = Variable.get("BQ_LOCATION") +CURATED_PRJ = Variable.get("CURATED_PRJ") +CURATED_BQ_DATASET = Variable.get("CURATED_BQ_DATASET") +CURATED_GCS = Variable.get("CURATED_GCS") +LAND_PRJ = Variable.get("LAND_PRJ") +LAND_GCS = Variable.get("LAND_GCS") +PROCESSING_GCS = Variable.get("PROCESSING_GCS") +PROCESSING_SA = Variable.get("PROCESSING_SA") +PROCESSING_PRJ = Variable.get("PROCESSING_PRJ") +PROCESSING_SUBNET = Variable.get("PROCESSING_SUBNET") +PROCESSING_VPC = Variable.get("PROCESSING_VPC") +DP_KMS_KEY = Variable.get("DP_KMS_KEY", "") +DP_REGION = Variable.get("DP_REGION") +DP_ZONE = Variable.get("DP_REGION") + "-b" # -------------------------------------------------------------------------------- # Set default arguments @@ -85,12 +79,12 @@ with models.DAG( 'dataflow_gcs2bq', default_args=default_args, schedule_interval=None) as dag: - start = dummy.DummyOperator( + start = empty.EmptyOperator( task_id='start', trigger_rule='all_success' ) - end = dummy.DummyOperator( + end = empty.EmptyOperator( task_id='end', trigger_rule='all_success' ) diff --git a/blueprints/data-solutions/data-platform-minimal/demo/dag_dataproc_gcs2bq.py b/blueprints/data-solutions/data-platform-minimal/demo/dag_dataproc_gcs2bq.py index a404fa06..3a3dab52 100644 --- a/blueprints/data-solutions/data-platform-minimal/demo/dag_dataproc_gcs2bq.py +++ b/blueprints/data-solutions/data-platform-minimal/demo/dag_dataproc_gcs2bq.py @@ -14,14 +14,13 @@ # See the License for the specific language governing permissions and # limitations under the License. -import datetime import time -import os from airflow import models -from airflow.operators import dummy +from airflow.models.variable import Variable +from airflow.operators import empty from airflow.providers.google.cloud.operators.dataproc import ( - DataprocCreateBatchOperator, DataprocDeleteBatchOperator, DataprocGetBatchOperator, DataprocListBatchesOperator + DataprocCreateBatchOperator ) from airflow.utils.dates import days_ago @@ -29,22 +28,21 @@ from airflow.utils.dates import days_ago # -------------------------------------------------------------------------------- # Get variables # -------------------------------------------------------------------------------- -BQ_LOCATION = os.environ.get("BQ_LOCATION") -CURATED_BQ_DATASET = os.environ.get("CURATED_BQ_DATASET") -CURATED_GCS = os.environ.get("CURATED_GCS") -CURATED_PRJ = os.environ.get("CURATED_PRJ") -DP_KMS_KEY = os.environ.get("DP_KMS_KEY", "") -DP_REGION = os.environ.get("DP_REGION") -GCP_REGION = os.environ.get("GCP_REGION") -LAND_PRJ = os.environ.get("LAND_PRJ") -LAND_BQ_DATASET = os.environ.get("LAND_BQ_DATASET") -LAND_GCS = os.environ.get("LAND_GCS") -PHS_CLUSTER_NAME = os.environ.get("PHS_CLUSTER_NAME") -PROCESSING_GCS = os.environ.get("PROCESSING_GCS") -PROCESSING_PRJ = os.environ.get("PROCESSING_PRJ") -PROCESSING_SA = os.environ.get("PROCESSING_SA") -PROCESSING_SUBNET = os.environ.get("PROCESSING_SUBNET") -PROCESSING_VPC = os.environ.get("PROCESSING_VPC") +BQ_LOCATION = Variable.get("BQ_LOCATION") +CURATED_BQ_DATASET = Variable.get("CURATED_BQ_DATASET") +CURATED_GCS = Variable.get("CURATED_GCS") +CURATED_PRJ = Variable.get("CURATED_PRJ") +DP_KMS_KEY = Variable.get("DP_KMS_KEY", "") +DP_REGION = Variable.get("DP_REGION") +LAND_PRJ = Variable.get("LAND_PRJ") +LAND_BQ_DATASET = Variable.get("LAND_BQ_DATASET") +LAND_GCS = Variable.get("LAND_GCS") +PHS_CLUSTER_NAME = Variable.get("PHS_CLUSTER_NAME") +PROCESSING_GCS = Variable.get("PROCESSING_GCS") +PROCESSING_PRJ = Variable.get("PROCESSING_PRJ") +PROCESSING_SA = Variable.get("PROCESSING_SA") +PROCESSING_SUBNET = Variable.get("PROCESSING_SUBNET") +PROCESSING_VPC = Variable.get("PROCESSING_VPC") PYTHON_FILE_LOCATION = PROCESSING_GCS+"/pyspark_gcs2bq.py" PHS_CLUSTER_PATH = "projects/"+PROCESSING_PRJ+"/regions/"+DP_REGION+"/clusters/"+PHS_CLUSTER_NAME @@ -61,12 +59,12 @@ with models.DAG( default_args=default_args, # The interval with which to schedule the DAG schedule_interval=None, # Override to match your needs ) as dag: - start = dummy.DummyOperator( + start = empty.EmptyOperator( task_id='start', trigger_rule='all_success' ) - end = dummy.DummyOperator( + end = empty.EmptyOperator( task_id='end', trigger_rule='all_success' ) diff --git a/blueprints/data-solutions/data-platform-minimal/demo/dag_delete_table.py b/blueprints/data-solutions/data-platform-minimal/demo/dag_delete_table.py index c17c1381..9653cac7 100644 --- a/blueprints/data-solutions/data-platform-minimal/demo/dag_delete_table.py +++ b/blueprints/data-solutions/data-platform-minimal/demo/dag_delete_table.py @@ -16,36 +16,31 @@ # Load The Dependencies # -------------------------------------------------------------------------------- -import csv import datetime -import io -import json -import logging -import os from airflow import models -from airflow.providers.google.cloud.operators.dataflow import DataflowTemplatedJobStartOperator -from airflow.operators import dummy +from airflow.models.variable import Variable +from airflow.operators import empty from airflow.providers.google.cloud.operators.bigquery import BigQueryDeleteTableOperator from airflow.utils.task_group import TaskGroup # -------------------------------------------------------------------------------- # Set variables - Needed for the DEMO # -------------------------------------------------------------------------------- -BQ_LOCATION = os.environ.get("BQ_LOCATION") -CURATED_PRJ = os.environ.get("CURATED_PRJ") -CURATED_BQ_DATASET = os.environ.get("CURATED_BQ_DATASET") -CURATED_GCS = os.environ.get("CURATED_GCS") -LAND_PRJ = os.environ.get("LAND_PRJ") -LAND_GCS = os.environ.get("LAND_GCS") -PROCESSING_GCS = os.environ.get("PROCESSING_GCS") -PROCESSING_SA = os.environ.get("PROCESSING_SA") -PROCESSING_PRJ = os.environ.get("PROCESSING_PRJ") -PROCESSING_SUBNET = os.environ.get("PROCESSING_SUBNET") -PROCESSING_VPC = os.environ.get("PROCESSING_VPC") -DP_KMS_KEY = os.environ.get("DP_KMS_KEY", "") -DP_REGION = os.environ.get("DP_REGION") -DP_ZONE = os.environ.get("DP_REGION") + "-b" +BQ_LOCATION = Variable.get("BQ_LOCATION") +CURATED_PRJ = Variable.get("CURATED_PRJ") +CURATED_BQ_DATASET = Variable.get("CURATED_BQ_DATASET") +CURATED_GCS = Variable.get("CURATED_GCS") +LAND_PRJ = Variable.get("LAND_PRJ") +LAND_GCS = Variable.get("LAND_GCS") +PROCESSING_GCS = Variable.get("PROCESSING_GCS") +PROCESSING_SA = Variable.get("PROCESSING_SA") +PROCESSING_PRJ = Variable.get("PROCESSING_PRJ") +PROCESSING_SUBNET = Variable.get("PROCESSING_SUBNET") +PROCESSING_VPC = Variable.get("PROCESSING_VPC") +DP_KMS_KEY = Variable.get("DP_KMS_KEY", "") +DP_REGION = Variable.get("DP_REGION") +DP_ZONE = Variable.get("DP_REGION") + "-b" # -------------------------------------------------------------------------------- # Set default arguments @@ -75,23 +70,23 @@ with models.DAG( 'delete_tables_dag', default_args=default_args, schedule_interval=None) as dag: - start = dummy.DummyOperator( + start = empty.EmptyOperator( task_id='start', trigger_rule='all_success' ) - end = dummy.DummyOperator( + end = empty.EmptyOperator( task_id='end', trigger_rule='all_success' ) # Bigquery Tables deleted here for demo porpuse. # Consider a dedicated pipeline or tool for a real life scenario. - with TaskGroup('delete_table') as delte_table: + with TaskGroup('delete_table') as delete_table: delete_table_customers = BigQueryDeleteTableOperator( task_id="delete_table_customers", deletion_dataset_table=CURATED_PRJ+"."+CURATED_BQ_DATASET+".customers", impersonation_chain=[PROCESSING_SA] ) - start >> delte_table >> end + start >> delete_table >> end diff --git a/blueprints/data-solutions/data-platform-minimal/demo/dag_orchestrate_pyspark.py b/blueprints/data-solutions/data-platform-minimal/demo/dag_orchestrate_pyspark.py index 0a68dbc0..4258e7e4 100644 --- a/blueprints/data-solutions/data-platform-minimal/demo/dag_orchestrate_pyspark.py +++ b/blueprints/data-solutions/data-platform-minimal/demo/dag_orchestrate_pyspark.py @@ -14,41 +14,38 @@ # See the License for the specific language governing permissions and # limitations under the License. -import datetime import time -import os from airflow import models -from airflow.operators import dummy +from airflow.models.variable import Variable +from airflow.operators import empty from airflow.providers.google.cloud.operators.dataproc import ( - DataprocCreateBatchOperator, DataprocDeleteBatchOperator, DataprocGetBatchOperator, DataprocListBatchesOperator - + DataprocCreateBatchOperator ) from airflow.utils.dates import days_ago # -------------------------------------------------------------------------------- # Get variables # -------------------------------------------------------------------------------- -BQ_LOCATION = os.environ.get("BQ_LOCATION") -CURATED_BQ_DATASET = os.environ.get("CURATED_BQ_DATASET") -CURATED_GCS = os.environ.get("CURATED_GCS") -CURATED_PRJ = os.environ.get("CURATED_PRJ") -DP_KMS_KEY = os.environ.get("DP_KMS_KEY", "") -DP_REGION = os.environ.get("DP_REGION") -GCP_REGION = os.environ.get("GCP_REGION") -LAND_PRJ = os.environ.get("LAND_PRJ") -LAND_BQ_DATASET = os.environ.get("LAND_BQ_DATASET") -LAND_GCS = os.environ.get("LAND_GCS") -PHS_CLUSTER_NAME = os.environ.get("PHS_CLUSTER_NAME") -PROCESSING_GCS = os.environ.get("PROCESSING_GCS") -PROCESSING_PRJ = os.environ.get("PROCESSING_PRJ") -PROCESSING_SA = os.environ.get("PROCESSING_SA") -PROCESSING_SUBNET = os.environ.get("PROCESSING_SUBNET") -PROCESSING_VPC = os.environ.get("PROCESSING_VPC") +BQ_LOCATION = Variable.get("BQ_LOCATION") +CURATED_BQ_DATASET = Variable.get("CURATED_BQ_DATASET") +CURATED_GCS = Variable.get("CURATED_GCS") +CURATED_PRJ = Variable.get("CURATED_PRJ") +DP_KMS_KEY = Variable.get("DP_KMS_KEY", "") +DP_REGION = Variable.get("DP_REGION") +LAND_PRJ = Variable.get("LAND_PRJ") +LAND_BQ_DATASET = Variable.get("LAND_BQ_DATASET") +LAND_GCS = Variable.get("LAND_GCS") +PHS_CLUSTER_NAME = Variable.get("PHS_CLUSTER_NAME") +PROCESSING_GCS = Variable.get("PROCESSING_GCS") +PROCESSING_PRJ = Variable.get("PROCESSING_PRJ") +PROCESSING_SA = Variable.get("PROCESSING_SA") +PROCESSING_SUBNET = Variable.get("PROCESSING_SUBNET") +PROCESSING_VPC = Variable.get("PROCESSING_VPC") -PYTHON_FILE_LOCATION = PROCESSING_GCS+"/pyspark_sort.py" -PHS_CLUSTER_PATH = "projects/"+PROCESSING_PRJ+"/regions/"+DP_REGION+"/clusters/"+PHS_CLUSTER_NAME -BATCH_ID = "batch-create-phs-"+str(int(time.time())) +PYTHON_FILE_LOCATION = PROCESSING_GCS + "/pyspark_sort.py" +PHS_CLUSTER_PATH = f"projects/{PROCESSING_PRJ}/regions/{DP_REGION}/clusters/{PHS_CLUSTER_NAME}" +BATCH_ID = "batch-create-phs-" + str(int(time.time())) default_args = { # Tell airflow to start one day ago, so that it runs as soon as you upload it @@ -60,12 +57,12 @@ with models.DAG( default_args=default_args, # The interval with which to schedule the DAG schedule_interval=None, # Override to match your needs ) as dag: - start = dummy.DummyOperator( + start = empty.EmptyOperator( task_id='start', trigger_rule='all_success' ) - end = dummy.DummyOperator( + end = empty.EmptyOperator( task_id='end', trigger_rule='all_success' ) diff --git a/blueprints/data-solutions/data-platform-minimal/variables.tf b/blueprints/data-solutions/data-platform-minimal/variables.tf index 0dc29003..0bd1deed 100644 --- a/blueprints/data-solutions/data-platform-minimal/variables.tf +++ b/blueprints/data-solutions/data-platform-minimal/variables.tf @@ -19,10 +19,11 @@ variable "composer_config" { type = object({ environment_size = optional(string, "ENVIRONMENT_SIZE_SMALL") software_config = optional(object({ - airflow_config_overrides = optional(map(string), {}) - pypi_packages = optional(map(string), {}) - env_variables = optional(map(string), {}) - image_version = optional(string, "composer-2-airflow-2") + airflow_config_overrides = optional(map(string), {}) + pypi_packages = optional(map(string), {}) + env_variables = optional(map(string), {}) + image_version = optional(string, "composer-2-airflow-2") + cloud_data_lineage_integration = optional(bool, true) }), {}) web_server_access_control = optional(map(string), {}) workloads_config = optional(object({ diff --git a/blueprints/data-solutions/data-playground/versions.tf b/blueprints/data-solutions/data-playground/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/data-solutions/data-playground/versions.tf +++ b/blueprints/data-solutions/data-playground/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/data-solutions/gcs-to-bq-with-least-privileges/kms.tf b/blueprints/data-solutions/gcs-to-bq-with-least-privileges/kms.tf index 5e616630..722016b7 100644 --- a/blueprints/data-solutions/gcs-to-bq-with-least-privileges/kms.tf +++ b/blueprints/data-solutions/gcs-to-bq-with-least-privileges/kms.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -21,26 +21,27 @@ module "kms" { location = var.region } keys = { - key-df = null - key-gcs = null - key-bq = null - } - key_iam = { - key-gcs = { - "roles/cloudkms.cryptoKeyEncrypterDecrypter" = [ - "serviceAccount:${module.project.service_accounts.robots.storage}" - ] - }, - key-bq = { - "roles/cloudkms.cryptoKeyEncrypterDecrypter" = [ - "serviceAccount:${module.project.service_accounts.robots.bq}" - ] - }, key-df = { - "roles/cloudkms.cryptoKeyEncrypterDecrypter" = [ - "serviceAccount:${module.project.service_accounts.robots.dataflow}", - "serviceAccount:${module.project.service_accounts.robots.compute}", - ] + iam = { + "roles/cloudkms.cryptoKeyEncrypterDecrypter" = [ + "serviceAccount:${module.project.service_accounts.robots.dataflow}", + "serviceAccount:${module.project.service_accounts.robots.compute}", + ] + } + } + key-gcs = { + iam = { + "roles/cloudkms.cryptoKeyEncrypterDecrypter" = [ + "serviceAccount:${module.project.service_accounts.robots.storage}" + ] + } + } + key-bq = { + iam = { + "roles/cloudkms.cryptoKeyEncrypterDecrypter" = [ + "serviceAccount:${module.project.service_accounts.robots.bq}" + ] + } } } } diff --git a/blueprints/data-solutions/gcs-to-bq-with-least-privileges/versions.tf b/blueprints/data-solutions/gcs-to-bq-with-least-privileges/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/data-solutions/gcs-to-bq-with-least-privileges/versions.tf +++ b/blueprints/data-solutions/gcs-to-bq-with-least-privileges/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/data-solutions/shielded-folder/README.md b/blueprints/data-solutions/shielded-folder/README.md index ed177d27..72a6b69f 100644 --- a/blueprints/data-solutions/shielded-folder/README.md +++ b/blueprints/data-solutions/shielded-folder/README.md @@ -159,18 +159,18 @@ terraform apply |---|---|:---:|:---:|:---:| | [access_policy_config](variables.tf#L17) | Provide 'access_policy_create' values if a folder scoped Access Policy creation is needed, uses existing 'policy_name' otherwise. Parent is in 'organizations/123456' format. Policy will be created scoped to the folder. | object({…}) | ✓ | | | [folder_config](variables.tf#L49) | Provide 'folder_create' values if folder creation is needed, uses existing 'folder_id' otherwise. Parent is in 'folders/nnn' or 'organizations/nnn' format. | object({…}) | ✓ | | -| [organization](variables.tf#L129) | Organization details. | object({…}) | ✓ | | -| [prefix](variables.tf#L137) | Prefix used for resources that need unique names. | string | ✓ | | -| [project_config](variables.tf#L142) | Provide 'billing_account_id' value if project creation is needed, uses existing 'project_ids' if null. Parent is in 'folders/nnn' or 'organizations/nnn' format. | object({…}) | ✓ | | +| [organization](variables.tf#L148) | Organization details. | object({…}) | ✓ | | +| [prefix](variables.tf#L156) | Prefix used for resources that need unique names. | string | ✓ | | +| [project_config](variables.tf#L161) | Provide 'billing_account_id' value if project creation is needed, uses existing 'project_ids' if null. Parent is in 'folders/nnn' or 'organizations/nnn' format. | object({…}) | ✓ | | | [data_dir](variables.tf#L29) | Relative path for the folder storing configuration data. | string | | "data" | | [enable_features](variables.tf#L35) | Flag to enable features on the solution. | object({…}) | | {…} | | [groups](variables.tf#L65) | User groups. | object({…}) | | {} | -| [kms_keys](variables.tf#L75) | KMS keys to create, keyed by name. | map(object({…})) | | {} | -| [log_locations](variables.tf#L87) | Optional locations for GCS, BigQuery, and logging buckets created here. | object({…}) | | {…} | -| [log_sinks](variables.tf#L104) | Org-level log sinks, in name => {type, filter} format. | map(object({…})) | | {…} | -| [vpc_sc_access_levels](variables.tf#L162) | VPC SC access level definitions. | map(object({…})) | | {} | -| [vpc_sc_egress_policies](variables.tf#L191) | VPC SC egress policy definitions. | map(object({…})) | | {} | -| [vpc_sc_ingress_policies](variables.tf#L211) | VPC SC ingress policy definitions. | map(object({…})) | | {} | +| [kms_keys](variables.tf#L75) | KMS keys to create, keyed by name. | map(object({…})) | | {} | +| [log_locations](variables.tf#L111) | Optional locations for GCS, BigQuery, and logging buckets created here. | object({…}) | | {} | +| [log_sinks](variables.tf#L123) | Org-level log sinks, in name => {type, filter} format. | map(object({…})) | | {…} | +| [vpc_sc_access_levels](variables.tf#L181) | VPC SC access level definitions. | map(object({…})) | | {} | +| [vpc_sc_egress_policies](variables.tf#L210) | VPC SC egress policy definitions. | map(object({…})) | | {} | +| [vpc_sc_ingress_policies](variables.tf#L230) | VPC SC ingress policy definitions. | map(object({…})) | | {} | ## Outputs diff --git a/blueprints/data-solutions/shielded-folder/kms.tf b/blueprints/data-solutions/shielded-folder/kms.tf index 9953d458..4a634fcc 100644 --- a/blueprints/data-solutions/shielded-folder/kms.tf +++ b/blueprints/data-solutions/shielded-folder/kms.tf @@ -17,12 +17,17 @@ # tfdoc:file:description Security project, Cloud KMS and Secret Manager resources. locals { + # list of locations with keys kms_locations = distinct(flatten([ for k, v in var.kms_keys : v.locations ])) + # map { location -> { key_name -> key_details } } kms_locations_keys = { - for loc in local.kms_locations : loc => { - for k, v in var.kms_keys : k => v if contains(v.locations, loc) + for loc in local.kms_locations : + loc => { + for k, v in var.kms_keys : + k => v + if contains(v.locations, loc) } } kms_log_locations = distinct(flatten([ @@ -30,17 +35,14 @@ locals { ])) kms_log_sink_keys = { "storage" = { - labels = {} locations = [var.log_locations.storage] rotation_period = "7776000s" } "bq" = { - labels = {} locations = [var.log_locations.bq] rotation_period = "7776000s" } "pubsub" = { - labels = {} locations = [var.log_locations.pubsub] rotation_period = "7776000s" } @@ -88,12 +90,6 @@ module "sec-kms" { location = each.key name = "sec-${each.key}" } - key_iam = { - for k, v in local.kms_locations_keys[each.key] : k => v.iam - } - key_iam_bindings_additive = { - for k, v in local.kms_locations_keys[each.key] : k => v.iam_bindings_additive - } keys = local.kms_locations_keys[each.key] } diff --git a/blueprints/data-solutions/shielded-folder/variables.tf b/blueprints/data-solutions/shielded-folder/variables.tf index 5bb80d57..03fea7c4 100644 --- a/blueprints/data-solutions/shielded-folder/variables.tf +++ b/blueprints/data-solutions/shielded-folder/variables.tf @@ -75,11 +75,35 @@ variable "groups" { variable "kms_keys" { description = "KMS keys to create, keyed by name." type = map(object({ - iam = optional(map(list(string)), {}) - iam_bindings_additive = optional(map(map(any)), {}) - labels = optional(map(string), {}) - locations = optional(list(string), ["global", "europe", "europe-west1"]) - rotation_period = optional(string, "7776000s") + labels = optional(map(string)) + locations = optional(list(string), ["global", "europe", "europe-west1"]) + rotation_period = optional(string, "7776000s") + purpose = optional(string, "ENCRYPT_DECRYPT") + skip_initial_version_creation = optional(bool, false) + version_template = optional(object({ + algorithm = string + protection_level = optional(string, "SOFTWARE") + })) + + iam = optional(map(list(string)), {}) + iam_bindings = optional(map(object({ + members = list(string) + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) + iam_bindings_additive = optional(map(object({ + member = string + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) + })) default = {} } @@ -92,12 +116,7 @@ variable "log_locations" { logging = optional(string, "global") pubsub = optional(string, "global") }) - default = { - bq = "europe" - storage = "europe" - logging = "global" - pubsub = null - } + default = {} nullable = false } diff --git a/blueprints/factories/net-vpc-firewall-yaml/versions.tf b/blueprints/factories/net-vpc-firewall-yaml/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/factories/net-vpc-firewall-yaml/versions.tf +++ b/blueprints/factories/net-vpc-firewall-yaml/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/factories/project-factory/README.md b/blueprints/factories/project-factory/README.md index d144a11a..74682ae9 100644 --- a/blueprints/factories/project-factory/README.md +++ b/blueprints/factories/project-factory/README.md @@ -55,6 +55,7 @@ billing_account: 012345-67890A-BCDEF0 labels: app: app-1 team: foo +parent: folders/12345678 service_encryption_key_ids: compute: - projects/kms-central-prj/locations/europe-west3/keyRings/my-keyring/cryptoKeys/europe3-gce @@ -71,6 +72,7 @@ service_accounts: labels: app: app-1 team: foo +parent: folders/12345678 service_accounts: app-2-be: {} @@ -81,10 +83,10 @@ service_accounts: | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [factory_data](variables.tf#L83) | Project data from either YAML files or externally parsed data. | object({…}) | ✓ | | -| [data_defaults](variables.tf#L17) | Optional default values used when corresponding project data from files are missing. | object({…}) | | {} | -| [data_merges](variables.tf#L44) | Optional values that will be merged with corresponding data from files. Combines with `data_defaults`, file data, and `data_overrides`. | object({…}) | | {} | -| [data_overrides](variables.tf#L63) | Optional values that override corresponding data from files. Takes precedence over file data and `data_defaults`. | object({…}) | | {} | +| [factory_data](variables.tf#L85) | Project data from either YAML files or externally parsed data. | object({…}) | ✓ | | +| [data_defaults](variables.tf#L17) | Optional default values used when corresponding project data from files are missing. | object({…}) | | {} | +| [data_merges](variables.tf#L45) | Optional values that will be merged with corresponding data from files. Combines with `data_defaults`, file data, and `data_overrides`. | object({…}) | | {} | +| [data_overrides](variables.tf#L64) | Optional values that override corresponding data from files. Takes precedence over file data and `data_defaults`. | object({…}) | | {} | ## Outputs diff --git a/blueprints/factories/project-factory/factory.tf b/blueprints/factories/project-factory/factory.tf index dac843df..0390b055 100644 --- a/blueprints/factories/project-factory/factory.tf +++ b/blueprints/factories/project-factory/factory.tf @@ -28,11 +28,11 @@ locals { ) projects = { for k, v in local._data : k => merge(v, { - billing_account = coalesce( + billing_account = try(coalesce( var.data_overrides.billing_account, try(v.billing_account, null), var.data_defaults.billing_account - ) + ), null) contacts = coalesce( var.data_overrides.contacts, try(v.contacts, null), @@ -46,6 +46,11 @@ locals { try(v.metric_scopes, null), var.data_defaults.metric_scopes ) + parent = coalesce( + var.data_overrides.parent, + try(v.parent, null), + var.data_defaults.parent + ) prefix = coalesce( var.data_overrides.prefix, try(v.prefix, null), diff --git a/blueprints/factories/project-factory/main.tf b/blueprints/factories/project-factory/main.tf index 7d173a11..9a230063 100644 --- a/blueprints/factories/project-factory/main.tf +++ b/blueprints/factories/project-factory/main.tf @@ -33,11 +33,13 @@ module "projects" { iam = try(each.value.iam, {}) iam_bindings = try(each.value.iam_bindings, {}) iam_bindings_additive = try(each.value.iam_bindings_additive, {}) - labels = each.value.labels - lien_reason = try(each.value.lien_reason, null) - logging_data_access = try(each.value.logging_data_access, {}) - logging_exclusions = try(each.value.logging_exclusions, {}) - logging_sinks = try(each.value.logging_sinks, {}) + labels = merge( + each.value.labels, var.data_merges.labels + ) + lien_reason = try(each.value.lien_reason, null) + logging_data_access = try(each.value.logging_data_access, {}) + logging_exclusions = try(each.value.logging_exclusions, {}) + logging_sinks = try(each.value.logging_sinks, {}) metric_scopes = distinct(concat( each.value.metric_scopes, var.data_merges.metric_scopes )) diff --git a/blueprints/factories/project-factory/variables.tf b/blueprints/factories/project-factory/variables.tf index 67917846..d7176474 100644 --- a/blueprints/factories/project-factory/variables.tf +++ b/blueprints/factories/project-factory/variables.tf @@ -21,6 +21,7 @@ variable "data_defaults" { contacts = optional(map(list(string)), {}) labels = optional(map(string), {}) metric_scopes = optional(list(string), []) + parent = optional(string) prefix = optional(string) service_encryption_key_ids = optional(map(list(string)), {}) service_perimeter_bridges = optional(list(string), []) @@ -65,6 +66,7 @@ variable "data_overrides" { type = object({ billing_account = optional(string) contacts = optional(map(list(string))) + parent = optional(string) prefix = optional(string) service_encryption_key_ids = optional(map(list(string))) service_perimeter_bridges = optional(list(string)) diff --git a/blueprints/gke/autopilot/cluster.tf b/blueprints/gke/autopilot/cluster.tf index ed6fa661..49409c44 100644 --- a/blueprints/gke/autopilot/cluster.tf +++ b/blueprints/gke/autopilot/cluster.tf @@ -20,12 +20,9 @@ module "cluster" { name = "cluster" location = var.region vpc_config = { - network = module.vpc.self_link - subnetwork = module.vpc.subnet_self_links["${var.region}/subnet-cluster"] - secondary_range_names = { - pods = "pods" - services = "services" - } + network = module.vpc.self_link + subnetwork = module.vpc.subnet_self_links["${var.region}/subnet-cluster"] + secondary_range_names = {} master_authorized_ranges = var.cluster_network_config.master_authorized_cidr_blocks master_ipv4_cidr_block = var.cluster_network_config.master_cidr_block } @@ -33,8 +30,17 @@ module "cluster" { # autopilot = true # } # monitoring_config = { - # enenable_components = ["SYSTEM_COMPONENTS"] - # managed_prometheus = true + # # (Optional) control plane metrics + # enable_api_server_metrics = true + # enable_controller_manager_metrics = true + # enable_scheduler_metrics = true + # # (Optional) kube state metrics + # enable_daemonset_metrics = true + # enable_deployment_metrics = true + # enable_hpa_metrics = true + # enable_pod_metrics = true + # enable_statefulset_metrics = true + # enable_storage_metrics = true # } # cluster_autoscaling = { # auto_provisioning_defaults = { @@ -51,4 +57,4 @@ module "node_sa" { source = "../../../modules/iam-service-account" project_id = module.project.project_id name = "sa-node" -} \ No newline at end of file +} diff --git a/blueprints/gke/binauthz/main.tf b/blueprints/gke/binauthz/main.tf index 2eac7c56..8cff68a0 100644 --- a/blueprints/gke/binauthz/main.tf +++ b/blueprints/gke/binauthz/main.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -115,20 +115,16 @@ module "kms" { project_id = module.project.project_id keyring = { location = var.region, name = "test-keyring" } keyring_create = true - keys = { test-key = null } - key_purpose = { + keys = { test-key = { purpose = "ASYMMETRIC_SIGN" version_template = { - algorithm = "RSA_SIGN_PKCS1_4096_SHA512" - protection_level = null + algorithm = "RSA_SIGN_PKCS1_4096_SHA512" + } + iam = { + "roles/cloudkms.publicKeyViewer" = [module.image_cb_sa.iam_email] + "roles/cloudkms.signer" = [module.image_cb_sa.iam_email] } - } - } - key_iam = { - test-key = { - "roles/cloudkms.publicKeyViewer" = [module.image_cb_sa.iam_email] - "roles/cloudkms.signer" = [module.image_cb_sa.iam_email] } } } diff --git a/blueprints/gke/multitenant-fleet/README.md b/blueprints/gke/multitenant-fleet/README.md index baaf288f..ed89a878 100644 --- a/blueprints/gke/multitenant-fleet/README.md +++ b/blueprints/gke/multitenant-fleet/README.md @@ -244,21 +244,21 @@ module "gke" { | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [billing_account_id](variables.tf#L17) | Billing account id. | string | ✓ | | -| [folder_id](variables.tf#L138) | Folder used for the GKE project in folders/nnnnnnnnnnn format. | string | ✓ | | -| [prefix](variables.tf#L189) | Prefix used for resource names. | string | ✓ | | -| [project_id](variables.tf#L198) | ID of the project that will contain all the clusters. | string | ✓ | | -| [vpc_config](variables.tf#L210) | Shared VPC project and VPC details. | object({…}) | ✓ | | -| [clusters](variables.tf#L22) | Clusters configuration. Refer to the gke-cluster module for type details. | map(object({…})) | | {} | -| [fleet_configmanagement_clusters](variables.tf#L76) | Config management features enabled on specific sets of member clusters, in config name => [cluster name] format. | map(list(string)) | | {} | -| [fleet_configmanagement_templates](variables.tf#L83) | Sets of config management configurations that can be applied to member clusters, in config name => {options} format. | map(object({…})) | | {} | -| [fleet_features](variables.tf#L118) | Enable and configure fleet features. Set to null to disable GKE Hub if fleet workload identity is not used. | object({…}) | | null | -| [fleet_workload_identity](variables.tf#L131) | Use Fleet Workload Identity for clusters. Enables GKE Hub if set to true. | bool | | false | -| [group_iam](variables.tf#L143) | Project-level IAM bindings for groups. Use group emails as keys, list of roles as values. | map(list(string)) | | {} | -| [iam](variables.tf#L150) | Project-level authoritative IAM bindings for users and service accounts in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | -| [labels](variables.tf#L157) | Project-level labels. | map(string) | | {} | -| [nodepools](variables.tf#L163) | Nodepools configuration. Refer to the gke-nodepool module for type details. | map(map(object({…}))) | | {} | -| [project_services](variables.tf#L203) | Additional project services to enable. | list(string) | | [] | +| [billing_account_id](variables.tf#L17) | Billing account ID. | string | ✓ | | +| [folder_id](variables.tf#L154) | Folder used for the GKE project in folders/nnnnnnnnnnn format. | string | ✓ | | +| [prefix](variables.tf#L205) | Prefix used for resource names. | string | ✓ | | +| [project_id](variables.tf#L214) | ID of the project that will contain all the clusters. | string | ✓ | | +| [vpc_config](variables.tf#L226) | Shared VPC project and VPC details. | object({…}) | ✓ | | +| [clusters](variables.tf#L22) | Clusters configuration. Refer to the gke-cluster module for type details. | map(object({…})) | | {} | +| [fleet_configmanagement_clusters](variables.tf#L92) | Config management features enabled on specific sets of member clusters, in config name => [cluster name] format. | map(list(string)) | | {} | +| [fleet_configmanagement_templates](variables.tf#L99) | Sets of config management configurations that can be applied to member clusters, in config name => {options} format. | map(object({…})) | | {} | +| [fleet_features](variables.tf#L134) | Enable and configure fleet features. Set to null to disable GKE Hub if fleet workload identity is not used. | object({…}) | | null | +| [fleet_workload_identity](variables.tf#L147) | Use Fleet Workload Identity for clusters. Enables GKE Hub if set to true. | bool | | false | +| [group_iam](variables.tf#L159) | Project-level IAM bindings for groups. Use group emails as keys, list of roles as values. | map(list(string)) | | {} | +| [iam](variables.tf#L166) | Project-level authoritative IAM bindings for users and service accounts in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | +| [labels](variables.tf#L173) | Project-level labels. | map(string) | | {} | +| [nodepools](variables.tf#L179) | Nodepools configuration. Refer to the gke-nodepool module for type details. | map(map(object({…}))) | | {} | +| [project_services](variables.tf#L219) | Additional project services to enable. | list(string) | | [] | ## Outputs diff --git a/blueprints/gke/multitenant-fleet/variables.tf b/blueprints/gke/multitenant-fleet/variables.tf index 2461ea8a..5d34440f 100644 --- a/blueprints/gke/multitenant-fleet/variables.tf +++ b/blueprints/gke/multitenant-fleet/variables.tf @@ -15,7 +15,7 @@ */ variable "billing_account_id" { - description = "Billing account id." + description = "Billing account ID." type = string } @@ -48,9 +48,25 @@ variable "clusters" { max_pods_per_node = optional(number, 110) min_master_version = optional(string) monitoring_config = optional(object({ - enable_components = optional(list(string), ["SYSTEM_COMPONENTS"]) - managed_prometheus = optional(bool) - })) + enable_system_metrics = optional(bool, true) + + # (Optional) control plane metrics + enable_api_server_metrics = optional(bool, false) + enable_controller_manager_metrics = optional(bool, false) + enable_scheduler_metrics = optional(bool, false) + + # (Optional) kube state metrics + enable_daemonset_metrics = optional(bool, false) + enable_deployment_metrics = optional(bool, false) + enable_hpa_metrics = optional(bool, false) + enable_pod_metrics = optional(bool, false) + enable_statefulset_metrics = optional(bool, false) + enable_storage_metrics = optional(bool, false) + + # Google Cloud Managed Service for Prometheus + enable_managed_prometheus = optional(bool, true) + }), {}) + node_locations = optional(list(string)) private_cluster_config = optional(any) release_channel = optional(string) diff --git a/blueprints/networking/__need_fixing/nginx-reverse-proxy-cluster/versions.tf b/blueprints/networking/__need_fixing/nginx-reverse-proxy-cluster/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/networking/__need_fixing/nginx-reverse-proxy-cluster/versions.tf +++ b/blueprints/networking/__need_fixing/nginx-reverse-proxy-cluster/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/networking/__need_fixing/onprem-google-access-dns/versions.tf b/blueprints/networking/__need_fixing/onprem-google-access-dns/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/networking/__need_fixing/onprem-google-access-dns/versions.tf +++ b/blueprints/networking/__need_fixing/onprem-google-access-dns/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/networking/decentralized-firewall/versions.tf b/blueprints/networking/decentralized-firewall/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/networking/decentralized-firewall/versions.tf +++ b/blueprints/networking/decentralized-firewall/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/networking/filtering-proxy-psc/versions.tf b/blueprints/networking/filtering-proxy-psc/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/networking/filtering-proxy-psc/versions.tf +++ b/blueprints/networking/filtering-proxy-psc/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/networking/filtering-proxy/versions.tf b/blueprints/networking/filtering-proxy/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/networking/filtering-proxy/versions.tf +++ b/blueprints/networking/filtering-proxy/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/networking/hub-and-spoke-peering/versions.tf b/blueprints/networking/hub-and-spoke-peering/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/networking/hub-and-spoke-peering/versions.tf +++ b/blueprints/networking/hub-and-spoke-peering/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/networking/hub-and-spoke-vpn/versions.tf b/blueprints/networking/hub-and-spoke-vpn/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/networking/hub-and-spoke-vpn/versions.tf +++ b/blueprints/networking/hub-and-spoke-vpn/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/networking/ilb-next-hop/versions.tf b/blueprints/networking/ilb-next-hop/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/networking/ilb-next-hop/versions.tf +++ b/blueprints/networking/ilb-next-hop/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/networking/private-cloud-function-from-onprem/versions.tf b/blueprints/networking/private-cloud-function-from-onprem/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/networking/private-cloud-function-from-onprem/versions.tf +++ b/blueprints/networking/private-cloud-function-from-onprem/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/networking/shared-vpc-gke/main.tf b/blueprints/networking/shared-vpc-gke/main.tf index 302ce735..88f48463 100644 --- a/blueprints/networking/shared-vpc-gke/main.tf +++ b/blueprints/networking/shared-vpc-gke/main.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -102,6 +102,11 @@ module "vpc-shared" { ip_cidr_range = var.ip_ranges.gce name = "gce" region = var.region + iam = { + "roles/compute.networkUser" = concat(var.owners_gce, [ + "serviceAccount:${module.project-svc-gce.service_accounts.cloud_services}", + ]) + } }, { ip_cidr_range = var.ip_ranges.gke @@ -111,24 +116,17 @@ module "vpc-shared" { pods = var.ip_secondary_ranges.gke-pods services = var.ip_secondary_ranges.gke-services } + iam = { + "roles/compute.networkUser" = concat(var.owners_gke, [ + "serviceAccount:${module.project-svc-gke.service_accounts.cloud_services}", + "serviceAccount:${module.project-svc-gke.service_accounts.robots.container-engine}", + ]) + "roles/compute.securityAdmin" = [ + "serviceAccount:${module.project-svc-gke.service_accounts.robots.container-engine}", + ] + } } ] - subnet_iam = { - "${var.region}/gce" = { - "roles/compute.networkUser" = concat(var.owners_gce, [ - "serviceAccount:${module.project-svc-gce.service_accounts.cloud_services}", - ]) - } - "${var.region}/gke" = { - "roles/compute.networkUser" = concat(var.owners_gke, [ - "serviceAccount:${module.project-svc-gke.service_accounts.cloud_services}", - "serviceAccount:${module.project-svc-gke.service_accounts.robots.container-engine}", - ]) - "roles/compute.securityAdmin" = [ - "serviceAccount:${module.project-svc-gke.service_accounts.robots.container-engine}", - ] - } - } } module "vpc-shared-firewall" { diff --git a/blueprints/networking/shared-vpc-gke/versions.tf b/blueprints/networking/shared-vpc-gke/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/networking/shared-vpc-gke/versions.tf +++ b/blueprints/networking/shared-vpc-gke/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/serverless/cloud-run-explore/README.md b/blueprints/serverless/cloud-run-explore/README.md index ff1454c1..9005165f 100644 --- a/blueprints/serverless/cloud-run-explore/README.md +++ b/blueprints/serverless/cloud-run-explore/README.md @@ -214,5 +214,5 @@ module "test" { } } -# tftest modules=4 resources=18 +# tftest modules=4 resources=19 ``` diff --git a/blueprints/third-party-solutions/README.md b/blueprints/third-party-solutions/README.md index c81bc144..62e3304e 100644 --- a/blueprints/third-party-solutions/README.md +++ b/blueprints/third-party-solutions/README.md @@ -6,12 +6,18 @@ The blueprints in this folder show how to automate installation of specific thir ### OpenShift cluster bootstrap on Shared VPC - This [example](./openshift/) shows how to quickly bootstrap an OpenShift 4.7 cluster on GCP, using typical enterprise features like Shared VPC and CMEK for instance disks. +

This [example](./openshift/) shows how to quickly bootstrap an OpenShift 4.7 cluster on GCP, using typical enterprise features like Shared VPC and CMEK for instance disks.


### Wordpress deployment on Cloud Run - This [example](./wordpress/cloudrun/) shows how to deploy a functioning new Wordpress website exposed to the public internet via CloudRun and Cloud SQL, with minimal technical overhead. +

This [example](./wordpress/cloudrun/) shows how to deploy a functioning new Wordpress website exposed to the public internet via CloudRun and Cloud SQL, with minimal technical overhead.


+ +### Serverless phpIPAM on Cloud Run + +

This [example](./phpipam/) shows how to quickly bootstrap a serverless phpIPAM instance on GCP using Cloud Run. This comes with typical enterprise features like Shared VPC, Cloud Armor with IAP and, possibly, private exposure via Internal Application Load Balancer. Indeed, the script supports deploying the application either publicly via Global Application Load Balancer with restricted access based on IPs (Cloud Armor) and identities (Identity Aware Proxy) or privately via Internal Application Load Balancer.

+ +
\ No newline at end of file diff --git a/blueprints/third-party-solutions/openshift/tf/versions.tf b/blueprints/third-party-solutions/openshift/tf/versions.tf index e4f7404f..91a91a31 100644 --- a/blueprints/third-party-solutions/openshift/tf/versions.tf +++ b/blueprints/third-party-solutions/openshift/tf/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/blueprints/third-party-solutions/phpipam/README.md b/blueprints/third-party-solutions/phpipam/README.md new file mode 100644 index 00000000..14502306 --- /dev/null +++ b/blueprints/third-party-solutions/phpipam/README.md @@ -0,0 +1,239 @@ +# Serverless phpIPAM on Cloud Run + +[phpIPAM](https://phpipam.net/) is an open-source IP address management (IPAM) +system that can be used to manage IP addresses in both on-premises and cloud +environments. It is a powerful tool that can help businesses to automate IP +address management, proactively identify and resolve IP address conflicts, and +plan for future IP address needs. + +This repository aims to speed up deployment of phpIPAM software on Google Cloud +Platform Cloud Run serverless product. The web application can be exposed either +publicly via Global Application Load Balancer or internally via Internal +Application Load Balancer. More information on the architecture section. + +## Architecture + +![Serverless phpIPAM on Cloud Run](images/phpipam.png "Wordpress on Cloud Run") + +The main components that are deployed in this architecture are the following ( +you can learn about them by following the hyperlinks): + +- [Cloud Run](https://cloud.google.com/run): serverless PaaS offering to host + containers for web-oriented applications, while offering security, scalability + and easy versioning +- [Cloud SQL](https://cloud.google.com/sql): Managed solution for SQL databases +- [VPC Serverless Connector](https://cloud.google.com/vpc/docs/serverless-vpc-access): + Solution to access the CloudSQL VPC from Cloud Run, using only internal IP + addresses +- [Global Application Load Balancer](https://cloud.google.com/load-balancing/docs/https) (\*): + An external Application Load Balancer is a proxy-based Layer 7 load balancer + that enables you to run and scale your services behind a single external IP + address. +- [Cloud Armor](https://cloud.google.com/armor/docs/cloud-armor-overview) (\*): + Help protect your applications and websites against denial of service and web + attacks. +- [Identity Aware Proxy](https://cloud.google.com/iap/docs/concepts-overview) (\*): + IAP lets you establish a central authorization layer for applications accessed + by HTTPS, so you can use an application-level access control model instead of + relying on network-level firewalls. +- [Regional Internal Application Load Balancer](https://cloud.google.com/load-balancing/docs/l7-internal) (\*): + A Google Cloud internal Application Load Balancer is a regional proxy-based + layer 7 load balancer that enables you expose your services behind a single + internal IP address. + +> (\*) Product deployment depends on input variables + +## Setup + +### Prerequisites + +#### Setting up the project for the deployment + +This example will deploy all its resources into the project defined by +the `project_id` variable. Please note that we assume this project already +exists. However, if you provide the appropriate values to the `project_create` +variable, the project will be created as part of the deployment. + +If `project_create` is left to null, the identity performing the deployment +needs the `owner` role on the project defined by the `project_id` variable. +Otherwise, the identity performing the deployment +needs `resourcemanager.projectCreator` on the resource hierarchy node specified +by `project_create.parent` and `billing.user` on the billing account specified +by `project_create.billing_account_id`. + +### Deployment + +#### Step 0: Cloning the repository + +If you want to deploy from your Cloud Shell, click on the image below, sign in +if required and when the prompt appears, click on “confirm”. + +[![Open Cloudshell](../../../assets/images/cloud-shell-button.png)](https://shell.cloud.google.com/cloudshell/editor?cloudshell_git_repo=https%3A%2F%2Fgithub.com%2FGoogleCloudPlatform%2Fcloud-foundation-fabric&cloudshell_workspace=blueprints%2Fthird-party-solutions%2Fwordpress%2Fcloudrun) + +Otherwise, in your console of choice: + +```bash +git clone https://github.com/GoogleCloudPlatform/cloud-foundation-fabric +``` + +Before you deploy the architecture, you will need at least the following +information (for more precise configuration see the Variables section): + +* The project ID. + +#### Step 2: Prepare the variables + +Once you have the required information, head back to your cloned repository. +Make sure you’re in the directory of this tutorial (where this README is in). + +Configure the Terraform variables in your `terraform.tfvars` file. +See [terraform.tfvars.sample](terraform.tfvars.sample) as starting point - just +copy it to `terraform.tfvars` and edit the latter. See the variables +documentation below. + +**Notes**: + +1. If you have + the [domain restriction org. policy](https://cloud.google.com/resource-manager/docs/organization-policy/restricting-domains) + on your organization, you have to edit the `cloud_run_invoker` variable and + give it a value that will be accepted in accordance to your policy. +2. By default, the application will be exposed externally through Global + Application Load Balancer, for restricting access to specific identities + please check IAP configuration or deploy the application internally via the + ILB +3. Setting the `phpipam_exposure` variable to "INTERNAL" will deploy an Internal + Application Load Balancer on the same VPC. This might be the preferred option + for enterprises since it prevents exposing the application publicly still + allowing internal access through private network (via either VPN and/or + Interconnect) + +#### Step 3: Deploy resources + +Initialize your Terraform environment and deploy the resources: + +```shell +terraform init +terraform apply +``` + +#### Step 4: Use the created resources + +Upon completion, you will see the output with the values for the Cloud Run +service and the user and password to access the application. +You can also view it later with: + +```shell +terraform output +# or for the concrete variable: +terraform output cloud_run_service +``` + +Please be aware that the password created in the script is not yet configured in the +application, you will be prompted to insert that during phpIPAM installation +process at first login. +To access the newly deployed application follow these instructions: + +1. Get the default phpIPAM url from the terraform output in the form + {IP_ADDRESS}.nip.io +2. Open your browser at that URL and you will see your phpIPAM installation page + like the following one: + +![phpIPAM Installation page](images/phpipam_install.png "phpIPAM installation page") + +3. Click on "New phpipam installation". On the next page click "Automatic + database installation", you will be prompted to the following form: + +![phpIPAM DB install](images/phpipam_db.png "phpIPAM DB installation") + +4. Insert "admin" as the MySQL username and the password available on the + terraform output of this command below (without quotes). + Untick the "Create new database" otherwise you'll get an error during + installation, leave all the other values as default and then click on " + Install phpipam database" + +``` +terraform output cloudsql_password +``` + +5. After some time a "Database installed successfully!" message should pop up. + Then click "continue" and you'll be prompted to the last form for configuring + admin credentials: + +![phpIPAM Admin setup](images/phpipam_admin.png "phpIPAM DB installation") + +6. Insert the phpipam password available in the output of the following command + and choose a site title. Then insert the site url and click "Save + settings". "A Settings updated, installation complete!" message should pop up + and clicking "Proceed to login." will redirect you to the login page. + Be aware this is just a convenient way to have a backup admin password in + terraform, you could use whatever password you prefer. + +``` +terraform output phpipam_password +``` + +7. Insert "admin" as username and the password configured on the previous step + and after login you'll finally get to the phpIPAM homepage. + +![phpIPAM Homepage](images/phpipam_home.png "phpIPAM Homepage") + +### Cleaning up your environment + +The easiest way to remove all the deployed resources is to run the following +command in Cloud Shell: + +``` {shell} +terraform destroy +``` + +The above command will delete the associated resources so there will be no +billable charges made afterwards. + +## Variables + +| name | description | type | required | default | +|---|---|:---:|:---:|:---:| +| [prefix](variables.tf#L109) | Prefix used for resource names. | string | ✓ | | +| [project_id](variables.tf#L128) | Project id, references existing project if `project_create` is null. | string | ✓ | | +| [admin_principals](variables.tf#L19) | Users, groups and/or service accounts that are assigned roles, in IAM format (`group:foo@example.com`). | list(string) | | [] | +| [cloud_run_invoker](variables.tf#L25) | IAM member authorized to access the end-point (for example, 'user:YOUR_IAM_USER' for only you or 'allUsers' for everyone). | string | | "allUsers" | +| [cloudsql_password](variables.tf#L31) | CloudSQL password (will be randomly generated by default). | string | | null | +| [connector](variables.tf#L37) | Existing VPC serverless connector to use if not creating a new one. | string | | null | +| [create_connector](variables.tf#L43) | Should a VPC serverless connector be created or not. | bool | | true | +| [custom_domain](variables.tf#L49) | Cloud Run service custom domain for GLB. | string | | null | +| [iap](variables.tf#L55) | Identity-Aware Proxy for Cloud Run in the LB. | object({…}) | | {} | +| [ip_ranges](variables.tf#L67) | CIDR blocks: VPC serverless connector, Private Service Access(PSA) for CloudSQL, CloudSQL VPC. | object({…}) | | {…} | +| [phpipam_config](variables.tf#L81) | PHPIpam configuration. | object({…}) | | {…} | +| [phpipam_exposure](variables.tf#L93) | Whether to expose the application publicly via GLB or internally via ILB, default GLB. | string | | "EXTERNAL" | +| [phpipam_password](variables.tf#L103) | Password for the phpipam user (will be randomly generated by default). | string | | null | +| [project_create](variables.tf#L119) | Provide values if project creation is needed, uses existing project if null. Parent is in 'folders/nnn' or 'organizations/nnn' format. | object({…}) | | null | +| [region](variables.tf#L133) | Region for the created resources. | string | | "europe-west4" | +| [security_policy](variables.tf#L139) | Security policy (Cloud Armor) to enforce in the LB. | object({…}) | | {} | +| [vpc_config](variables.tf#L149) | VPC Network and subnetwork self links for internal LB setup. | object({…}) | | null | + +## Outputs + +| name | description | sensitive | +|---|---|:---:| +| [cloud_run_service](outputs.tf#L17) | CloudRun service URL. | ✓ | +| [cloudsql_password](outputs.tf#L23) | CloudSQL password. | ✓ | +| [phpipam_ip_address](outputs.tf#L29) | PHPIPAM IP Address either external or internal according to app exposure. | | +| [phpipam_password](outputs.tf#L34) | PHPIPAM user password. | ✓ | +| [phpipam_url](outputs.tf#L40) | PHPIPAM website url. | | +| [phpipam_user](outputs.tf#L45) | PHPIPAM username. | | + +## Test + +```hcl +module "test" { + source = "./fabric/blueprints/third-party-solutions/phpipam" + admin_principals = ["group:foo@example.com"] + prefix = "test" + project_create = { + billing_account_id = "1234-ABCD-1234" + parent = "folders/1234563" + } + project_id = "test-prj" +} +# tftest modules=7 resources=43 +``` diff --git a/blueprints/third-party-solutions/phpipam/cloudsql.tf b/blueprints/third-party-solutions/phpipam/cloudsql.tf new file mode 100644 index 00000000..0dc89b9a --- /dev/null +++ b/blueprints/third-party-solutions/phpipam/cloudsql.tf @@ -0,0 +1,31 @@ +/** + * Copyright 2023 Google LLC + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +# Set up CloudSQL +module "cloudsql" { + source = "../../../modules/cloudsql-instance" + project_id = module.project.project_id + name = "${var.prefix}-mysql" + database_version = local.cloudsql_conf.database_version + databases = [local.cloudsql_conf.db] + network = local.network + prefix = var.prefix + region = var.region + tier = local.cloudsql_conf.tier + users = { + "${local.cloudsql_conf.user}" = var.cloudsql_password + } +} diff --git a/blueprints/third-party-solutions/phpipam/diagrams/phpipam.excalidraw b/blueprints/third-party-solutions/phpipam/diagrams/phpipam.excalidraw new file mode 100644 index 00000000..f9896973 --- /dev/null +++ b/blueprints/third-party-solutions/phpipam/diagrams/phpipam.excalidraw @@ -0,0 +1,4821 @@ +{ + "type": "excalidraw", + "version": 2, + "source": "https://excalidraw.com", + "elements": [ + { + "type": "image", + "version": 481, + "versionNonce": 537873588, + "isDeleted": false, + "id": "1XbyXgzt6oISJX4bJOqgJ", + "fillStyle": "hachure", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1793.5245329083443, + "y": -2032.4573238238672, + "strokeColor": "transparent", + "backgroundColor": "transparent", + "width": 87.0394357600626, + "height": 66.35855006612174, + "seed": 1031721740, + "groupIds": [], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "status": "saved", + "fileId": "af2541e7127d4fdc679914759de23d8bd87e9264", + "scale": [ + 1, + 1 + ] + }, + { + "type": "line", + "version": 660, + "versionNonce": 618662028, + "isDeleted": false, + "id": "KUKHKtwx4uIJzebhF0ZW1", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1766.4112728934037, + "y": -2002.44215921633, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 49.11275214513097, + "height": 36.92648039990984, + "seed": 292309772, + "groupIds": [ + "143QJr2AU36qqThhRKQql", + "Nr52ogYxUnYvl_fIZutZ_" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 12.265055829310315, + 36.92648039990984 + ], + [ + 49.11275214513097, + 36.92648039990984 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 660, + "versionNonce": 527144500, + "isDeleted": false, + "id": "03GsUk9b3uMGDNQosA5W_", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1815.5240250385348, + "y": -1965.5156788164204, + "strokeColor": "#000000", + "backgroundColor": "#4285f4", + "width": 49.11275214513097, + "height": 36.92648673988745, + "seed": 1447496076, + "groupIds": [ + "143QJr2AU36qqThhRKQql", + "Nr52ogYxUnYvl_fIZutZ_" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + -36.847696315820656, + 0 + ], + [ + -49.11275214513097, + 36.92648673988745 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 661, + "versionNonce": 258414348, + "isDeleted": false, + "id": "wzCWvE55EqWjCYcux-V0-", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1744.875204393739, + "y": -1928.5891920765328, + "strokeColor": "#000000", + "backgroundColor": "#4285f4", + "width": 21.536068499663806, + "height": 36.92648673988745, + "seed": 1581643788, + "groupIds": [ + "143QJr2AU36qqThhRKQql", + "Nr52ogYxUnYvl_fIZutZ_" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 12.317583248316135, + -6.145664348279347 + ], + [ + 21.536068499663806, + -36.92648673988745 + ], + [ + 9.21848947799943, + -36.92648673988745 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 660, + "versionNonce": 1333964724, + "isDeleted": false, + "id": "AmWl3EKGBEqQ6c-2l5fLr", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1744.875204393739, + "y": -2002.44215921633, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 21.536068499663806, + "height": 36.92648039990984, + "seed": 358815372, + "groupIds": [ + "143QJr2AU36qqThhRKQql", + "Nr52ogYxUnYvl_fIZutZ_" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 9.21848947799943, + 36.92648039990984 + ], + [ + 21.536068499663806, + 36.92648039990984 + ], + [ + 12.317583248316135, + 6.145659417185632 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "text", + "version": 749, + "versionNonce": 1945012, + "isDeleted": false, + "id": "IfVzFaOMx3j3dME8GrhUs", + "fillStyle": "hachure", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1743.866131613274, + "y": -1927.1534159338844, + "strokeColor": "#000000", + "backgroundColor": "transparent", + "width": 68.65559387207031, + "height": 16.7247155341873, + "seed": 1482188044, + "groupIds": [ + "Nr52ogYxUnYvl_fIZutZ_" + ], + "frameId": null, + "roundness": { + "type": 2 + }, + "boundElements": [ + { + "id": "1hR9SCYu3Fd8-OWyibUBe", + "type": "arrow" + } + ], + "updated": 1693311484476, + "link": null, + "locked": false, + "fontSize": 14.539679438756231, + "fontFamily": 2, + "text": "Cloud Run", + "textAlign": "left", + "verticalAlign": "top", + "containerId": null, + "originalText": "Cloud Run", + "lineHeight": 1.150280898876405, + "baseline": 13 + }, + { + "type": "rectangle", + "version": 528, + "versionNonce": 1009242420, + "isDeleted": false, + "id": "c9Cux6NrH-jflel7CZ993", + "fillStyle": "hachure", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1491.6056084907252, + "y": -2130.145262517028, + "strokeColor": "#000000", + "backgroundColor": "transparent", + "width": 701.1157994906367, + "height": 539.060730392323, + "seed": 304311604, + "groupIds": [], + "frameId": null, + "roundness": { + "type": 3 + }, + "boundElements": [], + "updated": 1693311392567, + "link": null, + "locked": false + }, + { + "type": "image", + "version": 709, + "versionNonce": 519142028, + "isDeleted": false, + "id": "YYw7gXl4W97O0JXZAMzhR", + "fillStyle": "hachure", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1472.3435624427782, + "y": -2215.1254824711386, + "strokeColor": "transparent", + "backgroundColor": "transparent", + "width": 372.22474653284047, + "height": 248.14983102189362, + "seed": 505448500, + "groupIds": [], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311401662, + "link": null, + "locked": false, + "status": "saved", + "fileId": "7f10a90d0c745f95f1922694e27ad51a6bf7d09e", + "scale": [ + 1, + 1 + ] + }, + { + "type": "rectangle", + "version": 672, + "versionNonce": 1565720756, + "isDeleted": false, + "id": "hWzo_PR1wR4eOgN7GCA76", + "fillStyle": "hachure", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1532.7305950497039, + "y": -1813.6835962459613, + "strokeColor": "#000000", + "backgroundColor": "#a5d8ff", + "width": 603.3558049160198, + "height": 204.09209589366222, + "seed": 168241844, + "groupIds": [], + "frameId": null, + "roundness": { + "type": 3 + }, + "boundElements": [], + "updated": 1693311318058, + "link": null, + "locked": false + }, + { + "type": "line", + "version": 566, + "versionNonce": 1441061940, + "isDeleted": false, + "id": "YlvLcdA67ovtgbCNjDHKi", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1737.185641562936, + "y": -1701.0911930806487, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 30.93220427159039, + "height": 29.15983311685192, + "seed": 2145151540, + "groupIds": [ + "4QQEDIAcbGDabZcoMrnE9", + "aDHYiPoTbYMWlla5qLL3x", + "sRnoZ2rKaS2Y28Pz_3wfo" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 0, + 12.702040814491287 + ], + [ + 30.93220427159039, + 29.15983311685192 + ], + [ + 30.93220427159039, + 16.457792302360613 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 566, + "versionNonce": 210579724, + "isDeleted": false, + "id": "AJGjPZwDhTGk5R9odCXcm", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1737.185641562936, + "y": -1681.4684411845014, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 30.93220427159039, + "height": 29.159827080170565, + "seed": 314114996, + "groupIds": [ + "-mwo8PSPLEJROjucGMNV9", + "aDHYiPoTbYMWlla5qLL3x", + "sRnoZ2rKaS2Y28Pz_3wfo" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 0, + 12.702040814491289 + ], + [ + 30.93220427159039, + 29.159827080170565 + ], + [ + 30.93220427159039, + 16.45778626567926 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 568, + "versionNonce": 853751220, + "isDeleted": false, + "id": "3JOs7lBPu2ZLdLKA7z_sc", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1768.1178458345266, + "y": -1671.9313599637967, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 30.932208799101403, + "height": 29.15983311685192, + "seed": 566652212, + "groupIds": [ + "Ssfz8of57AsqfvU9c6tHU", + "aDHYiPoTbYMWlla5qLL3x", + "sRnoZ2rKaS2Y28Pz_3wfo" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 30.932208799101403, + -16.45779230236061 + ], + [ + 30.932208799101403, + -29.15983311685192 + ], + [ + 0, + -12.702040814491282 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 568, + "versionNonce": 1213935500, + "isDeleted": false, + "id": "EkV4IW-AJzsz-vh97G-3_", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1768.1178458345266, + "y": -1652.3086141043307, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 30.932208799101403, + "height": 29.159827080170565, + "seed": 241870516, + "groupIds": [ + "9FDnYXoLyfWDYgY1D52rq", + "aDHYiPoTbYMWlla5qLL3x", + "sRnoZ2rKaS2Y28Pz_3wfo" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 30.932208799101403, + -16.457786265679268 + ], + [ + 30.932208799101403, + -29.159827080170565 + ], + [ + 0, + -12.702040814491303 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 568, + "versionNonce": 1641701172, + "isDeleted": false, + "id": "NM4FCQHCF6jXUQseMSki-", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1799.050054633628, + "y": -1707.5477105312384, + "strokeColor": "#000000", + "backgroundColor": "#4285f4", + "width": 30.932208799101403, + "height": 29.159827834755752, + "seed": 491499572, + "groupIds": [ + "z8fP_4PYXZfW0WAcJfUPu", + "aDHYiPoTbYMWlla5qLL3x", + "sRnoZ2rKaS2Y28Pz_3wfo" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 0, + -12.702037796150632 + ], + [ + -30.932208799101403, + -29.159827834755752 + ], + [ + -30.932208799101403, + -16.457789284019967 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 569, + "versionNonce": 115695116, + "isDeleted": false, + "id": "i8zbbwYqriRe6mw4nCYgK", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1768.1178458345264, + "y": -1736.7075383659944, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 30.93220427159039, + "height": 29.159827834755752, + "seed": 240093620, + "groupIds": [ + "1_yORLPOgADxV6GB4-GxX", + "aDHYiPoTbYMWlla5qLL3x", + "sRnoZ2rKaS2Y28Pz_3wfo" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + -30.93220427159039, + 16.457790038605133 + ], + [ + -30.93220427159039, + 29.159827834755752 + ], + [ + 0, + 12.702038550735798 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 566, + "versionNonce": 1261459636, + "isDeleted": false, + "id": "nLcf6dXvi-Dg0zFYxD3my", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1737.185641562936, + "y": -1720.376346590407, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 30.93220427159039, + "height": 29.20202650117651, + "seed": 882651956, + "groupIds": [ + "9KxAiBauJwpvFBEwLOUoa", + "aDHYiPoTbYMWlla5qLL3x", + "sRnoZ2rKaS2Y28Pz_3wfo" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 0, + 12.74424023549724 + ], + [ + 30.93220427159039, + 29.20202650117651 + ], + [ + 30.93220427159039, + 16.457792302360623 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 569, + "versionNonce": 19250316, + "isDeleted": false, + "id": "h6Z26XLvWgyFchxTQvpXL", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1768.1178458345266, + "y": -1691.1743200892304, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 30.932208799101403, + "height": 29.20202650117651, + "seed": 244821172, + "groupIds": [ + "-h4pDIR_NFTn_DviMiwQz", + "aDHYiPoTbYMWlla5qLL3x", + "sRnoZ2rKaS2Y28Pz_3wfo" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 30.932208799101403, + -16.457786265679268 + ], + [ + 30.932208799101403, + -29.20202650117651 + ], + [ + 0, + -12.744234198815874 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "text", + "version": 832, + "versionNonce": 1519067700, + "isDeleted": false, + "id": "EgR1hwDJN0PjLrGd5nbjr", + "fillStyle": "hachure", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1732.6497236445011, + "y": -1650.0718103364015, + "strokeColor": "#000000", + "backgroundColor": "transparent", + "width": 71.41729736328125, + "height": 16.969289811898413, + "seed": 1575482932, + "groupIds": [ + "10xnq85pGHDASfiSQPfuC", + "xRkpIu4RUHYZful5rB5uJ", + "m17ghiEvwrmuZDB7XkBzD", + "sRnoZ2rKaS2Y28Pz_3wfo" + ], + "frameId": null, + "roundness": { + "type": 2 + }, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "fontSize": 14.604231998393391, + "fontFamily": 2, + "text": "Cloud SQL", + "textAlign": "left", + "verticalAlign": "top", + "containerId": null, + "originalText": "Cloud SQL", + "lineHeight": 1.161943319838058, + "baseline": 13 + }, + { + "type": "text", + "version": 11, + "versionNonce": 1087785740, + "isDeleted": false, + "id": "8TOTAlez0vKnEmM_OajUD", + "fillStyle": "hachure", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1604.7981078973241, + "y": -1786.4960135936278, + "strokeColor": "#495057", + "backgroundColor": "#a5d8ff", + "width": 57.572265625, + "height": 32.199999999999996, + "seed": 631585716, + "groupIds": [], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "fontSize": 28, + "fontFamily": 2, + "text": "VPC", + "textAlign": "left", + "verticalAlign": "top", + "containerId": null, + "originalText": "VPC", + "lineHeight": 1.15, + "baseline": 26 + }, + { + "type": "rectangle", + "version": 664, + "versionNonce": 701096844, + "isDeleted": false, + "id": "WZfd3JxWdQGj02Nx1ywUK", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1757.5152703538752, + "y": -1843.3509692696189, + "strokeColor": "#1864ab", + "backgroundColor": "#669df6", + "width": 30.71336203849055, + "height": 5.031485400485886, + "seed": 374877708, + "groupIds": [ + "xe_VmpQuCkK-2Lu9CGL8R" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 689, + "versionNonce": 450947892, + "isDeleted": false, + "id": "C58IGor8Vlna-k9T4SG_E", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1758.8846917733617, + "y": -1801.2793496901554, + "strokeColor": "#1864ab", + "backgroundColor": "#669df6", + "width": 30.71336203849055, + "height": 5.031485400485886, + "seed": 968789132, + "groupIds": [ + "xe_VmpQuCkK-2Lu9CGL8R" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 715, + "versionNonce": 811438604, + "isDeleted": false, + "id": "2tGkxza5W0dNG2l7A52cu", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 1.5707963267948957, + "x": 1778.548046982738, + "y": -1821.9384827513968, + "strokeColor": "#1864ab", + "backgroundColor": "#669df6", + "width": 30.71336203849055, + "height": 5.031485400485886, + "seed": 232069900, + "groupIds": [ + "xe_VmpQuCkK-2Lu9CGL8R" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 724, + "versionNonce": 998597812, + "isDeleted": false, + "id": "jfdivAKJ-QRP9KZrYLtRZ", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 1.5707963267948957, + "x": 1736.2414295015294, + "y": -1820.9136694039341, + "strokeColor": "#1864ab", + "backgroundColor": "#669df6", + "width": 30.71336203849055, + "height": 5.031485400485886, + "seed": 1830148492, + "groupIds": [ + "xe_VmpQuCkK-2Lu9CGL8R" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 964, + "versionNonce": 897020044, + "isDeleted": false, + "id": "qWQrT53vm2Vegs-_kUpu5", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1742.5563882472707, + "y": -1849.643844484846, + "strokeColor": "#669df6", + "backgroundColor": "#aecbfa", + "width": 8.85797007441361, + "height": 17.70860035786427, + "seed": 1387972620, + "groupIds": [ + "6TZ5hG1Ee6MddXwuJXdr5", + "xe_VmpQuCkK-2Lu9CGL8R" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 1006, + "versionNonce": 341749300, + "isDeleted": false, + "id": "e3s68qp5MX_7Ayqq5sf77", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1751.7514222120528, + "y": -1849.7837438562246, + "strokeColor": "#1864ab", + "backgroundColor": "#669df6", + "width": 8.85797007441361, + "height": 17.70860035786427, + "seed": 1119741580, + "groupIds": [ + "6TZ5hG1Ee6MddXwuJXdr5", + "xe_VmpQuCkK-2Lu9CGL8R" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 940, + "versionNonce": 1758560012, + "isDeleted": false, + "id": "B8bLOHZrRhslEVbBP9jp4", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1784.9536781277313, + "y": -1850.050828266343, + "strokeColor": "#669df6", + "backgroundColor": "#aecbfa", + "width": 8.85797007441361, + "height": 17.70860035786427, + "seed": 836318476, + "groupIds": [ + "6DOjq1TwR59SoS2HlstbS", + "xe_VmpQuCkK-2Lu9CGL8R" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 982, + "versionNonce": 1716701108, + "isDeleted": false, + "id": "DWq3ahV34UH2RP3JIa7EI", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1794.1487120925142, + "y": -1850.1907276377208, + "strokeColor": "#1864ab", + "backgroundColor": "#669df6", + "width": 8.85797007441361, + "height": 17.70860035786427, + "seed": 1837544332, + "groupIds": [ + "6DOjq1TwR59SoS2HlstbS", + "xe_VmpQuCkK-2Lu9CGL8R" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 940, + "versionNonce": 1927658892, + "isDeleted": false, + "id": "qDYX7fV1q3K5MDGAqCMtJ", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1785.4598412517405, + "y": -1806.9553369965429, + "strokeColor": "#669df6", + "backgroundColor": "#aecbfa", + "width": 8.85797007441361, + "height": 17.70860035786427, + "seed": 67133964, + "groupIds": [ + "hdInUI-orAUWqQtInirJI", + "xe_VmpQuCkK-2Lu9CGL8R" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 982, + "versionNonce": 1703391540, + "isDeleted": false, + "id": "SeTrg7R5VpHNGmyPOfW-J", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1794.6548752165222, + "y": -1807.0952363679203, + "strokeColor": "#1864ab", + "backgroundColor": "#669df6", + "width": 8.85797007441361, + "height": 17.70860035786427, + "seed": 742408332, + "groupIds": [ + "hdInUI-orAUWqQtInirJI", + "xe_VmpQuCkK-2Lu9CGL8R" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 944, + "versionNonce": 1559112716, + "isDeleted": false, + "id": "cYzBD-ipbA2Cd4ciFIXPC", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1742.5257427528738, + "y": -1807.5070327656533, + "strokeColor": "#669df6", + "backgroundColor": "#aecbfa", + "width": 8.85797007441361, + "height": 17.70860035786427, + "seed": 771772172, + "groupIds": [ + "OYW2zQVmsyxVaA_wYND5b", + "xe_VmpQuCkK-2Lu9CGL8R" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 986, + "versionNonce": 1365469876, + "isDeleted": false, + "id": "Zi6tOTdx4Ut6ljQvl5B9v", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1751.7207767176571, + "y": -1807.6469321370298, + "strokeColor": "#1864ab", + "backgroundColor": "#669df6", + "width": 8.85797007441361, + "height": 17.70860035786427, + "seed": 1236962700, + "groupIds": [ + "OYW2zQVmsyxVaA_wYND5b", + "xe_VmpQuCkK-2Lu9CGL8R" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false + }, + { + "type": "line", + "version": 659, + "versionNonce": 2028259980, + "isDeleted": false, + "id": "5ggsny_XDGStwZ4geHTfV", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2028.395096217105, + "y": -1979.2189212533528, + "strokeColor": "#000000", + "backgroundColor": "#4285f4", + "width": 7.100055542062618, + "height": 14.200096227246, + "seed": 1263001868, + "groupIds": [ + "aKhaUT8I7Mv1hKXBftWpR", + "s71cWJFwFITMU-Lps6d9w", + "_AHsh0V9g7Gmkyg8iVyyC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + -7.100055542062618, + 0 + ], + [ + -7.100055542062618, + -14.200096227246 + ], + [ + 0, + -14.200096227246 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 658, + "versionNonce": 210498612, + "isDeleted": false, + "id": "FoSfSZMYBdt05snHqeZzA", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1996.444869801216, + "y": -1979.2189212533528, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 56.80039233742361, + "height": 17.750125236350584, + "seed": 1010818956, + "groupIds": [ + "8t5lPH-tVD4D3JjRJY2Da", + "s71cWJFwFITMU-Lps6d9w", + "_AHsh0V9g7Gmkyg8iVyyC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 0, + 17.750125236350584 + ], + [ + 7.100049351696269, + 17.750125236350584 + ], + [ + 7.100049351696269, + 7.10005554206262 + ], + [ + 24.850170873827043, + 7.10005554206262 + ], + [ + 24.850170873827043, + 17.750125236350584 + ], + [ + 31.950226415889656, + 17.750125236350584 + ], + [ + 31.950226415889656, + 7.10005554206262 + ], + [ + 49.70034917609371, + 7.10005554206262 + ], + [ + 49.70034917609371, + 17.750125236350584 + ], + [ + 56.80039233742361, + 17.750125236350584 + ], + [ + 56.80039233742361, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 658, + "versionNonce": 1233361164, + "isDeleted": false, + "id": "ypWdYRNc4UGk91mI9W6qc", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2003.544919152912, + "y": -2011.1691427169494, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 42.60029982439741, + "height": 17.750125236350584, + "seed": 2058620428, + "groupIds": [ + "iivjceHzn0JoLGUUUq30p", + "s71cWJFwFITMU-Lps6d9w", + "_AHsh0V9g7Gmkyg8iVyyC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 42.60029982439741, + 0 + ], + [ + 42.60029982439741, + 17.750125236350584 + ], + [ + 0, + 17.750125236350584 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 658, + "versionNonce": 887573940, + "isDeleted": false, + "id": "S0OfeeLQomDTwrfbWdVPW", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2024.8450672080003, + "y": -2011.1691427169494, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 21.30015176930862, + "height": 17.750125236350584, + "seed": 1738435724, + "groupIds": [ + "gxQeb-Dyeh10hmcLocvwG", + "s71cWJFwFITMU-Lps6d9w", + "_AHsh0V9g7Gmkyg8iVyyC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 21.30015176930862, + 0 + ], + [ + 21.30015176930862, + 17.750125236350584 + ], + [ + 0, + 17.750125236350584 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 658, + "versionNonce": 1782880140, + "isDeleted": false, + "id": "msPcz2lJcuW8pI52B7no2", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2039.045165911394, + "y": -1961.4687960170022, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 21.300149293162075, + "height": 21.300149293162075, + "seed": 884538124, + "groupIds": [ + "OotFB7H6XWAQ1ekdcaEQw", + "s71cWJFwFITMU-Lps6d9w", + "_AHsh0V9g7Gmkyg8iVyyC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 21.300149293162075, + 0 + ], + [ + 21.300149293162075, + 21.300149293162075 + ], + [ + 0, + 21.300149293162075 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 658, + "versionNonce": 1000044340, + "isDeleted": false, + "id": "46ogLanYL-b5Vshd1BuQ_", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1989.3448192114458, + "y": -1961.4687960170022, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 21.300149293162075, + "height": 21.300149293162075, + "seed": 1283307916, + "groupIds": [ + "OotFB7H6XWAQ1ekdcaEQw", + "s71cWJFwFITMU-Lps6d9w", + "_AHsh0V9g7Gmkyg8iVyyC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 21.300149293162075, + 0 + ], + [ + 21.300149293162075, + 21.300149293162075 + ], + [ + 0, + 21.300149293162075 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 658, + "versionNonce": 2002896396, + "isDeleted": false, + "id": "jOvslEebqD-I0qJnprYsh", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1999.9948950961002, + "y": -1961.4687960170022, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 10.650073408507769, + "height": 21.300149293162075, + "seed": 975611916, + "groupIds": [ + "6wBq97BQG5vcRxZ7GY2Li", + "s71cWJFwFITMU-Lps6d9w", + "_AHsh0V9g7Gmkyg8iVyyC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 10.650073408507769, + 0 + ], + [ + 10.650073408507769, + 21.300149293162075 + ], + [ + 0, + 21.300149293162075 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 658, + "versionNonce": 2098098356, + "isDeleted": false, + "id": "aNxix0zmn9vAvQeeYHjXp", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2014.1949925614203, + "y": -1961.4687960170022, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 21.30015176930862, + "height": 21.300149293162075, + "seed": 296601228, + "groupIds": [ + "PmWrgGGmRyNNh7W_7SpcI", + "s71cWJFwFITMU-Lps6d9w", + "_AHsh0V9g7Gmkyg8iVyyC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 21.30015176930862, + 0 + ], + [ + 21.30015176930862, + 21.300149293162075 + ], + [ + 0, + 21.300149293162075 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 658, + "versionNonce": 1976902796, + "isDeleted": false, + "id": "-gCeUl23RAdBaqghoMu75", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2024.8450672080003, + "y": -1961.4687960170022, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 10.650077122727579, + "height": 21.300149293162075, + "seed": 1473058060, + "groupIds": [ + "KZ7foUUozdX0JleP4ZFjN", + "s71cWJFwFITMU-Lps6d9w", + "_AHsh0V9g7Gmkyg8iVyyC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 10.650077122727579, + 0 + ], + [ + 10.650077122727579, + 21.300149293162075 + ], + [ + 0, + 21.300149293162075 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 658, + "versionNonce": 1491483188, + "isDeleted": false, + "id": "UuIl_4Ro0nQeczSgTWIqF", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2049.695245510268, + "y": -1961.4687960170022, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 10.650069694287957, + "height": 21.300149293162075, + "seed": 1778291596, + "groupIds": [ + "KZ7foUUozdX0JleP4ZFjN", + "s71cWJFwFITMU-Lps6d9w", + "_AHsh0V9g7Gmkyg8iVyyC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 10.650069694287957, + 0 + ], + [ + 10.650069694287957, + 21.300149293162075 + ], + [ + 0, + 21.300149293162075 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "text", + "version": 1380, + "versionNonce": 995668748, + "isDeleted": false, + "id": "CyL4xr_Q5hzWp5O3epy6O", + "fillStyle": "hachure", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1975.1627292376666, + "y": -1937.3655267831248, + "strokeColor": "#000000", + "backgroundColor": "transparent", + "width": 99.56015014648438, + "height": 27.44457849673917, + "seed": 1719419404, + "groupIds": [ + "vBFiVSGUjnxeTQibkcWbp", + "2Xg7V_RgexkPamV5bhliA", + "Jy4_A0VUJJS52Onc5RubG", + "keZ69FOJuasvauJpOdukW", + "1whHlGRkzVeXj0v3-syM0", + "GwTn6jd8QGpnJKyf_0Ggi", + "_AHsh0V9g7Gmkyg8iVyyC" + ], + "frameId": null, + "roundness": { + "type": 2 + }, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "fontSize": 11.942915477701884, + "fontFamily": 2, + "text": "Global Application \nLoad Balancer", + "textAlign": "center", + "verticalAlign": "top", + "containerId": null, + "originalText": "Global Application \nLoad Balancer", + "lineHeight": 1.1489898989898986, + "baseline": 24 + }, + { + "type": "rectangle", + "version": 571, + "versionNonce": 1239784204, + "isDeleted": false, + "id": "vGubQl3uFUNUf5EgTMZxr", + "fillStyle": "solid", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2460.4412056033975, + "y": -1998.999805226251, + "strokeColor": "#343a40", + "backgroundColor": "#ced4da", + "width": 58.14103866046347, + "height": 38.76069244030904, + "seed": 484798004, + "groupIds": [ + "AgHaNJVHW2KnAgQ7rVvSW" + ], + "frameId": null, + "roundness": { + "type": 1 + }, + "boundElements": [], + "updated": 1693311622859, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 682, + "versionNonce": 1696492468, + "isDeleted": false, + "id": "UboAAINFFvnut6GEQ5Qf0", + "fillStyle": "solid", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2454.8958967490294, + "y": -1955.924839909427, + "strokeColor": "#343a40", + "backgroundColor": "#ced4da", + "width": 68.31684981684984, + "height": 9.351355868465966, + "seed": 805406644, + "groupIds": [ + "AgHaNJVHW2KnAgQ7rVvSW" + ], + "frameId": null, + "roundness": { + "type": 1 + }, + "boundElements": [], + "updated": 1693311622859, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 851, + "versionNonce": 1393973644, + "isDeleted": false, + "id": "fgmq6SWA3TxH_OK31cxRI", + "fillStyle": "solid", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2505.263704355122, + "y": -1952.500399732242, + "strokeColor": "#343a40", + "backgroundColor": "#343a40", + "width": 12.241641915449078, + "height": 2.3597905067140177, + "seed": 190738740, + "groupIds": [ + "AgHaNJVHW2KnAgQ7rVvSW" + ], + "frameId": null, + "roundness": { + "type": 1 + }, + "boundElements": [], + "updated": 1693311622859, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 953, + "versionNonce": 1396626740, + "isDeleted": false, + "id": "zfNuhr69KIBjKjVv3Te23", + "fillStyle": "solid", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2483.575583232952, + "y": -1959.6346501013777, + "strokeColor": "#343a40", + "backgroundColor": "#343a40", + "width": 12.241641915449078, + "height": 2.3597905067140177, + "seed": 241314484, + "groupIds": [ + "AgHaNJVHW2KnAgQ7rVvSW" + ], + "frameId": null, + "roundness": { + "type": 1 + }, + "boundElements": [], + "updated": 1693311622859, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 1280, + "versionNonce": 615204876, + "isDeleted": false, + "id": "m4iruD5GCZYHmsh6ARTfN", + "fillStyle": "solid", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2465.434373252083, + "y": -1994.5155791557954, + "strokeColor": "#343a40", + "backgroundColor": "#343a40", + "width": 48.22892577732466, + "height": 30.250725686721108, + "seed": 1001567284, + "groupIds": [ + "AgHaNJVHW2KnAgQ7rVvSW" + ], + "frameId": null, + "roundness": { + "type": 1 + }, + "boundElements": [ + { + "id": "TAuiOhdXL8nMhW4lSzGVF", + "type": "arrow" + } + ], + "updated": 1693311622859, + "link": null, + "locked": false + }, + { + "type": "arrow", + "version": 393, + "versionNonce": 1150684852, + "isDeleted": false, + "id": "TAuiOhdXL8nMhW4lSzGVF", + "fillStyle": "hachure", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 2449.6334814011047, + "y": -1973.621191427633, + "strokeColor": "#495057", + "backgroundColor": "#a5d8ff", + "width": 367.16286324641396, + "height": 1.267797616311782, + "seed": 540427276, + "groupIds": [], + "frameId": null, + "roundness": { + "type": 2 + }, + "boundElements": [], + "updated": 1693311622859, + "link": null, + "locked": false, + "startBinding": { + "elementId": "m4iruD5GCZYHmsh6ARTfN", + "focus": -0.37026341157566467, + "gap": 15.800891850978132 + }, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": "arrow", + "points": [ + [ + 0, + 0 + ], + [ + -367.16286324641396, + 1.267797616311782 + ] + ] + }, + { + "type": "arrow", + "version": 619, + "versionNonce": 545017524, + "isDeleted": false, + "id": "jld-qaYp-lDgq1Hm1GEN6", + "fillStyle": "hachure", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 2449.642702346363, + "y": -1700.1766895233552, + "strokeColor": "#495057", + "backgroundColor": "#a5d8ff", + "width": 368.65484385066657, + "height": 0.699874537994674, + "seed": 992116916, + "groupIds": [], + "frameId": null, + "roundness": { + "type": 2 + }, + "boundElements": [], + "updated": 1693311370548, + "link": null, + "locked": false, + "startBinding": { + "elementId": "oDtXSp8ctOQP7XMgXUvae", + "focus": 4.148172941424359, + "gap": 14.90177671033041 + }, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": "arrow", + "points": [ + [ + 0, + 0 + ], + [ + -368.65484385066657, + 0.699874537994674 + ] + ] + }, + { + "type": "line", + "version": 1061, + "versionNonce": 349228300, + "isDeleted": false, + "id": "R5B-Lf8AWDyW_GkYfTlqF", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2027.5186511344352, + "y": -1712.8244280181282, + "strokeColor": "#000000", + "backgroundColor": "#4285f4", + "width": 7.100055542062618, + "height": 14.200096227246, + "seed": 851713204, + "groupIds": [ + "CQ1bM3lzktqbLiEs8kcm9", + "GBOtEdRzL8dZfz5OAKnkX", + "0mZoIb0G3Op6Tv2Ek2tUm" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + -7.100055542062618, + 0 + ], + [ + -7.100055542062618, + -14.200096227246 + ], + [ + 0, + -14.200096227246 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 1060, + "versionNonce": 2000116148, + "isDeleted": false, + "id": "75HIMaRCT06X2FxFa6xIo", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1995.568424718546, + "y": -1712.8244280181282, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 56.80039233742361, + "height": 17.750125236350584, + "seed": 587621940, + "groupIds": [ + "YbcJIKMp3pnjXFjw5gmjG", + "GBOtEdRzL8dZfz5OAKnkX", + "0mZoIb0G3Op6Tv2Ek2tUm" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 0, + 17.750125236350584 + ], + [ + 7.100049351696269, + 17.750125236350584 + ], + [ + 7.100049351696269, + 7.10005554206262 + ], + [ + 24.850170873827043, + 7.10005554206262 + ], + [ + 24.850170873827043, + 17.750125236350584 + ], + [ + 31.950226415889656, + 17.750125236350584 + ], + [ + 31.950226415889656, + 7.10005554206262 + ], + [ + 49.70034917609371, + 7.10005554206262 + ], + [ + 49.70034917609371, + 17.750125236350584 + ], + [ + 56.80039233742361, + 17.750125236350584 + ], + [ + 56.80039233742361, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 1060, + "versionNonce": 1036733324, + "isDeleted": false, + "id": "iygoDAQ2e2pWIXqjFLgtr", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2002.668474070242, + "y": -1744.774649481725, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 42.60029982439741, + "height": 17.750125236350584, + "seed": 927170484, + "groupIds": [ + "oTK-E8aRZNeeuwG7ncCQb", + "GBOtEdRzL8dZfz5OAKnkX", + "0mZoIb0G3Op6Tv2Ek2tUm" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 42.60029982439741, + 0 + ], + [ + 42.60029982439741, + 17.750125236350584 + ], + [ + 0, + 17.750125236350584 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 1060, + "versionNonce": 1342833460, + "isDeleted": false, + "id": "STTal_nPnwwcdnULvH1s_", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2023.9686221253303, + "y": -1744.774649481725, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 21.30015176930862, + "height": 17.750125236350584, + "seed": 1201760564, + "groupIds": [ + "gCinajIwnuUWSBHE-sQcZ", + "GBOtEdRzL8dZfz5OAKnkX", + "0mZoIb0G3Op6Tv2Ek2tUm" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 21.30015176930862, + 0 + ], + [ + 21.30015176930862, + 17.750125236350584 + ], + [ + 0, + 17.750125236350584 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 1060, + "versionNonce": 267516428, + "isDeleted": false, + "id": "dxF-hE2_N_vU2cU-pBAxQ", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2038.1687208287235, + "y": -1695.0743027817778, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 21.300149293162075, + "height": 21.300149293162075, + "seed": 931537588, + "groupIds": [ + "Gh2KqpIV1BDMOrlVjRw0t", + "GBOtEdRzL8dZfz5OAKnkX", + "0mZoIb0G3Op6Tv2Ek2tUm" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 21.300149293162075, + 0 + ], + [ + 21.300149293162075, + 21.300149293162075 + ], + [ + 0, + 21.300149293162075 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 1060, + "versionNonce": 466320564, + "isDeleted": false, + "id": "g5zqGfYvXPKxPuBkOysUV", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1988.468374128776, + "y": -1695.0743027817778, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 21.300149293162075, + "height": 21.300149293162075, + "seed": 228043828, + "groupIds": [ + "Gh2KqpIV1BDMOrlVjRw0t", + "GBOtEdRzL8dZfz5OAKnkX", + "0mZoIb0G3Op6Tv2Ek2tUm" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 21.300149293162075, + 0 + ], + [ + 21.300149293162075, + 21.300149293162075 + ], + [ + 0, + 21.300149293162075 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 1060, + "versionNonce": 1983830156, + "isDeleted": false, + "id": "2uQ9yIYgEOGIY0aMPaISL", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1999.1184500134302, + "y": -1695.0743027817778, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 10.650073408507769, + "height": 21.300149293162075, + "seed": 196871604, + "groupIds": [ + "WYbK7bfNXbkEfUGJfZMQq", + "GBOtEdRzL8dZfz5OAKnkX", + "0mZoIb0G3Op6Tv2Ek2tUm" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 10.650073408507769, + 0 + ], + [ + 10.650073408507769, + 21.300149293162075 + ], + [ + 0, + 21.300149293162075 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 1060, + "versionNonce": 874628660, + "isDeleted": false, + "id": "hTgnL6v7qkAPTso2cg7Cc", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2013.3185474787504, + "y": -1695.0743027817778, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 21.30015176930862, + "height": 21.300149293162075, + "seed": 1192832820, + "groupIds": [ + "Hu7ZxdfF0OFO-s4CEPgpT", + "GBOtEdRzL8dZfz5OAKnkX", + "0mZoIb0G3Op6Tv2Ek2tUm" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 21.30015176930862, + 0 + ], + [ + 21.30015176930862, + 21.300149293162075 + ], + [ + 0, + 21.300149293162075 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 1060, + "versionNonce": 1819010828, + "isDeleted": false, + "id": "K3s1Vnsu7Ig84d8WlyZLN", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2023.9686221253303, + "y": -1695.0743027817778, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 10.650077122727579, + "height": 21.300149293162075, + "seed": 1075128500, + "groupIds": [ + "DtinCYcF5v_IxZzOSB7KJ", + "GBOtEdRzL8dZfz5OAKnkX", + "0mZoIb0G3Op6Tv2Ek2tUm" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 10.650077122727579, + 0 + ], + [ + 10.650077122727579, + 21.300149293162075 + ], + [ + 0, + 21.300149293162075 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 1060, + "versionNonce": 1307762612, + "isDeleted": false, + "id": "ddCzKIj9MKTWcEJNDkTPP", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2048.8188004275976, + "y": -1695.0743027817778, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 10.650069694287957, + "height": 21.300149293162075, + "seed": 2052452916, + "groupIds": [ + "DtinCYcF5v_IxZzOSB7KJ", + "GBOtEdRzL8dZfz5OAKnkX", + "0mZoIb0G3Op6Tv2Ek2tUm" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 10.650069694287957, + 0 + ], + [ + 10.650069694287957, + 21.300149293162075 + ], + [ + 0, + 21.300149293162075 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "text", + "version": 1790, + "versionNonce": 1727210892, + "isDeleted": false, + "id": "NdTyUMyVg94zhiQoU_aYH", + "fillStyle": "hachure", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 1971.6306902829263, + "y": -1670.9710335479006, + "strokeColor": "#000000", + "backgroundColor": "transparent", + "width": 104.871337890625, + "height": 27.44457849673917, + "seed": 348228532, + "groupIds": [ + "41ylW99tmvbdcONHuTjBJ", + "6SNEKlxIFFvifHmQdQfYo", + "l_CRgPkxtok1To7KswRaa", + "DRfmOGZAtVLdORn2xR7yn", + "itc1FZ0Xs2C1kbMujZH3W", + "poY-lWcY20jfnarj8L3hI", + "0mZoIb0G3Op6Tv2Ek2tUm" + ], + "frameId": null, + "roundness": { + "type": 2 + }, + "boundElements": [], + "updated": 1693311295407, + "link": null, + "locked": false, + "fontSize": 11.942915477701884, + "fontFamily": 2, + "text": "Internal Application \nLoad Balancer", + "textAlign": "center", + "verticalAlign": "top", + "containerId": null, + "originalText": "Internal Application \nLoad Balancer", + "lineHeight": 1.1489898989898986, + "baseline": 24 + }, + { + "type": "line", + "version": 311, + "versionNonce": 754670260, + "isDeleted": false, + "id": "il4-XEVmby3tUIrvWychm", + "fillStyle": "hachure", + "strokeWidth": 4, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 2135.7533145705465, + "y": -1723.4518645312019, + "strokeColor": "#495057", + "backgroundColor": "#a5d8ff", + "width": 229.85181919907745, + "height": 1.5896375165302743, + "seed": 1306986508, + "groupIds": [], + "frameId": null, + "roundness": { + "type": 2 + }, + "boundElements": [], + "updated": 1693311374017, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 229.85181919907745, + 1.5896375165302743 + ] + ] + }, + { + "type": "rectangle", + "version": 820, + "versionNonce": 1107363852, + "isDeleted": false, + "id": "6D4oJaBAuLoDYS0zF_CWc", + "fillStyle": "hachure", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 2366.761316286691, + "y": -1810.3894047977235, + "strokeColor": "#000000", + "backgroundColor": "#e9ecef", + "width": 267.30751899828243, + "height": 204.09209589366222, + "seed": 1790217356, + "groupIds": [], + "frameId": null, + "roundness": { + "type": 3 + }, + "boundElements": [], + "updated": 1693311370548, + "link": null, + "locked": false + }, + { + "type": "text", + "version": 106, + "versionNonce": 999402420, + "isDeleted": false, + "id": "aOb2ctCdAG_zpbjcLInk7", + "fillStyle": "hachure", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 2386.830190811656, + "y": -1791.7940740188417, + "strokeColor": "#495057", + "backgroundColor": "#a5d8ff", + "width": 113.572265625, + "height": 32.199999999999996, + "seed": 5710604, + "groupIds": [], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311325062, + "link": null, + "locked": false, + "fontSize": 28, + "fontFamily": 2, + "text": "On-Prem", + "textAlign": "left", + "verticalAlign": "top", + "containerId": null, + "originalText": "On-Prem", + "lineHeight": 1.15, + "baseline": 26 + }, + { + "type": "rectangle", + "version": 498, + "versionNonce": 651282572, + "isDeleted": false, + "id": "8prp-Y-70ERWfgc7aC2Go", + "fillStyle": "solid", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2466.891987197782, + "y": -1728.3498781298488, + "strokeColor": "#343a40", + "backgroundColor": "#ced4da", + "width": 58.14103866046347, + "height": 38.76069244030904, + "seed": 1368666548, + "groupIds": [ + "fva9Mw0UhifIbppAvrWKB" + ], + "frameId": null, + "roundness": { + "type": 1 + }, + "boundElements": [], + "updated": 1693311341279, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 610, + "versionNonce": 852047372, + "isDeleted": false, + "id": "oDtXSp8ctOQP7XMgXUvae", + "fillStyle": "solid", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2461.3466783434137, + "y": -1685.2749128130247, + "strokeColor": "#343a40", + "backgroundColor": "#ced4da", + "width": 68.31684981684984, + "height": 9.351355868465966, + "seed": 2030820148, + "groupIds": [ + "fva9Mw0UhifIbppAvrWKB" + ], + "frameId": null, + "roundness": { + "type": 1 + }, + "boundElements": [ + { + "id": "jld-qaYp-lDgq1Hm1GEN6", + "type": "arrow" + } + ], + "updated": 1693311367412, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 778, + "versionNonce": 1830868748, + "isDeleted": false, + "id": "K5WdDbm7qlHVQ9sg0unq-", + "fillStyle": "solid", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2511.714485949507, + "y": -1681.8504726358399, + "strokeColor": "#343a40", + "backgroundColor": "#343a40", + "width": 12.241641915449078, + "height": 2.3597905067140177, + "seed": 1993495732, + "groupIds": [ + "fva9Mw0UhifIbppAvrWKB" + ], + "frameId": null, + "roundness": { + "type": 1 + }, + "boundElements": [], + "updated": 1693311341279, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 880, + "versionNonce": 323284916, + "isDeleted": false, + "id": "itEeNm3te2cPocf6QqiJM", + "fillStyle": "solid", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2490.0263648273362, + "y": -1688.9847230049756, + "strokeColor": "#343a40", + "backgroundColor": "#343a40", + "width": 12.241641915449078, + "height": 2.3597905067140177, + "seed": 948805172, + "groupIds": [ + "fva9Mw0UhifIbppAvrWKB" + ], + "frameId": null, + "roundness": { + "type": 1 + }, + "boundElements": [], + "updated": 1693311341279, + "link": null, + "locked": false + }, + { + "type": "rectangle", + "version": 1207, + "versionNonce": 1669993868, + "isDeleted": false, + "id": "qehCG6gKwZ0RnSR7ipnqd", + "fillStyle": "solid", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2471.8851548464677, + "y": -1723.8656520593934, + "strokeColor": "#343a40", + "backgroundColor": "#343a40", + "width": 48.22892577732466, + "height": 30.250725686721108, + "seed": 119781300, + "groupIds": [ + "fva9Mw0UhifIbppAvrWKB" + ], + "frameId": null, + "roundness": { + "type": 1 + }, + "boundElements": [], + "updated": 1693311341279, + "link": null, + "locked": false + }, + { + "type": "text", + "version": 33, + "versionNonce": 1139228212, + "isDeleted": false, + "id": "xCVELrM_0z2Bt7m7t6pMl", + "fillStyle": "hachure", + "strokeWidth": 4, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 2197.826319894205, + "y": -1758.9976717266175, + "strokeColor": "#495057", + "backgroundColor": "#e9ecef", + "width": 156.748046875, + "height": 23, + "seed": 262530100, + "groupIds": [], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311490560, + "link": null, + "locked": false, + "fontSize": 20, + "fontFamily": 2, + "text": "VPN/Interconnect", + "textAlign": "left", + "verticalAlign": "top", + "containerId": null, + "originalText": "VPN/Interconnect", + "lineHeight": 1.15, + "baseline": 19 + }, + { + "type": "line", + "version": 187, + "versionNonce": 1239730612, + "isDeleted": false, + "id": "n_lhRcvZtm3yWi3zNEBJV", + "fillStyle": "cross-hatch", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1964.9459496117454, + "y": -1958.8875906849437, + "strokeColor": "#1971c2", + "backgroundColor": "#e9ecef", + "width": 126.17815604760767, + "height": 1.1773083313553343, + "seed": 1396605748, + "groupIds": [], + "frameId": null, + "roundness": { + "type": 2 + }, + "boundElements": [], + "updated": 1693311460507, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + -126.17815604760767, + 1.1773083313553343 + ] + ] + }, + { + "type": "line", + "version": 306, + "versionNonce": 1257036684, + "isDeleted": false, + "id": "4L4IgDappf0lRmyc8X10d", + "fillStyle": "cross-hatch", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1961.783334454876, + "y": -1710.9000432513847, + "strokeColor": "#1971c2", + "backgroundColor": "#e9ecef", + "width": 122.06028957987155, + "height": 243.10060696483674, + "seed": 913199116, + "groupIds": [], + "frameId": null, + "roundness": { + "type": 2 + }, + "boundElements": [], + "updated": 1693311460507, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + -122.06028957987155, + -243.10060696483674 + ] + ] + }, + { + "type": "arrow", + "version": 208, + "versionNonce": 2022298036, + "isDeleted": false, + "id": "1hR9SCYu3Fd8-OWyibUBe", + "fillStyle": "cross-hatch", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1772.833101624224, + "y": -1902.1597754192694, + "strokeColor": "#1971c2", + "backgroundColor": "#e9ecef", + "width": 0.6456206978398313, + "height": 155.9743650605269, + "seed": 69677324, + "groupIds": [], + "frameId": null, + "roundness": { + "type": 2 + }, + "boundElements": [], + "updated": 1693311488870, + "link": null, + "locked": false, + "startBinding": { + "elementId": "IfVzFaOMx3j3dME8GrhUs", + "focus": 0.15801185672017465, + "gap": 8.268924980427641 + }, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": "arrow", + "points": [ + [ + 0, + 0 + ], + [ + 0.6456206978398313, + 155.9743650605269 + ] + ] + }, + { + "type": "text", + "version": 304, + "versionNonce": 594979252, + "isDeleted": false, + "id": "n7ln0pmmtpM6jtsJAZLmo", + "fillStyle": "hachure", + "strokeWidth": 4, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1617.267374474415, + "y": -1860.5351407849744, + "strokeColor": "#495057", + "backgroundColor": "#e9ecef", + "width": 117.3671875, + "height": 36.8, + "seed": 910776244, + "groupIds": [], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311514550, + "link": null, + "locked": false, + "fontSize": 16, + "fontFamily": 2, + "text": "VPC Serverless \nConnector", + "textAlign": "center", + "verticalAlign": "top", + "containerId": null, + "originalText": "VPC Serverless \nConnector", + "lineHeight": 1.15, + "baseline": 33 + }, + { + "type": "line", + "version": 337, + "versionNonce": 1336321716, + "isDeleted": false, + "id": "R-U4aOs1dKPpH1p-kUXVj", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2194.3454487369822, + "y": -2008.1902074796785, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 53.252513658530155, + "height": 66.25938635522165, + "seed": 1866338828, + "groupIds": [ + "ng1U6l9sAI234KMxvTZ2o", + "LA_S6hEfLFuoibT7K3arg", + "omvCuEw-yZaaMA9sUJfIC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311607367, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 26.626256829265078, + 11.78184860439602 + ], + [ + 26.626256829265078, + 29.652788806337103 + ], + [ + 26.626256829265078, + 29.652788806337103 + ], + [ + 26.604619250085825, + 31.214368306506216 + ], + [ + 26.52013407235635, + 32.76351547468527 + ], + [ + 26.373875363635207, + 34.29878764285813 + ], + [ + 26.166873252353522, + 35.818725055570226 + ], + [ + 25.900201806069838, + 37.32187772161756 + ], + [ + 25.574910681716354, + 38.806795649796086 + ], + [ + 25.192054418350562, + 40.272023966776544 + ], + [ + 24.752692437155186, + 41.71612244560541 + ], + [ + 24.257874395062434, + 43.13762644870285 + ], + [ + 23.708659713255045, + 44.535090866990146 + ], + [ + 23.10610781291576, + 45.90706570926324 + ], + [ + 22.451263468851515, + 47.252091220067584 + ], + [ + 21.745200748620857, + 48.56872717244969 + ], + [ + 20.98894978065492, + 49.855513810955 + ], + [ + 20.183584632512247, + 51.11100602650476 + ], + [ + 19.330159843250307, + 52.33374894576966 + ], + [ + 18.4297250698013, + 53.52228769542044 + ], + [ + 17.48333485122271, + 54.675177166378305 + ], + [ + 16.492048608697264, + 55.790962485313976 + ], + [ + 15.456920881282457, + 56.868193661023454 + ], + [ + 14.379006208035735, + 57.9054158201774 + ], + [ + 13.259368892265126, + 58.90118385369711 + ], + [ + 12.09904882665229, + 59.85404288825326 + ], + [ + 10.89911031450523, + 60.76254293264181 + ], + [ + 9.66060789488143, + 61.6252291135335 + ], + [ + 8.384600988963609, + 62.44065143972429 + ], + [ + 7.072144135809265, + 63.20735992001017 + ], + [ + 5.724286992350592, + 63.9239045631871 + ], + [ + 4.342088979770334, + 64.58883049592579 + ], + [ + 2.926599755000689, + 65.20068772702223 + ], + [ + 1.4788885034749268, + 65.7580213831471 + ], + [ + 0, + 66.25938635522165 + ], + [ + -1.477797348477959, + 65.7591882110857 + ], + [ + -2.9244906768857386, + 65.20307508627732 + ], + [ + -4.339025446165864, + 64.59250185412587 + ], + [ + -5.720344676198234, + 63.92892338796062 + ], + [ + -7.067391386862741, + 63.21377991473506 + ], + [ + -8.379113480164545, + 62.44851654352796 + ], + [ + -9.654453975983534, + 61.63458326554331 + ], + [ + -10.892353453136977, + 60.77343007198517 + ], + [ + -12.091764695755302, + 59.86649718980701 + ], + [ + -13.251623400530494, + 58.91522972808762 + ], + [ + -14.370879910530354, + 57.92108744228152 + ], + [ + -15.448477245634779, + 56.88551055934222 + ], + [ + -16.48335598466102, + 55.809934424097946 + ], + [ + -17.47446647067688, + 54.695823674128555 + ], + [ + -18.420749282499617, + 53.54461853638747 + ], + [ + -19.32114988107176, + 52.35776411995351 + ], + [ + -20.17461372733583, + 51.13671529815592 + ], + [ + -20.980083841171723, + 49.88290741582297 + ], + [ + -21.736505683521976, + 48.59779534628392 + ], + [ + -22.442822274266465, + 47.28281931649227 + ], + [ + -23.097979074347734, + 45.93943419977733 + ], + [ + -23.700921544708308, + 44.56908510521784 + ], + [ + -24.250591484696756, + 43.17322202401783 + ], + [ + -24.74593557578693, + 41.75327541888024 + ], + [ + -25.185895617327397, + 40.310709927384934 + ], + [ + -25.569419511323336, + 38.84697065861065 + ], + [ + -25.89545149818594, + 37.36349783951088 + ], + [ + -26.162932156732477, + 35.8617463434149 + ], + [ + -26.3708093889681, + 34.34315151515097 + ], + [ + -26.51802621477272, + 32.80916822804836 + ], + [ + -26.603526874557538, + 31.261246473311093 + ], + [ + -26.626256829265078, + 29.70082647789267 + ], + [ + -26.626256829265078, + 11.865918801477871 + ], + [ + 0, + 0.08407080734751268 + ] + ] + }, + { + "type": "line", + "version": 337, + "versionNonce": 1619218060, + "isDeleted": false, + "id": "n0rqf1bsn46wLsUI73IjO", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2194.3454487369822, + "y": -2014.5074880864959, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 64.79416597169477, + "height": 78.53365069094667, + "seed": 1145565324, + "groupIds": [ + "ng1U6l9sAI234KMxvTZ2o", + "LA_S6hEfLFuoibT7K3arg", + "omvCuEw-yZaaMA9sUJfIC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311607367, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + -32.3910758358403, + 14.448078211167381 + ], + [ + -32.3910758358403, + 36.00609705655551 + ], + [ + -32.3910758358403, + 36.00609705655551 + ], + [ + -32.367369456079544, + 37.84777384749002 + ], + [ + -32.2678552659841, + 39.674028004708994 + ], + [ + -32.093853880438466, + 41.48310440417927 + ], + [ + -31.84668286299882, + 43.27322839336664 + ], + [ + -31.527663438815274, + 45.04263752505005 + ], + [ + -31.138114391975353, + 46.78956446988316 + ], + [ + -30.67935450656653, + 48.51224189851966 + ], + [ + -30.15270500773895, + 50.20890736373851 + ], + [ + -29.559482848783137, + 51.87779841831865 + ], + [ + -28.90100986511489, + 53.517137968663214 + ], + [ + -28.17860423055603, + 55.12516844967642 + ], + [ + -27.393585339459733, + 56.70012253201196 + ], + [ + -26.54727380671047, + 58.24023776844875 + ], + [ + -25.64098780613007, + 59.74373706538998 + ], + [ + -24.676047952603025, + 61.208867739865106 + ], + [ + -23.65377241995116, + 62.63385758040253 + ], + [ + -22.575480602527637, + 64.01693925765596 + ], + [ + -21.44249311521693, + 65.35635032440432 + ], + [ + -20.25613057290352, + 66.65032345130129 + ], + [ + -19.017711149409237, + 67.89709130900057 + ], + [ + -17.728551798024615, + 69.0948914502811 + ], + [ + -16.389973133634122, + 70.2419614279218 + ], + [ + -15.003298212184866, + 71.33651926620058 + ], + [ + -13.569842766436057, + 72.37681228214687 + ], + [ + -12.090927411272164, + 73.36107314641444 + ], + [ + -10.567872761577664, + 74.28753941178218 + ], + [ + -9.001996991174408, + 75.15443398465321 + ], + [ + -7.394618273884215, + 75.96000418205706 + ], + [ + -5.747059665654212, + 76.70247291039686 + ], + [ + -4.060636899243595, + 77.38008260457683 + ], + [ + -2.336670589536845, + 77.99106593525062 + ], + [ + -0.5764813514184316, + 78.53365069094667 + ], + [ + 0.6005014077275319, + 78.53365069094667 + ], + [ + 0.6005014077275319, + 78.53365069094667 + ], + [ + 2.353018385990306, + 77.99457618331694 + ], + [ + 4.06974450392746, + 77.38739114610014 + ], + [ + 5.749351823466625, + 76.71383361589105 + ], + [ + 7.3905368171617685, + 75.97567580416117 + ], + [ + 8.991981311191044, + 75.17466062963058 + ], + [ + 10.552362249607338, + 74.31256030377082 + ], + [ + 12.070371222839338, + 73.39111286317662 + ], + [ + 13.544694939190483, + 72.41209540144482 + ], + [ + 14.974020106964192, + 71.37725571942072 + ], + [ + 16.357023670213366, + 70.28834650007481 + ], + [ + 17.692392337241404, + 69.14713019062812 + ], + [ + 18.978817698477027, + 67.9553594740512 + ], + [ + 20.21498158009839, + 66.7148016796904 + ], + [ + 21.399565808283615, + 65.42720460839091 + ], + [ + 22.531252209210923, + 64.09432582524855 + ], + [ + 23.608732373308964, + 62.71793265960966 + ], + [ + 24.630693008881156, + 61.29976314806893 + ], + [ + 25.595815942105688, + 59.841589502097975 + ], + [ + 26.502782999160708, + 58.3451644046673 + ], + [ + 27.350280888349634, + 56.81225030299795 + ], + [ + 28.137006082226424, + 55.244594997935216 + ], + [ + 28.861625760593434, + 53.643960936700104 + ], + [ + 29.522826631754107, + 52.01210080226318 + ], + [ + 30.11930516826239, + 50.35077704184546 + ], + [ + 30.649738314171188, + 48.661747220542765 + ], + [ + 31.112807895658626, + 46.946759139200324 + ], + [ + 31.507210385278697, + 45.20758012716447 + ], + [ + 31.831622727084287, + 43.44596774953099 + ], + [ + 32.08473162937882, + 41.663669807145155 + ], + [ + 32.26521891834042, + 39.86244874722799 + ], + [ + 32.371781066523106, + 38.04406457593793 + ], + [ + 32.40309013585447, + 36.210269976245506 + ], + [ + 32.40309013585447, + 14.448078211167381 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 337, + "versionNonce": 1460121652, + "isDeleted": false, + "id": "peJDVA9mTcOvWBbtedtk9", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2194.3454487369822, + "y": -2008.1902074796785, + "strokeColor": "#000000", + "backgroundColor": "#fff", + "width": 53.252513658530155, + "height": 66.25938635522165, + "seed": 1234304780, + "groupIds": [ + "JHrgg4sS7bNU14okiLtbP", + "LA_S6hEfLFuoibT7K3arg", + "omvCuEw-yZaaMA9sUJfIC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311607367, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + 26.626256829265078, + 11.78184860439602 + ], + [ + 26.626256829265078, + 29.652788806337103 + ], + [ + 26.626256829265078, + 29.652788806337103 + ], + [ + 26.604619250085825, + 31.214368306506216 + ], + [ + 26.52013407235635, + 32.76351547468527 + ], + [ + 26.373875363635207, + 34.29878764285813 + ], + [ + 26.166873252353522, + 35.818725055570226 + ], + [ + 25.900201806069838, + 37.32187772161756 + ], + [ + 25.574910681716354, + 38.806795649796086 + ], + [ + 25.192054418350562, + 40.272023966776544 + ], + [ + 24.752692437155186, + 41.71612244560541 + ], + [ + 24.257874395062434, + 43.13762644870285 + ], + [ + 23.708659713255045, + 44.535090866990146 + ], + [ + 23.10610781291576, + 45.90706570926324 + ], + [ + 22.451263468851515, + 47.252091220067584 + ], + [ + 21.745200748620857, + 48.56872717244969 + ], + [ + 20.98894978065492, + 49.855513810955 + ], + [ + 20.183584632512247, + 51.11100602650476 + ], + [ + 19.330159843250307, + 52.33374894576966 + ], + [ + 18.4297250698013, + 53.52228769542044 + ], + [ + 17.48333485122271, + 54.675177166378305 + ], + [ + 16.492048608697264, + 55.790962485313976 + ], + [ + 15.456920881282457, + 56.868193661023454 + ], + [ + 14.379006208035735, + 57.9054158201774 + ], + [ + 13.259368892265126, + 58.90118385369711 + ], + [ + 12.09904882665229, + 59.85404288825326 + ], + [ + 10.89911031450523, + 60.76254293264181 + ], + [ + 9.66060789488143, + 61.6252291135335 + ], + [ + 8.384600988963609, + 62.44065143972429 + ], + [ + 7.072144135809265, + 63.20735992001017 + ], + [ + 5.724286992350592, + 63.9239045631871 + ], + [ + 4.342088979770334, + 64.58883049592579 + ], + [ + 2.926599755000689, + 65.20068772702223 + ], + [ + 1.4788885034749268, + 65.7580213831471 + ], + [ + 0, + 66.25938635522165 + ], + [ + -1.477797348477959, + 65.7591882110857 + ], + [ + -2.9244906768857386, + 65.20307508627732 + ], + [ + -4.339025446165864, + 64.59250185412587 + ], + [ + -5.720344676198234, + 63.92892338796062 + ], + [ + -7.067391386862741, + 63.21377991473506 + ], + [ + -8.379113480164545, + 62.44851654352796 + ], + [ + -9.654453975983534, + 61.63458326554331 + ], + [ + -10.892353453136977, + 60.77343007198517 + ], + [ + -12.091764695755302, + 59.86649718980701 + ], + [ + -13.251623400530494, + 58.91522972808762 + ], + [ + -14.370879910530354, + 57.92108744228152 + ], + [ + -15.448477245634779, + 56.88551055934222 + ], + [ + -16.48335598466102, + 55.809934424097946 + ], + [ + -17.47446647067688, + 54.695823674128555 + ], + [ + -18.420749282499617, + 53.54461853638747 + ], + [ + -19.32114988107176, + 52.35776411995351 + ], + [ + -20.17461372733583, + 51.13671529815592 + ], + [ + -20.980083841171723, + 49.88290741582297 + ], + [ + -21.736505683521976, + 48.59779534628392 + ], + [ + -22.442822274266465, + 47.28281931649227 + ], + [ + -23.097979074347734, + 45.93943419977733 + ], + [ + -23.700921544708308, + 44.56908510521784 + ], + [ + -24.250591484696756, + 43.17322202401783 + ], + [ + -24.74593557578693, + 41.75327541888024 + ], + [ + -25.185895617327397, + 40.310709927384934 + ], + [ + -25.569419511323336, + 38.84697065861065 + ], + [ + -25.89545149818594, + 37.36349783951088 + ], + [ + -26.162932156732477, + 35.8617463434149 + ], + [ + -26.3708093889681, + 34.34315151515097 + ], + [ + -26.51802621477272, + 32.80916822804836 + ], + [ + -26.603526874557538, + 31.261246473311093 + ], + [ + -26.626256829265078, + 29.70082647789267 + ], + [ + -26.626256829265078, + 11.865918801477871 + ], + [ + 0, + 0.08407080734751268 + ] + ] + }, + { + "type": "line", + "version": 337, + "versionNonce": 1118936332, + "isDeleted": false, + "id": "OBVgG77jqBVttubO-8vdq", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2202.872578490964, + "y": -1967.1038596648962, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 23.59972973431832, + "height": 22.73500282506541, + "seed": 1737899404, + "groupIds": [ + "flen9nINK9vnXf-Fs5Ue0", + "LA_S6hEfLFuoibT7K3arg", + "omvCuEw-yZaaMA9sUJfIC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311607367, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + -19.51631527964584, + 19.61239062275698 + ], + [ + -19.51631527964584, + 19.61239062275698 + ], + [ + -18.30029748793496, + 20.463418288513278 + ], + [ + -17.048252052823056, + 21.26827569562828 + ], + [ + -15.760176533247499, + 22.02584971954132 + ], + [ + -14.436068488145656, + 22.73500282506541 + ], + [ + 4.083414454672477, + 4.119439657010865 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 337, + "versionNonce": 814451124, + "isDeleted": false, + "id": "KWoQ8q1bgV6O9ngOVNten", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2199.605845950801, + "y": -1983.5576153240688, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 29.892986928365477, + "height": 30.613588617638523, + "seed": 1737403404, + "groupIds": [ + "flen9nINK9vnXf-Fs5Ue0", + "LA_S6hEfLFuoibT7K3arg", + "omvCuEw-yZaaMA9sUJfIC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311607367, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + -25.797562445538446, + 25.941687665518323 + ], + [ + -25.797562445538446, + 25.941687665518323 + ], + [ + -24.980507048446146, + 27.159768155154122 + ], + [ + -24.116158503901357, + 28.345192108885136 + ], + [ + -23.206772353777005, + 29.49684640215069 + ], + [ + -22.254601698883377, + 30.613588617638523 + ], + [ + 4.095424482827033, + 4.1194420980735 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "line", + "version": 337, + "versionNonce": 387062668, + "isDeleted": false, + "id": "REGazF5VKFCTQzMNRFKbP", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2183.2721930142357, + "y": -1986.896408033159, + "strokeColor": "#000000", + "backgroundColor": "#aecbfa", + "width": 19.095961853173932, + "height": 21.570032535136626, + "seed": 1534413452, + "groupIds": [ + "flen9nINK9vnXf-Fs5Ue0", + "LA_S6hEfLFuoibT7K3arg", + "omvCuEw-yZaaMA9sUJfIC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311607367, + "link": null, + "locked": false, + "startBinding": null, + "endBinding": null, + "lastCommittedPoint": null, + "startArrowhead": null, + "endArrowhead": null, + "points": [ + [ + 0, + 0 + ], + [ + -15.012549839564088, + 15.07259753927421 + ], + [ + -15.012549839564088, + 15.07259753927421 + ], + [ + -14.688467041213968, + 16.736367244450225 + ], + [ + -14.293449403810369, + 18.375360163900897 + ], + [ + -13.828622257227131, + 19.987335402129094 + ], + [ + -13.295114592932032, + 21.570032535136626 + ], + [ + 4.083412013609845, + 4.119446980198766 + ], + [ + 0, + 0 + ], + [ + 0, + 0 + ] + ] + }, + { + "type": "ellipse", + "version": 337, + "versionNonce": 794309428, + "isDeleted": false, + "id": "2RGRHTUVawHblLxdmnPhC", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2199.3416253314003, + "y": -1970.5147125429141, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 11.145317112204834, + "height": 11.145317112204834, + "seed": 100931852, + "groupIds": [ + "e235bEG92vASATYdRDkSW", + "LA_S6hEfLFuoibT7K3arg", + "omvCuEw-yZaaMA9sUJfIC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311607367, + "link": null, + "locked": false + }, + { + "type": "ellipse", + "version": 337, + "versionNonce": 937347596, + "isDeleted": false, + "id": "r41NRvAWP0G6p9PkQtixW", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2196.038867588899, + "y": -1986.896408033159, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 11.145317112204834, + "height": 11.145317112204834, + "seed": 1119164300, + "groupIds": [ + "e235bEG92vASATYdRDkSW", + "LA_S6hEfLFuoibT7K3arg", + "omvCuEw-yZaaMA9sUJfIC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311607367, + "link": null, + "locked": false + }, + { + "type": "ellipse", + "version": 337, + "versionNonce": 1372826804, + "isDeleted": false, + "id": "4iFM40fUx6bWn2AckREZ7", + "fillStyle": "solid", + "strokeWidth": 1, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2179.7052097702085, + "y": -1990.2351983011868, + "strokeColor": "#000000", + "backgroundColor": "#669df6", + "width": 11.145317112204834, + "height": 11.145317112204834, + "seed": 1841448460, + "groupIds": [ + "e235bEG92vASATYdRDkSW", + "LA_S6hEfLFuoibT7K3arg", + "omvCuEw-yZaaMA9sUJfIC" + ], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693311607367, + "link": null, + "locked": false + }, + { + "type": "text", + "version": 1046, + "versionNonce": 945544060, + "isDeleted": false, + "id": "zokrrtrqCTA4sdSchyeKi", + "fillStyle": "hachure", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 0, + "opacity": 100, + "angle": 0, + "x": 2154.586397934257, + "y": -1931.2655151672457, + "strokeColor": "#000000", + "backgroundColor": "transparent", + "width": 79.36479187011719, + "height": 16.251850252262567, + "seed": 1277535372, + "groupIds": [ + "il6ujkh8lWpwImIyEFFwS", + "eL6pb70rQtosyYRIkkTz6", + "sUq8jzZlPCueNX8Vkw8R_", + "2oxJyo2US2MWfhDq8hBIX", + "YAXC5Z8rCERiRzJ07BtDR", + "BB12claUSzMP_AqjEGS7C", + "omvCuEw-yZaaMA9sUJfIC" + ], + "frameId": null, + "roundness": { + "type": 2 + }, + "boundElements": [], + "updated": 1693399360386, + "link": null, + "locked": false, + "fontSize": 14.144467472298855, + "fontFamily": 2, + "text": "Cloud Armor", + "textAlign": "center", + "verticalAlign": "top", + "containerId": null, + "originalText": "Cloud Armor", + "lineHeight": 1.1489898989898986, + "baseline": 13 + }, + { + "type": "rectangle", + "version": 158, + "versionNonce": 1795918644, + "isDeleted": false, + "id": "43t08qUBgpYV35dPr4FqE", + "fillStyle": "solid", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1490.9084466447387, + "y": -2228.622425041188, + "strokeColor": "#1864ab", + "backgroundColor": "#4285f4", + "width": 1157, + "height": 66, + "seed": 1070535860, + "groupIds": [], + "frameId": null, + "roundness": { + "type": 3 + }, + "boundElements": [ + { + "type": "text", + "id": "aR0cFrtx68oO4Hn-Pp404" + } + ], + "updated": 1693319736943, + "link": null, + "locked": false + }, + { + "type": "text", + "version": 143, + "versionNonce": 1168962060, + "isDeleted": false, + "id": "aR0cFrtx68oO4Hn-Pp404", + "fillStyle": "solid", + "strokeWidth": 2, + "strokeStyle": "solid", + "roughness": 1, + "opacity": 100, + "angle": 0, + "x": 1742.4553216447387, + "y": -2217.2224250411878, + "strokeColor": "#ffffff", + "backgroundColor": "#4285f4", + "width": 653.90625, + "height": 43.199999999999996, + "seed": 276268940, + "groupIds": [], + "frameId": null, + "roundness": null, + "boundElements": [], + "updated": 1693319736943, + "link": null, + "locked": false, + "fontSize": 36, + "fontFamily": 3, + "text": "Serverless PHPIPAM on Cloud Run", + "textAlign": "center", + "verticalAlign": "middle", + "containerId": "43t08qUBgpYV35dPr4FqE", + "originalText": "Serverless PHPIPAM on Cloud Run", + "lineHeight": 1.2, + "baseline": 35 + } + ], + "appState": { + "gridSize": null, + "viewBackgroundColor": "#ffffff" + }, + "files": { + "af2541e7127d4fdc679914759de23d8bd87e9264": { + "mimeType": "image/png", + "id": "af2541e7127d4fdc679914759de23d8bd87e9264", + "dataURL": "", + "created": 1693297560288, + "lastRetrieved": 1693819633924 + }, + "7f10a90d0c745f95f1922694e27ad51a6bf7d09e": { + "mimeType": "image/png", + "id": "7f10a90d0c745f95f1922694e27ad51a6bf7d09e", + "dataURL": "", + "created": 1693297606675, + "lastRetrieved": 1693819633924 + } + } +} \ No newline at end of file diff --git a/blueprints/third-party-solutions/phpipam/glb.tf b/blueprints/third-party-solutions/phpipam/glb.tf new file mode 100644 index 00000000..9016330e --- /dev/null +++ b/blueprints/third-party-solutions/phpipam/glb.tf @@ -0,0 +1,153 @@ +/** + * Copyright 2023 Google LLC + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +locals { + glb_create = var.phpipam_exposure == "EXTERNAL" + iap_sa_email = try(module.project.service_accounts.robots["iap"].email, "") +} + +# Reserved static IP for the Load Balancer +module "addresses" { + source = "../../../modules/net-address" + count = local.glb_create ? 1 : 0 + project_id = var.project_id + global_addresses = ["phpipam"] +} + +# Global L7 HTTPS Load Balancer in front of Cloud Run +module "glb" { + source = "../../../modules/net-lb-app-ext" + count = local.glb_create ? 1 : 0 + project_id = module.project.project_id + name = "phpipam-glb" + address = module.addresses.0.global_addresses["phpipam"].address + protocol = "HTTPS" + + backend_service_configs = { + default = { + backends = [ + { backend = "phpipam" } + ] + health_checks = [] + port_name = "http" + security_policy = try(google_compute_security_policy.policy[0].name, + null) + iap_config = try({ + oauth2_client_id = google_iap_client.iap_client[0].client_id, + oauth2_client_secret = google_iap_client.iap_client[0].secret + }, null) + } + } + health_check_configs = {} + neg_configs = { + phpipam = { + cloudrun = { + region = var.region + target_service = { + name = module.cloud_run.service_name + } + } + } + } + ssl_certificates = { + managed_configs = { + default = { + domains = [local.domain] + } + } + } +} + +# Cloud Armor configuration +resource "google_compute_security_policy" "policy" { + count = local.glb_create && var.security_policy.enabled ? 1 : 0 + project = module.project.project_id + name = "cloud-run-policy" + + rule { + action = "deny(403)" + priority = 1000 + match { + versioned_expr = "SRC_IPS_V1" + config { + src_ip_ranges = var.security_policy.ip_blacklist + } + } + description = "Deny access to list of IPs" + } + rule { + action = "deny(403)" + priority = 900 + match { + expr { + expression = "request.path.matches(\"${var.security_policy.path_blocked}\")" + } + } + description = "Deny access to specific URL paths" + } + rule { + action = "allow" + priority = "2147483647" + match { + versioned_expr = "SRC_IPS_V1" + config { + src_ip_ranges = ["*"] + } + } + description = "Default rule" + } +} + +# Identity-Aware Proxy (IAP) or OAuth brand (see OAuth consent screen) +# Note: +# Only "Organization Internal" brands can be created programmatically +# via API. To convert it into an external brand please use the GCP +# Console. +# Brands can only be created once for a Google Cloud project and the +# underlying Google API doesn't support DELETE or PATCH methods. +# Destroying a Terraform-managed Brand will remove it from state but +# will not delete it from Google Cloud. +resource "google_iap_brand" "iap_brand" { + count = local.glb_create && var.iap.enabled ? 1 : 0 + project = module.project.project_id + # Support email displayed on the OAuth consent screen. The caller must be + # the user with the associated email address, or if a group email is + # specified, the caller can be either a user or a service account which + # is an owner of the specified group in Cloud Identity. + support_email = var.iap.email + application_title = var.iap.app_title +} + +# IAP owned OAuth2 client +# Note: +# Only internal org clients can be created via declarative tools. +# External clients must be manually created via the GCP console. +# Warning: +# All arguments including secret will be stored in the raw state as plain-text. +resource "google_iap_client" "iap_client" { + count = local.glb_create && var.iap.enabled ? 1 : 0 + display_name = var.iap.oauth2_client_name + brand = google_iap_brand.iap_brand[0].name +} + +# IAM policy for IAP +# For simplicity we use the same email as support_email and authorized member +resource "google_iap_web_iam_member" "iap_iam" { + count = local.glb_create && var.iap.enabled ? 1 : 0 + project = module.project.project_id + role = "roles/iap.httpsResourceAccessor" + member = "user:${var.iap.email}" +} diff --git a/blueprints/third-party-solutions/phpipam/ilb.tf b/blueprints/third-party-solutions/phpipam/ilb.tf new file mode 100644 index 00000000..814f937f --- /dev/null +++ b/blueprints/third-party-solutions/phpipam/ilb.tf @@ -0,0 +1,89 @@ +/** + * Copyright 2023 Google LLC + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +locals { + ilb_create = var.phpipam_exposure == "INTERNAL" +} + +# default ssl certificate +resource "tls_private_key" "default" { + algorithm = "RSA" + rsa_bits = 2048 +} + +resource "tls_self_signed_cert" "default" { + private_key_pem = tls_private_key.default.private_key_pem + validity_period_hours = 720 + allowed_uses = [ + "key_encipherment", + "digital_signature", + "server_auth", + ] + subject { + common_name = local.domain + organization = "ACME Examples, Inc" + } +} + +module "ilb-l7" { + source = "../../../modules/net-lb-app-int" + count = local.ilb_create ? 1 : 0 + project_id = var.project_id + name = "ilb-l7-cr" + protocol = "HTTPS" + region = var.region + + backend_service_configs = { + default = { + project_id = var.project_id + backends = [ + { + group = "phpipam" + } + ] + health_checks = [] + } + } + health_check_configs = { + default = { + https = { port = 443 } + } + } + neg_configs = { + phpipam = { + project_id = var.project_id + cloudrun = { + region = var.region + target_service = { + name = module.cloud_run.service_name + } + } + } + } + ssl_certificates = { + create_configs = { + default = { + # certificate and key could also be read via file() from external files + certificate = tls_self_signed_cert.default.cert_pem + private_key = tls_private_key.default.private_key_pem + } + } + } + vpc_config = { + network = local.network + subnetwork = local.subnetwork + } +} diff --git a/blueprints/third-party-solutions/phpipam/images/phpipam.png b/blueprints/third-party-solutions/phpipam/images/phpipam.png new file mode 100644 index 00000000..6d032778 Binary files /dev/null and b/blueprints/third-party-solutions/phpipam/images/phpipam.png differ diff --git a/blueprints/third-party-solutions/phpipam/images/phpipam_admin.png b/blueprints/third-party-solutions/phpipam/images/phpipam_admin.png new file mode 100644 index 00000000..aea68b03 Binary files /dev/null and b/blueprints/third-party-solutions/phpipam/images/phpipam_admin.png differ diff --git a/blueprints/third-party-solutions/phpipam/images/phpipam_db.png b/blueprints/third-party-solutions/phpipam/images/phpipam_db.png new file mode 100644 index 00000000..9d218a42 Binary files /dev/null and b/blueprints/third-party-solutions/phpipam/images/phpipam_db.png differ diff --git a/blueprints/third-party-solutions/phpipam/images/phpipam_home.png b/blueprints/third-party-solutions/phpipam/images/phpipam_home.png new file mode 100644 index 00000000..49168616 Binary files /dev/null and b/blueprints/third-party-solutions/phpipam/images/phpipam_home.png differ diff --git a/blueprints/third-party-solutions/phpipam/images/phpipam_install.png b/blueprints/third-party-solutions/phpipam/images/phpipam_install.png new file mode 100644 index 00000000..35835cc9 Binary files /dev/null and b/blueprints/third-party-solutions/phpipam/images/phpipam_install.png differ diff --git a/blueprints/third-party-solutions/phpipam/main.tf b/blueprints/third-party-solutions/phpipam/main.tf new file mode 100644 index 00000000..7998dfa2 --- /dev/null +++ b/blueprints/third-party-solutions/phpipam/main.tf @@ -0,0 +1,144 @@ +/** + * Copyright 2023 Google LLC + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +locals { + cloudsql_conf = { + database_version = "MYSQL_8_0" + tier = "db-g1-small" + db = "phpipam" + user = "admin" + } + connector = var.connector == null ? module.cloud_run.vpc_connector : var.connector + domain = ( + var.custom_domain != null ? var.custom_domain : ( + var.phpipam_exposure == "EXTERNAL" ? + "${module.addresses.0.global_addresses["phpipam"].address}.nip.io" : "phpipam.internal") + ) + iam = { + # CloudSQL + "roles/cloudsql.admin" = var.admin_principals + "roles/cloudsql.client" = var.admin_principals + "roles/cloudsql.instanceUser" = var.admin_principals + # common roles + "roles/logging.admin" = var.admin_principals + "roles/iam.serviceAccountUser" = var.admin_principals + "roles/iam.serviceAccountTokenCreator" = var.admin_principals + } + network = var.vpc_config == null ? module.vpc.0.self_link : var.vpc_config.network + phpipam_password = var.phpipam_password == null ? random_password.phpipam_password.result : var.phpipam_password + subnetwork = var.vpc_config == null ? module.vpc.0.subnet_self_links["${var.region}/ilb"] : var.vpc_config.subnetwork +} + + +# either create a project or set up the given one +module "project" { + source = "../../../modules/project" + billing_account = try(var.project_create.billing_account_id, null) + iam = var.project_create != null ? local.iam : {} + name = var.project_id + parent = try(var.project_create.parent, null) + prefix = var.project_create == null ? null : var.prefix + project_create = var.project_create != null + services = [ + "iap.googleapis.com", + "logging.googleapis.com", + "monitoring.googleapis.com", + "run.googleapis.com", + "servicenetworking.googleapis.com", + "sqladmin.googleapis.com", + "sql-component.googleapis.com", + "vpcaccess.googleapis.com" + ] +} + + +# create a VPC for CloudSQL and ILB +module "vpc" { + source = "../../../modules/net-vpc" + count = var.vpc_config == null ? 1 : 0 + project_id = module.project.project_id + name = "${var.prefix}-sql-vpc" + + psa_config = { + ranges = { + cloud-sql = var.ip_ranges.psa + } + } + subnets = [ + { + ip_cidr_range = var.ip_ranges.ilb + name = "ilb" + region = var.region + } + ] +} + +resource "random_password" "phpipam_password" { + length = 8 +} + +# create the Cloud Run service +module "cloud_run" { + source = "../../../modules/cloud-run" + project_id = module.project.project_id + name = "${var.prefix}-cr-phpipam" + prefix = var.prefix + ingress_settings = "all" + region = var.region + + containers = { + phpipam = { + image = var.phpipam_config.image + ports = { + http = { + name = "http1" + protocol = null + container_port = var.phpipam_config.port + } + } + env_from = null + # set up the database connection + env = { + "TZ" = "Europe/Rome" + "IPAM_DATABASE_HOST" = module.cloudsql.ip + "IPAM_DATABASE_USER" = local.cloudsql_conf.user + "IPAM_DATABASE_PASS" = var.cloudsql_password == null ? module.cloudsql.user_passwords[local.cloudsql_conf.user] : var.cloudsql_password + "IPAM_DATABASE_NAME" = local.cloudsql_conf.db + "IPAM_DATABASE_PORT" = "3306" + } + } + } + iam = local.glb_create && var.iap.enabled ? { + "roles/run.invoker" : ["serviceAccount:${local.iap_sa_email}"] + } : { + "roles/run.invoker" : [var.cloud_run_invoker] + } + revision_annotations = { + autoscaling = { + min_scale = 1 + max_scale = 2 + } + # connect to CloudSQL + cloudsql_instances = [module.cloudsql.connection_name] + # allow all traffic + vpcaccess_egress = "private-ranges-only" + vpcaccess_connector = local.connector + } + vpc_connector_create = var.create_connector ? { + ip_cidr_range = var.ip_ranges.connector + vpc_self_link = local.network + } : null +} diff --git a/blueprints/third-party-solutions/phpipam/outputs.tf b/blueprints/third-party-solutions/phpipam/outputs.tf new file mode 100644 index 00000000..0795c0f2 --- /dev/null +++ b/blueprints/third-party-solutions/phpipam/outputs.tf @@ -0,0 +1,48 @@ +/** + * Copyright 2023 Google LLC + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +output "cloud_run_service" { + description = "CloudRun service URL." + value = module.cloud_run.service.status[0].url + sensitive = true +} + +output "cloudsql_password" { + description = "CloudSQL password." + value = var.cloudsql_password == null ? module.cloudsql.user_passwords[local.cloudsql_conf.user] : var.cloudsql_password + sensitive = true +} + +output "phpipam_ip_address" { + description = "PHPIPAM IP Address either external or internal according to app exposure." + value = local.glb_create ? module.addresses.0.global_addresses["phpipam"].address : module.ilb-l7.0.address +} + +output "phpipam_password" { + description = "PHPIPAM user password." + value = local.phpipam_password + sensitive = true +} + +output "phpipam_url" { + description = "PHPIPAM website url." + value = local.domain +} + +output "phpipam_user" { + description = "PHPIPAM username." + value = "admin" +} diff --git a/blueprints/third-party-solutions/phpipam/terraform.tfvars.sample b/blueprints/third-party-solutions/phpipam/terraform.tfvars.sample new file mode 100644 index 00000000..776bedf9 --- /dev/null +++ b/blueprints/third-party-solutions/phpipam/terraform.tfvars.sample @@ -0,0 +1,2 @@ +prefix = "phpipam" +project_id = "my-phpipam-project" diff --git a/blueprints/third-party-solutions/phpipam/variables.tf b/blueprints/third-party-solutions/phpipam/variables.tf new file mode 100644 index 00000000..75d3d2c6 --- /dev/null +++ b/blueprints/third-party-solutions/phpipam/variables.tf @@ -0,0 +1,156 @@ +/** + * Copyright 2023 Google LLC + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +# Documentation: https://cloud.google.com/run/docs/securing/managing-access#making_a_service_public + +variable "admin_principals" { + description = "Users, groups and/or service accounts that are assigned roles, in IAM format (`group:foo@example.com`)." + type = list(string) + default = [] +} + +variable "cloud_run_invoker" { + description = "IAM member authorized to access the end-point (for example, 'user:YOUR_IAM_USER' for only you or 'allUsers' for everyone)." + type = string + default = "allUsers" +} + +variable "cloudsql_password" { + description = "CloudSQL password (will be randomly generated by default)." + type = string + default = null +} + +variable "connector" { + description = "Existing VPC serverless connector to use if not creating a new one." + type = string + default = null +} + +variable "create_connector" { + description = "Should a VPC serverless connector be created or not." + type = bool + default = true +} + +variable "custom_domain" { + description = "Cloud Run service custom domain for GLB." + type = string + default = null +} + +variable "iap" { + description = "Identity-Aware Proxy for Cloud Run in the LB." + type = object({ + enabled = optional(bool, false) + app_title = optional(string, "Cloud Run Explore Application") + oauth2_client_name = optional(string, "Test Client") + email = optional(string) + }) + default = {} +} + +# PSA: documentation: https://cloud.google.com/vpc/docs/configure-private-services-access#allocating-range +variable "ip_ranges" { + description = "CIDR blocks: VPC serverless connector, Private Service Access(PSA) for CloudSQL, CloudSQL VPC." + type = object({ + connector = string + psa = string + ilb = string + }) + default = { + connector = "10.8.0.0/28" + psa = "10.60.0.0/24" + ilb = "10.128.0.0/28" + } +} + +variable "phpipam_config" { + description = "PHPIpam configuration." + type = object({ + image = optional(string, "phpipam/phpipam-www:latest") + port = optional(number, 80) + }) + default = { + image = "phpipam/phpipam-www:latest" + port = 80 + } +} + +variable "phpipam_exposure" { + description = "Whether to expose the application publicly via GLB or internally via ILB, default GLB." + type = string + default = "EXTERNAL" + validation { + condition = var.phpipam_exposure == "INTERNAL" || var.phpipam_exposure == "EXTERNAL" + error_message = "phpipam_exposure supports only 'INTERNAL' or 'EXTERNAL'" + } +} + +variable "phpipam_password" { + description = "Password for the phpipam user (will be randomly generated by default)." + type = string + default = null +} + +variable "prefix" { + description = "Prefix used for resource names." + type = string + nullable = false + validation { + condition = var.prefix != "" + error_message = "Prefix cannot be empty." + } +} + +variable "project_create" { + description = "Provide values if project creation is needed, uses existing project if null. Parent is in 'folders/nnn' or 'organizations/nnn' format." + type = object({ + billing_account_id = string + parent = string + }) + default = null +} + +variable "project_id" { + description = "Project id, references existing project if `project_create` is null." + type = string +} + +variable "region" { + description = "Region for the created resources." + type = string + default = "europe-west4" +} + +variable "security_policy" { + description = "Security policy (Cloud Armor) to enforce in the LB." + type = object({ + enabled = optional(bool, false) + ip_blacklist = optional(list(string), ["*"]) + path_blocked = optional(string, "/login.html") + }) + default = {} +} + +variable "vpc_config" { + description = "VPC Network and subnetwork self links for internal LB setup." + type = object({ + network = string + subnetwork = string + }) + default = null +} diff --git a/default-versions.tf b/default-versions.tf index f494b243..91a91a31 100644 --- a/default-versions.tf +++ b/default-versions.tf @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/fast/stages/0-bootstrap/organization.tf b/fast/stages/0-bootstrap/organization.tf index 946e3d7b..d9f62221 100644 --- a/fast/stages/0-bootstrap/organization.tf +++ b/fast/stages/0-bootstrap/organization.tf @@ -88,8 +88,9 @@ module "organization" { ) # delegated role grant for resource manager service account iam_bindings = { - (module.organization.custom_role_id[var.custom_role_names.organization_iam_admin]) = { + organization_iam_admin_conditional = { members = [module.automation-tf-resman-sa.iam_email] + role = module.organization.custom_role_id[var.custom_role_names.organization_iam_admin] condition = { expression = format( "api.getAttribute('iam.googleapis.com/modifiedGrantsByRole', []).hasOnly([%s])", diff --git a/fast/stages/1-resman/outputs.tf b/fast/stages/1-resman/outputs.tf index 41994e98..fcfa4ff3 100644 --- a/fast/stages/1-resman/outputs.tf +++ b/fast/stages/1-resman/outputs.tf @@ -223,9 +223,9 @@ locals { tfvars = { folder_ids = local.folder_ids service_accounts = local.service_accounts - tag_keys = { for k, v in module.organization.tag_keys : k => v.id } + tag_keys = { for k, v in try(module.organization.tag_keys, {}) : k => v.id } tag_names = var.tag_names - tag_values = { for k, v in module.organization.tag_values : k => v.id } + tag_values = { for k, v in try(module.organization.tag_values, {}) : k => v.id } } } diff --git a/fast/stages/2-networking-a-peering/README.md b/fast/stages/2-networking-a-peering/README.md index 75c5fb66..f536b943 100644 --- a/fast/stages/2-networking-a-peering/README.md +++ b/fast/stages/2-networking-a-peering/README.md @@ -406,10 +406,10 @@ DNS configurations are centralised in the `dns-*.tf` files. Spokes delegate DNS | [factories_config](variables.tf#L80) | Configuration for network resource factories. | object({…}) | | {…} | | | [outputs_location](variables.tf#L121) | Path where providers and tfvars files for the following stages are written. Leave empty to disable. | string | | null | | | [peering_configs](variables-peerings.tf#L19) | Peering configurations. | object({…}) | | {} | | -| [psa_ranges](variables.tf#L138) | IP ranges used for Private Service Access (CloudSQL, etc.). | object({…}) | | null | | -| [regions](variables.tf#L159) | Region definitions. | object({…}) | | {…} | | -| [service_accounts](variables.tf#L171) | Automation service accounts in name => email format. | object({…}) | | null | 1-resman | -| [vpn_onprem_primary_config](variables.tf#L185) | VPN gateway configuration for onprem interconnection in the primary region. | object({…}) | | null | | +| [psa_ranges](variables.tf#L138) | IP ranges used for Private Service Access (CloudSQL, etc.). | object({…}) | | null | | +| [regions](variables.tf#L155) | Region definitions. | object({…}) | | {…} | | +| [service_accounts](variables.tf#L167) | Automation service accounts in name => email format. | object({…}) | | null | 1-resman | +| [vpn_onprem_primary_config](variables.tf#L181) | VPN gateway configuration for onprem interconnection in the primary region. | object({…}) | | null | | ## Outputs diff --git a/fast/stages/2-networking-a-peering/data/subnets/dev/dev-dataplatform-ew1.yaml b/fast/stages/2-networking-a-peering/data/subnets/dev/dev-dataplatform-ew1.yaml index ad5a06d5..444903eb 100644 --- a/fast/stages/2-networking-a-peering/data/subnets/dev/dev-dataplatform-ew1.yaml +++ b/fast/stages/2-networking-a-peering/data/subnets/dev/dev-dataplatform-ew1.yaml @@ -4,5 +4,5 @@ region: europe-west1 description: Default subnet for dev Data Platform ip_cidr_range: 10.127.48.0/24 secondary_ip_ranges: - pods: 100.64.0.0/24 + pods: 100.64.0.0/16 services: 100.64.1.0/24 diff --git a/fast/stages/2-networking-a-peering/data/subnets/dev/dev-gke-nodes-ew1.yaml b/fast/stages/2-networking-a-peering/data/subnets/dev/dev-gke-nodes-ew1.yaml index 9844d0f0..74ca5f42 100644 --- a/fast/stages/2-networking-a-peering/data/subnets/dev/dev-gke-nodes-ew1.yaml +++ b/fast/stages/2-networking-a-peering/data/subnets/dev/dev-gke-nodes-ew1.yaml @@ -4,5 +4,5 @@ region: europe-west1 description: Default subnet for prod gke nodes ip_cidr_range: 10.127.49.0/24 secondary_ip_ranges: - pods: 100.65.0.0/24 + pods: 100.65.0.0/16 services: 100.65.1.0/24 diff --git a/fast/stages/2-networking-a-peering/landing.tf b/fast/stages/2-networking-a-peering/landing.tf index 013c6e86..e2309f1b 100644 --- a/fast/stages/2-networking-a-peering/landing.tf +++ b/fast/stages/2-networking-a-peering/landing.tf @@ -55,7 +55,9 @@ module "landing-vpc" { private = true restricted = true } - data_folder = "${var.factories_config.data_dir}/subnets/landing" + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/landing" + } } module "landing-firewall" { diff --git a/fast/stages/2-networking-a-peering/spoke-dev.tf b/fast/stages/2-networking-a-peering/spoke-dev.tf index 838ba6a4..bfff002b 100644 --- a/fast/stages/2-networking-a-peering/spoke-dev.tf +++ b/fast/stages/2-networking-a-peering/spoke-dev.tf @@ -46,12 +46,14 @@ module "dev-spoke-project" { } module "dev-spoke-vpc" { - source = "../../../modules/net-vpc" - project_id = module.dev-spoke-project.project_id - name = "dev-spoke-0" - mtu = 1500 - data_folder = "${var.factories_config.data_dir}/subnets/dev" - psa_config = try(var.psa_ranges.dev, null) + source = "../../../modules/net-vpc" + project_id = module.dev-spoke-project.project_id + name = "dev-spoke-0" + mtu = 1500 + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/dev" + } + psa_config = try(var.psa_ranges.dev, null) # set explicit routes for googleapis in case the default route is deleted create_googleapis_routes = { private = true diff --git a/fast/stages/2-networking-a-peering/spoke-prod.tf b/fast/stages/2-networking-a-peering/spoke-prod.tf index 7569647e..505005bd 100644 --- a/fast/stages/2-networking-a-peering/spoke-prod.tf +++ b/fast/stages/2-networking-a-peering/spoke-prod.tf @@ -45,12 +45,14 @@ module "prod-spoke-project" { } module "prod-spoke-vpc" { - source = "../../../modules/net-vpc" - project_id = module.prod-spoke-project.project_id - name = "prod-spoke-0" - mtu = 1500 - data_folder = "${var.factories_config.data_dir}/subnets/prod" - psa_config = try(var.psa_ranges.prod, null) + source = "../../../modules/net-vpc" + project_id = module.prod-spoke-project.project_id + name = "prod-spoke-0" + mtu = 1500 + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/prod" + } + psa_config = try(var.psa_ranges.prod, null) # set explicit routes for googleapis in case the default route is deleted create_googleapis_routes = { private = true diff --git a/fast/stages/2-networking-a-peering/variables.tf b/fast/stages/2-networking-a-peering/variables.tf index a0ff0a79..d0190dfa 100644 --- a/fast/stages/2-networking-a-peering/variables.tf +++ b/fast/stages/2-networking-a-peering/variables.tf @@ -139,18 +139,14 @@ variable "psa_ranges" { description = "IP ranges used for Private Service Access (CloudSQL, etc.)." type = object({ dev = object({ - ranges = map(string) - routes = object({ - export = bool - import = bool - }) + ranges = map(string) + export_routes = optional(bool, false) + import_routes = optional(bool, false) }) prod = object({ - ranges = map(string) - routes = object({ - export = bool - import = bool - }) + ranges = map(string) + export_routes = optional(bool, false) + import_routes = optional(bool, false) }) }) default = null diff --git a/fast/stages/2-networking-b-vpn/README.md b/fast/stages/2-networking-b-vpn/README.md index e87cee14..3cbf75f3 100644 --- a/fast/stages/2-networking-b-vpn/README.md +++ b/fast/stages/2-networking-b-vpn/README.md @@ -430,11 +430,11 @@ DNS configurations are centralised in the `dns-*.tf` files. Spokes delegate DNS | [dns](variables.tf#L72) | Onprem DNS resolvers. | map(list(string)) | | {…} | | | [factories_config](variables.tf#L80) | Configuration for network resource factories. | object({…}) | | {…} | | | [outputs_location](variables.tf#L121) | Path where providers and tfvars files for the following stages are written. Leave empty to disable. | string | | null | | -| [psa_ranges](variables.tf#L138) | IP ranges used for Private Service Access (CloudSQL, etc.). | object({…}) | | null | | -| [regions](variables.tf#L159) | Region definitions. | object({…}) | | {…} | | -| [service_accounts](variables.tf#L171) | Automation service accounts in name => email format. | object({…}) | | null | 1-resman | +| [psa_ranges](variables.tf#L138) | IP ranges used for Private Service Access (CloudSQL, etc.). | object({…}) | | null | | +| [regions](variables.tf#L155) | Region definitions. | object({…}) | | {…} | | +| [service_accounts](variables.tf#L167) | Automation service accounts in name => email format. | object({…}) | | null | 1-resman | | [vpn_configs](variables-vpn.tf#L17) | Hub to spokes VPN configurations. | object({…}) | | {…} | | -| [vpn_onprem_primary_config](variables.tf#L185) | VPN gateway configuration for onprem interconnection in the primary region. | object({…}) | | null | | +| [vpn_onprem_primary_config](variables.tf#L181) | VPN gateway configuration for onprem interconnection in the primary region. | object({…}) | | null | | ## Outputs diff --git a/fast/stages/2-networking-b-vpn/data/subnets/dev/dev-dataplatform-ew1.yaml b/fast/stages/2-networking-b-vpn/data/subnets/dev/dev-dataplatform-ew1.yaml index ad5a06d5..444903eb 100644 --- a/fast/stages/2-networking-b-vpn/data/subnets/dev/dev-dataplatform-ew1.yaml +++ b/fast/stages/2-networking-b-vpn/data/subnets/dev/dev-dataplatform-ew1.yaml @@ -4,5 +4,5 @@ region: europe-west1 description: Default subnet for dev Data Platform ip_cidr_range: 10.127.48.0/24 secondary_ip_ranges: - pods: 100.64.0.0/24 + pods: 100.64.0.0/16 services: 100.64.1.0/24 diff --git a/fast/stages/2-networking-b-vpn/data/subnets/dev/dev-gke-nodes-ew1.yaml b/fast/stages/2-networking-b-vpn/data/subnets/dev/dev-gke-nodes-ew1.yaml index 9844d0f0..74ca5f42 100644 --- a/fast/stages/2-networking-b-vpn/data/subnets/dev/dev-gke-nodes-ew1.yaml +++ b/fast/stages/2-networking-b-vpn/data/subnets/dev/dev-gke-nodes-ew1.yaml @@ -4,5 +4,5 @@ region: europe-west1 description: Default subnet for prod gke nodes ip_cidr_range: 10.127.49.0/24 secondary_ip_ranges: - pods: 100.65.0.0/24 + pods: 100.65.0.0/16 services: 100.65.1.0/24 diff --git a/fast/stages/2-networking-b-vpn/landing.tf b/fast/stages/2-networking-b-vpn/landing.tf index 013c6e86..e2309f1b 100644 --- a/fast/stages/2-networking-b-vpn/landing.tf +++ b/fast/stages/2-networking-b-vpn/landing.tf @@ -55,7 +55,9 @@ module "landing-vpc" { private = true restricted = true } - data_folder = "${var.factories_config.data_dir}/subnets/landing" + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/landing" + } } module "landing-firewall" { diff --git a/fast/stages/2-networking-b-vpn/spoke-dev.tf b/fast/stages/2-networking-b-vpn/spoke-dev.tf index 838ba6a4..bfff002b 100644 --- a/fast/stages/2-networking-b-vpn/spoke-dev.tf +++ b/fast/stages/2-networking-b-vpn/spoke-dev.tf @@ -46,12 +46,14 @@ module "dev-spoke-project" { } module "dev-spoke-vpc" { - source = "../../../modules/net-vpc" - project_id = module.dev-spoke-project.project_id - name = "dev-spoke-0" - mtu = 1500 - data_folder = "${var.factories_config.data_dir}/subnets/dev" - psa_config = try(var.psa_ranges.dev, null) + source = "../../../modules/net-vpc" + project_id = module.dev-spoke-project.project_id + name = "dev-spoke-0" + mtu = 1500 + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/dev" + } + psa_config = try(var.psa_ranges.dev, null) # set explicit routes for googleapis in case the default route is deleted create_googleapis_routes = { private = true diff --git a/fast/stages/2-networking-b-vpn/spoke-prod.tf b/fast/stages/2-networking-b-vpn/spoke-prod.tf index 7569647e..505005bd 100644 --- a/fast/stages/2-networking-b-vpn/spoke-prod.tf +++ b/fast/stages/2-networking-b-vpn/spoke-prod.tf @@ -45,12 +45,14 @@ module "prod-spoke-project" { } module "prod-spoke-vpc" { - source = "../../../modules/net-vpc" - project_id = module.prod-spoke-project.project_id - name = "prod-spoke-0" - mtu = 1500 - data_folder = "${var.factories_config.data_dir}/subnets/prod" - psa_config = try(var.psa_ranges.prod, null) + source = "../../../modules/net-vpc" + project_id = module.prod-spoke-project.project_id + name = "prod-spoke-0" + mtu = 1500 + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/prod" + } + psa_config = try(var.psa_ranges.prod, null) # set explicit routes for googleapis in case the default route is deleted create_googleapis_routes = { private = true diff --git a/fast/stages/2-networking-b-vpn/variables.tf b/fast/stages/2-networking-b-vpn/variables.tf index a0ff0a79..d0190dfa 100644 --- a/fast/stages/2-networking-b-vpn/variables.tf +++ b/fast/stages/2-networking-b-vpn/variables.tf @@ -139,18 +139,14 @@ variable "psa_ranges" { description = "IP ranges used for Private Service Access (CloudSQL, etc.)." type = object({ dev = object({ - ranges = map(string) - routes = object({ - export = bool - import = bool - }) + ranges = map(string) + export_routes = optional(bool, false) + import_routes = optional(bool, false) }) prod = object({ - ranges = map(string) - routes = object({ - export = bool - import = bool - }) + ranges = map(string) + export_routes = optional(bool, false) + import_routes = optional(bool, false) }) }) default = null diff --git a/fast/stages/2-networking-c-nva/README.md b/fast/stages/2-networking-c-nva/README.md index dfc41a0c..5d7cc9b4 100644 --- a/fast/stages/2-networking-c-nva/README.md +++ b/fast/stages/2-networking-c-nva/README.md @@ -488,11 +488,11 @@ DNS configurations are centralised in the `dns-*.tf` files. Spokes delegate DNS | [gcp_ranges](variables.tf#L111) | GCP address ranges in name => range format. | map(string) | | {…} | | | [onprem_cidr](variables.tf#L126) | Onprem addresses in name => range format. | map(string) | | {…} | | | [outputs_location](variables.tf#L144) | Path where providers and tfvars files for the following stages are written. Leave empty to disable. | string | | null | | -| [psa_ranges](variables.tf#L161) | IP ranges used for Private Service Access (e.g. CloudSQL). Ranges is in name => range format. | object({…}) | | null | | -| [regions](variables.tf#L182) | Region definitions. | object({…}) | | {…} | | -| [service_accounts](variables.tf#L194) | Automation service accounts in name => email format. | object({…}) | | null | 1-resman | -| [vpn_onprem_primary_config](variables.tf#L208) | VPN gateway configuration for onprem interconnection in the primary region. | object({…}) | | null | | -| [vpn_onprem_secondary_config](variables.tf#L251) | VPN gateway configuration for onprem interconnection in the secondary region. | object({…}) | | null | | +| [psa_ranges](variables.tf#L161) | IP ranges used for Private Service Access (e.g. CloudSQL). Ranges is in name => range format. | object({…}) | | null | | +| [regions](variables.tf#L178) | Region definitions. | object({…}) | | {…} | | +| [service_accounts](variables.tf#L190) | Automation service accounts in name => email format. | object({…}) | | null | 1-resman | +| [vpn_onprem_primary_config](variables.tf#L204) | VPN gateway configuration for onprem interconnection in the primary region. | object({…}) | | null | | +| [vpn_onprem_secondary_config](variables.tf#L247) | VPN gateway configuration for onprem interconnection in the secondary region. | object({…}) | | null | | ## Outputs diff --git a/fast/stages/2-networking-c-nva/data/subnets/dev/dev-dataplatform-ew1.yaml b/fast/stages/2-networking-c-nva/data/subnets/dev/dev-dataplatform-ew1.yaml index ad5a06d5..444903eb 100644 --- a/fast/stages/2-networking-c-nva/data/subnets/dev/dev-dataplatform-ew1.yaml +++ b/fast/stages/2-networking-c-nva/data/subnets/dev/dev-dataplatform-ew1.yaml @@ -4,5 +4,5 @@ region: europe-west1 description: Default subnet for dev Data Platform ip_cidr_range: 10.127.48.0/24 secondary_ip_ranges: - pods: 100.64.0.0/24 + pods: 100.64.0.0/16 services: 100.64.1.0/24 diff --git a/fast/stages/2-networking-c-nva/landing.tf b/fast/stages/2-networking-c-nva/landing.tf index e7329a43..fb19c31b 100644 --- a/fast/stages/2-networking-c-nva/landing.tf +++ b/fast/stages/2-networking-c-nva/landing.tf @@ -54,7 +54,9 @@ module "landing-untrusted-vpc" { logging = false } create_googleapis_routes = null - data_folder = "${var.factories_config.data_dir}/subnets/landing-untrusted" + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/landing-untrusted" + } } module "landing-untrusted-firewall" { @@ -110,7 +112,9 @@ module "landing-trusted-vpc" { name = "prod-trusted-landing-0" delete_default_routes_on_create = true mtu = 1500 - data_folder = "${var.factories_config.data_dir}/subnets/landing-trusted" + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/landing-trusted" + } dns_policy = { inbound = true } diff --git a/fast/stages/2-networking-c-nva/spoke-dev.tf b/fast/stages/2-networking-c-nva/spoke-dev.tf index a90d25aa..0f6e8b8f 100644 --- a/fast/stages/2-networking-c-nva/spoke-dev.tf +++ b/fast/stages/2-networking-c-nva/spoke-dev.tf @@ -45,11 +45,13 @@ module "dev-spoke-project" { } module "dev-spoke-vpc" { - source = "../../../modules/net-vpc" - project_id = module.dev-spoke-project.project_id - name = "dev-spoke-0" - mtu = 1500 - data_folder = "${var.factories_config.data_dir}/subnets/dev" + source = "../../../modules/net-vpc" + project_id = module.dev-spoke-project.project_id + name = "dev-spoke-0" + mtu = 1500 + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/dev" + } delete_default_routes_on_create = true psa_config = try(var.psa_ranges.dev, null) # Set explicit routes for googleapis; send everything else to NVAs diff --git a/fast/stages/2-networking-c-nva/spoke-prod.tf b/fast/stages/2-networking-c-nva/spoke-prod.tf index 8dd5af44..98959509 100644 --- a/fast/stages/2-networking-c-nva/spoke-prod.tf +++ b/fast/stages/2-networking-c-nva/spoke-prod.tf @@ -44,11 +44,13 @@ module "prod-spoke-project" { } module "prod-spoke-vpc" { - source = "../../../modules/net-vpc" - project_id = module.prod-spoke-project.project_id - name = "prod-spoke-0" - mtu = 1500 - data_folder = "${var.factories_config.data_dir}/subnets/prod" + source = "../../../modules/net-vpc" + project_id = module.prod-spoke-project.project_id + name = "prod-spoke-0" + mtu = 1500 + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/prod" + } delete_default_routes_on_create = true psa_config = try(var.psa_ranges.prod, null) # Set explicit routes for googleapis; send everything else to NVAs diff --git a/fast/stages/2-networking-c-nva/variables.tf b/fast/stages/2-networking-c-nva/variables.tf index 1b4ad4ec..67697a22 100644 --- a/fast/stages/2-networking-c-nva/variables.tf +++ b/fast/stages/2-networking-c-nva/variables.tf @@ -162,18 +162,14 @@ variable "psa_ranges" { description = "IP ranges used for Private Service Access (e.g. CloudSQL). Ranges is in name => range format." type = object({ dev = object({ - ranges = map(string) - routes = object({ - export = bool - import = bool - }) + ranges = map(string) + export_routes = optional(bool, false) + import_routes = optional(bool, false) }) prod = object({ - ranges = map(string) - routes = object({ - export = bool - import = bool - }) + ranges = map(string) + export_routes = optional(bool, false) + import_routes = optional(bool, false) }) }) default = null diff --git a/fast/stages/2-networking-d-separate-envs/README.md b/fast/stages/2-networking-d-separate-envs/README.md index 7514454f..31a69ef6 100644 --- a/fast/stages/2-networking-d-separate-envs/README.md +++ b/fast/stages/2-networking-d-separate-envs/README.md @@ -348,11 +348,11 @@ Regions are defined via the `regions` variable which sets up a mapping between t | [dns](variables.tf#L72) | Onprem DNS resolvers. | map(list(string)) | | {…} | | | [factories_config](variables.tf#L81) | Configuration for network resource factories. | object({…}) | | {…} | | | [outputs_location](variables.tf#L122) | Path where providers and tfvars files for the following stages are written. Leave empty to disable. | string | | null | | -| [psa_ranges](variables.tf#L139) | IP ranges used for Private Service Access (e.g. CloudSQL). | object({…}) | | null | | -| [regions](variables.tf#L160) | Region definitions. | object({…}) | | {…} | | -| [service_accounts](variables.tf#L170) | Automation service accounts in name => email format. | object({…}) | | null | 1-resman | -| [vpn_onprem_dev_primary_config](variables.tf#L184) | VPN gateway configuration for onprem interconnection from dev in the primary region. | object({…}) | | null | | -| [vpn_onprem_prod_primary_config](variables.tf#L227) | VPN gateway configuration for onprem interconnection from prod in the primary region. | object({…}) | | null | | +| [psa_ranges](variables.tf#L139) | IP ranges used for Private Service Access (e.g. CloudSQL). | object({…}) | | null | | +| [regions](variables.tf#L156) | Region definitions. | object({…}) | | {…} | | +| [service_accounts](variables.tf#L166) | Automation service accounts in name => email format. | object({…}) | | null | 1-resman | +| [vpn_onprem_dev_primary_config](variables.tf#L180) | VPN gateway configuration for onprem interconnection from dev in the primary region. | object({…}) | | null | | +| [vpn_onprem_prod_primary_config](variables.tf#L223) | VPN gateway configuration for onprem interconnection from prod in the primary region. | object({…}) | | null | | ## Outputs diff --git a/fast/stages/2-networking-d-separate-envs/data/subnets/dev/dev-dataplatform-ew1.yaml b/fast/stages/2-networking-d-separate-envs/data/subnets/dev/dev-dataplatform-ew1.yaml index ad5a06d5..444903eb 100644 --- a/fast/stages/2-networking-d-separate-envs/data/subnets/dev/dev-dataplatform-ew1.yaml +++ b/fast/stages/2-networking-d-separate-envs/data/subnets/dev/dev-dataplatform-ew1.yaml @@ -4,5 +4,5 @@ region: europe-west1 description: Default subnet for dev Data Platform ip_cidr_range: 10.127.48.0/24 secondary_ip_ranges: - pods: 100.64.0.0/24 + pods: 100.64.0.0/16 services: 100.64.1.0/24 diff --git a/fast/stages/2-networking-d-separate-envs/spoke-dev.tf b/fast/stages/2-networking-d-separate-envs/spoke-dev.tf index b5b485be..61562f44 100644 --- a/fast/stages/2-networking-d-separate-envs/spoke-dev.tf +++ b/fast/stages/2-networking-d-separate-envs/spoke-dev.tf @@ -46,12 +46,14 @@ module "dev-spoke-project" { } module "dev-spoke-vpc" { - source = "../../../modules/net-vpc" - project_id = module.dev-spoke-project.project_id - name = "dev-spoke-0" - mtu = 1500 - data_folder = "${var.factories_config.data_dir}/subnets/dev" - psa_config = try(var.psa_ranges.dev, null) + source = "../../../modules/net-vpc" + project_id = module.dev-spoke-project.project_id + name = "dev-spoke-0" + mtu = 1500 + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/dev" + } + psa_config = try(var.psa_ranges.dev, null) # set explicit routes for googleapis in case the default route is deleted create_googleapis_routes = { private = true diff --git a/fast/stages/2-networking-d-separate-envs/spoke-prod.tf b/fast/stages/2-networking-d-separate-envs/spoke-prod.tf index bf43728d..7b42f546 100644 --- a/fast/stages/2-networking-d-separate-envs/spoke-prod.tf +++ b/fast/stages/2-networking-d-separate-envs/spoke-prod.tf @@ -45,12 +45,14 @@ module "prod-spoke-project" { } module "prod-spoke-vpc" { - source = "../../../modules/net-vpc" - project_id = module.prod-spoke-project.project_id - name = "prod-spoke-0" - mtu = 1500 - data_folder = "${var.factories_config.data_dir}/subnets/prod" - psa_config = try(var.psa_ranges.prod, null) + source = "../../../modules/net-vpc" + project_id = module.prod-spoke-project.project_id + name = "prod-spoke-0" + mtu = 1500 + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/prod" + } + psa_config = try(var.psa_ranges.prod, null) # set explicit routes for googleapis in case the default route is deleted create_googleapis_routes = { private = true diff --git a/fast/stages/2-networking-d-separate-envs/variables.tf b/fast/stages/2-networking-d-separate-envs/variables.tf index 29d4788a..8edcd72c 100644 --- a/fast/stages/2-networking-d-separate-envs/variables.tf +++ b/fast/stages/2-networking-d-separate-envs/variables.tf @@ -140,18 +140,14 @@ variable "psa_ranges" { description = "IP ranges used for Private Service Access (e.g. CloudSQL)." type = object({ dev = object({ - ranges = map(string) - routes = object({ - export = bool - import = bool - }) + ranges = map(string) + export_routes = optional(bool, false) + import_routes = optional(bool, false) }) prod = object({ - ranges = map(string) - routes = object({ - export = bool - import = bool - }) + ranges = map(string) + export_routes = optional(bool, false) + import_routes = optional(bool, false) }) }) default = null diff --git a/fast/stages/2-networking-e-nva-bgp/README.md b/fast/stages/2-networking-e-nva-bgp/README.md index eabd74db..be1526c8 100644 --- a/fast/stages/2-networking-e-nva-bgp/README.md +++ b/fast/stages/2-networking-e-nva-bgp/README.md @@ -515,12 +515,12 @@ DNS configurations are centralised in the `dns-*.tf` files. Spokes delegate DNS | [ncc_asn](variables.tf#L126) | The NCC Cloud Routers ASN configuration. | map(number) | | {…} | | | [onprem_cidr](variables.tf#L137) | Onprem addresses in name => range format. | map(string) | | {…} | | | [outputs_location](variables.tf#L155) | Path where providers and tfvars files for the following stages are written. Leave empty to disable. | string | | null | | -| [psa_ranges](variables.tf#L172) | IP ranges used for Private Service Access (e.g. CloudSQL). Ranges is in name => range format. | object({…}) | | null | | -| [regions](variables.tf#L193) | Region definitions. | object({…}) | | {…} | | -| [service_accounts](variables.tf#L205) | Automation service accounts in name => email format. | object({…}) | | null | 1-resman | -| [vpn_onprem_primary_config](variables.tf#L219) | VPN gateway configuration for onprem interconnection in the primary region. | object({…}) | | null | | -| [vpn_onprem_secondary_config](variables.tf#L262) | VPN gateway configuration for onprem interconnection in the secondary region. | object({…}) | | null | | -| [zones](variables.tf#L305) | Zones in which NVAs are deployed. | list(string) | | ["b", "c"] | | +| [psa_ranges](variables.tf#L172) | IP ranges used for Private Service Access (e.g. CloudSQL). Ranges is in name => range format. | object({…}) | | null | | +| [regions](variables.tf#L189) | Region definitions. | object({…}) | | {…} | | +| [service_accounts](variables.tf#L201) | Automation service accounts in name => email format. | object({…}) | | null | 1-resman | +| [vpn_onprem_primary_config](variables.tf#L215) | VPN gateway configuration for onprem interconnection in the primary region. | object({…}) | | null | | +| [vpn_onprem_secondary_config](variables.tf#L258) | VPN gateway configuration for onprem interconnection in the secondary region. | object({…}) | | null | | +| [zones](variables.tf#L301) | Zones in which NVAs are deployed. | list(string) | | ["b", "c"] | | ## Outputs diff --git a/fast/stages/2-networking-e-nva-bgp/data/subnets/dev/dev-dataplatform-ew1.yaml b/fast/stages/2-networking-e-nva-bgp/data/subnets/dev/dev-dataplatform-ew1.yaml index cdb41e3f..1a8596b0 100644 --- a/fast/stages/2-networking-e-nva-bgp/data/subnets/dev/dev-dataplatform-ew1.yaml +++ b/fast/stages/2-networking-e-nva-bgp/data/subnets/dev/dev-dataplatform-ew1.yaml @@ -4,5 +4,5 @@ region: europe-west1 description: Default subnet for dev Data Platform ip_cidr_range: 10.127.48.0/24 secondary_ip_ranges: - pods: 100.64.0.0/24 + pods: 100.64.0.0/16 services: 100.64.1.0/24 diff --git a/fast/stages/2-networking-e-nva-bgp/landing.tf b/fast/stages/2-networking-e-nva-bgp/landing.tf index ab6c94eb..07331717 100644 --- a/fast/stages/2-networking-e-nva-bgp/landing.tf +++ b/fast/stages/2-networking-e-nva-bgp/landing.tf @@ -55,7 +55,9 @@ module "landing-untrusted-vpc" { logging = false } create_googleapis_routes = null - data_folder = "${var.factories_config.data_dir}/subnets/landing-untrusted" + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/landing-untrusted" + } } module "landing-untrusted-firewall" { @@ -111,7 +113,9 @@ module "landing-trusted-vpc" { name = "prod-trusted-landing-0" delete_default_routes_on_create = true mtu = 1500 - data_folder = "${var.factories_config.data_dir}/subnets/landing-trusted" + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/landing-trusted" + } dns_policy = { inbound = true } diff --git a/fast/stages/2-networking-e-nva-bgp/spoke-dev.tf b/fast/stages/2-networking-e-nva-bgp/spoke-dev.tf index 0c70b550..56b65e39 100644 --- a/fast/stages/2-networking-e-nva-bgp/spoke-dev.tf +++ b/fast/stages/2-networking-e-nva-bgp/spoke-dev.tf @@ -45,11 +45,13 @@ module "dev-spoke-project" { } module "dev-spoke-vpc" { - source = "../../../modules/net-vpc" - project_id = module.dev-spoke-project.project_id - name = "dev-spoke-0" - mtu = 1500 - data_folder = "${var.factories_config.data_dir}/subnets/dev" + source = "../../../modules/net-vpc" + project_id = module.dev-spoke-project.project_id + name = "dev-spoke-0" + mtu = 1500 + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/dev" + } delete_default_routes_on_create = true psa_config = try(var.psa_ranges.dev, null) # Set explicit routes for googleapis; send everything else to NVAs diff --git a/fast/stages/2-networking-e-nva-bgp/spoke-prod.tf b/fast/stages/2-networking-e-nva-bgp/spoke-prod.tf index c0ba4414..6ae49dee 100644 --- a/fast/stages/2-networking-e-nva-bgp/spoke-prod.tf +++ b/fast/stages/2-networking-e-nva-bgp/spoke-prod.tf @@ -44,11 +44,13 @@ module "prod-spoke-project" { } module "prod-spoke-vpc" { - source = "../../../modules/net-vpc" - project_id = module.prod-spoke-project.project_id - name = "prod-spoke-0" - mtu = 1500 - data_folder = "${var.factories_config.data_dir}/subnets/prod" + source = "../../../modules/net-vpc" + project_id = module.prod-spoke-project.project_id + name = "prod-spoke-0" + mtu = 1500 + factories_config = { + subnets_folder = "${var.factories_config.data_dir}/subnets/prod" + } delete_default_routes_on_create = true psa_config = try(var.psa_ranges.prod, null) # Set explicit routes for googleapis; send everything else to NVAs diff --git a/fast/stages/2-networking-e-nva-bgp/variables.tf b/fast/stages/2-networking-e-nva-bgp/variables.tf index b8773041..a784fda3 100644 --- a/fast/stages/2-networking-e-nva-bgp/variables.tf +++ b/fast/stages/2-networking-e-nva-bgp/variables.tf @@ -173,18 +173,14 @@ variable "psa_ranges" { description = "IP ranges used for Private Service Access (e.g. CloudSQL). Ranges is in name => range format." type = object({ dev = object({ - ranges = map(string) - routes = object({ - export = bool - import = bool - }) + ranges = map(string) + export_routes = optional(bool, false) + import_routes = optional(bool, false) }) prod = object({ - ranges = map(string) - routes = object({ - export = bool - import = bool - }) + ranges = map(string) + export_routes = optional(bool, false) + import_routes = optional(bool, false) }) }) default = null diff --git a/fast/stages/2-security/README.md b/fast/stages/2-security/README.md index e28aac7b..9d47bdaf 100644 --- a/fast/stages/2-security/README.md +++ b/fast/stages/2-security/README.md @@ -284,13 +284,12 @@ Some references that might be useful in setting up this stage: - ## Files | name | description | modules | resources | |---|---|---|---| -| [core-dev.tf](./core-dev.tf) | None | kms · project | google_project_iam_member | -| [core-prod.tf](./core-prod.tf) | None | kms · project | google_project_iam_member | +| [core-dev.tf](./core-dev.tf) | None | kms · project | | +| [core-prod.tf](./core-prod.tf) | None | kms · project | | | [main.tf](./main.tf) | Module-level locals and resources. | | | | [outputs.tf](./outputs.tf) | Module outputs. | | google_storage_bucket_object · local_file | | [variables.tf](./variables.tf) | Module variables. | | | @@ -303,17 +302,16 @@ Some references that might be useful in setting up this stage: | [automation](variables.tf#L17) | Automation resources created by the bootstrap stage. | object({…}) | ✓ | | 0-bootstrap | | [billing_account](variables.tf#L25) | Billing account id. If billing account is not part of the same org set `is_org_level` to false. | object({…}) | ✓ | | 0-bootstrap | | [folder_ids](variables.tf#L38) | Folder name => id mappings, the 'security' folder name must exist. | object({…}) | ✓ | | 1-resman | -| [organization](variables.tf#L84) | Organization details. | object({…}) | ✓ | | 0-bootstrap | -| [prefix](variables.tf#L100) | Prefix used for resources that need unique names. Use 9 characters or less. | string | ✓ | | 0-bootstrap | -| [service_accounts](variables.tf#L111) | Automation service accounts that can assign the encrypt/decrypt roles on keys. | object({…}) | ✓ | | 1-resman | +| [organization](variables.tf#L97) | Organization details. | object({…}) | ✓ | | 0-bootstrap | +| [prefix](variables.tf#L113) | Prefix used for resources that need unique names. Use 9 characters or less. | string | ✓ | | 0-bootstrap | +| [service_accounts](variables.tf#L124) | Automation service accounts that can assign the encrypt/decrypt roles on keys. | object({…}) | ✓ | | 1-resman | | [groups](variables.tf#L46) | Group names to grant organization-level permissions. | map(string) | | {…} | 0-bootstrap | -| [kms_defaults](variables.tf#L61) | Defaults used for KMS keys. | object({…}) | | {…} | | -| [kms_keys](variables.tf#L73) | KMS keys to create, keyed by name. Null attributes will be interpolated with defaults. | map(object({…})) | | {} | | -| [outputs_location](variables.tf#L94) | Path where providers, tfvars files, and lists for the following stages are written. Leave empty to disable. | string | | null | | -| [vpc_sc_access_levels](variables.tf#L122) | VPC SC access level definitions. | map(object({…})) | | {} | | -| [vpc_sc_egress_policies](variables.tf#L151) | VPC SC egress policy definitions. | map(object({…})) | | {} | | -| [vpc_sc_ingress_policies](variables.tf#L171) | VPC SC ingress policy definitions. | map(object({…})) | | {} | | -| [vpc_sc_perimeters](variables.tf#L192) | VPC SC regular perimeter definitions. | object({…}) | | {} | | +| [kms_keys](variables.tf#L61) | KMS keys to create, keyed by name. | map(object({…})) | | {} | | +| [outputs_location](variables.tf#L107) | Path where providers, tfvars files, and lists for the following stages are written. Leave empty to disable. | string | | null | | +| [vpc_sc_access_levels](variables.tf#L135) | VPC SC access level definitions. | map(object({…})) | | {} | | +| [vpc_sc_egress_policies](variables.tf#L164) | VPC SC egress policy definitions. | map(object({…})) | | {} | | +| [vpc_sc_ingress_policies](variables.tf#L184) | VPC SC ingress policy definitions. | map(object({…})) | | {} | | +| [vpc_sc_perimeters](variables.tf#L205) | VPC SC regular perimeter definitions. | object({…}) | | {} | | ## Outputs @@ -322,5 +320,4 @@ Some references that might be useful in setting up this stage: | [kms_keys](outputs.tf#L59) | KMS key ids. | | | | [stage_perimeter_projects](outputs.tf#L64) | Security project numbers. They can be added to perimeter resources. | | | | [tfvars](outputs.tf#L74) | Terraform variable files for the following stages. | ✓ | | - diff --git a/fast/stages/2-security/core-dev.tf b/fast/stages/2-security/core-dev.tf index 1b494947..6f71318d 100644 --- a/fast/stages/2-security/core-dev.tf +++ b/fast/stages/2-security/core-dev.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -16,11 +16,11 @@ locals { dev_kms_restricted_admins = [ - for sa in compact([ + for sa in distinct(compact([ var.service_accounts.data-platform-dev, var.service_accounts.project-factory-dev, var.service_accounts.project-factory-prod - ]) : "serviceAccount:${sa}" + ])) : "serviceAccount:${sa}" ] } @@ -33,6 +33,12 @@ module "dev-sec-project" { iam = { "roles/cloudkms.viewer" = local.dev_kms_restricted_admins } + iam_bindings_additive = { + for member in local.dev_kms_restricted_admins : + "kms_restricted_admin.${member}" => merge(local.kms_restricted_admin_template, { + member = member + }) + } labels = { environment = "dev", team = "security" } services = local.project_services } @@ -45,30 +51,5 @@ module "dev-sec-kms" { location = each.key name = "dev-${each.key}" } - # rename to `key_iam` to switch to authoritative bindings - key_iam = { - for k, v in local.kms_locations_keys[each.key] : k => v.iam - } keys = local.kms_locations_keys[each.key] } - -# TODO(ludo): add support for conditions to Fabric modules - -resource "google_project_iam_member" "dev_key_admin_delegated" { - for_each = toset(local.dev_kms_restricted_admins) - project = module.dev-sec-project.project_id - role = "roles/cloudkms.admin" - member = each.key - condition { - title = "kms_sa_delegated_grants" - description = "Automation service account delegated grants." - expression = format( - "api.getAttribute('iam.googleapis.com/modifiedGrantsByRole', []).hasOnly([%s]) && resource.type == 'cloudkms.googleapis.com/CryptoKey'", - join(",", formatlist("'%s'", [ - "roles/cloudkms.cryptoKeyEncrypterDecrypter", - "roles/cloudkms.cryptoKeyEncrypterDecrypterViaDelegation" - ])) - ) - } - depends_on = [module.dev-sec-project] -} diff --git a/fast/stages/2-security/core-prod.tf b/fast/stages/2-security/core-prod.tf index 559ff32f..1d536249 100644 --- a/fast/stages/2-security/core-prod.tf +++ b/fast/stages/2-security/core-prod.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -16,10 +16,10 @@ locals { prod_kms_restricted_admins = [ - for sa in compact([ + for sa in distinct(compact([ var.service_accounts.data-platform-prod, var.service_accounts.project-factory-prod - ]) : "serviceAccount:${sa}" + ])) : "serviceAccount:${sa}" ] } @@ -32,6 +32,12 @@ module "prod-sec-project" { iam = { "roles/cloudkms.viewer" = local.prod_kms_restricted_admins } + iam_bindings_additive = { + for member in local.prod_kms_restricted_admins : + "kms_restricted_admin.${member}" => merge(local.kms_restricted_admin_template, { + member = member + }) + } labels = { environment = "prod", team = "security" } services = local.project_services } @@ -44,30 +50,5 @@ module "prod-sec-kms" { location = each.key name = "prod-${each.key}" } - # rename to `key_iam` to switch to authoritative bindings - key_iam = { - for k, v in local.kms_locations_keys[each.key] : k => v.iam - } keys = local.kms_locations_keys[each.key] } - -# TODO(ludo): add support for conditions to Fabric modules - -resource "google_project_iam_member" "prod_key_admin_delegated" { - for_each = toset(local.prod_kms_restricted_admins) - project = module.prod-sec-project.project_id - role = "roles/cloudkms.admin" - member = each.key - condition { - title = "kms_sa_delegated_grants" - description = "Automation service account delegated grants." - expression = format( - "api.getAttribute('iam.googleapis.com/modifiedGrantsByRole', []).hasOnly([%s]) && resource.type == 'cloudkms.googleapis.com/CryptoKey'", - join(",", formatlist("'%s'", [ - "roles/cloudkms.cryptoKeyEncrypterDecrypter", - "roles/cloudkms.cryptoKeyEncrypterDecrypterViaDelegation" - ])) - ) - } - depends_on = [module.prod-sec-project] -} diff --git a/fast/stages/2-security/main.tf b/fast/stages/2-security/main.tf index 13078d12..70799011 100644 --- a/fast/stages/2-security/main.tf +++ b/fast/stages/2-security/main.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -15,28 +15,36 @@ */ locals { - kms_keys = { - for k, v in var.kms_keys : k => { - iam = coalesce(v.iam, {}) - labels = coalesce(v.labels, {}) - locations = ( - v.locations == null - ? var.kms_defaults.locations - : v.locations - ) - rotation_period = ( - v.rotation_period == null - ? var.kms_defaults.rotation_period - : v.rotation_period + # additive IAM binding for delegated KMS admins + kms_restricted_admin_template = { + role = "roles/cloudkms.admin" + condition = { + title = "kms_sa_delegated_grants" + description = "Automation service account delegated grants." + expression = format( + <<-EOT + api.getAttribute('iam.googleapis.com/modifiedGrantsByRole', []).hasOnly([%s]) && + resource.type == 'cloudkms.googleapis.com/CryptoKey' + EOT + , join(",", formatlist("'%s'", [ + "roles/cloudkms.cryptoKeyEncrypterDecrypter", + "roles/cloudkms.cryptoKeyEncrypterDecrypterViaDelegation" + ])) ) } } + + # list of locations with keys kms_locations = distinct(flatten([ - for k, v in local.kms_keys : v.locations + for k, v in var.kms_keys : v.locations ])) + # map { location -> { key_name -> key_details } } kms_locations_keys = { - for loc in local.kms_locations : loc => { - for k, v in local.kms_keys : k => v if contains(v.locations, loc) + for loc in local.kms_locations : + loc => { + for k, v in var.kms_keys : + k => v + if contains(v.locations, loc) } } project_services = [ diff --git a/fast/stages/2-security/variables.tf b/fast/stages/2-security/variables.tf index f798de78..fa439c8c 100644 --- a/fast/stages/2-security/variables.tf +++ b/fast/stages/2-security/variables.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -58,27 +58,40 @@ variable "groups" { } } -variable "kms_defaults" { - description = "Defaults used for KMS keys." - type = object({ - locations = list(string) - rotation_period = string - }) - default = { - locations = ["europe", "europe-west1", "europe-west3", "global"] - rotation_period = "7776000s" - } -} - variable "kms_keys" { - description = "KMS keys to create, keyed by name. Null attributes will be interpolated with defaults." + description = "KMS keys to create, keyed by name." type = map(object({ - iam = map(list(string)) - labels = map(string) - locations = list(string) - rotation_period = string + rotation_period = optional(string, "7776000s") + labels = optional(map(string)) + locations = optional(list(string), ["europe", "europe-west1", "europe-west3", "global"]) + purpose = optional(string, "ENCRYPT_DECRYPT") + skip_initial_version_creation = optional(bool, false) + version_template = optional(object({ + algorithm = string + protection_level = optional(string, "SOFTWARE") + })) + + iam = optional(map(list(string)), {}) + iam_bindings = optional(map(object({ + members = list(string) + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) + iam_bindings_additive = optional(map(object({ + member = string + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) })) - default = {} + default = {} + nullable = false } variable "organization" { diff --git a/fast/stages/3-gke-multitenant/dev/README.md b/fast/stages/3-gke-multitenant/dev/README.md index 23572297..f099c10b 100644 --- a/fast/stages/3-gke-multitenant/dev/README.md +++ b/fast/stages/3-gke-multitenant/dev/README.md @@ -163,21 +163,21 @@ Leave all these variables unset (or set to `null`) to disable fleet management. |---|---|:---:|:---:|:---:|:---:| | [automation](variables.tf#L21) | Automation resources created by the bootstrap stage. | object({…}) | ✓ | | 0-bootstrap | | [billing_account](variables.tf#L29) | Billing account id. If billing account is not part of the same org set `is_org_level` to false. | object({…}) | ✓ | | 0-bootstrap | -| [folder_ids](variables.tf#L159) | Folders to be used for the networking resources in folders/nnnnnnnnnnn format. If null, folder will be created. | object({…}) | ✓ | | 1-resman | -| [host_project_ids](variables.tf#L174) | Host project for the shared VPC. | object({…}) | ✓ | | 2-networking | -| [prefix](variables.tf#L227) | Prefix used for resources that need unique names. | string | ✓ | | | -| [vpc_self_links](variables.tf#L243) | Self link for the shared VPC. | object({…}) | ✓ | | 2-networking | -| [clusters](variables.tf#L42) | Clusters configuration. Refer to the gke-cluster module for type details. | map(object({…})) | | {} | | -| [fleet_configmanagement_clusters](variables.tf#L96) | Config management features enabled on specific sets of member clusters, in config name => [cluster name] format. | map(list(string)) | | {} | | -| [fleet_configmanagement_templates](variables.tf#L104) | Sets of config management configurations that can be applied to member clusters, in config name => {options} format. | map(object({…})) | | {} | | -| [fleet_features](variables.tf#L139) | Enable and configure fleet features. Set to null to disable GKE Hub if fleet workload identity is not used. | object({…}) | | null | | -| [fleet_workload_identity](variables.tf#L152) | Use Fleet Workload Identity for clusters. Enables GKE Hub if set to true. | bool | | false | | -| [group_iam](variables.tf#L167) | Project-level authoritative IAM bindings for groups in {GROUP_EMAIL => [ROLES]} format. Use group emails as keys, list of roles as values. | map(list(string)) | | {} | | -| [iam](variables.tf#L182) | Project-level authoritative IAM bindings for users and service accounts in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | | -| [labels](variables.tf#L189) | Project-level labels. | map(string) | | {} | | -| [nodepools](variables.tf#L195) | Nodepools configuration. Refer to the gke-nodepool module for type details. | map(map(object({…}))) | | {} | | -| [outputs_location](variables.tf#L221) | Path where providers, tfvars files, and lists for the following stages are written. Leave empty to disable. | string | | null | | -| [project_services](variables.tf#L236) | Additional project services to enable. | list(string) | | [] | | +| [folder_ids](variables.tf#L174) | Folders to be used for the networking resources in folders/nnnnnnnnnnn format. If null, folder will be created. | object({…}) | ✓ | | 1-resman | +| [host_project_ids](variables.tf#L189) | Host project for the shared VPC. | object({…}) | ✓ | | 2-networking | +| [prefix](variables.tf#L242) | Prefix used for resources that need unique names. | string | ✓ | | | +| [vpc_self_links](variables.tf#L258) | Self link for the shared VPC. | object({…}) | ✓ | | 2-networking | +| [clusters](variables.tf#L42) | Clusters configuration. Refer to the gke-cluster-standard module for type details. | map(object({…})) | | {} | | +| [fleet_configmanagement_clusters](variables.tf#L111) | Config management features enabled on specific sets of member clusters, in config name => [cluster name] format. | map(list(string)) | | {} | | +| [fleet_configmanagement_templates](variables.tf#L119) | Sets of config management configurations that can be applied to member clusters, in config name => {options} format. | map(object({…})) | | {} | | +| [fleet_features](variables.tf#L154) | Enable and configure fleet features. Set to null to disable GKE Hub if fleet workload identity is not used. | object({…}) | | null | | +| [fleet_workload_identity](variables.tf#L167) | Use Fleet Workload Identity for clusters. Enables GKE Hub if set to true. | bool | | false | | +| [group_iam](variables.tf#L182) | Project-level authoritative IAM bindings for groups in {GROUP_EMAIL => [ROLES]} format. Use group emails as keys, list of roles as values. | map(list(string)) | | {} | | +| [iam](variables.tf#L197) | Project-level authoritative IAM bindings for users and service accounts in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | | +| [labels](variables.tf#L204) | Project-level labels. | map(string) | | {} | | +| [nodepools](variables.tf#L210) | Nodepools configuration. Refer to the gke-nodepool module for type details. | map(map(object({…}))) | | {} | | +| [outputs_location](variables.tf#L236) | Path where providers, tfvars files, and lists for the following stages are written. Leave empty to disable. | string | | null | | +| [project_services](variables.tf#L251) | Additional project services to enable. | list(string) | | [] | | ## Outputs diff --git a/fast/stages/3-gke-multitenant/dev/variables.tf b/fast/stages/3-gke-multitenant/dev/variables.tf index 11e32ed6..831f828b 100644 --- a/fast/stages/3-gke-multitenant/dev/variables.tf +++ b/fast/stages/3-gke-multitenant/dev/variables.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -40,7 +40,7 @@ variable "billing_account" { } variable "clusters" { - description = "Clusters configuration. Refer to the gke-cluster module for type details." + description = "Clusters configuration. Refer to the gke-cluster-standard module for type details." type = map(object({ cluster_autoscaling = optional(any) description = optional(string) @@ -68,9 +68,24 @@ variable "clusters" { max_pods_per_node = optional(number, 110) min_master_version = optional(string) monitoring_config = optional(object({ - enable_components = optional(list(string), ["SYSTEM_COMPONENTS"]) - managed_prometheus = optional(bool) - })) + enable_system_metrics = optional(bool, true) + + # (Optional) control plane metrics + enable_api_server_metrics = optional(bool, false) + enable_controller_manager_metrics = optional(bool, false) + enable_scheduler_metrics = optional(bool, false) + + # (Optional) kube state metrics + enable_daemonset_metrics = optional(bool, false) + enable_deployment_metrics = optional(bool, false) + enable_hpa_metrics = optional(bool, false) + enable_pod_metrics = optional(bool, false) + enable_statefulset_metrics = optional(bool, false) + enable_storage_metrics = optional(bool, false) + + # Google Cloud Managed Service for Prometheus + enable_managed_prometheus = optional(bool, true) + }), {}) node_locations = optional(list(string)) private_cluster_config = optional(any) release_channel = optional(string) @@ -82,9 +97,9 @@ variable "clusters" { services = string })) secondary_range_names = optional(object({ - pods = string - services = string - }), { pods = "pods", services = "services" }) + pods = optional(string, "pods") + services = optional(string, "services") + })) master_authorized_ranges = optional(map(string)) master_ipv4_cidr_block = optional(string) }) diff --git a/fast/stages/3-project-factory/dev/README.md b/fast/stages/3-project-factory/dev/README.md index 2073e759..4c1fe75d 100644 --- a/fast/stages/3-project-factory/dev/README.md +++ b/fast/stages/3-project-factory/dev/README.md @@ -55,7 +55,7 @@ gcloud alpha storage cp gs://xxx-prod-iac-core-outputs-0/tfvars/2-security.auto. If you're not using FAST, refer to the [Variables](#variables) table at the bottom of this document for a full list of variables, their origin (e.g., a stage or specific to this one), and descriptions explaining their meaning. -Besides the values above, the project factory is drive by data files, with one file per project. +Besides the values above, the project factory is driven by data files which closely follow the variables exposed by the [project module](../../../../modules/project/), with one file per project. Please refer to the underlying [project factory blueprint](../../../../blueprints/factories/project-factory/) documentation for details on the format. Once the configuration is complete, run the project factory with: @@ -79,8 +79,8 @@ terraform apply | name | description | type | required | default | producer | |---|---|:---:|:---:|:---:|:---:| | [billing_account](variables.tf#L19) | Billing account id. If billing account is not part of the same org set `is_org_level` to false. | object({…}) | ✓ | | 0-bootstrap | -| [factory_data](variables.tf#L32) | Project data from either YAML files or externally parsed data. | object({…}) | ✓ | | | -| [prefix](variables.tf#L48) | Prefix used for resources that need unique names. Use 9 characters or less. | string | ✓ | | 0-bootstrap | +| [prefix](variables.tf#L51) | Prefix used for resources that need unique names. Use 9 characters or less. | string | ✓ | | 0-bootstrap | +| [factory_data](variables.tf#L32) | Project data from either YAML files or externally parsed data. | object({…}) | | {…} | | ## Outputs diff --git a/fast/stages/3-project-factory/dev/data/defaults.yaml b/fast/stages/3-project-factory/dev/data/defaults.yaml deleted file mode 100644 index e52bb132..00000000 --- a/fast/stages/3-project-factory/dev/data/defaults.yaml +++ /dev/null @@ -1,24 +0,0 @@ -# skip boilerplate check - -billing_account_id: 012345-67890A-BCDEF0 - -# [opt] Setup for billing alerts -billing_alert: - amount: 1000 - thresholds: - current: [0.5, 0.8] - forecasted: [0.5, 0.8] - credit_treatment: INCLUDE_ALL_CREDITS - -# [opt] Contacts for billing alerts and important notifications -essential_contacts: ["team-contacts@example.com"] - -# [opt] Labels set for all projects -labels: - environment: dev - department: accounting - application: example-app - foo: bar - -# [opt] Additional notification channels for billing -notification_channels: [] diff --git a/fast/stages/3-project-factory/dev/data/projects/project.yaml.sample b/fast/stages/3-project-factory/dev/data/projects/project.yaml.sample deleted file mode 100644 index 5311019d..00000000 --- a/fast/stages/3-project-factory/dev/data/projects/project.yaml.sample +++ /dev/null @@ -1,103 +0,0 @@ -# skip boilerplate check - -# [opt] Billing account id - overrides default if set -billing_account_id: 012345-67890A-BCDEF0 - -# [opt] Billing alerts config - overrides default if set -billing_alert: - amount: 10 - thresholds: - current: - - 0.5 - - 0.8 - forecasted: [] - credit_treatment: INCLUDE_ALL_CREDITS - -# [opt] DNS zones to be created as children of the environment_dns_zone defined in defaults -dns_zones: - - lorem - - ipsum - -# [opt] Contacts for billing alerts and important notifications -essential_contacts: - - team-a-contacts@example.com - -# Folder the project will be created as children of -folder_id: folders/012345678901 - -# [opt] Authoritative IAM bindings in group => [roles] format -group_iam: - test-team-foobar@fast-lab-0.gcp-pso-italy.net: - - roles/compute.admin - -# [opt] Authoritative IAM bindings in role => [principals] format -# Generally used to grant roles to service accounts external to the project -iam: - roles/compute.admin: - - serviceAccount:service-account - -# [opt] Service robots and keys they will be assigned as cryptoKeyEncrypterDecrypter -# in service => [keys] format -kms_service_agents: - compute: [key1, key2] - storage: [key1, key2] - -# [opt] Labels for the project - merged with the ones defined in defaults -labels: - environment: dev - -# [opt] Org policy overrides defined at project level -org_policies: - compute.disableGuestAttributesAccess: - rules: - - enforce: true - compute.trustedImageProjects: - rules: - - allow: - values: - - projects/fast-dev-iac-core-0 - compute.vmExternalIpAccess: - rules: - - deny: - all: true - -# [opt] Service account to create for the project and their roles on the project -# in name => [roles] format -service_accounts: - another-service-account: - - roles/compute.admin - my-service-account: - - roles/compute.admin - -# [opt] APIs to enable on the project. -services: - - storage.googleapis.com - - stackdriver.googleapis.com - - compute.googleapis.com - -# [opt] Roles to assign to the service identities in service => [roles] format -service_identities_iam: - compute: - - roles/storage.objectViewer - - # [opt] VPC setup. - # If set enables the `compute.googleapis.com` service and configures - # service project attachment -vpc: - # [opt] If set, enables the container API - gke_setup: - # Grants "roles/container.hostServiceAgentUser" to the container robot if set - enable_host_service_agent: false - - # Grants "roles/compute.securityAdmin" to the container robot if set - enable_security_admin: true - - # Host project the project will be service project of - host_project: fast-dev-net-spoke-0 - - # [opt] Subnets in the host project where principals will be granted networkUser - # in region/subnet-name => [principals] - subnets_iam: - europe-west1/dev-default-ew1: - - user:foobar@example.com - - serviceAccount:service-account1 diff --git a/fast/stages/3-project-factory/dev/data/projects/test-project.yaml b/fast/stages/3-project-factory/dev/data/projects/test-project.yaml new file mode 100644 index 00000000..dfe34e6c --- /dev/null +++ b/fast/stages/3-project-factory/dev/data/projects/test-project.yaml @@ -0,0 +1,20 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +labels: + team: team-0 +parent: folders/1234567890 +services: +- compute.googleapis.com +- storage.googleapis.com diff --git a/fast/stages/3-project-factory/dev/main.tf b/fast/stages/3-project-factory/dev/main.tf index 261351ca..4f23b492 100644 --- a/fast/stages/3-project-factory/dev/main.tf +++ b/fast/stages/3-project-factory/dev/main.tf @@ -31,7 +31,7 @@ module "projects" { ] } data_overrides = { - prefix = var.prefix + prefix = "${var.prefix}-dev" } factory_data = var.factory_data } diff --git a/fast/stages/3-project-factory/dev/variables.tf b/fast/stages/3-project-factory/dev/variables.tf index d004aeb8..c7165e3c 100644 --- a/fast/stages/3-project-factory/dev/variables.tf +++ b/fast/stages/3-project-factory/dev/variables.tf @@ -36,6 +36,9 @@ variable "factory_data" { data_path = optional(string) }) nullable = false + default = { + data_path = "data/projects" + } validation { condition = ( (var.factory_data.data != null ? 1 : 0) + @@ -49,7 +52,6 @@ variable "prefix" { # tfdoc:variable:source 0-bootstrap description = "Prefix used for resources that need unique names. Use 9 characters or less." type = string - validation { condition = try(length(var.prefix), 0) < 10 error_message = "Use a maximum of 9 characters for prefix." diff --git a/modules/__docs/20230816-iam-refactor.md b/modules/__docs/20230816-iam-refactor.md index 438252ac..46916657 100644 --- a/modules/__docs/20230816-iam-refactor.md +++ b/modules/__docs/20230816-iam-refactor.md @@ -6,6 +6,7 @@ ## Status Implemented in [#1595](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/pull/1595). +Authoritative bindings type changed as per [#1622](https://github.com/GoogleCloudPlatform/cloud-foundation-fabric/issues/1622). ## Context @@ -39,15 +40,18 @@ The new `iam_bindings` variable will look like this: ```hcl variable "iam_bindings" { - description = "Authoritative IAM bindings with support for conditions, in {ROLE => { members = [], condition = {}}} format." + description = "Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary." type = map(object({ - members = list(string) + members = list(string) + role = string condition = optional(object({ expression = string title = string description = optional(string) })) })) + nullable = false + default = {} } ``` @@ -94,8 +98,8 @@ The new variable will closely follow the type of the authoritative `iam_bindings variable "iam_bindings_additive" { description = "Additive IAM bindings with support for conditions, in {KEY => { role = ROLE, members = [], condition = {}}} format." type = map(object({ - member = string - role = string + member = string + role = string condition = optional(object({ expression = string title = string @@ -128,3 +132,213 @@ This brings several advantages over the previous handling of IAM: ### Blueprints A few data blueprints that leverage `iam_additive` have been refactored to use the new variable. This is most notable in data blueprints, where extra files have been added to the more complex examples like data foundations, to abstract IAM bindings in a way similar to what is described above for FAST. + +## Implementation + +The following sections provide a template for IAM-related variables and resources to ensure a consistent implementation of IAM across the repository. Use these code snippets to add IAM support to your module. + +### Top-level module IAM + +Use this template if your module manages a single instance of a given resource (e.g. a KMS keyring). + +```terraform +# variables.tf + +variable "iam" { + description = "IAM bindings in {ROLE => [MEMBERS]} format. Mutually exclusive with the access_* variables used for basic roles." + type = map(list(string)) + default = {} + nullable = false +} + +variable "iam_bindings" { + description = "Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary." + type = map(object({ + members = list(string) + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })) + default = {} + nullable = false +} + +variable "iam_bindings_additive" { + description = "Keyring individual additive IAM bindings. Keys are arbitrary." + type = map(object({ + member = string + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })) + default = {} + nullable = false +} +``` + +```terraform +# iam.tf + +resource "google_RESOURCE_TYPE_iam_binding" "authoritative" { + for_each = var.iam + role = each.key + members = each.value + // add extra attributes (e.g. resource id) +} + +resource "google_RESOURCE_TYPE_iam_binding" "bindings" { + for_each = var.iam_bindings + role = each.value.role + members = each.value.members + // add extra attributes (e.g. resource id) + + dynamic "condition" { + for_each = each.value.condition == null ? [] : [""] + content { + expression = each.value.condition.expression + title = each.value.condition.title + description = each.value.condition.description + } + } +} + +resource "google_RESOURCE_TYPE_iam_member" "bindings" { + for_each = var.iam_bindings_additive + role = each.value.role + member = each.value.member + // add extra attributes (e.g. resource id) + + dynamic "condition" { + for_each = each.value.condition == null ? [] : [""] + content { + expression = each.value.condition.expression + title = each.value.condition.title + description = each.value.condition.description + } + } +} +``` + +### Sub-resources IAM + +Use this template if your module manages multiple instances of a resource (e.g. keys in KMS keyring). + +```terraform +# variables.tf +variable "sub_resources" { + type = map(object({ + # sub-resource configuration here + + iam = optional(map(list(string)), {}) + iam_bindings = optional(map(object({ + members = list(string) + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) + iam_bindings_additive = optional(map(object({ + member = string + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) + })) + default = {} + nullable = false +} +``` + +```terraform +# iam.tf +locals { + SUB_RESOURCE_iam = flatten([ + for k, v in var.SUB_RESOURCEs : [ + for role, members in v.iam : { + key = k + role = role + members = members + } + ] + ]) + SUB_RESOURCE_iam_bindings = merge([ + for k, v in var.SUB_RESOURCEs : { + for binding_key, data in v.iam_bindings : + binding_key => { + SUB_RESOURCE = k + role = data.role + members = data.members + condition = data.condition + } + } + ]...) + SUB_RESOURCE_iam_bindings_additive = merge([ + for k, v in var.subresources : { + for binding_key, data in v.iam_bindings_additive : + binding_key => { + SUB_RESOURCE = k + role = data.role + member = data.member + condition = data.condition + } + } + ]...) +} +``` + +```terraform +# iam.tf + +resource "google_SUB_RESOURCE_iam_binding" "authoritative" { + for_each = { + for binding in local.SUB_RESOURCE_iam : + "${binding.key}.${binding.role}" => binding + } + role = each.value.role + members = each.value.members + // add extra attributes (e.g. sub resource id) +} + +resource "google_SUB_RESOURCE_iam_binding" "bindings" { + for_each = local.SUB_RESOURCE_iam_bindings + role = each.value.role + members = each.value.members + // add extra attributes (e.g. sub resource id) + + dynamic "condition" { + for_each = each.value.condition == null ? [] : [""] + content { + expression = each.value.condition.expression + title = each.value.condition.title + description = each.value.condition.description + } + } +} + +resource "google_SUB_RESOURCE_iam_member" "members" { + for_each = local.SUB_RESOURCE_iam_bindings_additive + role = each.value.role + member = each.value.member + // add extra attributes (e.g. sub resource id) + + dynamic "condition" { + for_each = each.value.condition == null ? [] : [""] + content { + expression = each.value.condition.expression + title = each.value.condition.title + description = each.value.condition.description + } + } +} + +``` diff --git a/modules/__experimental/net-neg/versions.tf b/modules/__experimental/net-neg/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/__experimental/net-neg/versions.tf +++ b/modules/__experimental/net-neg/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/alloydb-instance/versions.tf b/modules/alloydb-instance/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/alloydb-instance/versions.tf +++ b/modules/alloydb-instance/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/api-gateway/versions.tf b/modules/api-gateway/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/api-gateway/versions.tf +++ b/modules/api-gateway/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/apigee/README.md b/modules/apigee/README.md index 67daa729..cb99a34a 100644 --- a/modules/apigee/README.md +++ b/modules/apigee/README.md @@ -2,7 +2,121 @@ This module simplifies the creation of a Apigee resources (organization, environment groups, environment group attachments, environments, instances and instance attachments). -## Example +## Examples + + +- [Examples](#examples) + - [Minimal example (CLOUD)](#minimal-example-cloud) + - [Minimal example with existing organization (CLOUD)](#minimal-example-with-existing-organization-cloud) + - [Disable VPC Peering (CLOUD)](#disable-vpc-peering-cloud) + - [All resources (CLOUD)](#all-resources-cloud) + - [All resources (HYBRID control plane)](#all-resources-hybrid-control-plane) + - [New environment group](#new-environment-group) + - [New environment](#new-environment) + - [New instance (VPC Peering Provisioning Mode)](#new-instance-vpc-peering-provisioning-mode) + - [New instance (Non VPC Peering Provisioning Mode)](#new-instance-non-vpc-peering-provisioning-mode) + - [New endpoint attachment](#new-endpoint-attachment) + - [Apigee add-ons](#apigee-add-ons) +- [Variables](#variables) +- [Outputs](#outputs) + + +### Minimal example (CLOUD) + +This example shows how to create to create an Apigee organization and deploy instance in it. + +```hcl +module "apigee" { + source = "./fabric/modules/apigee" + project_id = var.project_id + organization = { + display_name = "Apigee" + billing_type = "PAYG" + analytics_region = "europe-west1" + authorized_network = var.vpc.id + runtime_type = "CLOUD" + } + envgroups = { + prod = ["prod.example.com"] + } + environments = { + apis-prod = { + display_name = "APIs prod" + description = "APIs Prod" + envgroups = ["prod"] + } + } + instances = { + europe-west1 = { + environments = ["apis-prod"] + runtime_ip_cidr_range = "10.32.0.0/22" + troubleshooting_ip_cidr_range = "10.64.0.0/28" + } + } +} +# tftest modules=1 resources=6 inventory=minimal-cloud.yaml +``` + +### Minimal example with existing organization (CLOUD) + +This example shows how to create to work with an existing organization in the project. Note that in this case we don't specify the IP ranges for the instance, so it requests and allocates an available /22 and /28 CIDR block from Service Networking to deploy the instance. + +```hcl +module "apigee" { + source = "./fabric/modules/apigee" + project_id = var.project_id + envgroups = { + prod = ["prod.example.com"] + } + environments = { + apis-prod = { + display_name = "APIs prod" + envgroups = ["prod"] + } + } + instances = { + europe-west1 = { + environments = ["apis-prod"] + } + } +} +# tftest modules=1 resources=5 inventory=minimal-cloud-no-org.yaml +``` + +### Disable VPC Peering (CLOUD) + +When a new Apigee organization is created, it is automatically peered to the authorized network. You can prevent this from happening by using the `disable_vpc_peering` key in the `organization` variable, as shown below: + + +```hcl +module "apigee" { + source = "./fabric/modules/apigee" + project_id = var.project_id + organization = { + display_name = "Apigee" + billing_type = "PAYG" + analytics_region = "europe-west1" + runtime_type = "CLOUD" + disable_vpc_peering = true + } + envgroups = { + prod = ["prod.example.com"] + } + environments = { + apis-prod = { + display_name = "APIs prod" + envgroups = ["prod"] + } + } + instances = { + europe-west1 = { + environments = ["apis-prod"] + } + } +} +# tftest modules=1 resources=6 inventory=no-peering.yaml +``` + ### All resources (CLOUD) @@ -28,13 +142,11 @@ module "apigee" { display_name = "APIs test" description = "APIs Test" envgroups = ["test"] - regions = ["europe-west1"] } apis-prod = { display_name = "APIs prod" description = "APIs prod" envgroups = ["prod"] - regions = ["europe-west3"] iam = { "roles/viewer" = ["group:devops@myorg.com"] } @@ -44,10 +156,12 @@ module "apigee" { europe-west1 = { runtime_ip_cidr_range = "10.0.4.0/22" troubleshooting_ip_cidr_range = "10.1.1.0.0/28" + environments = ["apis-test"] } europe-west3 = { runtime_ip_cidr_range = "10.0.8.0/22" troubleshooting_ip_cidr_range = "10.1.16.0/28" + environments = ["apis-prod"] enable_nat = true } } @@ -129,7 +243,7 @@ module "apigee" { # tftest modules=1 resources=1 ``` -### New instance +### New instance (VPC Peering Provisioning Mode) ```hcl module "apigee" { @@ -145,6 +259,28 @@ module "apigee" { # tftest modules=1 resources=1 ``` +### New instance (Non VPC Peering Provisioning Mode) + +```hcl +module "apigee" { + source = "./fabric/modules/apigee" + project_id = "my-project" + organization = { + display_name = "My Organization" + description = "My Organization" + runtime_type = "CLOUD" + billing_type = "Pay-as-you-go" + database_encryption_key = "123456789" + analytics_region = "europe-west1" + disable_vpc_peering = true + } + instances = { + europe-west1 = {} + } +} +# tftest modules=1 resources=2 +``` + ### New endpoint attachment Endpoint attachments allow to implement [Apigee southbound network patterns](https://cloud.google.com/apigee/docs/api-platform/architecture/southbound-networking-patterns-endpoints#create-the-psc-attachments). @@ -180,6 +316,7 @@ module "apigee" { | name | description | type | required | default | |---|---|:---:|:---:|:---:| +<<<<<<< HEAD | [project_id](variables.tf#L97) | Project ID. | string | ✓ | | | [addons_config](variables.tf#L17) | Addons configuration. | object({…}) | | null | | [endpoint_attachments](variables.tf#L29) | Endpoint attachments. | map(object({…})) | | {} | @@ -187,6 +324,15 @@ module "apigee" { | [environments](variables.tf#L46) | Environments. | map(object({…})) | | {} | | [instances](variables.tf#L65) | Instances ([REGION] => [INSTANCE]). | map(object({…})) | | {} | | [organization](variables.tf#L82) | Apigee organization. If set to null the organization must already exist. | object({…}) | | null | +======= +| [project_id](variables.tf#L117) | Project ID. | string | ✓ | | +| [addons_config](variables.tf#L17) | Addons configuration. | object({…}) | | null | +| [endpoint_attachments](variables.tf#L29) | Endpoint attachments. | map(object({…})) | | {} | +| [envgroups](variables.tf#L39) | Environment groups (NAME => [HOSTNAMES]). | map(list(string)) | | {} | +| [environments](variables.tf#L46) | Environments. | map(object({…})) | | {} | +| [instances](variables.tf#L64) | Instances ([REGION] => [INSTANCE]). | map(object({…})) | | {} | +| [organization](variables.tf#L89) | Apigee organization. If set to null the organization must already exist. | object({…}) | | null | +>>>>>>> master ## Outputs diff --git a/modules/apigee/main.tf b/modules/apigee/main.tf index 84c121db..cd1f7197 100644 --- a/modules/apigee/main.tf +++ b/modules/apigee/main.tf @@ -28,6 +28,7 @@ resource "google_apigee_organization" "organization" { runtime_type = var.organization.runtime_type runtime_database_encryption_key_name = var.organization.database_encryption_key retention = var.organization.retention + disable_vpc_peering = var.organization.disable_vpc_peering } resource "google_apigee_envgroup" "envgroups" { @@ -85,13 +86,17 @@ resource "google_apigee_environment_iam_binding" "binding" { } resource "google_apigee_instance" "instances" { - for_each = var.instances - name = coalesce(each.value.name, "instance-${each.key}") - display_name = each.value.display_name - description = each.value.description - location = each.key - org_id = local.org_id - ip_range = "${each.value.runtime_ip_cidr_range},${each.value.troubleshooting_ip_cidr_range}" + for_each = var.instances + name = coalesce(each.value.name, "instance-${each.key}") + display_name = each.value.display_name + description = each.value.description + location = each.key + org_id = local.org_id + ip_range = ( + compact([each.value.runtime_ip_cidr_range, each.value.troubleshooting_ip_cidr_range]) == [] + ? null + : join(",", compact([each.value.runtime_ip_cidr_range, each.value.troubleshooting_ip_cidr_range])) + ) disk_encryption_key_name = each.value.disk_encryption_key consumer_accept_list = each.value.consumer_accept_list } @@ -109,12 +114,12 @@ resource "google_apigee_nat_address" "apigee_nat" { resource "google_apigee_instance_attachment" "instance_attachments" { for_each = merge(concat([for k1, v1 in var.instances : { for v2 in coalesce(v1.environments, []) : - "${k1}-${v2}" => { + "${v2}-${k1}" => { instance = k1 environment = v2 } }])...) - instance_id = google_apigee_instance.instances[each.value.region].id + instance_id = google_apigee_instance.instances[each.value.instance].id environment = try(google_apigee_environment.environments[each.value.environment].name, "${local.org_id}/environments/${each.value.environment}") } @@ -127,7 +132,7 @@ resource "google_apigee_endpoint_attachment" "endpoint_attachments" { service_attachment = each.value.service_attachment } -resource "google_apigee_addons_config" "test_organization" { +resource "google_apigee_addons_config" "addons_config" { for_each = toset(var.addons_config == null ? [] : [""]) org = local.org_name addons_config { diff --git a/modules/apigee/variables.tf b/modules/apigee/variables.tf index db09c28c..3109956d 100644 --- a/modules/apigee/variables.tf +++ b/modules/apigee/variables.tf @@ -64,16 +64,26 @@ variable "environments" { variable "instances" { description = "Instances ([REGION] => [INSTANCE])." type = map(object({ + name = optional(string) display_name = optional(string) name = optional(string) description = optional(string, "Terraform-managed") - runtime_ip_cidr_range = string - troubleshooting_ip_cidr_range = string + runtime_ip_cidr_range = optional(string) + troubleshooting_ip_cidr_range = optional(string) disk_encryption_key = optional(string) consumer_accept_list = optional(list(string)) environments = optional(list(string)) enable_nat = optional(bool, false) + environments = optional(list(string)) })) + validation { + condition = alltrue([ + for k, v in var.instances : + # has troubleshooting_ip => has runtime_ip + v.runtime_ip_cidr_range != null || v.troubleshooting_ip_cidr_range == null + ]) + error_message = "Using a troubleshooting range requires specifying a runtime range too." + } default = {} nullable = false } @@ -89,7 +99,20 @@ variable "organization" { database_encryption_key = optional(string) analytics_region = optional(string, "europe-west1") retention = optional(string) + disable_vpc_peering = optional(bool, false) }) + validation { + condition = var.organization == null || ( + try(var.organization.runtime_type, null) == "CLOUD" || !try(var.organization.disable_vpc_peering, false) + ) + error_message = "Disabling the VPC peering can only be done in organization using the CLOUD runtime." + } + validation { + condition = var.organization == null || ( + try(var.organization.authorized_network, null) == null || !try(var.organization.disable_vpc_peering, false) + ) + error_message = "Disabling the VPC peering is mutually exclusive with authorized_network." + } default = null } diff --git a/modules/apigee/versions.tf b/modules/apigee/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/apigee/versions.tf +++ b/modules/apigee/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/artifact-registry/versions.tf b/modules/artifact-registry/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/artifact-registry/versions.tf +++ b/modules/artifact-registry/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/bigquery-dataset/versions.tf b/modules/bigquery-dataset/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/bigquery-dataset/versions.tf +++ b/modules/bigquery-dataset/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/bigtable-instance/versions.tf b/modules/bigtable-instance/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/bigtable-instance/versions.tf +++ b/modules/bigtable-instance/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/billing-budget/versions.tf b/modules/billing-budget/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/billing-budget/versions.tf +++ b/modules/billing-budget/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/binauthz/versions.tf b/modules/binauthz/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/binauthz/versions.tf +++ b/modules/binauthz/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-config-container/__need_fixing/onprem/versions.tf b/modules/cloud-config-container/__need_fixing/onprem/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-config-container/__need_fixing/onprem/versions.tf +++ b/modules/cloud-config-container/__need_fixing/onprem/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-config-container/coredns/versions.tf b/modules/cloud-config-container/coredns/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-config-container/coredns/versions.tf +++ b/modules/cloud-config-container/coredns/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-config-container/cos-generic-metadata/versions.tf b/modules/cloud-config-container/cos-generic-metadata/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-config-container/cos-generic-metadata/versions.tf +++ b/modules/cloud-config-container/cos-generic-metadata/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-config-container/envoy-traffic-director/versions.tf b/modules/cloud-config-container/envoy-traffic-director/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-config-container/envoy-traffic-director/versions.tf +++ b/modules/cloud-config-container/envoy-traffic-director/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-config-container/mysql/versions.tf b/modules/cloud-config-container/mysql/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-config-container/mysql/versions.tf +++ b/modules/cloud-config-container/mysql/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-config-container/nginx-tls/versions.tf b/modules/cloud-config-container/nginx-tls/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-config-container/nginx-tls/versions.tf +++ b/modules/cloud-config-container/nginx-tls/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-config-container/nginx/versions.tf b/modules/cloud-config-container/nginx/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-config-container/nginx/versions.tf +++ b/modules/cloud-config-container/nginx/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-config-container/simple-nva/versions.tf b/modules/cloud-config-container/simple-nva/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-config-container/simple-nva/versions.tf +++ b/modules/cloud-config-container/simple-nva/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-config-container/squid/versions.tf b/modules/cloud-config-container/squid/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-config-container/squid/versions.tf +++ b/modules/cloud-config-container/squid/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-function-v1/versions.tf b/modules/cloud-function-v1/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-function-v1/versions.tf +++ b/modules/cloud-function-v1/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-function-v2/versions.tf b/modules/cloud-function-v2/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-function-v2/versions.tf +++ b/modules/cloud-function-v2/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-identity-group/versions.tf b/modules/cloud-identity-group/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-identity-group/versions.tf +++ b/modules/cloud-identity-group/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloud-run/versions.tf b/modules/cloud-run/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloud-run/versions.tf +++ b/modules/cloud-run/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/cloudsql-instance/README.md b/modules/cloudsql-instance/README.md index 00cf5ded..74afa419 100644 --- a/modules/cloudsql-instance/README.md +++ b/modules/cloudsql-instance/README.md @@ -116,13 +116,12 @@ module "kms" { location = var.region } keys = { - key-sql = null - } - key_iam = { key-sql = { - "roles/cloudkms.cryptoKeyEncrypterDecrypter" = [ - "serviceAccount:${module.project.service_accounts.robots.sqladmin}" - ] + iam = { + "roles/cloudkms.cryptoKeyEncrypterDecrypter" = [ + "serviceAccount:${module.project.service_accounts.robots.sqladmin}" + ] + } } } } diff --git a/modules/cloudsql-instance/versions.tf b/modules/cloudsql-instance/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/cloudsql-instance/versions.tf +++ b/modules/cloudsql-instance/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/compute-mig/README.md b/modules/compute-mig/README.md index b281c2e3..5e3dbd8e 100644 --- a/modules/compute-mig/README.md +++ b/modules/compute-mig/README.md @@ -389,7 +389,6 @@ module "nginx-mig" { # tftest modules=2 resources=3 inventory=stateful.yaml ``` - ## Variables | name | description | type | required | default | @@ -400,7 +399,7 @@ module "nginx-mig" { | [project_id](variables.tf#L198) | Project id. | string | ✓ | | | [all_instances_config](variables.tf#L17) | Metadata and labels set to all instances in the group. | object({…}) | | null | | [auto_healing_policies](variables.tf#L26) | Auto-healing policies for this group. | object({…}) | | null | -| [autoscaler_config](variables.tf#L35) | Optional autoscaler configuration. | object({…}) | | null | +| [autoscaler_config](variables.tf#L35) | Optional autoscaler configuration. | object({…}) | | null | | [default_version_name](variables.tf#L83) | Name used for the default version. | string | | "default" | | [description](variables.tf#L89) | Optional description used for all resources managed by this module. | string | | "Terraform managed." | | [distribution_policy](variables.tf#L95) | DIstribution policy for regional MIG. | object({…}) | | null | @@ -422,5 +421,4 @@ module "nginx-mig" { | [group_manager](outputs.tf#L26) | Instance group resource. | | | [health_check](outputs.tf#L35) | Auto-created health-check resource. | | | [id](outputs.tf#L44) | Fully qualified group manager id. | | - diff --git a/modules/compute-mig/autoscaler.tf b/modules/compute-mig/autoscaler.tf index b8bd0acc..c0f77491 100644 --- a/modules/compute-mig/autoscaler.tf +++ b/modules/compute-mig/autoscaler.tf @@ -35,6 +35,7 @@ resource "google_compute_autoscaler" "default" { max_replicas = var.autoscaler_config.max_replicas min_replicas = var.autoscaler_config.min_replicas cooldown_period = var.autoscaler_config.cooldown_period + mode = var.autoscaler_config.mode dynamic "scale_down_control" { for_each = local.as_scaling.down == null ? [] : [""] @@ -138,6 +139,7 @@ resource "google_compute_region_autoscaler" "default" { max_replicas = var.autoscaler_config.max_replicas min_replicas = var.autoscaler_config.min_replicas cooldown_period = var.autoscaler_config.cooldown_period + mode = var.autoscaler_config.mode dynamic "scale_down_control" { for_each = local.as_scaling.down == null ? [] : [""] diff --git a/modules/compute-mig/variables.tf b/modules/compute-mig/variables.tf index 30f2ce96..20864d18 100644 --- a/modules/compute-mig/variables.tf +++ b/modules/compute-mig/variables.tf @@ -61,8 +61,8 @@ variable "autoscaler_config" { })) metrics = optional(list(object({ name = string - type = string # GAUGE, DELTA_PER_SECOND, DELTA_PER_MINUTE - target_value = number + type = optional(string) # GAUGE, DELTA_PER_SECOND, DELTA_PER_MINUTE + target_value = optional(number) single_instance_assignment = optional(number) time_series_filter = optional(string) }))) diff --git a/modules/compute-mig/versions.tf b/modules/compute-mig/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/compute-mig/versions.tf +++ b/modules/compute-mig/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/compute-vm/main.tf b/modules/compute-vm/main.tf index 0ca16257..e79cc18c 100644 --- a/modules/compute-vm/main.tf +++ b/modules/compute-vm/main.tf @@ -187,7 +187,7 @@ resource "google_compute_instance" "default" { source = ( config.value.source_type == "attach" ? config.value.source - : google_compute_region_disk.disks[config.key].name + : google_compute_region_disk.disks[config.key].id ) } } diff --git a/modules/compute-vm/versions.tf b/modules/compute-vm/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/compute-vm/versions.tf +++ b/modules/compute-vm/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/container-registry/versions.tf b/modules/container-registry/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/container-registry/versions.tf +++ b/modules/container-registry/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/data-catalog-policy-tag/README.md b/modules/data-catalog-policy-tag/README.md index b08a9feb..8a464784 100644 --- a/modules/data-catalog-policy-tag/README.md +++ b/modules/data-catalog-policy-tag/README.md @@ -79,17 +79,17 @@ module "cmn-dc" { | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [name](variables.tf#L76) | Name of this taxonomy. | string | ✓ | | -| [project_id](variables.tf#L91) | GCP project id. | | ✓ | | +| [name](variables.tf#L77) | Name of this taxonomy. | string | ✓ | | +| [project_id](variables.tf#L92) | GCP project id. | | ✓ | | | [activated_policy_types](variables.tf#L17) | A list of policy types that are activated for this taxonomy. | list(string) | | ["FINE_GRAINED_ACCESS_CONTROL"] | | [description](variables.tf#L23) | Description of this taxonomy. | string | | "Taxonomy - Terraform managed" | | [group_iam](variables.tf#L29) | Authoritative IAM binding for organization groups, in {GROUP_EMAIL => [ROLES]} format. Group emails need to be static. Can be used in combination with the `iam` variable. | map(list(string)) | | {} | | [iam](variables.tf#L35) | IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | -| [iam_bindings](variables.tf#L41) | Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}. | map(object({…})) | | {} | -| [iam_bindings_additive](variables.tf#L55) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | -| [location](variables.tf#L70) | Data Catalog Taxonomy location. | string | | "eu" | -| [prefix](variables.tf#L81) | Optional prefix used to generate project id and name. | string | | null | -| [tags](variables.tf#L95) | List of Data Catalog Policy tags to be created with optional IAM binging configuration in {tag => {ROLE => [MEMBERS]}} format. | map(object({…})) | | {} | +| [iam_bindings](variables.tf#L41) | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | map(object({…})) | | {} | +| [iam_bindings_additive](variables.tf#L56) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | +| [location](variables.tf#L71) | Data Catalog Taxonomy location. | string | | "eu" | +| [prefix](variables.tf#L82) | Optional prefix used to generate project id and name. | string | | null | +| [tags](variables.tf#L96) | List of Data Catalog Policy tags to be created with optional IAM binging configuration in {tag => {ROLE => [MEMBERS]}} format. | map(object({…})) | | {} | ## Outputs diff --git a/modules/data-catalog-policy-tag/iam.tf b/modules/data-catalog-policy-tag/iam.tf index 268c0c58..06c30763 100644 --- a/modules/data-catalog-policy-tag/iam.tf +++ b/modules/data-catalog-policy-tag/iam.tf @@ -53,7 +53,7 @@ resource "google_data_catalog_taxonomy_iam_binding" "bindings" { provider = google-beta for_each = var.iam_bindings taxonomy = google_data_catalog_taxonomy.default.id - role = each.key + role = each.value.role members = each.value.members dynamic "condition" { for_each = each.value.condition == null ? [] : [""] diff --git a/modules/data-catalog-policy-tag/variables.tf b/modules/data-catalog-policy-tag/variables.tf index b0df313d..0fef9e7b 100644 --- a/modules/data-catalog-policy-tag/variables.tf +++ b/modules/data-catalog-policy-tag/variables.tf @@ -39,9 +39,10 @@ variable "iam" { } variable "iam_bindings" { - description = "Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}." + description = "Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary." type = map(object({ members = list(string) + role = string condition = optional(object({ expression = string title = string diff --git a/modules/data-catalog-policy-tag/versions.tf b/modules/data-catalog-policy-tag/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/data-catalog-policy-tag/versions.tf +++ b/modules/data-catalog-policy-tag/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/datafusion/versions.tf b/modules/datafusion/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/datafusion/versions.tf +++ b/modules/datafusion/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/dataplex-datascan/README.md b/modules/dataplex-datascan/README.md index 1c950184..4116732f 100644 --- a/modules/dataplex-datascan/README.md +++ b/modules/dataplex-datascan/README.md @@ -431,9 +431,9 @@ module "dataplex-datascan" { | name | description | type | required | default | |---|---|:---:|:---:|:---:| | [data](variables.tf#L17) | The data source for DataScan. The source can be either a Dataplex `entity` or a BigQuery `resource`. | object({…}) | ✓ | | -| [name](variables.tf#L156) | Name of Dataplex Scan. | string | ✓ | | -| [project_id](variables.tf#L167) | The ID of the project where the Dataplex DataScan will be created. | string | ✓ | | -| [region](variables.tf#L172) | Region for the Dataplex DataScan. | string | ✓ | | +| [name](variables.tf#L157) | Name of Dataplex Scan. | string | ✓ | | +| [project_id](variables.tf#L168) | The ID of the project where the Dataplex DataScan will be created. | string | ✓ | | +| [region](variables.tf#L173) | Region for the Dataplex DataScan. | string | ✓ | | | [data_profile_spec](variables.tf#L29) | DataProfileScan related setting. Variable descriptions are provided in https://cloud.google.com/dataplex/docs/reference/rest/v1/DataProfileSpec. | object({…}) | | null | | [data_quality_spec](variables.tf#L38) | DataQualityScan related setting. Variable descriptions are provided in https://cloud.google.com/dataplex/docs/reference/rest/v1/DataQualitySpec. | object({…}) | | null | | [data_quality_spec_file](variables.tf#L80) | Path to a YAML file containing DataQualityScan related setting. Input content can use either camelCase or snake_case. Variables description are provided in https://cloud.google.com/dataplex/docs/reference/rest/v1/DataQualitySpec. | object({…}) | | null | @@ -441,11 +441,11 @@ module "dataplex-datascan" { | [execution_schedule](variables.tf#L94) | Schedule DataScan to run periodically based on a cron schedule expression. If not specified, the DataScan is created with `on_demand` schedule, which means it will not run until the user calls `dataScans.run` API. | string | | null | | [group_iam](variables.tf#L100) | Authoritative IAM binding for organization groups, in {GROUP_EMAIL => [ROLES]} format. Group emails need to be static. Can be used in combination with the `iam` variable. | map(list(string)) | | {} | | [iam](variables.tf#L107) | Dataplex DataScan IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | -| [iam_bindings](variables.tf#L114) | Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}. | map(object({…})) | | {} | -| [iam_bindings_additive](variables.tf#L128) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | -| [incremental_field](variables.tf#L143) | The unnested field (of type Date or Timestamp) that contains values which monotonically increase over time. If not specified, a data scan will run for all data in the table. | string | | null | -| [labels](variables.tf#L149) | Resource labels. | map(string) | | {} | -| [prefix](variables.tf#L161) | Optional prefix used to generate Dataplex DataScan ID. | string | | null | +| [iam_bindings](variables.tf#L114) | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | map(object({…})) | | {} | +| [iam_bindings_additive](variables.tf#L129) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | +| [incremental_field](variables.tf#L144) | The unnested field (of type Date or Timestamp) that contains values which monotonically increase over time. If not specified, a data scan will run for all data in the table. | string | | null | +| [labels](variables.tf#L150) | Resource labels. | map(string) | | {} | +| [prefix](variables.tf#L162) | Optional prefix used to generate Dataplex DataScan ID. | string | | null | ## Outputs diff --git a/modules/dataplex-datascan/iam.tf b/modules/dataplex-datascan/iam.tf index 9a496ff1..9ed59144 100644 --- a/modules/dataplex-datascan/iam.tf +++ b/modules/dataplex-datascan/iam.tf @@ -44,7 +44,7 @@ resource "google_dataplex_datascan_iam_binding" "bindings" { project = google_dataplex_datascan.datascan.project location = google_dataplex_datascan.datascan.location data_scan_id = google_dataplex_datascan.datascan.data_scan_id - role = each.key + role = each.value.role members = each.value.members dynamic "condition" { for_each = each.value.condition == null ? [] : [""] diff --git a/modules/dataplex-datascan/variables.tf b/modules/dataplex-datascan/variables.tf index 4e6b2bb1..a13cdc55 100644 --- a/modules/dataplex-datascan/variables.tf +++ b/modules/dataplex-datascan/variables.tf @@ -112,9 +112,10 @@ variable "iam" { } variable "iam_bindings" { - description = "Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}." + description = "Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary." type = map(object({ members = list(string) + role = string condition = optional(object({ expression = string title = string diff --git a/modules/dataplex-datascan/versions.tf b/modules/dataplex-datascan/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/dataplex-datascan/versions.tf +++ b/modules/dataplex-datascan/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/dataplex/versions.tf b/modules/dataplex/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/dataplex/versions.tf +++ b/modules/dataplex/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/dataproc/README.md b/modules/dataproc/README.md index aa532671..5cd220cb 100644 --- a/modules/dataproc/README.md +++ b/modules/dataproc/README.md @@ -146,17 +146,17 @@ module "processing-dp-cluster" { | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [name](variables.tf#L234) | Cluster name. | string | ✓ | | -| [project_id](variables.tf#L249) | Project ID. | string | ✓ | | -| [region](variables.tf#L254) | Dataproc region. | string | ✓ | | +| [name](variables.tf#L235) | Cluster name. | string | ✓ | | +| [project_id](variables.tf#L250) | Project ID. | string | ✓ | | +| [region](variables.tf#L255) | Dataproc region. | string | ✓ | | | [dataproc_config](variables.tf#L17) | Dataproc cluster config. | object({…}) | | {} | | [group_iam](variables.tf#L185) | Authoritative IAM binding for organization groups, in {GROUP_EMAIL => [ROLES]} format. Group emails need to be static. Can be used in combination with the `iam` variable. | map(list(string)) | | {} | | [iam](variables.tf#L192) | IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | -| [iam_bindings](variables.tf#L199) | Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}. | map(object({…})) | | {} | -| [iam_bindings_additive](variables.tf#L213) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | -| [labels](variables.tf#L228) | The resource labels for instance to use to annotate any related underlying resources, such as Compute Engine VMs. | map(string) | | {} | -| [prefix](variables.tf#L239) | Optional prefix used to generate project id and name. | string | | null | -| [service_account](variables.tf#L259) | Service account to set on the Dataproc cluster. | string | | null | +| [iam_bindings](variables.tf#L199) | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | map(object({…})) | | {} | +| [iam_bindings_additive](variables.tf#L214) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | +| [labels](variables.tf#L229) | The resource labels for instance to use to annotate any related underlying resources, such as Compute Engine VMs. | map(string) | | {} | +| [prefix](variables.tf#L240) | Optional prefix used to generate project id and name. | string | | null | +| [service_account](variables.tf#L260) | Service account to set on the Dataproc cluster. | string | | null | ## Outputs diff --git a/modules/dataproc/iam.tf b/modules/dataproc/iam.tf index fba2eca9..ef0428d1 100644 --- a/modules/dataproc/iam.tf +++ b/modules/dataproc/iam.tf @@ -46,7 +46,7 @@ resource "google_dataproc_cluster_iam_binding" "bindings" { project = var.project_id cluster = google_dataproc_cluster.cluster.name region = var.region - role = each.key + role = each.value.role members = each.value.members dynamic "condition" { for_each = each.value.condition == null ? [] : [""] diff --git a/modules/dataproc/variables.tf b/modules/dataproc/variables.tf index 49f4fa90..8b77c5b9 100644 --- a/modules/dataproc/variables.tf +++ b/modules/dataproc/variables.tf @@ -197,9 +197,10 @@ variable "iam" { } variable "iam_bindings" { - description = "Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}." + description = "Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary." type = map(object({ members = list(string) + role = string condition = optional(object({ expression = string title = string diff --git a/modules/dataproc/versions.tf b/modules/dataproc/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/dataproc/versions.tf +++ b/modules/dataproc/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/dns-response-policy/versions.tf b/modules/dns-response-policy/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/dns-response-policy/versions.tf +++ b/modules/dns-response-policy/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/dns/README.md b/modules/dns/README.md index cdfff0e3..5b293768 100644 --- a/modules/dns/README.md +++ b/modules/dns/README.md @@ -140,17 +140,16 @@ module "public-dns" { # tftest modules=1 resources=4 inventory=public-zone.yaml ``` - ## Variables | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [name](variables.tf#L33) | Zone name, must be unique within the project. | string | ✓ | | -| [project_id](variables.tf#L38) | Project id for the zone. | string | ✓ | | -| [description](variables.tf#L21) | Domain description. | string | | "Terraform managed." | -| [iam](variables.tf#L27) | IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) | | null | -| [recordsets](variables.tf#L43) | Map of DNS recordsets in \"type name\" => {ttl, [records]} format. | map(object({…})) | | {} | -| [zone_config](variables.tf#L78) | DNS zone configuration. | object({…}) | | null | +| [name](variables.tf#L29) | Zone name, must be unique within the project. | string | ✓ | | +| [project_id](variables.tf#L34) | Project id for the zone. | string | ✓ | | +| [description](variables.tf#L17) | Domain description. | string | | "Terraform managed." | +| [iam](variables.tf#L23) | IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) | | null | +| [recordsets](variables.tf#L39) | Map of DNS recordsets in \"type name\" => {ttl, [records]} format. | map(object({…})) | | {} | +| [zone_config](variables.tf#L74) | DNS zone configuration. | object({…}) | | null | ## Outputs @@ -162,5 +161,4 @@ module "public-dns" { | [name](outputs.tf#L32) | The DNS zone name. | | | [name_servers](outputs.tf#L37) | The DNS zone name servers. | | | [zone](outputs.tf#L42) | DNS zone resource. | | - diff --git a/modules/dns/variables.tf b/modules/dns/variables.tf index 9c2bf545..08395ba0 100644 --- a/modules/dns/variables.tf +++ b/modules/dns/variables.tf @@ -14,10 +14,6 @@ * limitations under the License. */ -############################################################################### -# zone variables # -############################################################################### - variable "description" { description = "Domain description." type = string diff --git a/modules/dns/versions.tf b/modules/dns/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/dns/versions.tf +++ b/modules/dns/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/endpoints/versions.tf b/modules/endpoints/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/endpoints/versions.tf +++ b/modules/endpoints/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/folder/README.md b/modules/folder/README.md index b4f41601..65661210 100644 --- a/modules/folder/README.md +++ b/modules/folder/README.md @@ -290,17 +290,17 @@ module "folder" { | [folder_create](variables.tf#L33) | Create folder. When set to false, uses id to reference an existing folder. | bool | | true | | [group_iam](variables.tf#L39) | Authoritative IAM binding for organization groups, in {GROUP_EMAIL => [ROLES]} format. Group emails need to be static. Can be used in combination with the `iam` variable. | map(list(string)) | | {} | | [iam](variables.tf#L46) | IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | -| [iam_bindings](variables.tf#L53) | Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}. | map(object({…})) | | {} | -| [iam_bindings_additive](variables.tf#L67) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | -| [id](variables.tf#L82) | Folder ID in case you use folder_create=false. | string | | null | -| [logging_data_access](variables.tf#L88) | Control activation of data access logs. Format is service => { log type => [exempted members]}. The special 'allServices' key denotes configuration for all services. | map(map(list(string))) | | {} | -| [logging_exclusions](variables.tf#L103) | Logging exclusions for this folder in the form {NAME -> FILTER}. | map(string) | | {} | -| [logging_sinks](variables.tf#L110) | Logging sinks to create for the organization. | map(object({…})) | | {} | -| [name](variables.tf#L140) | Folder name. | string | | null | -| [org_policies](variables.tf#L146) | Organization policies applied to this folder keyed by policy name. | map(object({…})) | | {} | -| [org_policies_data_path](variables.tf#L173) | Path containing org policies in YAML format. | string | | null | -| [parent](variables.tf#L179) | Parent in folders/folder_id or organizations/org_id format. | string | | null | -| [tag_bindings](variables.tf#L189) | Tag bindings for this folder, in key => tag value id format. | map(string) | | null | +| [iam_bindings](variables.tf#L53) | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | map(object({…})) | | {} | +| [iam_bindings_additive](variables.tf#L68) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | +| [id](variables.tf#L83) | Folder ID in case you use folder_create=false. | string | | null | +| [logging_data_access](variables.tf#L89) | Control activation of data access logs. Format is service => { log type => [exempted members]}. The special 'allServices' key denotes configuration for all services. | map(map(list(string))) | | {} | +| [logging_exclusions](variables.tf#L104) | Logging exclusions for this folder in the form {NAME -> FILTER}. | map(string) | | {} | +| [logging_sinks](variables.tf#L111) | Logging sinks to create for the organization. | map(object({…})) | | {} | +| [name](variables.tf#L141) | Folder name. | string | | null | +| [org_policies](variables.tf#L147) | Organization policies applied to this folder keyed by policy name. | map(object({…})) | | {} | +| [org_policies_data_path](variables.tf#L174) | Path containing org policies in YAML format. | string | | null | +| [parent](variables.tf#L180) | Parent in folders/folder_id or organizations/org_id format. | string | | null | +| [tag_bindings](variables.tf#L190) | Tag bindings for this folder, in key => tag value id format. | map(string) | | null | ## Outputs diff --git a/modules/folder/iam.tf b/modules/folder/iam.tf index 976e312c..20025b28 100644 --- a/modules/folder/iam.tf +++ b/modules/folder/iam.tf @@ -42,7 +42,7 @@ resource "google_folder_iam_binding" "authoritative" { resource "google_folder_iam_binding" "bindings" { for_each = var.iam_bindings folder = local.folder.name - role = each.key + role = each.value.role members = each.value.members dynamic "condition" { for_each = each.value.condition == null ? [] : [""] diff --git a/modules/folder/variables.tf b/modules/folder/variables.tf index 619ee9c3..86efc215 100644 --- a/modules/folder/variables.tf +++ b/modules/folder/variables.tf @@ -51,9 +51,10 @@ variable "iam" { } variable "iam_bindings" { - description = "Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}." + description = "Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary." type = map(object({ members = list(string) + role = string condition = optional(object({ expression = string title = string diff --git a/modules/folder/versions.tf b/modules/folder/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/folder/versions.tf +++ b/modules/folder/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/gcs/versions.tf b/modules/gcs/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/gcs/versions.tf +++ b/modules/gcs/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/gcve-private-cloud/versions.tf b/modules/gcve-private-cloud/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/gcve-private-cloud/versions.tf +++ b/modules/gcve-private-cloud/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/gke-cluster-autopilot/README.md b/modules/gke-cluster-autopilot/README.md index da639066..b54588c8 100644 --- a/modules/gke-cluster-autopilot/README.md +++ b/modules/gke-cluster-autopilot/README.md @@ -1,10 +1,23 @@ -# GKE cluster Autopilot module +# GKE Autopilot cluster module -This module allows simplified creation and management of GKE Autopilot clusters. Some sensible defaults are set initially, in order to allow less verbose usage for most use cases. +This module offers a way to create and manage Google Kubernetes Engine (GKE) [Autopilot clusters](https://cloud.google.com/kubernetes-engine/docs/concepts/autopilot-overview). With its sensible default settings based on best practices and authors' experience as Google Cloud practitioners, the module accommodates for many common use cases out-of-the-box, without having to rely on verbose configuration. -## Example + +- [Examples](#examples) + - [GKE Autopilot cluster](#gke-autopilot-cluster) + - [Cloud DNS](#cloud-dns) + - [Logging configuration](#logging-configuration) + - [Monitoring configuration](#monitoring-configuration) + - [Backup for GKE](#backup-for-gke) +- [Variables](#variables) +- [Outputs](#outputs) + -### GKE Cluster +## Examples + +### GKE Autopilot cluster + +This example shows how to [create a GKE cluster in Autopilot mode](https://cloud.google.com/kubernetes-engine/docs/how-to/creating-an-autopilot-cluster). ```hcl module "cluster-1" { @@ -37,7 +50,10 @@ module "cluster-1" { ### Cloud DNS -This example shows how to [use Cloud DNS as a Kubernetes DNS provider](https://cloud.google.com/kubernetes-engine/docs/how-to/cloud-dns) for GKE Standard clusters. +> [!WARNING] +> [Cloud DNS is the only DNS provider for Autopilot clusters](https://cloud.google.com/kubernetes-engine/docs/concepts/service-discovery#cloud_dns) running version `1.25.9-gke.400` and later, and version `1.26.4-gke.500` and later. It is [pre-configured](https://cloud.google.com/kubernetes-engine/docs/resources/autopilot-standard-feature-comparison#feature-comparison) for those clusters. The following example *only* applies to Autopilot clusters running *earlier* versions. + +This example shows how to [use Cloud DNS as a Kubernetes DNS provider](https://cloud.google.com/kubernetes-engine/docs/how-to/cloud-dns). ```hcl module "cluster-1" { @@ -48,7 +64,7 @@ module "cluster-1" { vpc_config = { network = var.vpc.self_link subnetwork = var.subnet.self_link - secondary_range_names = { pods = "pods", services = "services" } + secondary_range_names = {} # use default names "pods" and "services" } enable_features = { dns = { @@ -63,11 +79,11 @@ module "cluster-1" { ### Logging configuration -This example shows how to [collect logs for the Kubernetes control plane components](https://cloud.google.com/stackdriver/docs/solutions/gke/installing). The logs for these components are not collected by default. - -> **Note** +> [!NOTE] > System and workload logs collection is pre-configured for Autopilot clusters and cannot be disabled. +This example shows how to [collect logs for the Kubernetes control plane components](https://cloud.google.com/stackdriver/docs/solutions/gke/installing). The logs for these components are not collected by default. + ```hcl module "cluster-1" { source = "./fabric/modules/gke-cluster-autopilot" @@ -75,8 +91,9 @@ module "cluster-1" { name = "cluster-1" location = "europe-west1" vpc_config = { - network = var.vpc.self_link - subnetwork = var.subnet.self_link + network = var.vpc.self_link + subnetwork = var.subnet.self_link + secondary_range_names = {} # use default names "pods" and "services" } logging_config = { enable_api_server_logs = true @@ -89,36 +106,13 @@ module "cluster-1" { ### Monitoring configuration -This example shows how to [configure collection of Kubernetes control plane metrics](https://cloud.google.com/stackdriver/docs/solutions/gke/managing-metrics#enable-control-plane-metrics). The metrics for these components are not collected by default. +> [!NOTE] +> [System metrics](https://cloud.google.com/stackdriver/docs/solutions/gke/managing-metrics#enable-system-metrics) collection is pre-configured for Autopilot clusters and cannot be disabled. -> **Note** -> System metrics collection is pre-configured for Autopilot clusters and cannot be disabled. - -> **Warning** +> [!WARNING] > GKE **workload metrics** is deprecated and removed in GKE 1.24 and later. Workload metrics is replaced by [Google Cloud Managed Service for Prometheus](https://cloud.google.com/stackdriver/docs/managed-prometheus), which is Google's recommended way to monitor Kubernetes applications by using Cloud Monitoring. -```hcl -module "cluster-1" { - source = "./fabric/modules/gke-cluster-autopilot" - project_id = var.project_id - name = "cluster-1" - location = "europe-west1" - vpc_config = { - network = var.vpc.self_link - subnetwork = var.subnet.self_link - } - monitoring_config = { - enable_api_server_metrics = true - enable_controller_manager_metrics = true - enable_scheduler_metrics = true - } -} -# tftest modules=1 resources=1 inventory=monitoring-config-control-plane.yaml -``` - -### Backup for GKE - -This example shows how to [enable the Backup for GKE agent and configure a Backup Plan](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/concepts/backup-for-gke) for GKE Standard clusters. +This example shows how to [configure collection of Kubernetes control plane metrics](https://cloud.google.com/stackdriver/docs/solutions/gke/managing-metrics#enable-control-plane-metrics). These metrics are optional and are not collected by default. ```hcl module "cluster-1" { @@ -129,7 +123,71 @@ module "cluster-1" { vpc_config = { network = var.vpc.self_link subnetwork = var.subnet.self_link - secondary_range_names = { pods = "pods", services = "services" } + secondary_range_names = {} # use default names "pods" and "services" + } + monitoring_config = { + enable_api_server_metrics = true + enable_controller_manager_metrics = true + enable_scheduler_metrics = true + } +} +# tftest modules=1 resources=1 inventory=monitoring-config-control-plane.yaml +``` + +The next example shows how to [configure collection of kube state metrics](https://cloud.google.com/stackdriver/docs/solutions/gke/managing-metrics#enable-ksm). These metrics are optional and are not collected by default. + +```hcl +module "cluster-1" { + source = "./fabric/modules/gke-cluster-autopilot" + project_id = var.project_id + name = "cluster-1" + location = "europe-west1" + vpc_config = { + network = var.vpc.self_link + subnetwork = var.subnet.self_link + secondary_range_names = {} # use default names "pods" and "services" + } + monitoring_config = { + enable_daemonset_metrics = true + enable_deployment_metrics = true + enable_hpa_metrics = true + enable_pod_metrics = true + enable_statefulset_metrics = true + enable_storage_metrics = true + # Kube state metrics collection requires Google Cloud Managed Service for Prometheus, + # which is enabled by default. + # enable_managed_prometheus = true + } +} +# tftest modules=1 resources=1 inventory=monitoring-config-kube-state.yaml +``` + +The *control plane metrics* and *kube state metrics* collection can be configured in a single `monitoring_config` block. + +### Backup for GKE + +> [!NOTE] +> Although Backup for GKE can be enabled as an add-on when configuring your GKE clusters, it is a separate service from GKE. + +[Backup for GKE](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/concepts/backup-for-gke) is a service for backing up and restoring workloads in GKE clusters. It has two components: + +* A [Google Cloud API](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/reference/rest) that serves as the control plane for the service. +* A GKE add-on (the [Backup for GKE agent](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/concepts/backup-for-gke#agent_overview)) that must be enabled in each cluster for which you wish to perform backup and restore operations. + +Backup for GKE is supported in GKE Autopilot clusters with [some restrictions](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/concepts/about-autopilot). + +This example shows how to [enable Backup for GKE on a new Autopilot cluster](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/how-to/install#enable_on_a_new_cluster_optional) and [plan a set of backups](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/how-to/backup-plan). + +```hcl +module "cluster-1" { + source = "./fabric/modules/gke-cluster-autopilot" + project_id = var.project_id + name = "cluster-1" + location = "europe-west1" + vpc_config = { + network = var.vpc.self_link + subnetwork = var.subnet.self_link + secondary_range_names = {} } backup_configs = { enable_backup_agent = true @@ -148,10 +206,10 @@ module "cluster-1" { | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [location](variables.tf#L110) | Autopilot cluster are always regional. | string | ✓ | | -| [name](variables.tf#L170) | Cluster name. | string | ✓ | | -| [project_id](variables.tf#L196) | Cluster project id. | string | ✓ | | -| [vpc_config](variables.tf#L224) | VPC-level configuration. | object({…}) | ✓ | | +| [location](variables.tf#L110) | Autopilot clusters are always regional. | string | ✓ | | +| [name](variables.tf#L187) | Cluster name. | string | ✓ | | +| [project_id](variables.tf#L213) | Cluster project ID. | string | ✓ | | +| [vpc_config](variables.tf#L242) | VPC-level configuration. | object({…}) | ✓ | | | [backup_configs](variables.tf#L17) | Configuration for Backup for GKE. | object({…}) | | {} | | [description](variables.tf#L37) | Cluster description. | string | | null | | [enable_addons](variables.tf#L43) | Addons enabled in the cluster (true means enabled). | object({…}) | | {…} | @@ -161,12 +219,12 @@ module "cluster-1" { | [logging_config](variables.tf#L115) | Logging configuration. | object({…}) | | {} | | [maintenance_config](variables.tf#L126) | Maintenance window configuration. | object({…}) | | {…} | | [min_master_version](variables.tf#L149) | Minimum version of the master, defaults to the version of the most recent official release. | string | | null | -| [monitoring_config](variables.tf#L155) | Monitoring configuration. System metrics collection cannot be disabled for Autopilot clusters. Control plane metrics are optional. Google Cloud Managed Service for Prometheus is enabled by default. | object({…}) | | {} | -| [node_locations](variables.tf#L175) | Zones in which the cluster's nodes are located. | list(string) | | [] | -| [private_cluster_config](variables.tf#L182) | Private cluster configuration. | object({…}) | | null | -| [release_channel](variables.tf#L201) | Release channel for GKE upgrades. Clusters created in the Autopilot mode must use a release channel. Choose between \"RAPID\", \"REGULAR\", and \"STABLE\". | string | | "REGULAR" | -| [service_account](variables.tf#L212) | The Google Cloud Platform Service Account to be used by the node VMs created by GKE Autopilot. | string | | null | -| [tags](variables.tf#L218) | Network tags applied to nodes. | list(string) | | null | +| [monitoring_config](variables.tf#L155) | Monitoring configuration. System metrics collection cannot be disabled. Control plane metrics are optional. Kube state metrics are optional. Google Cloud Managed Service for Prometheus is enabled by default. | object({…}) | | {} | +| [node_locations](variables.tf#L192) | Zones in which the cluster's nodes are located. | list(string) | | [] | +| [private_cluster_config](variables.tf#L199) | Private cluster configuration. | object({…}) | | null | +| [release_channel](variables.tf#L218) | Release channel for GKE upgrades. Clusters created in the Autopilot mode must use a release channel. Choose between \"RAPID\", \"REGULAR\", and \"STABLE\". | string | | "REGULAR" | +| [service_account](variables.tf#L229) | The Google Cloud Platform Service Account to be used by the node VMs created by GKE Autopilot. | string | | null | +| [tags](variables.tf#L235) | Network tags applied to nodes. | list(string) | | [] | ## Outputs @@ -175,7 +233,7 @@ module "cluster-1" { | [ca_certificate](outputs.tf#L17) | Public certificate of the cluster (base64-encoded). | ✓ | | [cluster](outputs.tf#L23) | Cluster resource. | ✓ | | [endpoint](outputs.tf#L29) | Cluster endpoint. | | -| [id](outputs.tf#L34) | Fully qualified cluster id. | | +| [id](outputs.tf#L34) | Fully qualified cluster ID. | | | [location](outputs.tf#L39) | Cluster location. | | | [master_version](outputs.tf#L44) | Master version. | | | [name](outputs.tf#L49) | Cluster name. | | diff --git a/modules/gke-cluster-autopilot/main.tf b/modules/gke-cluster-autopilot/main.tf index 330c4993..4ca8ee54 100644 --- a/modules/gke-cluster-autopilot/main.tf +++ b/modules/gke-cluster-autopilot/main.tf @@ -103,12 +103,19 @@ resource "google_container_cluster" "cluster" { } } + dynamic "gateway_api_config" { + for_each = var.enable_features.gateway_api ? [""] : [] + content { + channel = "CHANNEL_STANDARD" + } + } + dynamic "ip_allocation_policy" { for_each = var.vpc_config.secondary_range_blocks != null ? [""] : [] content { cluster_ipv4_cidr_block = var.vpc_config.secondary_range_blocks.pods services_ipv4_cidr_block = var.vpc_config.secondary_range_blocks.services - stack_type = try(var.vpc_config.stack_type, null) + stack_type = var.vpc_config.stack_type } } @@ -117,7 +124,7 @@ resource "google_container_cluster" "cluster" { content { cluster_secondary_range_name = var.vpc_config.secondary_range_names.pods services_secondary_range_name = var.vpc_config.secondary_range_names.services - stack_type = try(var.vpc_config.stack_type, null) + stack_type = var.vpc_config.stack_type } } @@ -131,13 +138,6 @@ resource "google_container_cluster" "cluster" { ])) } - dynamic "gateway_api_config" { - for_each = var.enable_features.gateway_api ? [""] : [] - content { - channel = "CHANNEL_STANDARD" - } - } - maintenance_policy { dynamic "daily_maintenance_window" { for_each = ( @@ -207,10 +207,17 @@ resource "google_container_cluster" "cluster" { enable_components = toset(compact([ # System metrics collection cannot be disabled for Autopilot clusters. "SYSTEM_COMPONENTS", - # Control plane metrics. + # Control plane metrics: var.monitoring_config.enable_api_server_metrics ? "APISERVER" : null, var.monitoring_config.enable_controller_manager_metrics ? "CONTROLLER_MANAGER" : null, var.monitoring_config.enable_scheduler_metrics ? "SCHEDULER" : null, + # Kube state metrics: + var.monitoring_config.enable_daemonset_metrics ? "DAEMONSET" : null, + var.monitoring_config.enable_deployment_metrics ? "DEPLOYMENT" : null, + var.monitoring_config.enable_hpa_metrics ? "HPA" : null, + var.monitoring_config.enable_pod_metrics ? "POD" : null, + var.monitoring_config.enable_statefulset_metrics ? "STATEFULSET" : null, + var.monitoring_config.enable_storage_metrics ? "STORAGE" : null, ])) managed_prometheus { enabled = var.monitoring_config.enable_managed_prometheus @@ -231,6 +238,15 @@ resource "google_container_cluster" "cluster" { } } + dynamic "node_pool_auto_config" { + for_each = length(var.tags) > 0 ? [""] : [] + content { + network_tags { + tags = toset(var.tags) + } + } + } + dynamic "private_cluster_config" { for_each = ( var.private_cluster_config != null ? [""] : [] diff --git a/modules/gke-cluster-autopilot/outputs.tf b/modules/gke-cluster-autopilot/outputs.tf index 029ab06a..7978e55b 100644 --- a/modules/gke-cluster-autopilot/outputs.tf +++ b/modules/gke-cluster-autopilot/outputs.tf @@ -32,7 +32,7 @@ output "endpoint" { } output "id" { - description = "Fully qualified cluster id." + description = "Fully qualified cluster ID." value = google_container_cluster.cluster.id } diff --git a/modules/gke-cluster-autopilot/variables.tf b/modules/gke-cluster-autopilot/variables.tf index 52896bbd..24f8cd2b 100644 --- a/modules/gke-cluster-autopilot/variables.tf +++ b/modules/gke-cluster-autopilot/variables.tf @@ -108,7 +108,7 @@ variable "labels" { } variable "location" { - description = "Autopilot cluster are always regional." + description = "Autopilot clusters are always regional." type = string } @@ -153,18 +153,35 @@ variable "min_master_version" { } variable "monitoring_config" { - description = "Monitoring configuration. System metrics collection cannot be disabled for Autopilot clusters. Control plane metrics are optional. Google Cloud Managed Service for Prometheus is enabled by default." + description = "Monitoring configuration. System metrics collection cannot be disabled. Control plane metrics are optional. Kube state metrics are optional. Google Cloud Managed Service for Prometheus is enabled by default." type = object({ # Control plane metrics enable_api_server_metrics = optional(bool, false) enable_controller_manager_metrics = optional(bool, false) enable_scheduler_metrics = optional(bool, false) - # Google Cloud Managed Service for Prometheus - # GKE Autopilot clusters running GKE version 1.25 or greater must have this on. + # Kube state metrics. Requires managed Prometheus. Requires provider version >= v4.82.0 + enable_daemonset_metrics = optional(bool, false) + enable_deployment_metrics = optional(bool, false) + enable_hpa_metrics = optional(bool, false) + enable_pod_metrics = optional(bool, false) + enable_statefulset_metrics = optional(bool, false) + enable_storage_metrics = optional(bool, false) + # Google Cloud Managed Service for Prometheus. Autopilot clusters version >= 1.25 must have this on. enable_managed_prometheus = optional(bool, true) }) default = {} nullable = false + validation { + condition = anytrue([ + var.monitoring_config.enable_daemonset_metrics, + var.monitoring_config.enable_deployment_metrics, + var.monitoring_config.enable_hpa_metrics, + var.monitoring_config.enable_pod_metrics, + var.monitoring_config.enable_statefulset_metrics, + var.monitoring_config.enable_storage_metrics, + ]) ? var.monitoring_config.enable_managed_prometheus : true + error_message = "Kube state metrics collection requires Google Cloud Managed Service for Prometheus to be enabled." + } } variable "name" { @@ -194,7 +211,7 @@ variable "private_cluster_config" { } variable "project_id" { - description = "Cluster project id." + description = "Cluster project ID." type = string } @@ -218,7 +235,8 @@ variable "service_account" { variable "tags" { description = "Network tags applied to nodes." type = list(string) - default = null + default = [] + nullable = false } variable "vpc_config" { @@ -232,9 +250,9 @@ variable "vpc_config" { services = string })) secondary_range_names = optional(object({ - pods = string - services = string - }), { pods = "pods", services = "services" }) + pods = optional(string, "pods") + services = optional(string, "services") + })) master_authorized_ranges = optional(map(string)) stack_type = optional(string) }) diff --git a/modules/gke-cluster-autopilot/versions.tf b/modules/gke-cluster-autopilot/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/gke-cluster-autopilot/versions.tf +++ b/modules/gke-cluster-autopilot/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/gke-cluster-standard/README.md b/modules/gke-cluster-standard/README.md index e80a4e6d..3c9b1eb8 100644 --- a/modules/gke-cluster-standard/README.md +++ b/modules/gke-cluster-standard/README.md @@ -1,10 +1,29 @@ -# GKE cluster Standard module +# GKE Standard cluster module -This module allows simplified creation and management of GKE Standard clusters and should be used together with the GKE nodepool module, as the default nodepool is turned off here and cannot be re-enabled. Some sensible defaults are set initially, in order to allow less verbose usage for most use cases. +This module offers a way to create and manage Google Kubernetes Engine (GKE) [Standard clusters](https://cloud.google.com/kubernetes-engine/docs/concepts/choose-cluster-mode#why-standard). With its sensible default settings based on best practices and authors' experience as Google Cloud practitioners, the module accommodates for many common use cases out-of-the-box, without having to rely on verbose configuration. + +> [!IMPORTANT] +> This module should be used together with the [`gke-nodepool`](../gke-nodepool/) module because the default node pool is deleted upon cluster creation and cannot be re-created. + + +- [Example](#example) + - [GKE Standard cluster](#gke-standard-cluster) + - [Enable Dataplane V2](#enable-dataplane-v2) + - [Managing GKE logs](#managing-gke-logs) + - [Monitoring configuration](#monitoring-configuration) + - [Disable GKE logs or metrics collection](#disable-gke-logs-or-metrics-collection) + - [Cloud DNS](#cloud-dns) + - [Backup for GKE](#backup-for-gke) + - [Automatic creation of new secondary ranges](#automatic-creation-of-new-secondary-ranges) +- [Variables](#variables) +- [Outputs](#outputs) + ## Example -### GKE Cluster +### GKE Standard cluster + +This example shows how to [create a zonal GKE cluster in Standard mode](https://cloud.google.com/kubernetes-engine/docs/how-to/creating-a-zonal-cluster). ```hcl module "cluster-1" { @@ -36,7 +55,9 @@ module "cluster-1" { # tftest modules=1 resources=1 inventory=basic.yaml ``` -### GKE Cluster with Dataplane V2 enabled +### Enable Dataplane V2 + +This example shows how to [create a zonal GKE Cluster with Dataplane V2 enabled](https://cloud.google.com/kubernetes-engine/docs/how-to/dataplane-v2). ```hcl module "cluster-1" { @@ -45,12 +66,9 @@ module "cluster-1" { name = "cluster-dataplane-v2" location = "europe-west1-b" vpc_config = { - network = var.vpc.self_link - subnetwork = var.subnet.self_link - secondary_range_names = { - pods = "pods" - services = "services" - } + network = var.vpc.self_link + subnetwork = var.subnet.self_link + secondary_range_names = {} # use default names "pods" and "services" master_authorized_ranges = { internal-vms = "10.0.0.0/8" } @@ -84,8 +102,9 @@ module "cluster-1" { name = "cluster-1" location = "europe-west1-b" vpc_config = { - network = var.vpc.self_link - subnetwork = var.subnet.self_link + network = var.vpc.self_link + subnetwork = var.subnet.self_link + secondary_range_names = {} } logging_config = { enable_workloads_logs = true @@ -97,14 +116,9 @@ module "cluster-1" { # tftest modules=1 resources=1 inventory=logging-config-enable-all.yaml ``` -### Disable GKE logs collection +### Monitoring configuration -This example shows how to fully disable logs collection on a GKE Standard cluster. This is not recommended. - -> **Warning** -> If you've disabled Cloud Logging or Cloud Monitoring, GKE customer support -> is offered on a best-effort basis and might require additional effort -> from your engineering team. +This example shows how to [configure collection of Kubernetes control plane metrics](https://cloud.google.com/stackdriver/docs/solutions/gke/managing-metrics#enable-control-plane-metrics). These metrics are optional and are not collected by default. ```hcl module "cluster-1" { @@ -113,8 +127,68 @@ module "cluster-1" { name = "cluster-1" location = "europe-west1-b" vpc_config = { - network = var.vpc.self_link - subnetwork = var.subnet.self_link + network = var.vpc.self_link + subnetwork = var.subnet.self_link + secondary_range_names = {} # use default names "pods" and "services" + } + monitoring_config = { + enable_api_server_metrics = true + enable_controller_manager_metrics = true + enable_scheduler_metrics = true + } +} +# tftest modules=1 resources=1 inventory=monitoring-config-control-plane.yaml +``` + +The next example shows how to [configure collection of kube state metrics](https://cloud.google.com/stackdriver/docs/solutions/gke/managing-metrics#enable-ksm). These metrics are optional and are not collected by default. + +```hcl +module "cluster-1" { + source = "./fabric/modules/gke-cluster-standard" + project_id = "myproject" + name = "cluster-1" + location = "europe-west1-b" + vpc_config = { + network = var.vpc.self_link + subnetwork = var.subnet.self_link + secondary_range_names = {} # use default names "pods" and "services" + } + monitoring_config = { + enable_daemonset_metrics = true + enable_deployment_metrics = true + enable_hpa_metrics = true + enable_pod_metrics = true + enable_statefulset_metrics = true + enable_storage_metrics = true + # Kube state metrics collection requires Google Cloud Managed Service for Prometheus, + # which is enabled by default. + # enable_managed_prometheus = true + } +} +# tftest modules=1 resources=1 inventory=monitoring-config-kube-state.yaml +``` + +The *control plane metrics* and *kube state metrics* collection can be configured in a single `monitoring_config` block. + +### Disable GKE logs or metrics collection + +> [!WARNING] +> If you've disabled Cloud Logging or Cloud Monitoring, GKE customer support +> is offered on a best-effort basis and might require additional effort +> from your engineering team. + +This example shows how to fully disable logs collection on a zonal GKE Standard cluster. This is not recommended. + +```hcl +module "cluster-1" { + source = "./fabric/modules/gke-cluster-standard" + project_id = "myproject" + name = "cluster-1" + location = "europe-west1-b" + vpc_config = { + network = var.vpc.self_link + subnetwork = var.subnet.self_link + secondary_range_names = {} } logging_config = { enable_system_logs = false @@ -123,6 +197,27 @@ module "cluster-1" { # tftest modules=1 resources=1 inventory=logging-config-disable-all.yaml ``` +The next example shows how to fully disable metrics collection on a zonal GKE Standard cluster. This is not recommended. + +```hcl +module "cluster-1" { + source = "./fabric/modules/gke-cluster-standard" + project_id = "myproject" + name = "cluster-1" + location = "europe-west1-b" + vpc_config = { + network = var.vpc.self_link + subnetwork = var.subnet.self_link + secondary_range_names = {} + } + monitoring_config = { + enable_system_metrics = false + enable_managed_prometheus = false + } +} +# tftest modules=1 resources=1 inventory=monitoring-config-disable-all.yaml +``` + ### Cloud DNS This example shows how to [use Cloud DNS as a Kubernetes DNS provider](https://cloud.google.com/kubernetes-engine/docs/how-to/cloud-dns) for GKE Standard clusters. @@ -136,7 +231,7 @@ module "cluster-1" { vpc_config = { network = var.vpc.self_link subnetwork = var.subnet.self_link - secondary_range_names = { pods = "pods", services = "services" } + secondary_range_names = {} } enable_features = { dns = { @@ -151,7 +246,15 @@ module "cluster-1" { ### Backup for GKE -This example shows how to [enable the Backup for GKE agent and configure a Backup Plan](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/concepts/backup-for-gke) for GKE Standard clusters. +> [!NOTE] +> Although Backup for GKE can be enabled as an add-on when configuring your GKE clusters, it is a separate service from GKE. + +[Backup for GKE](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/concepts/backup-for-gke) is a service for backing up and restoring workloads in GKE clusters. It has two components: + +* A [Google Cloud API](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/reference/rest) that serves as the control plane for the service. +* A GKE add-on (the [Backup for GKE agent](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/concepts/backup-for-gke#agent_overview)) that must be enabled in each cluster for which you wish to perform backup and restore operations. + +This example shows how to [enable Backup for GKE on a new zonal GKE Standard cluster](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/how-to/install#enable_on_a_new_cluster_optional) and [plan a set of backups](https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke/how-to/backup-plan). ```hcl module "cluster-1" { @@ -162,7 +265,7 @@ module "cluster-1" { vpc_config = { network = var.vpc.self_link subnetwork = var.subnet.self_link - secondary_range_names = { pods = "pods", services = "services" } + secondary_range_names = {} } backup_configs = { enable_backup_agent = true @@ -176,15 +279,37 @@ module "cluster-1" { } # tftest modules=1 resources=2 inventory=backup.yaml ``` + +### Automatic creation of new secondary ranges + +You can use `var.vpc_config.secondary_range_blocks` to let GKE create new secondary ranges for the cluster. The example below reserves an available /14 block for pods and a /20 for services. + +```hcl +module "cluster-1" { + source = "./fabric/modules/gke-cluster-standard" + project_id = var.project_id + name = "cluster-1" + location = "europe-west1-b" + vpc_config = { + network = var.vpc.self_link + subnetwork = var.subnet.self_link + secondary_range_blocks = { + pods = "" + services = "/20" # can be an empty string as well + } + } +} +# tftest modules=1 resources=1 +``` ## Variables | name | description | type | required | default | |---|---|:---:|:---:|:---:| | [location](variables.tf#L138) | Cluster zone or region. | string | ✓ | | -| [name](variables.tf#L210) | Cluster name. | string | ✓ | | -| [project_id](variables.tf#L236) | Cluster project id. | string | ✓ | | -| [vpc_config](variables.tf#L253) | VPC-level configuration. | object({…}) | ✓ | | +| [name](variables.tf#L249) | Cluster name. | string | ✓ | | +| [project_id](variables.tf#L275) | Cluster project id. | string | ✓ | | +| [vpc_config](variables.tf#L292) | VPC-level configuration. | object({…}) | ✓ | | | [backup_configs](variables.tf#L17) | Configuration for Backup for GKE. | object({…}) | | {} | | [cluster_autoscaling](variables.tf#L37) | Enable and configure limits for Node Auto-Provisioning with Cluster Autoscaler. | object({…}) | | null | | [description](variables.tf#L58) | Cluster description. | string | | null | @@ -196,11 +321,11 @@ module "cluster-1" { | [maintenance_config](variables.tf#L164) | Maintenance window configuration. | object({…}) | | {…} | | [max_pods_per_node](variables.tf#L187) | Maximum number of pods per node in this cluster. | number | | 110 | | [min_master_version](variables.tf#L193) | Minimum version of the master, defaults to the version of the most recent official release. | string | | null | -| [monitoring_config](variables.tf#L199) | Monitoring components. | object({…}) | | {…} | -| [node_locations](variables.tf#L215) | Zones in which the cluster's nodes are located. | list(string) | | [] | -| [private_cluster_config](variables.tf#L222) | Private cluster configuration. | object({…}) | | null | -| [release_channel](variables.tf#L241) | Release channel for GKE upgrades. | string | | null | -| [tags](variables.tf#L247) | Network tags applied to nodes. | list(string) | | null | +| [monitoring_config](variables.tf#L199) | Monitoring configuration. Google Cloud Managed Service for Prometheus is enabled by default. | object({…}) | | {} | +| [node_locations](variables.tf#L254) | Zones in which the cluster's nodes are located. | list(string) | | [] | +| [private_cluster_config](variables.tf#L261) | Private cluster configuration. | object({…}) | | null | +| [release_channel](variables.tf#L280) | Release channel for GKE upgrades. | string | | null | +| [tags](variables.tf#L286) | Network tags applied to nodes. | list(string) | | null | ## Outputs diff --git a/modules/gke-cluster-standard/main.tf b/modules/gke-cluster-standard/main.tf index 8f0df84f..d27f6ab3 100644 --- a/modules/gke-cluster-standard/main.tf +++ b/modules/gke-cluster-standard/main.tf @@ -40,8 +40,8 @@ resource "google_container_cluster" "cluster" { : "DATAPATH_PROVIDER_UNSPECIFIED" ) - # the default nodepool is deleted here, use the gke-nodepool module instead - # default nodepool configuration based on a shielded_nodes variable + # the default node pool is deleted here, use the gke-nodepool module instead. + # the default node pool configuration is based on a shielded_nodes variable. node_config { dynamic "shielded_instance_config" { for_each = var.enable_features.shielded_nodes ? [""] : [] @@ -164,12 +164,19 @@ resource "google_container_cluster" "cluster" { } } + dynamic "gateway_api_config" { + for_each = var.enable_features.gateway_api ? [""] : [] + content { + channel = "CHANNEL_STANDARD" + } + } + dynamic "ip_allocation_policy" { for_each = var.vpc_config.secondary_range_blocks != null ? [""] : [] content { cluster_ipv4_cidr_block = var.vpc_config.secondary_range_blocks.pods services_ipv4_cidr_block = var.vpc_config.secondary_range_blocks.services - stack_type = try(var.vpc_config.stack_type, null) + stack_type = var.vpc_config.stack_type } } dynamic "ip_allocation_policy" { @@ -177,7 +184,7 @@ resource "google_container_cluster" "cluster" { content { cluster_secondary_range_name = var.vpc_config.secondary_range_names.pods services_secondary_range_name = var.vpc_config.secondary_range_names.services - stack_type = try(var.vpc_config.stack_type, null) + stack_type = var.vpc_config.stack_type } } @@ -205,13 +212,6 @@ resource "google_container_cluster" "cluster" { } } - dynamic "gateway_api_config" { - for_each = var.enable_features.gateway_api ? [""] : [] - content { - channel = "CHANNEL_STANDARD" - } - } - maintenance_policy { dynamic "daily_maintenance_window" { for_each = ( @@ -277,22 +277,28 @@ resource "google_container_cluster" "cluster" { } } - dynamic "monitoring_config" { - for_each = var.monitoring_config != null ? [""] : [] - content { - enable_components = var.monitoring_config.enable_components - dynamic "managed_prometheus" { - for_each = ( - try(var.monitoring_config.managed_prometheus, null) == true ? [""] : [] - ) - content { - enabled = true - } - } + monitoring_config { + enable_components = toset(compact([ + # System metrics is the minimum requirement if any other metrics are enabled. This is checked by input var validation. + var.monitoring_config.enable_system_metrics ? "SYSTEM_COMPONENTS" : null, + # Control plane metrics + var.monitoring_config.enable_api_server_metrics ? "APISERVER" : null, + var.monitoring_config.enable_controller_manager_metrics ? "CONTROLLER_MANAGER" : null, + var.monitoring_config.enable_scheduler_metrics ? "SCHEDULER" : null, + # Kube state metrics + var.monitoring_config.enable_daemonset_metrics ? "DAEMONSET" : null, + var.monitoring_config.enable_deployment_metrics ? "DEPLOYMENT" : null, + var.monitoring_config.enable_hpa_metrics ? "HPA" : null, + var.monitoring_config.enable_pod_metrics ? "POD" : null, + var.monitoring_config.enable_statefulset_metrics ? "STATEFULSET" : null, + var.monitoring_config.enable_storage_metrics ? "STORAGE" : null, + ])) + managed_prometheus { + enabled = var.monitoring_config.enable_managed_prometheus } } - # dataplane v2 has built-in network policies + # Dataplane V2 has built-in network policies dynamic "network_policy" { for_each = ( var.enable_addons.network_policy && !var.enable_features.dataplane_v2 diff --git a/modules/gke-cluster-standard/variables.tf b/modules/gke-cluster-standard/variables.tf index b9c4a113..6b76efa7 100644 --- a/modules/gke-cluster-standard/variables.tf +++ b/modules/gke-cluster-standard/variables.tf @@ -197,13 +197,52 @@ variable "min_master_version" { } variable "monitoring_config" { - description = "Monitoring components." + description = "Monitoring configuration. Google Cloud Managed Service for Prometheus is enabled by default." type = object({ - enable_components = optional(list(string)) - managed_prometheus = optional(bool) + enable_system_metrics = optional(bool, true) + + # Control plane metrics + enable_api_server_metrics = optional(bool, false) + enable_controller_manager_metrics = optional(bool, false) + enable_scheduler_metrics = optional(bool, false) + + # Kube state metrics + enable_daemonset_metrics = optional(bool, false) + enable_deployment_metrics = optional(bool, false) + enable_hpa_metrics = optional(bool, false) + enable_pod_metrics = optional(bool, false) + enable_statefulset_metrics = optional(bool, false) + enable_storage_metrics = optional(bool, false) + + # Google Cloud Managed Service for Prometheus + enable_managed_prometheus = optional(bool, true) }) - default = { - enable_components = ["SYSTEM_COMPONENTS"] + default = {} + nullable = false + validation { + condition = anytrue([ + var.monitoring_config.enable_api_server_metrics, + var.monitoring_config.enable_controller_manager_metrics, + var.monitoring_config.enable_scheduler_metrics, + var.monitoring_config.enable_daemonset_metrics, + var.monitoring_config.enable_deployment_metrics, + var.monitoring_config.enable_hpa_metrics, + var.monitoring_config.enable_pod_metrics, + var.monitoring_config.enable_statefulset_metrics, + var.monitoring_config.enable_storage_metrics, + ]) ? var.monitoring_config.enable_system_metrics : true + error_message = "System metrics are the minimum required component for enabling metrics collection." + } + validation { + condition = anytrue([ + var.monitoring_config.enable_daemonset_metrics, + var.monitoring_config.enable_deployment_metrics, + var.monitoring_config.enable_hpa_metrics, + var.monitoring_config.enable_pod_metrics, + var.monitoring_config.enable_statefulset_metrics, + var.monitoring_config.enable_storage_metrics, + ]) ? var.monitoring_config.enable_managed_prometheus : true + error_message = "Kube state metrics collection requires Google Cloud Managed Service for Prometheus to be enabled." } } @@ -261,9 +300,9 @@ variable "vpc_config" { services = string })) secondary_range_names = optional(object({ - pods = string - services = string - }), { pods = "pods", services = "services" }) + pods = optional(string, "pods") + services = optional(string, "services") + })) master_authorized_ranges = optional(map(string)) stack_type = optional(string) }) diff --git a/modules/gke-cluster-standard/versions.tf b/modules/gke-cluster-standard/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/gke-cluster-standard/versions.tf +++ b/modules/gke-cluster-standard/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/gke-hub/versions.tf b/modules/gke-hub/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/gke-hub/versions.tf +++ b/modules/gke-hub/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/gke-nodepool/versions.tf b/modules/gke-nodepool/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/gke-nodepool/versions.tf +++ b/modules/gke-nodepool/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/iam-service-account/README.md b/modules/iam-service-account/README.md index 9fd6cba0..ea3362c7 100644 --- a/modules/iam-service-account/README.md +++ b/modules/iam-service-account/README.md @@ -45,23 +45,23 @@ module "myproject-default-service-accounts" { | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [name](variables.tf#L113) | Name of the service account to create. | string | ✓ | | -| [project_id](variables.tf#L128) | Project id where service account will be created. | string | ✓ | | +| [name](variables.tf#L114) | Name of the service account to create. | string | ✓ | | +| [project_id](variables.tf#L129) | Project id where service account will be created. | string | ✓ | | | [description](variables.tf#L17) | Optional description. | string | | null | | [display_name](variables.tf#L23) | Display name of the service account to create. | string | | "Terraform-managed." | | [generate_key](variables.tf#L29) | Generate a key for service account. | bool | | false | | [iam](variables.tf#L35) | IAM bindings on the service account in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | | [iam_billing_roles](variables.tf#L42) | Billing account roles granted to this service account, by billing account id. Non-authoritative. | map(list(string)) | | {} | -| [iam_bindings](variables.tf#L49) | Authoritative IAM bindings on the service account in {ROLE => {members = [], condition = {}}}. | map(object({…})) | | {} | -| [iam_bindings_additive](variables.tf#L63) | Individual additive IAM bindings on the service account. Keys are arbitrary. | map(object({…})) | | {} | -| [iam_folder_roles](variables.tf#L78) | Folder roles granted to this service account, by folder id. Non-authoritative. | map(list(string)) | | {} | -| [iam_organization_roles](variables.tf#L85) | Organization roles granted to this service account, by organization id. Non-authoritative. | map(list(string)) | | {} | -| [iam_project_roles](variables.tf#L92) | Project roles granted to this service account, by project id. | map(list(string)) | | {} | -| [iam_sa_roles](variables.tf#L99) | Service account roles granted to this service account, by service account name. | map(list(string)) | | {} | -| [iam_storage_roles](variables.tf#L106) | Storage roles granted to this service account, by bucket name. | map(list(string)) | | {} | -| [prefix](variables.tf#L118) | Prefix applied to service account names. | string | | null | -| [public_keys_directory](variables.tf#L133) | Path to public keys data files to upload to the service account (should have `.pem` extension). | string | | "" | -| [service_account_create](variables.tf#L139) | Create service account. When set to false, uses a data source to reference an existing service account. | bool | | true | +| [iam_bindings](variables.tf#L49) | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | map(object({…})) | | {} | +| [iam_bindings_additive](variables.tf#L64) | Individual additive IAM bindings on the service account. Keys are arbitrary. | map(object({…})) | | {} | +| [iam_folder_roles](variables.tf#L79) | Folder roles granted to this service account, by folder id. Non-authoritative. | map(list(string)) | | {} | +| [iam_organization_roles](variables.tf#L86) | Organization roles granted to this service account, by organization id. Non-authoritative. | map(list(string)) | | {} | +| [iam_project_roles](variables.tf#L93) | Project roles granted to this service account, by project id. | map(list(string)) | | {} | +| [iam_sa_roles](variables.tf#L100) | Service account roles granted to this service account, by service account name. | map(list(string)) | | {} | +| [iam_storage_roles](variables.tf#L107) | Storage roles granted to this service account, by bucket name. | map(list(string)) | | {} | +| [prefix](variables.tf#L119) | Prefix applied to service account names. | string | | null | +| [public_keys_directory](variables.tf#L134) | Path to public keys data files to upload to the service account (should have `.pem` extension). | string | | "" | +| [service_account_create](variables.tf#L140) | Create service account. When set to false, uses a data source to reference an existing service account. | bool | | true | ## Outputs diff --git a/modules/iam-service-account/iam.tf b/modules/iam-service-account/iam.tf index a9423fb0..15ae1acc 100644 --- a/modules/iam-service-account/iam.tf +++ b/modules/iam-service-account/iam.tf @@ -71,7 +71,7 @@ resource "google_service_account_iam_binding" "authoritative" { resource "google_service_account_iam_binding" "bindings" { for_each = var.iam_bindings service_account_id = local.service_account.name - role = each.key + role = each.value.role members = each.value.members dynamic "condition" { for_each = each.value.condition == null ? [] : [""] diff --git a/modules/iam-service-account/variables.tf b/modules/iam-service-account/variables.tf index c9ca7069..4a75af46 100644 --- a/modules/iam-service-account/variables.tf +++ b/modules/iam-service-account/variables.tf @@ -47,9 +47,10 @@ variable "iam_billing_roles" { } variable "iam_bindings" { - description = "Authoritative IAM bindings on the service account in {ROLE => {members = [], condition = {}}}." + description = "Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary." type = map(object({ members = list(string) + role = string condition = optional(object({ expression = string title = string diff --git a/modules/iam-service-account/versions.tf b/modules/iam-service-account/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/iam-service-account/versions.tf +++ b/modules/iam-service-account/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/kms/README.md b/modules/kms/README.md index 56acff46..ddbf4b5c 100644 --- a/modules/kms/README.md +++ b/modules/kms/README.md @@ -31,7 +31,7 @@ module "kms" { } keyring = { location = "europe-west1", name = "test" } keyring_create = false - keys = { key-a = null, key-b = null, key-c = null } + keys = { key-a = {}, key-b = {}, key-c = {} } } # tftest skip (uses data sources) ``` @@ -42,26 +42,34 @@ module "kms" { module "kms" { source = "./fabric/modules/kms" project_id = "my-project" - key_iam = { - key-a = { - "roles/cloudkms.admin" = ["user:user3@example.com"] - } + keyring = { + location = "europe-west1" + name = "test" } - key_iam_bindings_additive = { - key-b-am1 = { - key = "key-b" - member = "user:am1@example.com" - role = "roles/cloudkms.cryptoKeyEncrypterDecrypter" - } - } - keyring = { location = "europe-west1", name = "test" } keys = { - key-a = null - key-b = { rotation_period = "604800s", labels = null } - key-c = { rotation_period = null, labels = { env = "test" } } + key-a = { + iam = { + "roles/cloudkms.admin" = ["user:user3@example.com"] + } + } + key-b = { + rotation_period = "604800s" + iam_bindings_additive = { + key-b-iam1 = { + key = "key-b" + member = "user:am1@example.com" + role = "roles/cloudkms.cryptoKeyEncrypterDecrypter" + } + } + } + key-c = { + labels = { + env = "test" + } + } } } -# tftest modules=1 resources=6 +# tftest modules=1 resources=6 inventory=basic.yaml ``` ### Crypto key purpose @@ -70,38 +78,35 @@ module "kms" { module "kms" { source = "./fabric/modules/kms" project_id = "my-project" - key_purpose = { - key-c = { + keyring = { + location = "europe-west1" + name = "test" + } + keys = { + key-a = { purpose = "ASYMMETRIC_SIGN" version_template = { algorithm = "EC_SIGN_P384_SHA384" - protection_level = null + protection_level = "HSM" } } } - keyring = { location = "europe-west1", name = "test" } - keys = { key-a = null, key-b = null, key-c = null } } -# tftest modules=1 resources=4 +# tftest modules=1 resources=2 inventory=purpose.yaml ``` ## Variables | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [keyring](variables.tf#L117) | Keyring attributes. | object({…}) | ✓ | | -| [project_id](variables.tf#L140) | Project id where the keyring will be created. | string | ✓ | | +| [keyring](variables.tf#L54) | Keyring attributes. | object({…}) | ✓ | | +| [project_id](variables.tf#L103) | Project id where the keyring will be created. | string | ✓ | | | [iam](variables.tf#L17) | Keyring IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | -| [iam_bindings](variables.tf#L23) | Keyring authoritative IAM bindings in {ROLE => {members = [], condition = {}}}. | map(object({…})) | | {} | -| [iam_bindings_additive](variables.tf#L37) | Keyring individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | -| [key_iam](variables.tf#L52) | Key IAM bindings in {KEY => {ROLE => [MEMBERS]}} format. | map(map(list(string))) | | {} | -| [key_iam_bindings](variables.tf#L58) | Key authoritative IAM bindings in {KEY => {ROLE => {members = [], condition = {}}}}. | map(object({…})) | | {} | -| [key_iam_bindings_additive](variables.tf#L72) | Key individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | -| [key_purpose](variables.tf#L88) | Per-key purpose, if not set defaults will be used. If purpose is not `ENCRYPT_DECRYPT` (the default), `version_template.algorithm` is required. | map(object({…})) | | {} | -| [key_purpose_defaults](variables.tf#L100) | Defaults used for key purpose when not defined at the key level. If purpose is not `ENCRYPT_DECRYPT` (the default), `version_template.algorithm` is required. | object({…}) | | {…} | -| [keyring_create](variables.tf#L125) | Set to false to manage keys and IAM bindings in an existing keyring. | bool | | true | -| [keys](variables.tf#L131) | Key names and base attributes. Set attributes to null if not needed. | map(object({…})) | | {} | -| [tag_bindings](variables.tf#L145) | Tag bindings for this keyring, in key => tag value id format. | map(string) | | null | +| [iam_bindings](variables.tf#L24) | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | map(object({…})) | | {} | +| [iam_bindings_additive](variables.tf#L39) | Keyring individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | +| [keyring_create](variables.tf#L62) | Set to false to manage keys and IAM bindings in an existing keyring. | bool | | true | +| [keys](variables.tf#L68) | Key names and base attributes. Set attributes to null if not needed. | map(object({…})) | | {} | +| [tag_bindings](variables.tf#L108) | Tag bindings for this keyring, in key => tag value id format. | map(string) | | {} | ## Outputs diff --git a/modules/kms/iam.tf b/modules/kms/iam.tf index 9a78c2cf..8ac17a56 100644 --- a/modules/kms/iam.tf +++ b/modules/kms/iam.tf @@ -16,24 +16,36 @@ locals { key_iam = flatten([ - for key, roles in var.key_iam : [ - for role, members in roles : { - key = key + for k, v in var.keys : [ + for role, members in v.iam : { + key = k role = role members = members } ] ]) - key_iam_bindings = flatten([ - for key, roles in var.key_iam_bindings : [ - for role, data in roles : { - key = key - role = role + key_iam_bindings = merge([ + for k, v in var.keys : { + for binding_key, data in v.iam_bindings : + binding_key => { + key = k + role = data.role members = data.members condition = data.condition } - ] - ]) + } + ]...) + key_iam_bindings_additive = merge([ + for k, v in var.keys : { + for binding_key, data in v.iam_bindings_additive : + binding_key => { + key = k + role = data.role + member = data.member + condition = data.condition + } + } + ]...) } resource "google_kms_key_ring_iam_binding" "authoritative" { @@ -46,7 +58,7 @@ resource "google_kms_key_ring_iam_binding" "authoritative" { resource "google_kms_key_ring_iam_binding" "bindings" { for_each = var.iam_bindings key_ring_id = local.keyring.id - role = each.key + role = each.value.role members = each.value.members dynamic "condition" { for_each = each.value.condition == null ? [] : [""] @@ -84,10 +96,7 @@ resource "google_kms_crypto_key_iam_binding" "authoritative" { } resource "google_kms_crypto_key_iam_binding" "bindings" { - for_each = { - for binding in local.key_iam_bindings : - "${binding.key}.${binding.role}" => binding - } + for_each = local.key_iam_bindings role = each.value.role crypto_key_id = google_kms_crypto_key.default[each.value.key].id members = each.value.members @@ -102,7 +111,7 @@ resource "google_kms_crypto_key_iam_binding" "bindings" { } resource "google_kms_crypto_key_iam_member" "members" { - for_each = var.key_iam_bindings_additive + for_each = local.key_iam_bindings_additive crypto_key_id = google_kms_crypto_key.default[each.value.key].id role = each.value.role member = each.value.member diff --git a/modules/kms/main.tf b/modules/kms/main.tf index 26624f15..6be7c812 100644 --- a/modules/kms/main.tf +++ b/modules/kms/main.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -15,11 +15,6 @@ */ locals { - key_purpose = { - for key, attrs in var.keys : key => try( - var.key_purpose[key], var.key_purpose_defaults - ) - } keyring = ( var.keyring_create ? google_kms_key_ring.default.0 @@ -42,17 +37,19 @@ resource "google_kms_key_ring" "default" { } resource "google_kms_crypto_key" "default" { - for_each = var.keys - key_ring = local.keyring.id - name = each.key - rotation_period = try(each.value.rotation_period, null) - labels = try(each.value.labels, null) - purpose = try(local.key_purpose[each.key].purpose, null) + for_each = var.keys + key_ring = local.keyring.id + name = each.key + rotation_period = each.value.rotation_period + labels = each.value.labels + purpose = each.value.purpose + skip_initial_version_creation = each.value.skip_initial_version_creation + dynamic "version_template" { - for_each = local.key_purpose[each.key].version_template == null ? [] : [""] + for_each = each.value.version_template == null ? [] : [""] content { - algorithm = local.key_purpose[each.key].version_template.algorithm - protection_level = local.key_purpose[each.key].version_template.protection_level + algorithm = each.value.version_template.algorithm + protection_level = each.value.version_template.protection_level } } } diff --git a/modules/kms/tags.tf b/modules/kms/tags.tf index 894c28aa..c0955c62 100644 --- a/modules/kms/tags.tf +++ b/modules/kms/tags.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -15,7 +15,7 @@ */ resource "google_tags_tag_binding" "binding" { - for_each = coalesce(var.tag_bindings, {}) + for_each = var.tag_bindings parent = "//cloudresourcemanager.googleapis.com/${local.keyring.id}" tag_value = each.value } diff --git a/modules/kms/variables.tf b/modules/kms/variables.tf index 44c98036..30861764 100644 --- a/modules/kms/variables.tf +++ b/modules/kms/variables.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -18,12 +18,14 @@ variable "iam" { description = "Keyring IAM bindings in {ROLE => [MEMBERS]} format." type = map(list(string)) default = {} + nullable = false } variable "iam_bindings" { - description = "Keyring authoritative IAM bindings in {ROLE => {members = [], condition = {}}}." + description = "Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary." type = map(object({ members = list(string) + role = string condition = optional(object({ expression = string title = string @@ -49,71 +51,6 @@ variable "iam_bindings_additive" { default = {} } -variable "key_iam" { - description = "Key IAM bindings in {KEY => {ROLE => [MEMBERS]}} format." - type = map(map(list(string))) - default = {} -} - -variable "key_iam_bindings" { - description = "Key authoritative IAM bindings in {KEY => {ROLE => {members = [], condition = {}}}}." - type = map(object({ - members = list(string) - condition = optional(object({ - expression = string - title = string - description = optional(string) - })) - })) - nullable = false - default = {} -} - -variable "key_iam_bindings_additive" { - description = "Key individual additive IAM bindings. Keys are arbitrary." - type = map(object({ - key = string - member = string - role = string - condition = optional(object({ - expression = string - title = string - description = optional(string) - })) - })) - nullable = false - default = {} -} - -variable "key_purpose" { - description = "Per-key purpose, if not set defaults will be used. If purpose is not `ENCRYPT_DECRYPT` (the default), `version_template.algorithm` is required." - type = map(object({ - purpose = string - version_template = object({ - algorithm = string - protection_level = string - }) - })) - default = {} -} - -variable "key_purpose_defaults" { - description = "Defaults used for key purpose when not defined at the key level. If purpose is not `ENCRYPT_DECRYPT` (the default), `version_template.algorithm` is required." - type = object({ - purpose = string - version_template = object({ - algorithm = string - protection_level = string - }) - }) - default = { - purpose = null - version_template = null - } -} - -# cf https://cloud.google.com/kms/docs/locations - variable "keyring" { description = "Keyring attributes." type = object({ @@ -131,10 +68,36 @@ variable "keyring_create" { variable "keys" { description = "Key names and base attributes. Set attributes to null if not needed." type = map(object({ - rotation_period = string - labels = map(string) + rotation_period = optional(string) + labels = optional(map(string)) + purpose = optional(string, "ENCRYPT_DECRYPT") + skip_initial_version_creation = optional(bool, false) + version_template = optional(object({ + algorithm = string + protection_level = optional(string, "SOFTWARE") + })) + + iam = optional(map(list(string)), {}) + iam_bindings = optional(map(object({ + members = list(string) + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) + iam_bindings_additive = optional(map(object({ + member = string + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) })) - default = {} + default = {} + nullable = false } variable "project_id" { @@ -145,5 +108,6 @@ variable "project_id" { variable "tag_bindings" { description = "Tag bindings for this keyring, in key => tag value id format." type = map(string) - default = null + default = {} + nullable = false } diff --git a/modules/kms/versions.tf b/modules/kms/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/kms/versions.tf +++ b/modules/kms/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/logging-bucket/versions.tf b/modules/logging-bucket/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/logging-bucket/versions.tf +++ b/modules/logging-bucket/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/ncc-spoke-ra/versions.tf b/modules/ncc-spoke-ra/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/ncc-spoke-ra/versions.tf +++ b/modules/ncc-spoke-ra/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-address/versions.tf b/modules/net-address/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-address/versions.tf +++ b/modules/net-address/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-cloudnat/versions.tf b/modules/net-cloudnat/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-cloudnat/versions.tf +++ b/modules/net-cloudnat/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-firewall-policy/versions.tf b/modules/net-firewall-policy/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-firewall-policy/versions.tf +++ b/modules/net-firewall-policy/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-ipsec-over-interconnect/versions.tf b/modules/net-ipsec-over-interconnect/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-ipsec-over-interconnect/versions.tf +++ b/modules/net-ipsec-over-interconnect/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-lb-app-ext/versions.tf b/modules/net-lb-app-ext/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-lb-app-ext/versions.tf +++ b/modules/net-lb-app-ext/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-lb-app-int/versions.tf b/modules/net-lb-app-int/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-lb-app-int/versions.tf +++ b/modules/net-lb-app-int/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-lb-ext/versions.tf b/modules/net-lb-ext/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-lb-ext/versions.tf +++ b/modules/net-lb-ext/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-lb-int/versions.tf b/modules/net-lb-int/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-lb-int/versions.tf +++ b/modules/net-lb-int/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-lb-proxy-int/versions.tf b/modules/net-lb-proxy-int/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-lb-proxy-int/versions.tf +++ b/modules/net-lb-proxy-int/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-swp/versions.tf b/modules/net-swp/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-swp/versions.tf +++ b/modules/net-swp/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-vlan-attachment/README.md b/modules/net-vlan-attachment/README.md index b013fe08..a1711709 100644 --- a/modules/net-vlan-attachment/README.md +++ b/modules/net-vlan-attachment/README.md @@ -81,7 +81,7 @@ module "example-va" { name = google_compute_router.interconnect-router.name } } -# tftest modules=1 resources=3 +# tftest modules=1 resources=2 ``` ### Dedicated Interconnect - Two VLAN Attachments on a single region (99.9% SLA) @@ -201,7 +201,7 @@ module "example-va-b" { edge_availability_domain = "AVAILABILITY_DOMAIN_2" } } -# tftest modules=2 resources=5 +# tftest modules=2 resources=3 ``` ### Dedicated Interconnect - Four VLAN Attachments on two regions (99.99% SLA) @@ -431,10 +431,10 @@ module "example-va-b-ew12" { edge_availability_domain = "AVAILABILITY_DOMAIN_2" } } -# tftest modules=4 resources=10 +# tftest modules=4 resources=6 ``` -### IPSec over Interconnect enabled setup +### IPSec for Dedicated Interconnect Refer to the [HA VPN over Interconnect Blueprint](../../blueprints/networking/ha-vpn-over-interconnect/) for an all-encompassing example. @@ -494,6 +494,47 @@ module "example-va-b" { } # tftest modules=2 resources=9 ``` + +### IPSec for Partner Interconnect + +```hcl +module "example-va-a" { + source = "./fabric/modules/net-vlan-attachment" + project_id = "myproject" + network = "mynet" + region = "europe-west8" + name = "encrypted-vlan-attachment-a" + description = "example-va-a vlan attachment" + peer_asn = "65001" + router_config = { + create = true + } + partner_interconnect_config = { + edge_availability_domain = "AVAILABILITY_DOMAIN_1" + } + vpn_gateways_ip_range = "10.255.255.0/29" # Allows for up to 8 tunnels +} + +module "example-va-b" { + source = "./fabric/modules/net-vlan-attachment" + project_id = "myproject" + network = "mynet" + region = "europe-west8" + name = "encrypted-vlan-attachment-b" + description = "example-va-b vlan attachment" + peer_asn = "65001" + router_config = { + create = true + } + partner_interconnect_config = { + edge_availability_domain = "AVAILABILITY_DOMAIN_2" + } + vpn_gateways_ip_range = "10.255.255.8/29" # Allows for up to 8 tunnels +} +# tftest modules=2 resources=6 +``` + + ## Variables diff --git a/modules/net-vlan-attachment/main.tf b/modules/net-vlan-attachment/main.tf index 877ec4a7..5cf5c328 100644 --- a/modules/net-vlan-attachment/main.tf +++ b/modules/net-vlan-attachment/main.tf @@ -61,7 +61,15 @@ resource "google_compute_router" "encrypted" { region = var.region encrypted_interconnect_router = true bgp { - asn = var.router_config.asn + asn = var.router_config.asn + advertise_mode = var.dedicated_interconnect_config == null ? "DEFAULT" : "CUSTOM" + dynamic "advertised_ip_ranges" { + for_each = var.dedicated_interconnect_config == null ? var.ipsec_gateway_ip_ranges : {} + content { + description = advertised_ip_ranges.key + range = advertised_ip_ranges.value + } + } } } @@ -106,13 +114,14 @@ resource "google_compute_router_interface" "default" { } resource "google_compute_router_peer" "default" { + count = var.dedicated_interconnect_config != null ? 1 : 0 name = "${var.name}-peer" project = var.project_id router = local.router region = var.region peer_ip_address = split("/", google_compute_interconnect_attachment.default.customer_router_ip_address)[0] peer_asn = var.peer_asn - interface = "${var.name}-intf" + interface = google_compute_router_interface.default[0].name advertised_route_priority = 100 advertise_mode = "CUSTOM" diff --git a/modules/net-vlan-attachment/versions.tf b/modules/net-vlan-attachment/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-vlan-attachment/versions.tf +++ b/modules/net-vlan-attachment/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-vpc-firewall/versions.tf b/modules/net-vpc-firewall/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-vpc-firewall/versions.tf +++ b/modules/net-vpc-firewall/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-vpc-peering/versions.tf b/modules/net-vpc-peering/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-vpc-peering/versions.tf +++ b/modules/net-vpc-peering/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-vpc/README.md b/modules/net-vpc/README.md index 3aaaa2a7..ea86930e 100644 --- a/modules/net-vpc/README.md +++ b/modules/net-vpc/README.md @@ -112,38 +112,35 @@ module "vpc" { name = "subnet-1" region = "europe-west1" ip_cidr_range = "10.0.1.0/24" + iam = { + "roles/compute.networkUser" = [ + "user:user1@example.com", "group:group1@example.com" + ] + } + iam_bindings = { + subnet-1-iam = { + members = ["group:group2@example.com"] + role = "roles/compute.networkUser" + condition = { + expression = "resource.matchTag('123456789012/env', 'prod')" + title = "test_condition" + } + } + } }, { name = "subnet-2" region = "europe-west1" ip_cidr_range = "10.0.1.0/24" - } - ] - subnet_iam = { - "europe-west1/subnet-1" = { - "roles/compute.networkUser" = [ - "user:user1@example.com", "group:group1@example.com" - ] - } - } - subnet_iam_bindings = { - "europe-west1/subnet-1" = { - "roles/compute.networkUser" = { - members = ["group:group2@example.com"] - condition = { - expression = "resource.matchTag('123456789012/env', 'prod')" - title = "test_condition" + iam_bindings_additive = { + subnet-2-iam = { + member = "user:am1@example.com" + role = "roles/compute.networkUser" + subnet = "europe-west1/subnet-2" } } } - } - subnet_iam_bindings_additive = { - subnet-2-am1 = { - member = "user:am1@example.com" - role = "roles/compute.networkUser" - subnet = "europe-west1/subnet-2" - } - } + ] } # tftest modules=1 resources=8 inventory=subnet-iam.yaml ``` @@ -212,6 +209,15 @@ module "vpc-host" { pods = "172.16.0.0/20" services = "192.168.0.0/24" } + iam = { + "roles/compute.networkUser" = [ + local.service_project_1.cloud_services_service_account, + local.service_project_1.gke_service_account + ] + "roles/compute.securityAdmin" = [ + local.service_project_1.gke_service_account + ] + } } ] shared_vpc_host = true @@ -219,17 +225,6 @@ module "vpc-host" { local.service_project_1.project_id, local.service_project_2.project_id ] - subnet_iam = { - "europe-west1/subnet-1" = { - "roles/compute.networkUser" = [ - local.service_project_1.cloud_services_service_account, - local.service_project_1.gke_service_account - ] - "roles/compute.securityAdmin" = [ - local.service_project_1.gke_service_account - ] - } - } } # tftest modules=1 resources=9 inventory=shared-vpc.yaml ``` @@ -299,6 +294,13 @@ module "vpc" { name = "regional-proxy" region = "europe-west1" active = true + }, + { + ip_cidr_range = "10.0.4.0/24" + name = "global-proxy" + region = "australia-southeast2" + active = true + global = true } ] subnets_psc = [ @@ -309,7 +311,7 @@ module "vpc" { } ] } -# tftest modules=1 resources=5 inventory=proxy-only-subnets.yaml +# tftest modules=1 resources=6 inventory=proxy-only-subnets.yaml ``` ### DNS Policies @@ -343,12 +345,14 @@ The `net-vpc` module includes a subnet factory (see [Resource Factories](../../b ```hcl module "vpc" { - source = "./fabric/modules/net-vpc" - project_id = "my-project" - name = "my-network" - data_folder = "config/subnets" + source = "./fabric/modules/net-vpc" + project_id = "my-project" + name = "my-network" + factories_config = { + subnets_folder = "config/subnets" + } } -# tftest modules=1 resources=9 files=subnet-simple,subnet-simple-2,subnet-detailed,subnet-proxy,subnet-psc inventory=factory.yaml +# tftest modules=1 resources=10 files=subnet-simple,subnet-simple-2,subnet-detailed,subnet-proxy,subnet-proxy-global,subnet-psc inventory=factory.yaml ``` ```yaml @@ -372,31 +376,39 @@ description: Sample description ip_cidr_range: 10.0.0.0/24 # optional attributes enable_private_access: false # defaults to true -iam: # grant roles/compute.networkUser - - group:lorem@example.com - - serviceAccount:fbz@prj.iam.gserviceaccount.com - - user:foobar@example.com +iam: + roles/compute.networkUser: + - group:lorem@example.com + - serviceAccount:fbz@prj.iam.gserviceaccount.com + - user:foobar@example.com secondary_ip_ranges: # map of secondary ip ranges secondary-range-a: 192.168.0.0/24 -flow_logs: # enable, set to empty map to use defaults +flow_logs_config: # enable, set to empty map to use defaults aggregation_interval: "INTERVAL_5_SEC" flow_sampling: 0.5 metadata: "INCLUDE_ALL_METADATA" - filter_expression: null ``` ```yaml # tftest-file id=subnet-proxy path=config/subnets/subnet-proxy.yaml region: europe-west4 ip_cidr_range: 10.1.0.0/24 -purpose: REGIONAL_MANAGED_PROXY +proxy_only: true +``` + +```yaml +# tftest-file id=subnet-proxy-global path=config/subnets/subnet-proxy-global.yaml +region: australia-southeast2 +ip_cidr_range: 10.4.0.0/24 +proxy_only: true +global: true ``` ```yaml # tftest-file id=subnet-psc path=config/subnets/subnet-psc.yaml region: europe-west4 ip_cidr_range: 10.2.0.0/24 -purpose: PRIVATE_SERVICE_CONNECT +psc: true ``` ### Custom Routes @@ -525,30 +537,27 @@ module "vpc" { | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [name](variables.tf#L93) | The name of the network being created. | string | ✓ | | -| [project_id](variables.tf#L109) | The ID of the project where this VPC will be created. | string | ✓ | | +| [name](variables.tf#L95) | The name of the network being created. | string | ✓ | | +| [project_id](variables.tf#L111) | The ID of the project where this VPC will be created. | string | ✓ | | | [auto_create_subnetworks](variables.tf#L17) | Set to true to create an auto mode subnet, defaults to custom mode. | bool | | false | | [create_googleapis_routes](variables.tf#L23) | Toggle creation of googleapis private/restricted routes. Disabled when vpc creation is turned off, or when set to null. | object({…}) | | {} | -| [data_folder](variables.tf#L34) | An optional folder containing the subnet configurations in YaML format. | string | | null | -| [delete_default_routes_on_create](variables.tf#L40) | Set to true to delete the default routes at creation time. | bool | | false | -| [description](variables.tf#L46) | An optional description of this resource (triggers recreation on change). | string | | "Terraform-managed." | -| [dns_policy](variables.tf#L52) | DNS policy setup for the VPC. | object({…}) | | null | -| [firewall_policy_enforcement_order](variables.tf#L65) | Order that Firewall Rules and Firewall Policies are evaluated. Can be either 'BEFORE_CLASSIC_FIREWALL' or 'AFTER_CLASSIC_FIREWALL'. | string | | "AFTER_CLASSIC_FIREWALL" | -| [ipv6_config](variables.tf#L77) | Optional IPv6 configuration for this network. | object({…}) | | {} | -| [mtu](variables.tf#L87) | Maximum Transmission Unit in bytes. The minimum value for this field is 1460 (the default) and the maximum value is 1500 bytes. | number | | null | -| [peering_config](variables.tf#L98) | VPC peering configuration. | object({…}) | | null | -| [psa_config](variables.tf#L114) | The Private Service Access configuration for Service Networking. | object({…}) | | null | -| [routes](variables.tf#L124) | Network routes, keyed by name. | map(object({…})) | | {} | -| [routing_mode](variables.tf#L145) | The network routing mode (default 'GLOBAL'). | string | | "GLOBAL" | -| [shared_vpc_host](variables.tf#L155) | Enable shared VPC for this project. | bool | | false | -| [shared_vpc_service_projects](variables.tf#L161) | Shared VPC service projects to register with this host. | list(string) | | [] | -| [subnet_iam](variables.tf#L167) | Subnet IAM bindings in {REGION/NAME => {ROLE => [MEMBERS]} format. | map(map(list(string))) | | {} | -| [subnet_iam_bindings](variables.tf#L173) | Authoritative IAM bindings in {REGION/NAME => {ROLE => {members = [], condition = {}}}}. | map(map(object({…}))) | | {} | -| [subnet_iam_bindings_additive](variables.tf#L187) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | -| [subnets](variables.tf#L203) | Subnet configuration. | list(object({…})) | | [] | -| [subnets_proxy_only](variables.tf#L229) | List of proxy-only subnets for Regional HTTPS or Internal HTTPS load balancers. Note: Only one proxy-only subnet for each VPC network in each region can be active. | list(object({…})) | | [] | -| [subnets_psc](variables.tf#L241) | List of subnets for Private Service Connect service producers. | list(object({…})) | | [] | -| [vpc_create](variables.tf#L252) | Create VPC. When set to false, uses a data source to reference existing VPC. | bool | | true | +| [delete_default_routes_on_create](variables.tf#L34) | Set to true to delete the default routes at creation time. | bool | | false | +| [description](variables.tf#L40) | An optional description of this resource (triggers recreation on change). | string | | "Terraform-managed." | +| [dns_policy](variables.tf#L46) | DNS policy setup for the VPC. | object({…}) | | null | +| [factories_config](variables.tf#L59) | Paths to data files and folders that enable factory functionality. | object({…}) | | null | +| [firewall_policy_enforcement_order](variables.tf#L67) | Order that Firewall Rules and Firewall Policies are evaluated. Can be either 'BEFORE_CLASSIC_FIREWALL' or 'AFTER_CLASSIC_FIREWALL'. | string | | "AFTER_CLASSIC_FIREWALL" | +| [ipv6_config](variables.tf#L79) | Optional IPv6 configuration for this network. | object({…}) | | {} | +| [mtu](variables.tf#L89) | Maximum Transmission Unit in bytes. The minimum value for this field is 1460 (the default) and the maximum value is 1500 bytes. | number | | null | +| [peering_config](variables.tf#L100) | VPC peering configuration. | object({…}) | | null | +| [psa_config](variables.tf#L116) | The Private Service Access configuration for Service Networking. | object({…}) | | null | +| [routes](variables.tf#L126) | Network routes, keyed by name. | map(object({…})) | | {} | +| [routing_mode](variables.tf#L147) | The network routing mode (default 'GLOBAL'). | string | | "GLOBAL" | +| [shared_vpc_host](variables.tf#L157) | Enable shared VPC for this project. | bool | | false | +| [shared_vpc_service_projects](variables.tf#L163) | Shared VPC service projects to register with this host. | list(string) | | [] | +| [subnets](variables.tf#L169) | Subnet configuration. | list(object({…})) | | [] | +| [subnets_proxy_only](variables.tf#L216) | List of proxy-only subnets for Regional HTTPS or Internal HTTPS load balancers. Note: Only one proxy-only subnet for each VPC network in each region can be active. | list(object({…})) | | [] | +| [subnets_psc](variables.tf#L250) | List of subnets for Private Service Connect service producers. | list(object({…})) | | [] | +| [vpc_create](variables.tf#L282) | Create VPC. When set to false, uses a data source to reference existing VPC. | bool | | true | ## Outputs diff --git a/modules/net-vpc/outputs.tf b/modules/net-vpc/outputs.tf index fbf07dba..503923d9 100644 --- a/modules/net-vpc/outputs.tf +++ b/modules/net-vpc/outputs.tf @@ -136,4 +136,4 @@ output "subnets_proxy_only" { output "subnets_psc" { description = "Private Service Connect subnet resources." value = { for k, v in google_compute_subnetwork.psc : k => v } -} +} \ No newline at end of file diff --git a/modules/net-vpc/subnets.tf b/modules/net-vpc/subnets.tf index 0e656fd8..fe5abea9 100644 --- a/modules/net-vpc/subnets.tf +++ b/modules/net-vpc/subnets.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -18,66 +18,114 @@ locals { _factory_data = { - for f in try(fileset(var.data_folder, "**/*.yaml"), []) : - trimsuffix(basename(f), ".yaml") => yamldecode(file("${var.data_folder}/${f}")) + for f in try(fileset(var.factories_config.subnets_folder, "**/*.yaml"), []) : + trimsuffix(basename(f), ".yaml") => yamldecode(file("${var.factories_config.subnets_folder}/${f}")) } _factory_subnets = { - for k, v in local._factory_data : "${v.region}/${try(v.name, k)}" => { - name = try(v.name, k) - ip_cidr_range = v.ip_cidr_range - region = v.region + for k, v in local._factory_data : + "${v.region}/${try(v.name, k)}" => { + active = try(v.active, true) description = try(v.description, null) enable_private_access = try(v.enable_private_access, true) - flow_logs_config = try(v.flow_logs, null) - ipv6 = try(v.ipv6, null) - secondary_ip_ranges = try(v.secondary_ip_ranges, null) - iam = try(v.iam, []) - iam_members = try(v.iam_members, []) - purpose = try(v.purpose, null) - active = try(v.active, null) + flow_logs_config = can(v.flow_logs_config) ? { + aggregation_interval = try(v.flow_logs_config.aggregation_interval, null) + filter_expression = try(v.flow_logs_config.filter_expression, null) + flow_sampling = try(v.flow_logs_config.flow_sampling, null) + metadata = try(v.flow_logs_config.metadata, null) + metadata_fields = try(v.flow_logs_config.metadata_fields, null) + } : null + global = try(v.global, false) + ip_cidr_range = v.ip_cidr_range + ipv6 = !can(v.ipv6) ? null : { + access_type = try(v.ipv6.access_type, "INTERNAL") + } + name = try(v.name, k) + region = v.region + secondary_ip_ranges = try(v.secondary_ip_ranges, null) + iam = try(v.iam, {}) + iam_bindings = !can(v.iam_bindings) ? {} : { + for k2, v2 in v.iam_bindings : + k2 => { + role = v2.role + members = v2.members + condition = !can(v2.condition) ? null : { + expression = v2.condition.expression + title = v2.condition.title + description = try(v2.condition.description, null) + } + } + } + iam_bindings_additive = !can(v.iam_bindings_additive) ? {} : { + for k2, v2 in v.iam_bindings_additive : + k2 => { + member = v2.member + role = v2.role + condition = !can(v2.condition) ? null : { + expression = v2.condition.expression + title = v2.condition.title + description = try(v2.condition.description, null) + } + } + } + _is_regular = !try(v.psc == true, false) && !try(v.proxy_only == true, false) + _is_psc = try(v.psc == true, false) + _is_proxy_only = try(v.proxy_only == true, false) } } - _factory_subnets_iam = [ - for k, v in local._factory_subnets : { - subnet = k - role = "roles/compute.networkUser" - members = v.iam - } if v.purpose == null && v.iam != null - ] - _subnet_iam = flatten([ - for subnet, roles in(var.subnet_iam == null ? {} : var.subnet_iam) : [ - for role, members in roles : { - members = members - role = role - subnet = subnet - } - ] - ]) - subnet_iam = concat( - [for k in local._factory_subnets_iam : k if length(k.members) > 0], - local._subnet_iam + + all_subnets = merge( + { for k, v in google_compute_subnetwork.subnetwork : k => v }, + { for k, v in google_compute_subnetwork.proxy_only : k => v }, + { for k, v in google_compute_subnetwork.psc : k => v } ) - subnet_iam_bindings = flatten([ - for subnet, roles in(var.subnet_iam_bindings == null ? {} : var.subnet_iam_bindings) : [ - for role, data in roles : { - role = role - subnet = subnet + subnet_iam = flatten(concat( + [ + for s in concat(var.subnets, var.subnets_psc, var.subnets_proxy_only, values(local._factory_subnets)) : [ + for role, members in s.iam : + { + role = role + members = members + subnet = "${s.region}/${s.name}" + } + ] + ], + )) + subnet_iam_bindings = merge([ + for s in concat(var.subnets, var.subnets_psc, var.subnets_proxy_only, values(local._factory_subnets)) : { + for key, data in s.iam_bindings : + key => { + role = data.role + subnet = "${s.region}/${s.name}" members = data.members condition = data.condition } - ] - ]) + } + ]...) + # note: all additive bindings share a single namespace for the key. + # In other words, if you have multiple additive bindings with the + # same name, only one will be used + subnet_iam_bindings_additive = merge([ + for s in concat(var.subnets, var.subnets_psc, var.subnets_proxy_only, values(local._factory_subnets)) : { + for key, data in s.iam_bindings_additive : + key => { + role = data.role + subnet = "${s.region}/${s.name}" + member = data.member + condition = data.condition + } + } + ]...) subnets = merge( { for s in var.subnets : "${s.region}/${s.name}" => s }, - { for k, v in local._factory_subnets : k => v if v.purpose == null } + { for k, v in local._factory_subnets : k => v if v._is_regular } ) subnets_proxy_only = merge( { for s in var.subnets_proxy_only : "${s.region}/${s.name}" => s }, - { for k, v in local._factory_subnets : k => v if v.purpose == "REGIONAL_MANAGED_PROXY" } + { for k, v in local._factory_subnets : k => v if v._is_proxy_only }, ) subnets_psc = merge( { for s in var.subnets_psc : "${s.region}/${s.name}" => s }, - { for k, v in local._factory_subnets : k => v if v.purpose == "PRIVATE_SERVICE_CONNECT" } + { for k, v in local._factory_subnets : k => v if v._is_psc } ) } @@ -128,13 +176,12 @@ resource "google_compute_subnetwork" "proxy_only" { name = each.value.name region = each.value.region ip_cidr_range = each.value.ip_cidr_range - description = ( - each.value.description == null - ? "Terraform-managed proxy-only subnet for Regional HTTPS or Internal HTTPS LB." - : each.value.description + description = coalesce( + each.value.description, + "Terraform-managed proxy-only subnet for Regional HTTPS, Internal HTTPS or Cross-Regional HTTPS Internal LB." ) - purpose = "REGIONAL_MANAGED_PROXY" - role = each.value.active != false ? "ACTIVE" : "BACKUP" + purpose = each.value.global ? "GLOBAL_MANAGED_PROXY" : "REGIONAL_MANAGED_PROXY" + role = each.value.active ? "ACTIVE" : "BACKUP" } resource "google_compute_subnetwork" "psc" { @@ -144,34 +191,31 @@ resource "google_compute_subnetwork" "psc" { name = each.value.name region = each.value.region ip_cidr_range = each.value.ip_cidr_range - description = ( - each.value.description == null - ? "Terraform-managed subnet for Private Service Connect (PSC NAT)." - : each.value.description + description = coalesce( + each.value.description, + "Terraform-managed subnet for Private Service Connect (PSC NAT)." ) purpose = "PRIVATE_SERVICE_CONNECT" } + resource "google_compute_subnetwork_iam_binding" "authoritative" { for_each = { for binding in local.subnet_iam : "${binding.subnet}.${binding.role}" => binding } project = var.project_id - subnetwork = google_compute_subnetwork.subnetwork[each.value.subnet].name - region = google_compute_subnetwork.subnetwork[each.value.subnet].region + subnetwork = local.all_subnets[each.value.subnet].name + region = local.all_subnets[each.value.subnet].region role = each.value.role members = each.value.members } resource "google_compute_subnetwork_iam_binding" "bindings" { - for_each = { - for binding in local.subnet_iam_bindings : - "${binding.subnet}.${binding.role}.${try(binding.condition.title, "")}" => binding - } + for_each = local.subnet_iam_bindings project = var.project_id - subnetwork = google_compute_subnetwork.subnetwork[each.value.subnet].name - region = google_compute_subnetwork.subnetwork[each.value.subnet].region + subnetwork = local.all_subnets[each.value.subnet].name + region = local.all_subnets[each.value.subnet].region role = each.value.role members = each.value.members dynamic "condition" { @@ -184,13 +228,11 @@ resource "google_compute_subnetwork_iam_binding" "bindings" { } } -# TODO: merge factory subnet IAM members - resource "google_compute_subnetwork_iam_member" "bindings" { - for_each = var.subnet_iam_bindings_additive + for_each = local.subnet_iam_bindings_additive project = var.project_id - subnetwork = google_compute_subnetwork.subnetwork[each.value.subnet].name - region = google_compute_subnetwork.subnetwork[each.value.subnet].region + subnetwork = local.all_subnets[each.value.subnet].name + region = local.all_subnets[each.value.subnet].region role = each.value.role member = each.value.member dynamic "condition" { diff --git a/modules/net-vpc/variables.tf b/modules/net-vpc/variables.tf index 3837c9b0..5c4cc692 100644 --- a/modules/net-vpc/variables.tf +++ b/modules/net-vpc/variables.tf @@ -31,12 +31,6 @@ variable "create_googleapis_routes" { default = {} } -variable "data_folder" { - description = "An optional folder containing the subnet configurations in YaML format." - type = string - default = null -} - variable "delete_default_routes_on_create" { description = "Set to true to delete the default routes at creation time." type = bool @@ -62,6 +56,14 @@ variable "dns_policy" { default = null } +variable "factories_config" { + description = "Paths to data files and folders that enable factory functionality." + type = object({ + subnets_folder = string + }) + default = null +} + variable "firewall_policy_enforcement_order" { description = "Order that Firewall Rules and Firewall Policies are evaluated. Can be either 'BEFORE_CLASSIC_FIREWALL' or 'AFTER_CLASSIC_FIREWALL'." type = string @@ -164,42 +166,6 @@ variable "shared_vpc_service_projects" { default = [] } -variable "subnet_iam" { - description = "Subnet IAM bindings in {REGION/NAME => {ROLE => [MEMBERS]} format." - type = map(map(list(string))) - default = {} -} - -variable "subnet_iam_bindings" { - description = "Authoritative IAM bindings in {REGION/NAME => {ROLE => {members = [], condition = {}}}}." - type = map(map(object({ - members = list(string) - condition = optional(object({ - expression = string - title = string - description = optional(string) - })) - }))) - nullable = false - default = {} -} - -variable "subnet_iam_bindings_additive" { - description = "Individual additive IAM bindings. Keys are arbitrary." - type = map(object({ - member = string - role = string - subnet = string - condition = optional(object({ - expression = string - title = string - description = optional(string) - })) - })) - nullable = false - default = {} -} - variable "subnets" { description = "Subnet configuration." type = list(object({ @@ -222,20 +188,63 @@ variable "subnets" { # enable_private_access = optional(string) })) secondary_ip_ranges = optional(map(string)) + + iam = optional(map(list(string)), {}) + iam_bindings = optional(map(object({ + role = string + members = list(string) + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) + iam_bindings_additive = optional(map(object({ + member = string + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) })) - default = [] + default = [] + nullable = false } variable "subnets_proxy_only" { - description = "List of proxy-only subnets for Regional HTTPS or Internal HTTPS load balancers. Note: Only one proxy-only subnet for each VPC network in each region can be active." + description = "List of proxy-only subnets for Regional HTTPS or Internal HTTPS load balancers. Note: Only one proxy-only subnet for each VPC network in each region can be active." type = list(object({ name = string ip_cidr_range = string region = string description = optional(string) - active = bool + active = optional(bool, true) + global = optional(bool, false) + + iam = optional(map(list(string)), {}) + iam_bindings = optional(map(object({ + role = string + members = list(string) + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) + iam_bindings_additive = optional(map(object({ + member = string + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) })) - default = [] + default = [] + nullable = false } variable "subnets_psc" { @@ -245,8 +254,29 @@ variable "subnets_psc" { ip_cidr_range = string region = string description = optional(string) + + iam = optional(map(list(string)), {}) + iam_bindings = optional(map(object({ + role = string + members = list(string) + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) + iam_bindings_additive = optional(map(object({ + member = string + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) })) - default = [] + default = [] + nullable = false } variable "vpc_create" { diff --git a/modules/net-vpc/versions.tf b/modules/net-vpc/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-vpc/versions.tf +++ b/modules/net-vpc/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-vpn-dynamic/versions.tf b/modules/net-vpn-dynamic/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-vpn-dynamic/versions.tf +++ b/modules/net-vpn-dynamic/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-vpn-ha/versions.tf b/modules/net-vpn-ha/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-vpn-ha/versions.tf +++ b/modules/net-vpn-ha/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/net-vpn-static/versions.tf b/modules/net-vpn-static/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/net-vpn-static/versions.tf +++ b/modules/net-vpn-static/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/organization/README.md b/modules/organization/README.md index eb228dcf..fd9ca094 100644 --- a/modules/organization/README.md +++ b/modules/organization/README.md @@ -446,24 +446,24 @@ module "org" { | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [organization_id](variables.tf#L210) | Organization id in organizations/nnnnnn format. | string | ✓ | | +| [organization_id](variables.tf#L211) | Organization id in organizations/nnnnnn format. | string | ✓ | | | [contacts](variables.tf#L17) | List of essential contacts for this resource. Must be in the form EMAIL -> [NOTIFICATION_TYPES]. Valid notification types are ALL, SUSPENSION, SECURITY, TECHNICAL, BILLING, LEGAL, PRODUCT_UPDATES. | map(list(string)) | | {} | | [custom_roles](variables.tf#L24) | Map of role name => list of permissions to create in this project. | map(list(string)) | | {} | | [firewall_policy](variables.tf#L31) | Hierarchical firewall policies to associate to the organization. | object({…}) | | null | | [group_iam](variables.tf#L40) | Authoritative IAM binding for organization groups, in {GROUP_EMAIL => [ROLES]} format. Group emails need to be static. Can be used in combination with the `iam` variable. | map(list(string)) | | {} | | [iam](variables.tf#L47) | IAM bindings, in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | -| [iam_bindings](variables.tf#L54) | Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}. | map(object({…})) | | {} | -| [iam_bindings_additive](variables.tf#L68) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | -| [logging_data_access](variables.tf#L83) | Control activation of data access logs. Format is service => { log type => [exempted members]}. The special 'allServices' key denotes configuration for all services. | map(map(list(string))) | | {} | -| [logging_exclusions](variables.tf#L98) | Logging exclusions for this organization in the form {NAME -> FILTER}. | map(string) | | {} | -| [logging_sinks](variables.tf#L105) | Logging sinks to create for the organization. | map(object({…})) | | {} | -| [network_tags](variables.tf#L135) | Network tags by key name. If `id` is provided, key creation is skipped. The `iam` attribute behaves like the similarly named one at module level. | map(object({…})) | | {} | -| [org_policies](variables.tf#L157) | Organization policies applied to this organization keyed by policy name. | map(object({…})) | | {} | -| [org_policies_data_path](variables.tf#L184) | Path containing org policies in YAML format. | string | | null | -| [org_policy_custom_constraints](variables.tf#L190) | Organization policy custom constraints keyed by constraint name. | map(object({…})) | | {} | -| [org_policy_custom_constraints_data_path](variables.tf#L204) | Path containing org policy custom constraints in YAML format. | string | | null | -| [tag_bindings](variables.tf#L219) | Tag bindings for this organization, in key => tag value id format. | map(string) | | null | -| [tags](variables.tf#L225) | Tags by key name. If `id` is provided, key or value creation is skipped. The `iam` attribute behaves like the similarly named one at module level. | map(object({…})) | | {} | +| [iam_bindings](variables.tf#L54) | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | map(object({…})) | | {} | +| [iam_bindings_additive](variables.tf#L69) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | +| [logging_data_access](variables.tf#L84) | Control activation of data access logs. Format is service => { log type => [exempted members]}. The special 'allServices' key denotes configuration for all services. | map(map(list(string))) | | {} | +| [logging_exclusions](variables.tf#L99) | Logging exclusions for this organization in the form {NAME -> FILTER}. | map(string) | | {} | +| [logging_sinks](variables.tf#L106) | Logging sinks to create for the organization. | map(object({…})) | | {} | +| [network_tags](variables.tf#L136) | Network tags by key name. If `id` is provided, key creation is skipped. The `iam` attribute behaves like the similarly named one at module level. | map(object({…})) | | {} | +| [org_policies](variables.tf#L158) | Organization policies applied to this organization keyed by policy name. | map(object({…})) | | {} | +| [org_policies_data_path](variables.tf#L185) | Path containing org policies in YAML format. | string | | null | +| [org_policy_custom_constraints](variables.tf#L191) | Organization policy custom constraints keyed by constraint name. | map(object({…})) | | {} | +| [org_policy_custom_constraints_data_path](variables.tf#L205) | Path containing org policy custom constraints in YAML format. | string | | null | +| [tag_bindings](variables.tf#L220) | Tag bindings for this organization, in key => tag value id format. | map(string) | | null | +| [tags](variables.tf#L226) | Tags by key name. If `id` is provided, key or value creation is skipped. The `iam` attribute behaves like the similarly named one at module level. | map(object({…})) | | {} | ## Outputs diff --git a/modules/organization/iam.tf b/modules/organization/iam.tf index 2882d02a..81a8d2b0 100644 --- a/modules/organization/iam.tf +++ b/modules/organization/iam.tf @@ -51,7 +51,7 @@ resource "google_organization_iam_binding" "authoritative" { resource "google_organization_iam_binding" "bindings" { for_each = var.iam_bindings org_id = local.organization_id_numeric - role = each.key + role = each.value.role members = each.value.members dynamic "condition" { for_each = each.value.condition == null ? [] : [""] diff --git a/modules/organization/variables.tf b/modules/organization/variables.tf index 99fe49c6..c9899e2e 100644 --- a/modules/organization/variables.tf +++ b/modules/organization/variables.tf @@ -52,9 +52,10 @@ variable "iam" { } variable "iam_bindings" { - description = "Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}." + description = "Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary." type = map(object({ members = list(string) + role = string condition = optional(object({ expression = string title = string diff --git a/modules/organization/versions.tf b/modules/organization/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/organization/versions.tf +++ b/modules/organization/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/project/README.md b/modules/project/README.md index 7479eca8..3fddf95f 100644 --- a/modules/project/README.md +++ b/modules/project/README.md @@ -117,10 +117,11 @@ module "project" { "stackdriver.googleapis.com" ] iam_bindings = { - "roles/resourcemanager.projectIamAdmin" = { + iam_admin_conditional = { members = [ "group:test-admins@example.org" ] + role = "roles/resourcemanager.projectIamAdmin" condition = { title = "delegated_network_user_one" expression = <<-END @@ -589,7 +590,7 @@ output "compute_robot" { | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [name](variables.tf#L185) | Project name and id suffix. | string | ✓ | | +| [name](variables.tf#L186) | Project name and id suffix. | string | ✓ | | | [auto_create_network](variables.tf#L17) | Whether to create the default network for the project. | bool | | false | | [billing_account](variables.tf#L23) | Billing account id. | string | | null | | [compute_metadata](variables.tf#L29) | Optional compute metadata key/values. Only usable if compute API has been enabled. | map(string) | | {} | @@ -599,28 +600,28 @@ output "compute_robot" { | [descriptive_name](variables.tf#L63) | Name of the project name. Used for project name instead of `name` variable. | string | | null | | [group_iam](variables.tf#L69) | Authoritative IAM binding for organization groups, in {GROUP_EMAIL => [ROLES]} format. Group emails need to be static. Can be used in combination with the `iam` variable. | map(list(string)) | | {} | | [iam](variables.tf#L76) | Authoritative IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | -| [iam_bindings](variables.tf#L83) | Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}. | map(object({…})) | | {} | -| [iam_bindings_additive](variables.tf#L97) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | -| [labels](variables.tf#L112) | Resource labels. | map(string) | | {} | -| [lien_reason](variables.tf#L119) | If non-empty, creates a project lien with this description. | string | | null | -| [logging_data_access](variables.tf#L125) | Control activation of data access logs. Format is service => { log type => [exempted members]}. The special 'allServices' key denotes configuration for all services. | map(map(list(string))) | | {} | -| [logging_exclusions](variables.tf#L140) | Logging exclusions for this project in the form {NAME -> FILTER}. | map(string) | | {} | -| [logging_sinks](variables.tf#L147) | Logging sinks to create for this project. | map(object({…})) | | {} | -| [metric_scopes](variables.tf#L178) | List of projects that will act as metric scopes for this project. | list(string) | | [] | -| [org_policies](variables.tf#L190) | Organization policies applied to this project keyed by policy name. | map(object({…})) | | {} | -| [org_policies_data_path](variables.tf#L217) | Path containing org policies in YAML format. | string | | null | -| [parent](variables.tf#L223) | Parent folder or organization in 'folders/folder_id' or 'organizations/org_id' format. | string | | null | -| [prefix](variables.tf#L233) | Optional prefix used to generate project id and name. | string | | null | -| [project_create](variables.tf#L243) | Create project. When set to false, uses a data source to reference existing project. | bool | | true | -| [service_config](variables.tf#L249) | Configure service API activation. | object({…}) | | {…} | -| [service_encryption_key_ids](variables.tf#L261) | Cloud KMS encryption key in {SERVICE => [KEY_URL]} format. | map(list(string)) | | {} | -| [service_perimeter_bridges](variables.tf#L268) | Name of VPC-SC Bridge perimeters to add project into. See comment in the variables file for format. | list(string) | | null | -| [service_perimeter_standard](variables.tf#L275) | Name of VPC-SC Standard perimeter to add project into. See comment in the variables file for format. | string | | null | -| [services](variables.tf#L281) | Service APIs to enable. | list(string) | | [] | -| [shared_vpc_host_config](variables.tf#L287) | Configures this project as a Shared VPC host project (mutually exclusive with shared_vpc_service_project). | object({…}) | | null | -| [shared_vpc_service_config](variables.tf#L296) | Configures this project as a Shared VPC service project (mutually exclusive with shared_vpc_host_config). | object({…}) | | {…} | -| [skip_delete](variables.tf#L318) | Allows the underlying resources to be destroyed without destroying the project itself. | bool | | false | -| [tag_bindings](variables.tf#L324) | Tag bindings for this project, in key => tag value id format. | map(string) | | null | +| [iam_bindings](variables.tf#L83) | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | map(object({…})) | | {} | +| [iam_bindings_additive](variables.tf#L98) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | +| [labels](variables.tf#L113) | Resource labels. | map(string) | | {} | +| [lien_reason](variables.tf#L120) | If non-empty, creates a project lien with this description. | string | | null | +| [logging_data_access](variables.tf#L126) | Control activation of data access logs. Format is service => { log type => [exempted members]}. The special 'allServices' key denotes configuration for all services. | map(map(list(string))) | | {} | +| [logging_exclusions](variables.tf#L141) | Logging exclusions for this project in the form {NAME -> FILTER}. | map(string) | | {} | +| [logging_sinks](variables.tf#L148) | Logging sinks to create for this project. | map(object({…})) | | {} | +| [metric_scopes](variables.tf#L179) | List of projects that will act as metric scopes for this project. | list(string) | | [] | +| [org_policies](variables.tf#L191) | Organization policies applied to this project keyed by policy name. | map(object({…})) | | {} | +| [org_policies_data_path](variables.tf#L218) | Path containing org policies in YAML format. | string | | null | +| [parent](variables.tf#L224) | Parent folder or organization in 'folders/folder_id' or 'organizations/org_id' format. | string | | null | +| [prefix](variables.tf#L234) | Optional prefix used to generate project id and name. | string | | null | +| [project_create](variables.tf#L244) | Create project. When set to false, uses a data source to reference existing project. | bool | | true | +| [service_config](variables.tf#L250) | Configure service API activation. | object({…}) | | {…} | +| [service_encryption_key_ids](variables.tf#L262) | Cloud KMS encryption key in {SERVICE => [KEY_URL]} format. | map(list(string)) | | {} | +| [service_perimeter_bridges](variables.tf#L269) | Name of VPC-SC Bridge perimeters to add project into. See comment in the variables file for format. | list(string) | | null | +| [service_perimeter_standard](variables.tf#L276) | Name of VPC-SC Standard perimeter to add project into. See comment in the variables file for format. | string | | null | +| [services](variables.tf#L282) | Service APIs to enable. | list(string) | | [] | +| [shared_vpc_host_config](variables.tf#L288) | Configures this project as a Shared VPC host project (mutually exclusive with shared_vpc_service_project). | object({…}) | | null | +| [shared_vpc_service_config](variables.tf#L297) | Configures this project as a Shared VPC service project (mutually exclusive with shared_vpc_host_config). | object({…}) | | {…} | +| [skip_delete](variables.tf#L319) | Allows the underlying resources to be destroyed without destroying the project itself. | bool | | false | +| [tag_bindings](variables.tf#L325) | Tag bindings for this project, in key => tag value id format. | map(string) | | null | ## Outputs diff --git a/modules/project/iam.tf b/modules/project/iam.tf index 16f187d6..0f00f286 100644 --- a/modules/project/iam.tf +++ b/modules/project/iam.tf @@ -58,7 +58,7 @@ resource "google_project_iam_binding" "authoritative" { resource "google_project_iam_binding" "bindings" { for_each = var.iam_bindings project = local.project.project_id - role = each.key + role = each.value.role members = each.value.members dynamic "condition" { for_each = each.value.condition == null ? [] : [""] diff --git a/modules/project/service-agents.yaml b/modules/project/service-agents.yaml index 4ef3cafd..c8eff2df 100644 --- a/modules/project/service-agents.yaml +++ b/modules/project/service-agents.yaml @@ -221,6 +221,7 @@ service_agent: "service-%s@gcp-sa-healthcare.iam.gserviceaccount.com" - name: "iap" service_agent: "service-%s@gcp-sa-iap.iam.gserviceaccount.com" + jit: true - name: "identitytoolkit" service_agent: "service-%s@gcp-sa-identitytoolkit.iam.gserviceaccount.com" - name: "ids" diff --git a/modules/project/variables.tf b/modules/project/variables.tf index 2824fcf3..68f8b6c0 100644 --- a/modules/project/variables.tf +++ b/modules/project/variables.tf @@ -81,9 +81,10 @@ variable "iam" { } variable "iam_bindings" { - description = "Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}." + description = "Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary." type = map(object({ members = list(string) + role = string condition = optional(object({ expression = string title = string diff --git a/modules/project/versions.tf b/modules/project/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/project/versions.tf +++ b/modules/project/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/projects-data-source/versions.tf b/modules/projects-data-source/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/projects-data-source/versions.tf +++ b/modules/projects-data-source/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/pubsub/README.md b/modules/pubsub/README.md index 44a0e737..69a18dbe 100644 --- a/modules/pubsub/README.md +++ b/modules/pubsub/README.md @@ -61,16 +61,10 @@ module "pubsub" { project_id = "my-project" name = "my-topic" subscriptions = { - test-pull = null + test-pull = {} test-pull-override = { - labels = { test = "override" } - options = { - ack_deadline_seconds = null - message_retention_duration = null - retain_acked_messages = true - expiration_policy_ttl = null - filter = null - } + labels = { test = "override" } + retain_acked_messages = true } } } @@ -87,13 +81,10 @@ module "pubsub" { project_id = "my-project" name = "my-topic" subscriptions = { - test-push = null - } - push_configs = { test-push = { - endpoint = "https://example.com/foo" - attributes = null - oidc_token = null + push = { + endpoint = "https://example.com/foo" + } } } } @@ -110,20 +101,45 @@ module "pubsub" { project_id = "my-project" name = "my-topic" subscriptions = { - test-bigquery = null - } - bigquery_subscription_configs = { test-bigquery = { - table = "my_project_id:my_dataset.my_table" - use_topic_schema = true - write_metadata = false - drop_unknown_fields = true + bigquery = { + table = "my_project_id:my_dataset.my_table" + use_topic_schema = true + write_metadata = false + drop_unknown_fields = true + } } } } # tftest modules=1 resources=2 ``` +### Cloud Storage subscriptions + +Cloud Storage subscriptions need extra configuration in the `cloud_storage_subscription_configs` variable. + +```hcl +module "pubsub" { + source = "./fabric/modules/pubsub" + project_id = "my-project" + name = "my-topic" + subscriptions = { + test-cloudstorage = { + cloud_storage = { + bucket = "my-bucket" + filename_prefix = "test_prefix" + filename_suffix = "test_suffix" + max_duration = "100s" + max_bytes = 1000 + avro_config = { + write_metadata = true + } + } + } + } +} +# tftest modules=1 resources=2 +``` ### Subscriptions with IAM ```hcl @@ -132,47 +148,40 @@ module "pubsub" { project_id = "my-project" name = "my-topic" subscriptions = { - test-1 = null - test-1 = null - } - subscription_iam = { test-1 = { - "roles/pubsub.subscriber" = ["user:user1@ludomagno.net"] + iam = { + "roles/pubsub.subscriber" = ["user:user1@example.com"] + } } } } # tftest modules=1 resources=3 ``` - ## Variables | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [name](variables.tf#L79) | PubSub topic name. | string | ✓ | | -| [project_id](variables.tf#L84) | Project used for resources. | string | ✓ | | -| [bigquery_subscription_configs](variables.tf#L17) | Configuration parameters for BigQuery subscriptions. | map(object({…})) | | {} | -| [dead_letter_configs](variables.tf#L28) | Per-subscription dead letter policy configuration. | map(object({…})) | | {} | -| [defaults](variables.tf#L37) | Subscription defaults for options. | object({…}) | | {…} | -| [iam](variables.tf#L55) | IAM bindings for topic in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | -| [kms_key](variables.tf#L61) | KMS customer managed encryption key. | string | | null | -| [labels](variables.tf#L67) | Labels. | map(string) | | {} | -| [message_retention_duration](variables.tf#L73) | Minimum duration to retain a message after it is published to the topic. | string | | null | -| [push_configs](variables.tf#L89) | Push subscription configurations. | map(object({…})) | | {} | -| [regions](variables.tf#L102) | List of regions used to set persistence policy. | list(string) | | [] | -| [schema](variables.tf#L108) | Topic schema. If set, all messages in this topic should follow this schema. | object({…}) | | null | -| [subscription_iam](variables.tf#L118) | IAM bindings for subscriptions in {SUBSCRIPTION => {ROLE => [MEMBERS]}} format. | map(map(list(string))) | | {} | -| [subscriptions](variables.tf#L124) | Topic subscriptions. Also define push configs for push subscriptions. If options is set to null subscription defaults will be used. Labels default to topic labels if set to null. | map(object({…})) | | {} | +| [name](variables.tf#L73) | PubSub topic name. | string | ✓ | | +| [project_id](variables.tf#L78) | Project used for resources. | string | ✓ | | +| [iam](variables.tf#L17) | IAM bindings for topic in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | +| [iam_bindings](variables.tf#L24) | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | map(object({…})) | | {} | +| [iam_bindings_additive](variables.tf#L39) | Keyring individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | +| [kms_key](variables.tf#L54) | KMS customer managed encryption key. | string | | null | +| [labels](variables.tf#L60) | Labels. | map(string) | | {} | +| [message_retention_duration](variables.tf#L67) | Minimum duration to retain a message after it is published to the topic. | string | | null | +| [regions](variables.tf#L83) | List of regions used to set persistence policy. | list(string) | | [] | +| [schema](variables.tf#L90) | Topic schema. If set, all messages in this topic should follow this schema. | object({…}) | | null | +| [subscriptions](variables.tf#L100) | Topic subscriptions. Also define push configs for push subscriptions. If options is set to null subscription defaults will be used. Labels default to topic labels if set to null. | map(object({…})) | | {} | ## Outputs | name | description | sensitive | |---|---|:---:| | [id](outputs.tf#L17) | Fully qualified topic id. | | -| [schema](outputs.tf#L26) | Schema resource. | | -| [schema_id](outputs.tf#L31) | Schema resource id. | | -| [subscription_id](outputs.tf#L36) | Subscription ids. | | -| [subscriptions](outputs.tf#L46) | Subscription resources. | | -| [topic](outputs.tf#L54) | Topic resource. | | - +| [schema](outputs.tf#L27) | Schema resource. | | +| [schema_id](outputs.tf#L32) | Schema resource id. | | +| [subscription_id](outputs.tf#L37) | Subscription ids. | | +| [subscriptions](outputs.tf#L48) | Subscription resources. | | +| [topic](outputs.tf#L57) | Topic resource. | | diff --git a/modules/pubsub/iam.tf b/modules/pubsub/iam.tf new file mode 100644 index 00000000..4e39b43a --- /dev/null +++ b/modules/pubsub/iam.tf @@ -0,0 +1,140 @@ +/** + * Copyright 2023 Google LLC + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the authoritative. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +locals { + subscription_iam = flatten([ + for k, v in var.subscriptions : [ + for role, members in v.iam : { + subscription = k + role = role + members = members + } + ] + ]) + subscription_iam_bindings = merge([ + for k, v in var.subscriptions : { + for binding_key, data in v.iam_bindings : + binding_key => { + subscription = k + role = data.role + members = data.members + condition = data.condition + } + } + ]...) + subscription_iam_bindings_additive = merge([ + for k, v in var.subscriptions : { + for binding_key, data in v.iam_bindings_additive : + binding_key => { + subscription = k + role = data.role + member = data.member + condition = data.condition + } + } + ]...) +} + +moved { + from = google_pubsub_topic_iam_binding.default + to = google_pubsub_topic_iam_binding.authoritative +} + +resource "google_pubsub_topic_iam_binding" "authoritative" { + for_each = var.iam + project = var.project_id + topic = google_pubsub_topic.default.name + role = each.key + members = each.value +} + +resource "google_pubsub_topic_iam_binding" "bindings" { + for_each = var.iam_bindings + topic = google_pubsub_topic.default.name + role = each.value.role + members = each.value.members + dynamic "condition" { + for_each = each.value.condition == null ? [] : [""] + content { + expression = each.value.condition.expression + title = each.value.condition.title + description = each.value.condition.description + } + } +} + +resource "google_pubsub_topic_iam_member" "bindings" { + for_each = var.iam_bindings_additive + topic = google_pubsub_topic.default.name + role = each.value.role + member = each.value.member + dynamic "condition" { + for_each = each.value.condition == null ? [] : [""] + content { + expression = each.value.condition.expression + title = each.value.condition.title + description = each.value.condition.description + } + } +} + +moved { + from = google_pubsub_subscription_iam_binding.default + to = google_pubsub_subscription_iam_binding.authoritative +} + +resource "google_pubsub_subscription_iam_binding" "authoritative" { + for_each = { + for binding in local.subscription_iam : + "${binding.subscription}.${binding.role}" => binding + } + project = var.project_id + subscription = google_pubsub_subscription.default[each.value.subscription].name + role = each.value.role + members = each.value.members +} + +resource "google_pubsub_subscription_iam_binding" "bindings" { + for_each = local.subscription_iam_bindings + project = var.project_id + subscription = google_pubsub_subscription.default[each.value.subscription].name + role = each.value.role + members = each.value.members + dynamic "condition" { + for_each = each.value.condition == null ? [] : [""] + content { + expression = each.value.condition.expression + title = each.value.condition.title + description = each.value.condition.description + } + } +} + +resource "google_pubsub_subscription_iam_member" "members" { + for_each = local.subscription_iam_bindings_additive + project = var.project_id + subscription = google_pubsub_subscription.default[each.value.subscription].name + role = each.value.role + member = each.value.member + dynamic "condition" { + for_each = each.value.condition == null ? [] : [""] + content { + expression = each.value.condition.expression + title = each.value.condition.title + description = each.value.condition.description + } + } +} diff --git a/modules/pubsub/main.tf b/modules/pubsub/main.tf index ccb6f5d7..de065029 100644 --- a/modules/pubsub/main.tf +++ b/modules/pubsub/main.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -15,24 +15,6 @@ */ locals { - sub_iam_members = flatten([ - for sub, roles in var.subscription_iam : [ - for role, members in roles : { - sub = sub - role = role - members = members - } - ] - ]) - oidc_config = { - for k, v in var.push_configs : k => v.oidc_token - } - subscriptions = { - for k, v in var.subscriptions : k => { - labels = try(v.labels, v, null) == null ? var.labels : v.labels - options = try(v.options, v, null) == null ? var.defaults : v.options - } - } topic_id_static = "projects/${var.project_id}/topics/${var.name}" } @@ -67,75 +49,73 @@ resource "google_pubsub_topic" "default" { } } -resource "google_pubsub_topic_iam_binding" "default" { - for_each = var.iam - project = var.project_id - topic = google_pubsub_topic.default.name - role = each.key - members = each.value -} - resource "google_pubsub_subscription" "default" { - for_each = local.subscriptions - project = var.project_id - name = each.key - topic = google_pubsub_topic.default.name - labels = each.value.labels - ack_deadline_seconds = each.value.options.ack_deadline_seconds - message_retention_duration = each.value.options.message_retention_duration - retain_acked_messages = each.value.options.retain_acked_messages - filter = each.value.options.filter + for_each = var.subscriptions + project = var.project_id + name = each.key + topic = google_pubsub_topic.default.name + labels = each.value.labels + ack_deadline_seconds = each.value.ack_deadline_seconds + message_retention_duration = each.value.message_retention_duration + retain_acked_messages = each.value.retain_acked_messages + filter = each.value.filter + enable_message_ordering = each.value.enable_message_ordering + enable_exactly_once_delivery = each.value.enable_exactly_once_delivery dynamic "expiration_policy" { - for_each = each.value.options.expiration_policy_ttl == null ? [] : [""] + for_each = each.value.expiration_policy_ttl == null ? [] : [""] content { - ttl = each.value.options.expiration_policy_ttl + ttl = each.value.expiration_policy_ttl } } dynamic "dead_letter_policy" { - for_each = try(var.dead_letter_configs[each.key], null) == null ? [] : [""] + for_each = each.value.dead_letter_policy == null ? [] : [""] content { - dead_letter_topic = var.dead_letter_configs[each.key].topic - max_delivery_attempts = var.dead_letter_configs[each.key].max_delivery_attempts + dead_letter_topic = each.value.dead_letter_policy.topic + max_delivery_attempts = each.value.dead_letter_policy.max_delivery_attempts } } dynamic "push_config" { - for_each = try(var.push_configs[each.key], null) == null ? [] : [""] + for_each = each.value.push == null ? [] : [""] content { - push_endpoint = var.push_configs[each.key].endpoint - attributes = var.push_configs[each.key].attributes + push_endpoint = each.value.push.endpoint + attributes = each.value.push.attributes dynamic "oidc_token" { - for_each = ( - local.oidc_config[each.key] == null ? [] : [""] - ) + for_each = each.value.push.oidc_token == null ? [] : [""] content { - service_account_email = local.oidc_config[each.key].service_account_email - audience = local.oidc_config[each.key].audience + service_account_email = each.value.push.oidc_token.service_account_email + audience = each.value.push.oidc_token.audience } } } } dynamic "bigquery_config" { - for_each = try(var.bigquery_subscription_configs[each.key], null) == null ? [] : [""] + for_each = each.value.bigquery == null ? [] : [""] content { - table = var.bigquery_subscription_configs[each.key].table - use_topic_schema = var.bigquery_subscription_configs[each.key].use_topic_schema - write_metadata = var.bigquery_subscription_configs[each.key].write_metadata - drop_unknown_fields = var.bigquery_subscription_configs[each.key].drop_unknown_fields + table = each.value.bigquery.table + use_topic_schema = each.value.bigquery.use_topic_schema + write_metadata = each.value.bigquery.write_metadata + drop_unknown_fields = each.value.bigquery.drop_unknown_fields + } + } + + dynamic "cloud_storage_config" { + for_each = each.value.cloud_storage == null ? [] : [""] + content { + bucket = each.value.cloud_storage.bucket + filename_prefix = each.value.cloud_storage.filename_prefix + filename_suffix = each.value.cloud_storage.filename_suffix + max_duration = each.value.cloud_storage.max_duration + max_bytes = each.value.cloud_storage.max_bytes + dynamic "avro_config" { + for_each = each.value.cloud_storage.avro_config == null ? [] : [""] + content { + write_metadata = each.value.cloud_storage.avro_config.write_metadata + } + } } } } - -resource "google_pubsub_subscription_iam_binding" "default" { - for_each = { - for binding in local.sub_iam_members : - "${binding.sub}.${binding.role}" => binding - } - project = var.project_id - subscription = google_pubsub_subscription.default[each.value.sub].name - role = each.value.role - members = each.value.members -} diff --git a/modules/pubsub/outputs.tf b/modules/pubsub/outputs.tf index 0d149302..8218e2b3 100644 --- a/modules/pubsub/outputs.tf +++ b/modules/pubsub/outputs.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -19,7 +19,8 @@ output "id" { value = local.topic_id_static depends_on = [ google_pubsub_topic.default, - google_pubsub_topic_iam_binding.default + google_pubsub_topic_iam_binding.authoritative, + google_pubsub_topic_iam_binding.bindings ] } @@ -39,7 +40,8 @@ output "subscription_id" { for k, v in google_pubsub_subscription.default : k => v.id } depends_on = [ - google_pubsub_subscription_iam_binding.default + google_pubsub_subscription_iam_binding.authoritative, + google_pubsub_subscription_iam_binding.bindings ] } @@ -47,7 +49,8 @@ output "subscriptions" { description = "Subscription resources." value = google_pubsub_subscription.default depends_on = [ - google_pubsub_subscription_iam_binding.default + google_pubsub_subscription_iam_binding.authoritative, + google_pubsub_subscription_iam_binding.bindings ] } @@ -55,6 +58,7 @@ output "topic" { description = "Topic resource." value = google_pubsub_topic.default depends_on = [ - google_pubsub_topic_iam_binding.default + google_pubsub_topic_iam_binding.authoritative, + google_pubsub_topic_iam_binding.bindings ] } diff --git a/modules/pubsub/variables.tf b/modules/pubsub/variables.tf index afefb4a8..370c42fa 100644 --- a/modules/pubsub/variables.tf +++ b/modules/pubsub/variables.tf @@ -1,5 +1,5 @@ /** - * Copyright 2022 Google LLC + * Copyright 2023 Google LLC * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -14,48 +14,41 @@ * limitations under the License. */ -variable "bigquery_subscription_configs" { - description = "Configuration parameters for BigQuery subscriptions." - type = map(object({ - table = string - use_topic_schema = bool - write_metadata = bool - drop_unknown_fields = bool - })) - default = {} -} - -variable "dead_letter_configs" { - description = "Per-subscription dead letter policy configuration." - type = map(object({ - topic = string - max_delivery_attempts = number - })) - default = {} -} - -variable "defaults" { - description = "Subscription defaults for options." - type = object({ - ack_deadline_seconds = number - message_retention_duration = string - retain_acked_messages = bool - expiration_policy_ttl = string - filter = string - }) - default = { - ack_deadline_seconds = null - message_retention_duration = null - retain_acked_messages = null - expiration_policy_ttl = null - filter = null - } -} - variable "iam" { description = "IAM bindings for topic in {ROLE => [MEMBERS]} format." type = map(list(string)) default = {} + nullable = false +} + +variable "iam_bindings" { + description = "Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary." + type = map(object({ + members = list(string) + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })) + nullable = false + default = {} +} + +variable "iam_bindings_additive" { + description = "Keyring individual additive IAM bindings. Keys are arbitrary." + type = map(object({ + member = string + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })) + nullable = false + default = {} } variable "kms_key" { @@ -68,6 +61,7 @@ variable "labels" { description = "Labels." type = map(string) default = {} + nullable = false } variable "message_retention_duration" { @@ -86,23 +80,11 @@ variable "project_id" { type = string } -variable "push_configs" { - description = "Push subscription configurations." - type = map(object({ - attributes = map(string) - endpoint = string - oidc_token = object({ - audience = string - service_account_email = string - }) - })) - default = {} -} - variable "regions" { description = "List of regions used to set persistence policy." type = list(string) default = [] + nullable = false } variable "schema" { @@ -115,23 +97,72 @@ variable "schema" { default = null } -variable "subscription_iam" { - description = "IAM bindings for subscriptions in {SUBSCRIPTION => {ROLE => [MEMBERS]}} format." - type = map(map(list(string))) - default = {} -} - variable "subscriptions" { description = "Topic subscriptions. Also define push configs for push subscriptions. If options is set to null subscription defaults will be used. Labels default to topic labels if set to null." type = map(object({ - labels = map(string) - options = object({ - ack_deadline_seconds = number - message_retention_duration = string - retain_acked_messages = bool - expiration_policy_ttl = string - filter = string - }) + labels = optional(map(string)) + ack_deadline_seconds = optional(number) + message_retention_duration = optional(string) + retain_acked_messages = optional(bool, false) + expiration_policy_ttl = optional(string) + filter = optional(string) + enable_message_ordering = optional(bool, false) + enable_exactly_once_delivery = optional(bool, false) + dead_letter_policy = optional(object({ + topic = string + max_delivery_attempts = optional(number) + })) + retry_policy = optional(object({ + minimum_backoff = optional(number) + maximum_backoff = optional(number) + })) + + bigquery = optional(object({ + table = string + use_topic_schema = optional(bool, false) + write_metadata = optional(bool, false) + drop_unknown_fields = optional(bool, false) + })) + cloud_storage = optional(object({ + bucket = string + filename_prefix = optional(string) + filename_suffix = optional(string) + max_duration = optional(string) + max_bytes = optional(number) + avro_config = optional(object({ + write_metadata = optional(bool, false) + })) + })) + push = optional(object({ + endpoint = string + attributes = optional(map(string)) + no_wrapper = optional(bool, false) + oidc_token = optional(object({ + audience = optional(string) + service_account_email = string + })) + })) + + iam = optional(map(list(string)), {}) + iam_bindings = optional(map(object({ + members = list(string) + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) + iam_bindings_additive = optional(map(object({ + member = string + role = string + condition = optional(object({ + expression = string + title = string + description = optional(string) + })) + })), {}) })) - default = {} + default = {} + nullable = false } diff --git a/modules/pubsub/versions.tf b/modules/pubsub/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/pubsub/versions.tf +++ b/modules/pubsub/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/secret-manager/versions.tf b/modules/secret-manager/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/secret-manager/versions.tf +++ b/modules/secret-manager/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/service-directory/versions.tf b/modules/service-directory/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/service-directory/versions.tf +++ b/modules/service-directory/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/source-repository/README.md b/modules/source-repository/README.md index a62013fa..c60ba7e4 100644 --- a/modules/source-repository/README.md +++ b/modules/source-repository/README.md @@ -75,13 +75,13 @@ module "repo" { | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [name](variables.tf#L60) | Repository name. | string | ✓ | | -| [project_id](variables.tf#L65) | Project used for resources. | string | ✓ | | +| [name](variables.tf#L61) | Repository name. | string | ✓ | | +| [project_id](variables.tf#L66) | Project used for resources. | string | ✓ | | | [group_iam](variables.tf#L17) | Authoritative IAM binding for organization groups, in {GROUP_EMAIL => [ROLES]} format. Group emails need to be static. Can be used in combination with the `iam` variable. | map(list(string)) | | {} | | [iam](variables.tf#L24) | IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | -| [iam_bindings](variables.tf#L31) | Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}. | map(object({…})) | | {} | -| [iam_bindings_additive](variables.tf#L45) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | -| [triggers](variables.tf#L70) | Cloud Build triggers. | map(object({…})) | | {} | +| [iam_bindings](variables.tf#L31) | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | map(object({…})) | | {} | +| [iam_bindings_additive](variables.tf#L46) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | +| [triggers](variables.tf#L71) | Cloud Build triggers. | map(object({…})) | | {} | ## Outputs diff --git a/modules/source-repository/iam.tf b/modules/source-repository/iam.tf index be0cf688..1b225d1b 100644 --- a/modules/source-repository/iam.tf +++ b/modules/source-repository/iam.tf @@ -44,7 +44,7 @@ resource "google_sourcerepo_repository_iam_binding" "bindings" { for_each = var.iam_bindings project = var.project_id repository = google_sourcerepo_repository.default.name - role = each.key + role = each.value.role members = each.value.members dynamic "condition" { for_each = each.value.condition == null ? [] : [""] diff --git a/modules/source-repository/variables.tf b/modules/source-repository/variables.tf index ce1c34e7..23bfa789 100644 --- a/modules/source-repository/variables.tf +++ b/modules/source-repository/variables.tf @@ -29,9 +29,10 @@ variable "iam" { } variable "iam_bindings" { - description = "Authoritative IAM bindings in {ROLE => {members = [], condition = {}}}." + description = "Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary." type = map(object({ members = list(string) + role = string condition = optional(object({ expression = string title = string diff --git a/modules/source-repository/versions.tf b/modules/source-repository/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/source-repository/versions.tf +++ b/modules/source-repository/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/modules/vpc-sc/versions.tf b/modules/vpc-sc/versions.tf index e4f7404f..91a91a31 100644 --- a/modules/vpc-sc/versions.tf +++ b/modules/vpc-sc/versions.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -17,11 +17,11 @@ terraform { required_providers { google = { source = "hashicorp/google" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } google-beta = { source = "hashicorp/google-beta" - version = ">= 4.80.0" # tftest + version = ">= 4.82.0" # tftest } } } diff --git a/tests/blueprints/factories/project_factory/examples/example.yaml b/tests/blueprints/factories/project_factory/examples/example.yaml index 5927caed..086fbd55 100644 --- a/tests/blueprints/factories/project_factory/examples/example.yaml +++ b/tests/blueprints/factories/project_factory/examples/example.yaml @@ -30,9 +30,10 @@ values: module.project-factory.module.projects["prj-app-1"].google_project.project[0]: auto_create_network: false billing_account: 012345-67890A-BCDEF0 - folder_id: null + folder_id: "12345678" labels: app: app-1 + environment: test team: foo name: test-pf-prj-app-1 org_id: null @@ -61,9 +62,10 @@ values: module.project-factory.module.projects["prj-app-2"].google_project.project[0]: auto_create_network: false billing_account: 012345-67890A-ABCDEF - folder_id: null + folder_id: "12345678" labels: app: app-1 + environment: test team: foo name: test-pf-prj-app-2 org_id: null diff --git a/tests/examples/variables.tf b/tests/examples/variables.tf index 3a5a3f75..9a65aa7a 100644 --- a/tests/examples/variables.tf +++ b/tests/examples/variables.tf @@ -1,4 +1,4 @@ -# Copyright 2022 Google LLC +# Copyright 2023 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -69,6 +69,7 @@ variable "vpc" { default = { name = "vpc_name" self_link = "projects/xxx/global/networks/aaa" + id = "projects/xxx/global/networks/aaa" } } diff --git a/tests/fast/stages/s2_networking_a_peering/stage.yaml b/tests/fast/stages/s2_networking_a_peering/stage.yaml index 2c2ca3da..85b123af 100644 --- a/tests/fast/stages/s2_networking_a_peering/stage.yaml +++ b/tests/fast/stages/s2_networking_a_peering/stage.yaml @@ -14,4 +14,4 @@ counts: modules: 28 - resources: 151 + resources: 154 diff --git a/tests/fast/stages/s2_networking_b_vpn/stage.yaml b/tests/fast/stages/s2_networking_b_vpn/stage.yaml index 9cb8ee83..831bcd50 100644 --- a/tests/fast/stages/s2_networking_b_vpn/stage.yaml +++ b/tests/fast/stages/s2_networking_b_vpn/stage.yaml @@ -14,4 +14,4 @@ counts: modules: 30 - resources: 188 + resources: 191 diff --git a/tests/fast/stages/s2_networking_c_nva/stage.yaml b/tests/fast/stages/s2_networking_c_nva/stage.yaml index 3da9b352..e1ce4a05 100644 --- a/tests/fast/stages/s2_networking_c_nva/stage.yaml +++ b/tests/fast/stages/s2_networking_c_nva/stage.yaml @@ -14,4 +14,4 @@ counts: modules: 42 - resources: 197 + resources: 200 diff --git a/tests/fast/stages/s2_networking_d_separate_envs/stage.yaml b/tests/fast/stages/s2_networking_d_separate_envs/stage.yaml index f60257c4..e2b6fe64 100644 --- a/tests/fast/stages/s2_networking_d_separate_envs/stage.yaml +++ b/tests/fast/stages/s2_networking_d_separate_envs/stage.yaml @@ -14,4 +14,4 @@ counts: modules: 21 - resources: 168 + resources: 170 diff --git a/tests/fast/stages/s2_networking_e_nva_bgp/stage.yaml b/tests/fast/stages/s2_networking_e_nva_bgp/stage.yaml index 960ac523..bc557683 100644 --- a/tests/fast/stages/s2_networking_e_nva_bgp/stage.yaml +++ b/tests/fast/stages/s2_networking_e_nva_bgp/stage.yaml @@ -14,4 +14,4 @@ counts: modules: 36 - resources: 208 + resources: 211 diff --git a/tests/fast/stages/s3_project_factory/data/projects/project.yaml b/tests/fast/stages/s3_project_factory/data/projects/project.yaml index 18b5cdb4..922b4044 100644 --- a/tests/fast/stages/s3_project_factory/data/projects/project.yaml +++ b/tests/fast/stages/s3_project_factory/data/projects/project.yaml @@ -12,7 +12,7 @@ # See the License for the specific language governing permissions and # limitations under the License. -parent_id: folders/012345678901 +parent: folders/012345678901 services: - storage.googleapis.com - stackdriver.googleapis.com diff --git a/tests/modules/apigee/all_psc_mode.tfvars b/tests/modules/apigee/all_psc_mode.tfvars new file mode 100644 index 00000000..41bafabb --- /dev/null +++ b/tests/modules/apigee/all_psc_mode.tfvars @@ -0,0 +1,47 @@ +project_id = "my-project" +organization = { + display_name = "My Organization" + description = "My Organization" + runtime_type = "CLOUD" + billing_type = "Pay-as-you-go" + database_encryption_key = "123456789" + analytics_region = "europe-west1" + disable_vpc_peering = true +} +envgroups = { + test = ["test.example.com"] + prod = ["prod.example.com"] +} +environments = { + apis-test = { + display_name = "APIs test" + description = "APIs Test" + envgroups = ["test"] + } + apis-prod = { + display_name = "APIs prod" + description = "APIs prod" + envgroups = ["prod"] + iam = { + "roles/viewer" = ["group:devops@myorg.com"] + } + } +} +instances = { + europe-west1 = { + environments = ["europe-west1"] + } + europe-west3 = { + environments = ["europe-west3"] + } +} +endpoint_attachments = { + endpoint-backend-1 = { + region = "europe-west1" + service_attachment = "projects/my-project-1/serviceAttachments/gkebackend1" + } + endpoint-backend-2 = { + region = "europe-west1" + service_attachment = "projects/my-project-2/serviceAttachments/gkebackend2" + } +} \ No newline at end of file diff --git a/tests/modules/apigee/all_psc_mode.yaml b/tests/modules/apigee/all_psc_mode.yaml new file mode 100644 index 00000000..c31c713a --- /dev/null +++ b/tests/modules/apigee/all_psc_mode.yaml @@ -0,0 +1,82 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +values: + google_apigee_endpoint_attachment.endpoint_attachments["endpoint-backend-1"]: + endpoint_attachment_id: endpoint-backend-1 + location: europe-west1 + service_attachment: projects/my-project-1/serviceAttachments/gkebackend1 + google_apigee_endpoint_attachment.endpoint_attachments["endpoint-backend-2"]: + endpoint_attachment_id: endpoint-backend-2 + location: europe-west1 + service_attachment: projects/my-project-2/serviceAttachments/gkebackend2 + google_apigee_envgroup.envgroups["prod"]: + hostnames: + - prod.example.com + name: prod + google_apigee_envgroup.envgroups["test"]: + hostnames: + - test.example.com + name: test + google_apigee_envgroup_attachment.envgroup_attachments["apis-prod-prod"]: + environment: apis-prod + google_apigee_envgroup_attachment.envgroup_attachments["apis-test-test"]: + environment: apis-test + google_apigee_environment.environments["apis-prod"]: + description: APIs prod + display_name: APIs prod + name: apis-prod + google_apigee_environment.environments["apis-test"]: + description: APIs Test + display_name: APIs test + name: apis-test + google_apigee_environment_iam_binding.binding["apis-prod-roles/viewer"]: + condition: [] + env_id: apis-prod + members: + - group:devops@myorg.com + role: roles/viewer + google_apigee_instance.instances["europe-west3"]: + description: Terraform-managed + disk_encryption_key_name: null + display_name: null + location: europe-west3 + name: instance-europe-west3 + google_apigee_instance.instances["europe-west1"]: + description: Terraform-managed + disk_encryption_key_name: null + display_name: null + location: europe-west1 + name: instance-europe-west1 + google_apigee_organization.organization[0]: + analytics_region: europe-west1 + authorized_network: null + billing_type: Pay-as-you-go + description: null + display_name: null + project_id: my-project + retention: DELETION_RETENTION_UNSPECIFIED + runtime_database_encryption_key_name: '123456789' + runtime_type: CLOUD + disable_vpc_peering: true + +counts: + google_apigee_endpoint_attachment: 2 + google_apigee_envgroup: 2 + google_apigee_envgroup_attachment: 2 + google_apigee_environment: 2 + google_apigee_environment_iam_binding: 1 + google_apigee_instance: 2 + google_apigee_instance_attachment: 2 + google_apigee_organization: 1 \ No newline at end of file diff --git a/tests/modules/apigee/all.tfvars b/tests/modules/apigee/all_vpc_mode.tfvars similarity index 90% rename from tests/modules/apigee/all.tfvars rename to tests/modules/apigee/all_vpc_mode.tfvars index 69ffb084..03626f76 100644 --- a/tests/modules/apigee/all.tfvars +++ b/tests/modules/apigee/all_vpc_mode.tfvars @@ -7,6 +7,7 @@ organization = { billing_type = "Pay-as-you-go" database_encryption_key = "123456789" analytics_region = "europe-west1" + disable_vpc_peering = false } envgroups = { test = ["test.example.com"] @@ -17,13 +18,11 @@ environments = { display_name = "APIs test" description = "APIs Test" envgroups = ["test"] - regions = ["europe-west1"] } apis-prod = { display_name = "APIs prod" description = "APIs prod" envgroups = ["prod"] - regions = ["europe-west3"] iam = { "roles/viewer" = ["group:devops@myorg.com"] } @@ -33,10 +32,12 @@ instances = { europe-west1 = { runtime_ip_cidr_range = "10.0.4.0/22" troubleshooting_ip_cidr_range = "10.1.0.0/28" + environments = ["apis-test"] } europe-west3 = { runtime_ip_cidr_range = "10.0.6.0/22" troubleshooting_ip_cidr_range = "10.1.0.16/28" + environments = ["apis-prod"] } } endpoint_attachments = { @@ -48,4 +49,4 @@ endpoint_attachments = { region = "europe-west1" service_attachment = "projects/my-project-2/serviceAttachments/gkebackend2" } -} +} \ No newline at end of file diff --git a/tests/modules/apigee/all.yaml b/tests/modules/apigee/all_vpc_mode.yaml similarity index 97% rename from tests/modules/apigee/all.yaml rename to tests/modules/apigee/all_vpc_mode.yaml index c23eab27..2d39429c 100644 --- a/tests/modules/apigee/all.yaml +++ b/tests/modules/apigee/all_vpc_mode.yaml @@ -12,6 +12,7 @@ # See the License for the specific language governing permissions and # limitations under the License. + values: google_apigee_endpoint_attachment.endpoint_attachments["endpoint-backend-1"]: endpoint_attachment_id: endpoint-backend-1 @@ -71,6 +72,7 @@ values: retention: DELETION_RETENTION_UNSPECIFIED runtime_database_encryption_key_name: '123456789' runtime_type: CLOUD + disable_vpc_peering: false counts: google_apigee_endpoint_attachment: 2 @@ -80,4 +82,4 @@ counts: google_apigee_environment_iam_binding: 1 google_apigee_instance: 2 google_apigee_instance_attachment: 2 - google_apigee_organization: 1 + google_apigee_organization: 1 \ No newline at end of file diff --git a/tests/modules/apigee/examples/minimal-cloud-no-org.yaml b/tests/modules/apigee/examples/minimal-cloud-no-org.yaml new file mode 100644 index 00000000..eee6638d --- /dev/null +++ b/tests/modules/apigee/examples/minimal-cloud-no-org.yaml @@ -0,0 +1,41 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +values: + module.apigee.google_apigee_envgroup.envgroups["prod"]: + hostnames: + - prod.example.com + name: prod + org_id: organizations/project-id + module.apigee.google_apigee_envgroup_attachment.envgroup_attachments["apis-prod-prod"]: + environment: apis-prod + module.apigee.google_apigee_environment.environments["apis-prod"]: + description: Terraform-managed + display_name: APIs prod + name: apis-prod + org_id: organizations/project-id + module.apigee.google_apigee_instance.instances["europe-west1"]: + description: Terraform-managed + disk_encryption_key_name: null + display_name: null + ip_range: '' + location: europe-west1 + name: instance-europe-west1 + org_id: organizations/project-id + +counts: + google_apigee_envgroup: 1 + google_apigee_envgroup_attachment: 1 + google_apigee_environment: 1 + google_apigee_instance: 1 diff --git a/tests/modules/apigee/examples/minimal-cloud.yaml b/tests/modules/apigee/examples/minimal-cloud.yaml new file mode 100644 index 00000000..3a963de6 --- /dev/null +++ b/tests/modules/apigee/examples/minimal-cloud.yaml @@ -0,0 +1,50 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +values: + module.apigee.google_apigee_envgroup.envgroups["prod"]: + hostnames: + - prod.example.com + name: prod + module.apigee.google_apigee_envgroup_attachment.envgroup_attachments["apis-prod-prod"]: + environment: apis-prod + module.apigee.google_apigee_environment.environments["apis-prod"]: + description: APIs Prod + display_name: APIs prod + name: apis-prod + module.apigee.google_apigee_instance.instances["europe-west1"]: + description: Terraform-managed + disk_encryption_key_name: null + display_name: null + ip_range: 10.32.0.0/22,10.64.0.0/28 + location: europe-west1 + name: instance-europe-west1 + module.apigee.google_apigee_organization.organization[0]: + analytics_region: europe-west1 + authorized_network: projects/xxx/global/networks/aaa + billing_type: PAYG + description: null + disable_vpc_peering: false + display_name: null + project_id: project-id + retention: DELETION_RETENTION_UNSPECIFIED + runtime_database_encryption_key_name: null + runtime_type: CLOUD + +counts: + google_apigee_envgroup: 1 + google_apigee_envgroup_attachment: 1 + google_apigee_environment: 1 + google_apigee_instance: 1 + google_apigee_organization: 1 diff --git a/tests/modules/apigee/examples/no-peering.yaml b/tests/modules/apigee/examples/no-peering.yaml new file mode 100644 index 00000000..02c6a5ec --- /dev/null +++ b/tests/modules/apigee/examples/no-peering.yaml @@ -0,0 +1,50 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +values: + module.apigee.google_apigee_envgroup.envgroups["prod"]: + hostnames: + - prod.example.com + name: prod + module.apigee.google_apigee_envgroup_attachment.envgroup_attachments["apis-prod-prod"]: + environment: apis-prod + module.apigee.google_apigee_environment.environments["apis-prod"]: + description: Terraform-managed + display_name: APIs prod + name: apis-prod + module.apigee.google_apigee_instance.instances["europe-west1"]: + description: Terraform-managed + disk_encryption_key_name: null + display_name: null + ip_range: '' + location: europe-west1 + name: instance-europe-west1 + module.apigee.google_apigee_organization.organization[0]: + analytics_region: europe-west1 + authorized_network: null + billing_type: PAYG + description: null + disable_vpc_peering: true + display_name: null + project_id: project-id + retention: DELETION_RETENTION_UNSPECIFIED + runtime_database_encryption_key_name: null + runtime_type: CLOUD + +counts: + google_apigee_envgroup: 1 + google_apigee_envgroup_attachment: 1 + google_apigee_environment: 1 + google_apigee_instance: 1 + google_apigee_organization: 1 diff --git a/tests/modules/apigee/instance_only_psc_mode.tfvars b/tests/modules/apigee/instance_only_psc_mode.tfvars new file mode 100644 index 00000000..05fb2cd7 --- /dev/null +++ b/tests/modules/apigee/instance_only_psc_mode.tfvars @@ -0,0 +1,13 @@ +project_id = "my-project" +organization = { + display_name = "My Organization" + description = "My Organization" + runtime_type = "CLOUD" + billing_type = "Pay-as-you-go" + database_encryption_key = "123456789" + analytics_region = "europe-west1" + disable_vpc_peering = true +} +instances = { + europe-west1 = {} +} \ No newline at end of file diff --git a/tests/modules/apigee/instance_only_psc_mode.yaml b/tests/modules/apigee/instance_only_psc_mode.yaml new file mode 100644 index 00000000..4583d7b4 --- /dev/null +++ b/tests/modules/apigee/instance_only_psc_mode.yaml @@ -0,0 +1,35 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +values: + google_apigee_instance.instances["europe-west1"]: + description: Terraform-managed + disk_encryption_key_name: null + display_name: null + location: europe-west1 + name: instance-europe-west1 + google_apigee_organization.organization[0]: + analytics_region: europe-west1 + billing_type: Pay-as-you-go + description: null + display_name: null + project_id: my-project + retention: DELETION_RETENTION_UNSPECIFIED + runtime_database_encryption_key_name: '123456789' + runtime_type: CLOUD + disable_vpc_peering: true + +counts: + google_apigee_instance: 1 + google_apigee_organization: 1 \ No newline at end of file diff --git a/tests/modules/apigee/instance_only.tfvars b/tests/modules/apigee/instance_only_vpc_mode.tfvars similarity index 67% rename from tests/modules/apigee/instance_only.tfvars rename to tests/modules/apigee/instance_only_vpc_mode.tfvars index 58074946..2367a884 100644 --- a/tests/modules/apigee/instance_only.tfvars +++ b/tests/modules/apigee/instance_only_vpc_mode.tfvars @@ -2,6 +2,6 @@ project_id = "my-project" instances = { europe-west1 = { runtime_ip_cidr_range = "10.0.4.0/22" - troubleshooting_ip_cidr_range = "10.1.1.0.0/28" + troubleshooting_ip_cidr_range = "10.1.1.0/28" } -} +} \ No newline at end of file diff --git a/tests/modules/apigee/instance_only.yaml b/tests/modules/apigee/instance_only_vpc_mode.yaml similarity index 82% rename from tests/modules/apigee/instance_only.yaml rename to tests/modules/apigee/instance_only_vpc_mode.yaml index bc42a370..cf5e7841 100644 --- a/tests/modules/apigee/instance_only.yaml +++ b/tests/modules/apigee/instance_only_vpc_mode.yaml @@ -14,7 +14,10 @@ values: google_apigee_instance.instances["europe-west1"]: - ip_range: 10.0.4.0/22,10.1.1.0.0/28 + ip_range: 10.0.4.0/22,10.1.1.0/28 + description: Terraform-managed + disk_encryption_key_name: null + display_name: null location: europe-west1 name: "instance-europe-west1" org_id: organizations/my-project diff --git a/tests/modules/apigee/organization_only_psc_mode.tfvars b/tests/modules/apigee/organization_only_psc_mode.tfvars new file mode 100644 index 00000000..f4808db5 --- /dev/null +++ b/tests/modules/apigee/organization_only_psc_mode.tfvars @@ -0,0 +1,10 @@ +project_id = "my-project" +organization = { + display_name = "My Organization" + description = "My Organization" + runtime_type = "CLOUD" + billing_type = "PAYG" + database_encryption_key = "123456789" + analytics_region = "europe-west1" + disable_vpc_peering = true +} \ No newline at end of file diff --git a/tests/modules/apigee/organization_only_psc_mode.yaml b/tests/modules/apigee/organization_only_psc_mode.yaml new file mode 100644 index 00000000..2bc93b4f --- /dev/null +++ b/tests/modules/apigee/organization_only_psc_mode.yaml @@ -0,0 +1,29 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +values: + google_apigee_organization.organization[0]: + analytics_region: europe-west1 + authorized_network: null + billing_type: PAYG + description: null + display_name: null + project_id: my-project + retention: DELETION_RETENTION_UNSPECIFIED + runtime_database_encryption_key_name: '123456789' + runtime_type: CLOUD + disable_vpc_peering: true + +counts: + google_apigee_organization: 1 diff --git a/tests/modules/apigee/organization_only.tfvars b/tests/modules/apigee/organization_only_vpc_mode.tfvars similarity index 100% rename from tests/modules/apigee/organization_only.tfvars rename to tests/modules/apigee/organization_only_vpc_mode.tfvars diff --git a/tests/modules/apigee/organization_only.yaml b/tests/modules/apigee/organization_only_vpc_mode.yaml similarity index 100% rename from tests/modules/apigee/organization_only.yaml rename to tests/modules/apigee/organization_only_vpc_mode.yaml diff --git a/tests/modules/apigee/tftest.yaml b/tests/modules/apigee/tftest.yaml index f4a9944e..6449de75 100644 --- a/tests/modules/apigee/tftest.yaml +++ b/tests/modules/apigee/tftest.yaml @@ -15,13 +15,16 @@ module: modules/apigee tests: - all: + all_psc_mode: + all_vpc_mode: endpoint_attachment_only: env_only: env_only_with_api_proxy_type: env_only_with_deployment_type: envgroup_only: - instance_only: + instance_only_psc_mode: + instance_only_vpc_mode: no_instances: - organization_only: + organization_only_psc_mode: + organization_only_vpc_mode: organization_retention: diff --git a/tests/modules/compute_vm/examples/disk-options.yaml b/tests/modules/compute_vm/examples/disk-options.yaml index 1a4d58b2..f2f1a053 100644 --- a/tests/modules/compute_vm/examples/disk-options.yaml +++ b/tests/modules/compute_vm/examples/disk-options.yaml @@ -29,7 +29,6 @@ values: - device_name: data1 disk_encryption_key_raw: null mode: READ_WRITE - source: test-data1 boot_disk: - auto_delete: true disk_encryption_key_raw: null diff --git a/tests/modules/gke_cluster_autopilot/examples/monitoring-config-kube-state.yaml b/tests/modules/gke_cluster_autopilot/examples/monitoring-config-kube-state.yaml new file mode 100644 index 00000000..32e5bad5 --- /dev/null +++ b/tests/modules/gke_cluster_autopilot/examples/monitoring-config-kube-state.yaml @@ -0,0 +1,30 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +values: + module.cluster-1.google_container_cluster.cluster: + monitoring_config: + - enable_components: + - DAEMONSET + - DEPLOYMENT + - HPA + - POD + - STATEFULSET + - STORAGE + - SYSTEM_COMPONENTS + managed_prometheus: + - enabled: true + +counts: + google_container_cluster: 1 diff --git a/tests/modules/gke_cluster_autopilot/network_tags.tfvars b/tests/modules/gke_cluster_autopilot/network_tags.tfvars new file mode 100644 index 00000000..4b188f31 --- /dev/null +++ b/tests/modules/gke_cluster_autopilot/network_tags.tfvars @@ -0,0 +1,14 @@ +project_id = "my-project" +location = "europe-west1" +name = "cluster-1" +vpc_config = { + network = "default" + subnetwork = "default" +} +tags = [ + "deep-dark-wood", + "hello-gruffalo", + "my--precious---nodes", + "cluster-1-nodes", + "nodes-cluster-1", +] diff --git a/tests/modules/gke_cluster_autopilot/network_tags.yaml b/tests/modules/gke_cluster_autopilot/network_tags.yaml new file mode 100644 index 00000000..5ca48260 --- /dev/null +++ b/tests/modules/gke_cluster_autopilot/network_tags.yaml @@ -0,0 +1,27 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +values: + google_container_cluster.cluster: + node_pool_auto_config: + - network_tags: + - tags: + - cluster-1-nodes + - deep-dark-wood + - hello-gruffalo + - my--precious---nodes + - nodes-cluster-1 + +counts: + google_container_cluster: 1 diff --git a/tests/modules/gke_cluster_autopilot/tftest.yaml b/tests/modules/gke_cluster_autopilot/tftest.yaml new file mode 100644 index 00000000..18fc6235 --- /dev/null +++ b/tests/modules/gke_cluster_autopilot/tftest.yaml @@ -0,0 +1,18 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +module: modules/gke-cluster-autopilot + +tests: + network_tags: diff --git a/tests/modules/gke_cluster_standard/examples/monitoring-config-control-plane.yaml b/tests/modules/gke_cluster_standard/examples/monitoring-config-control-plane.yaml new file mode 100644 index 00000000..b3108770 --- /dev/null +++ b/tests/modules/gke_cluster_standard/examples/monitoring-config-control-plane.yaml @@ -0,0 +1,27 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +values: + module.cluster-1.google_container_cluster.cluster: + monitoring_config: + - enable_components: + - APISERVER + - CONTROLLER_MANAGER + - SCHEDULER + - SYSTEM_COMPONENTS + managed_prometheus: + - enabled: true + +counts: + google_container_cluster: 1 diff --git a/tests/modules/gke_cluster_standard/examples/monitoring-config-disable-all.yaml b/tests/modules/gke_cluster_standard/examples/monitoring-config-disable-all.yaml new file mode 100644 index 00000000..1b5576a4 --- /dev/null +++ b/tests/modules/gke_cluster_standard/examples/monitoring-config-disable-all.yaml @@ -0,0 +1,23 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +values: + module.cluster-1.google_container_cluster.cluster: + monitoring_config: + - enable_components: [] + managed_prometheus: + - enabled: false + +counts: + google_container_cluster: 1 diff --git a/tests/modules/gke_cluster_standard/examples/monitoring-config-kube-state.yaml b/tests/modules/gke_cluster_standard/examples/monitoring-config-kube-state.yaml new file mode 100644 index 00000000..32e5bad5 --- /dev/null +++ b/tests/modules/gke_cluster_standard/examples/monitoring-config-kube-state.yaml @@ -0,0 +1,30 @@ +# Copyright 2023 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +values: + module.cluster-1.google_container_cluster.cluster: + monitoring_config: + - enable_components: + - DAEMONSET + - DEPLOYMENT + - HPA + - POD + - STATEFULSET + - STORAGE + - SYSTEM_COMPONENTS + managed_prometheus: + - enabled: true + +counts: + google_container_cluster: 1 diff --git a/tests/modules/kms/examples/basic.yaml b/tests/modules/kms/examples/basic.yaml index e29297a1..30f40627 100644 --- a/tests/modules/kms/examples/basic.yaml +++ b/tests/modules/kms/examples/basic.yaml @@ -18,37 +18,26 @@ values: name: key-a purpose: ENCRYPT_DECRYPT rotation_period: null - skip_initial_version_creation: null - timeouts: null + skip_initial_version_creation: false module.kms.google_kms_crypto_key.default["key-b"]: labels: null name: key-b purpose: ENCRYPT_DECRYPT rotation_period: 604800s - skip_initial_version_creation: null - timeouts: null + skip_initial_version_creation: false module.kms.google_kms_crypto_key.default["key-c"]: labels: env: test name: key-c purpose: ENCRYPT_DECRYPT rotation_period: null - skip_initial_version_creation: null - timeouts: null - module.kms.google_kms_crypto_key_iam_binding.default["key-a.roles/cloudkms.admin"]: + skip_initial_version_creation: false + module.kms.google_kms_crypto_key_iam_binding.authoritative["key-a.roles/cloudkms.admin"]: condition: [] members: - user:user3@example.com role: roles/cloudkms.admin - ? module.kms.google_kms_crypto_key_iam_member.default["key-b.roles/cloudkms.cryptoKeyEncrypterDecrypteruser:user4@example.com"] - : condition: [] - member: user:user4@example.com - role: roles/cloudkms.cryptoKeyEncrypterDecrypter - ? module.kms.google_kms_crypto_key_iam_member.default["key-b.roles/cloudkms.cryptoKeyEncrypterDecrypteruser:user5@example.com"] - : condition: [] - member: user:user5@example.com - role: roles/cloudkms.cryptoKeyEncrypterDecrypter - module.kms.google_kms_crypto_key_iam_member.members["key-b-am1"]: + module.kms.google_kms_crypto_key_iam_member.members["key-b-iam1"]: condition: [] member: user:am1@example.com role: roles/cloudkms.cryptoKeyEncrypterDecrypter @@ -56,23 +45,9 @@ values: location: europe-west1 name: test project: my-project - timeouts: null - module.kms.google_kms_key_ring_iam_member.default["roles/cloudkms.cryptoKeyEncrypterDecrypteruser:user1@example.com"]: - condition: [] - member: user:user1@example.com - role: roles/cloudkms.cryptoKeyEncrypterDecrypter - module.kms.google_kms_key_ring_iam_member.default["roles/cloudkms.cryptoKeyEncrypterDecrypteruser:user2@example.com"]: - condition: [] - member: user:user2@example.com - role: roles/cloudkms.cryptoKeyEncrypterDecrypter counts: google_kms_crypto_key: 3 google_kms_crypto_key_iam_binding: 1 - google_kms_crypto_key_iam_member: 3 + google_kms_crypto_key_iam_member: 1 google_kms_key_ring: 1 - google_kms_key_ring_iam_member: 2 - modules: 1 - resources: 10 - -outputs: {} diff --git a/tests/modules/kms/examples/purpose.yaml b/tests/modules/kms/examples/purpose.yaml index c08779b2..9f97ad52 100644 --- a/tests/modules/kms/examples/purpose.yaml +++ b/tests/modules/kms/examples/purpose.yaml @@ -15,25 +15,19 @@ values: module.kms.google_kms_crypto_key.default["key-a"]: name: key-a - purpose: ENCRYPT_DECRYPT - module.kms.google_kms_crypto_key.default["key-b"]: - name: key-b - purpose: ENCRYPT_DECRYPT - module.kms.google_kms_crypto_key.default["key-c"]: - name: key-c purpose: ASYMMETRIC_SIGN version_template: - algorithm: EC_SIGN_P384_SHA384 - protection_level: SOFTWARE + protection_level: HSM module.kms.google_kms_key_ring.default[0]: location: europe-west1 name: test project: my-project counts: - google_kms_crypto_key: 3 + google_kms_crypto_key: 1 google_kms_key_ring: 1 modules: 1 - resources: 4 + resources: 2 outputs: {} diff --git a/tests/modules/net_vpc/examples/factory.yaml b/tests/modules/net_vpc/examples/factory.yaml index fb348397..50aa01e1 100644 --- a/tests/modules/net_vpc/examples/factory.yaml +++ b/tests/modules/net_vpc/examples/factory.yaml @@ -48,8 +48,7 @@ values: tags: null timeouts: null module.vpc.google_compute_subnetwork.proxy_only["europe-west4/subnet-proxy"]: - description: Terraform-managed proxy-only subnet for Regional HTTPS or Internal - HTTPS LB. + description: Terraform-managed proxy-only subnet for Regional HTTPS, Internal HTTPS or Cross-Regional HTTPS Internal LB. ip_cidr_range: 10.1.0.0/24 ipv6_access_type: null log_config: [] @@ -59,6 +58,17 @@ values: region: europe-west4 role: ACTIVE timeouts: null + module.vpc.google_compute_subnetwork.proxy_only["australia-southeast2/subnet-proxy-global"]: + description: Terraform-managed proxy-only subnet for Regional HTTPS, Internal HTTPS or Cross-Regional HTTPS Internal LB. + ip_cidr_range: 10.4.0.0/24 + ipv6_access_type: null + log_config: [] + name: subnet-proxy-global + project: my-project + purpose: GLOBAL_MANAGED_PROXY + region: australia-southeast2 + role: ACTIVE + timeouts: null module.vpc.google_compute_subnetwork.psc["europe-west4/subnet-psc"]: description: Terraform-managed subnet for Private Service Connect (PSC NAT). ip_cidr_range: 10.2.0.0/24 @@ -127,9 +137,9 @@ values: counts: google_compute_network: 1 google_compute_route: 2 - google_compute_subnetwork: 5 + google_compute_subnetwork: 6 google_compute_subnetwork_iam_binding: 1 modules: 1 - resources: 9 + resources: 10 outputs: {} diff --git a/tests/modules/net_vpc/examples/proxy-only-subnets.yaml b/tests/modules/net_vpc/examples/proxy-only-subnets.yaml index 6e2069aa..cf32912d 100644 --- a/tests/modules/net_vpc/examples/proxy-only-subnets.yaml +++ b/tests/modules/net_vpc/examples/proxy-only-subnets.yaml @@ -17,7 +17,7 @@ values: name: my-network project: my-project module.vpc.google_compute_subnetwork.proxy_only["europe-west1/regional-proxy"]: - description: Terraform-managed proxy-only subnet for Regional HTTPS or Internal HTTPS LB. + description: Terraform-managed proxy-only subnet for Regional HTTPS, Internal HTTPS or Cross-Regional HTTPS Internal LB. ip_cidr_range: 10.0.1.0/24 log_config: [] name: regional-proxy @@ -25,6 +25,15 @@ values: purpose: REGIONAL_MANAGED_PROXY region: europe-west1 role: ACTIVE + module.vpc.google_compute_subnetwork.proxy_only["australia-southeast2/global-proxy"]: + description: Terraform-managed proxy-only subnet for Regional HTTPS, Internal HTTPS or Cross-Regional HTTPS Internal LB. + ip_cidr_range: 10.0.4.0/24 + log_config: [] + name: global-proxy + project: my-project + purpose: GLOBAL_MANAGED_PROXY + region: australia-southeast2 + role: ACTIVE module.vpc.google_compute_subnetwork.psc["europe-west1/psc"]: description: Terraform-managed subnet for Private Service Connect (PSC NAT). ip_cidr_range: 10.0.3.0/24 @@ -37,4 +46,4 @@ values: counts: google_compute_network: 1 - google_compute_subnetwork: 2 + google_compute_subnetwork: 3 diff --git a/tests/modules/net_vpc/examples/subnet-iam.yaml b/tests/modules/net_vpc/examples/subnet-iam.yaml index 68b03418..1b925f48 100644 --- a/tests/modules/net_vpc/examples/subnet-iam.yaml +++ b/tests/modules/net_vpc/examples/subnet-iam.yaml @@ -80,7 +80,7 @@ values: region: europe-west1 role: roles/compute.networkUser subnetwork: subnet-1 - module.vpc.google_compute_subnetwork_iam_binding.bindings["europe-west1/subnet-1.roles/compute.networkUser.test_condition"]: + module.vpc.google_compute_subnetwork_iam_binding.bindings["subnet-1-iam"]: condition: - description: null expression: resource.matchTag('123456789012/env', 'prod') @@ -91,7 +91,7 @@ values: region: europe-west1 role: roles/compute.networkUser subnetwork: subnet-1 - module.vpc.google_compute_subnetwork_iam_member.bindings["subnet-2-am1"]: + module.vpc.google_compute_subnetwork_iam_member.bindings["subnet-2-iam"]: condition: [] member: user:am1@example.com project: my-project diff --git a/tests/modules/project/examples/iam-bindings.yaml b/tests/modules/project/examples/iam-bindings.yaml index f1f09e36..c9fee925 100644 --- a/tests/modules/project/examples/iam-bindings.yaml +++ b/tests/modules/project/examples/iam-bindings.yaml @@ -23,7 +23,7 @@ values: project_id: foo-project-example skip_delete: false timeouts: null - module.project.google_project_iam_binding.bindings["roles/resourcemanager.projectIamAdmin"]: + module.project.google_project_iam_binding.bindings["iam_admin_conditional"]: condition: - description: null expression: "api.getAttribute(\n 'iam.googleapis.com/modifiedGrantsByRole',\ @@ -54,4 +54,3 @@ counts: resources: 4 outputs: {} - diff --git a/tests/modules/pubsub/examples/simple.yaml b/tests/modules/pubsub/examples/simple.yaml index 51094a51..6fe54ec6 100644 --- a/tests/modules/pubsub/examples/simple.yaml +++ b/tests/modules/pubsub/examples/simple.yaml @@ -16,14 +16,14 @@ values: module.pubsub.google_pubsub_topic.default: name: my-topic project: my-project - module.pubsub.google_pubsub_topic_iam_binding.default["roles/pubsub.subscriber"]: + module.pubsub.google_pubsub_topic_iam_binding.authoritative["roles/pubsub.subscriber"]: condition: [] members: - user:user1@example.com project: my-project role: roles/pubsub.subscriber topic: my-topic - module.pubsub.google_pubsub_topic_iam_binding.default["roles/pubsub.viewer"]: + module.pubsub.google_pubsub_topic_iam_binding.authoritative["roles/pubsub.viewer"]: condition: [] members: - group:foo@example.com diff --git a/tests/modules/pubsub/examples/subscription-iam.yaml b/tests/modules/pubsub/examples/subscription-iam.yaml index d0fa9fb6..42ed2565 100644 --- a/tests/modules/pubsub/examples/subscription-iam.yaml +++ b/tests/modules/pubsub/examples/subscription-iam.yaml @@ -13,10 +13,10 @@ # limitations under the License. values: - module.pubsub.google_pubsub_subscription_iam_binding.default["test-1.roles/pubsub.subscriber"]: + module.pubsub.google_pubsub_subscription_iam_binding.authoritative["test-1.roles/pubsub.subscriber"]: condition: [] members: - - user:user1@ludomagno.net + - user:user1@example.com project: my-project role: roles/pubsub.subscriber subscription: test-1 diff --git a/tests/modules/pubsub/examples/subscriptions.yaml b/tests/modules/pubsub/examples/subscriptions.yaml index a87a6d47..b1a94212 100644 --- a/tests/modules/pubsub/examples/subscriptions.yaml +++ b/tests/modules/pubsub/examples/subscriptions.yaml @@ -16,22 +16,22 @@ values: module.pubsub.google_pubsub_subscription.default["test-pull"]: bigquery_config: [] dead_letter_policy: [] - enable_exactly_once_delivery: null - enable_message_ordering: null + enable_exactly_once_delivery: False + enable_message_ordering: False filter: null labels: null message_retention_duration: 604800s name: test-pull project: my-project push_config: [] - retain_acked_messages: null + retain_acked_messages: False retry_policy: [] topic: my-topic module.pubsub.google_pubsub_subscription.default["test-pull-override"]: bigquery_config: [] dead_letter_policy: [] - enable_exactly_once_delivery: null - enable_message_ordering: null + enable_exactly_once_delivery: False + enable_message_ordering: False filter: null labels: test: override @@ -39,7 +39,7 @@ values: name: test-pull-override project: my-project push_config: [] - retain_acked_messages: true + retain_acked_messages: True retry_policy: [] topic: my-topic module.pubsub.google_pubsub_topic.default: