Added PSC support to CloudSQL Module (#1874)
* Added Feature * Added PSC to CloudSQL module * Added psc to read replica * Changed variables * Updated README * Ran fmt * Removed old variables * Fix README * Fixed blueprints * Fix README * Fixed output * Added more outputs and bug fixes * Changed variable structure * Bug fix * Added PSC example.
This commit is contained in:
parent
56fcb4f88a
commit
98accdb3ad
|
@ -17,7 +17,13 @@ module "db" {
|
||||||
project_id = module.project.project_id
|
project_id = module.project.project_id
|
||||||
availability_type = var.sql_configuration.availability_type
|
availability_type = var.sql_configuration.availability_type
|
||||||
encryption_key_name = var.service_encryption_keys != null ? try(var.service_encryption_keys[var.regions.primary], null) : null
|
encryption_key_name = var.service_encryption_keys != null ? try(var.service_encryption_keys[var.regions.primary], null) : null
|
||||||
network = local.vpc_self_link
|
network_config = {
|
||||||
|
connectivity = {
|
||||||
|
psa_config = {
|
||||||
|
private_network = local.vpc_self_link
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
name = "${var.prefix}-db"
|
name = "${var.prefix}-db"
|
||||||
region = var.regions.primary
|
region = var.regions.primary
|
||||||
database_version = var.sql_configuration.database_version
|
database_version = var.sql_configuration.database_version
|
||||||
|
|
|
@ -22,7 +22,13 @@ module "cloudsql" {
|
||||||
database_version = local.cloudsql_conf.database_version
|
database_version = local.cloudsql_conf.database_version
|
||||||
deletion_protection = var.deletion_protection
|
deletion_protection = var.deletion_protection
|
||||||
databases = [local.cloudsql_conf.db]
|
databases = [local.cloudsql_conf.db]
|
||||||
network = local.network
|
network_config = {
|
||||||
|
connectivity = {
|
||||||
|
psa_config = {
|
||||||
|
private_network = local.network
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
prefix = var.prefix
|
prefix = var.prefix
|
||||||
region = var.region
|
region = var.region
|
||||||
tier = local.cloudsql_conf.tier
|
tier = local.cloudsql_conf.tier
|
||||||
|
|
|
@ -54,7 +54,13 @@ resource "google_vpc_access_connector" "connector" {
|
||||||
module "cloudsql" {
|
module "cloudsql" {
|
||||||
source = "../../../../modules/cloudsql-instance"
|
source = "../../../../modules/cloudsql-instance"
|
||||||
project_id = module.project.project_id
|
project_id = module.project.project_id
|
||||||
network = module.vpc.self_link
|
network_config = {
|
||||||
|
connectivity = {
|
||||||
|
psa_config = {
|
||||||
|
private_network = module.vpc.self_link
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
name = "${var.prefix}-mysql"
|
name = "${var.prefix}-mysql"
|
||||||
region = var.region
|
region = var.region
|
||||||
database_version = local.cloudsql_conf.database_version
|
database_version = local.cloudsql_conf.database_version
|
||||||
|
|
|
@ -33,7 +33,13 @@ module "vpc" {
|
||||||
module "db" {
|
module "db" {
|
||||||
source = "./fabric/modules/cloudsql-instance"
|
source = "./fabric/modules/cloudsql-instance"
|
||||||
project_id = module.project.project_id
|
project_id = module.project.project_id
|
||||||
network = module.vpc.self_link
|
network_config = {
|
||||||
|
connectivity = {
|
||||||
|
psa_config = {
|
||||||
|
private_network = module.vpc.self_link
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
name = "db"
|
name = "db"
|
||||||
region = "europe-west1"
|
region = "europe-west1"
|
||||||
database_version = "POSTGRES_13"
|
database_version = "POSTGRES_13"
|
||||||
|
@ -48,7 +54,13 @@ module "db" {
|
||||||
module "db" {
|
module "db" {
|
||||||
source = "./fabric/modules/cloudsql-instance"
|
source = "./fabric/modules/cloudsql-instance"
|
||||||
project_id = var.project_id
|
project_id = var.project_id
|
||||||
network = var.vpc.self_link
|
network_config = {
|
||||||
|
connectivity = {
|
||||||
|
psa_config = {
|
||||||
|
private_network = var.vpc.self_link
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
prefix = "myprefix"
|
prefix = "myprefix"
|
||||||
name = "db"
|
name = "db"
|
||||||
region = "europe-west1"
|
region = "europe-west1"
|
||||||
|
@ -69,7 +81,13 @@ module "db" {
|
||||||
module "db" {
|
module "db" {
|
||||||
source = "./fabric/modules/cloudsql-instance"
|
source = "./fabric/modules/cloudsql-instance"
|
||||||
project_id = var.project_id
|
project_id = var.project_id
|
||||||
network = var.vpc.self_link
|
network_config = {
|
||||||
|
connectivity = {
|
||||||
|
psa_config = {
|
||||||
|
private_network = var.vpc.self_link
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
name = "db"
|
name = "db"
|
||||||
region = "europe-west1"
|
region = "europe-west1"
|
||||||
database_version = "MYSQL_8_0"
|
database_version = "MYSQL_8_0"
|
||||||
|
@ -134,7 +152,13 @@ module "db" {
|
||||||
source = "./fabric/modules/cloudsql-instance"
|
source = "./fabric/modules/cloudsql-instance"
|
||||||
project_id = module.project.project_id
|
project_id = module.project.project_id
|
||||||
encryption_key_name = module.kms.keys["key-sql"].id
|
encryption_key_name = module.kms.keys["key-sql"].id
|
||||||
network = var.vpc.self_link
|
network_config = {
|
||||||
|
connectivity = {
|
||||||
|
psa_config = {
|
||||||
|
private_network = var.vpc.self_link
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
name = "db"
|
name = "db"
|
||||||
region = var.region
|
region = var.region
|
||||||
database_version = "POSTGRES_13"
|
database_version = "POSTGRES_13"
|
||||||
|
@ -144,6 +168,27 @@ module "db" {
|
||||||
# tftest modules=3 resources=10
|
# tftest modules=3 resources=10
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Instance with PSC enabled
|
||||||
|
|
||||||
|
```hcl
|
||||||
|
module "db" {
|
||||||
|
source = "./fabric/modules/cloudsql-instance"
|
||||||
|
project_id = var.project_id
|
||||||
|
network_config = {
|
||||||
|
connectivity = {
|
||||||
|
psc_allowed_consumer_projects = ["my-project-id"]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
prefix = "myprefix"
|
||||||
|
name = "db"
|
||||||
|
region = "europe-west1"
|
||||||
|
availability_type = "REGIONAL"
|
||||||
|
database_version = "POSTGRES_13"
|
||||||
|
tier = "db-g1-small"
|
||||||
|
}
|
||||||
|
# tftest modules=1 resources=1
|
||||||
|
```
|
||||||
|
|
||||||
### Enable public IP
|
### Enable public IP
|
||||||
|
|
||||||
Use `ipv_enabled` to create instances with a public IP.
|
Use `ipv_enabled` to create instances with a public IP.
|
||||||
|
@ -152,12 +197,18 @@ Use `ipv_enabled` to create instances with a public IP.
|
||||||
module "db" {
|
module "db" {
|
||||||
source = "./fabric/modules/cloudsql-instance"
|
source = "./fabric/modules/cloudsql-instance"
|
||||||
project_id = var.project_id
|
project_id = var.project_id
|
||||||
network = var.vpc.self_link
|
network_config = {
|
||||||
|
connectivity = {
|
||||||
|
public_ipv4 = true
|
||||||
|
psa_config = {
|
||||||
|
private_network = var.vpc.self_link
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
name = "db"
|
name = "db"
|
||||||
region = "europe-west1"
|
region = "europe-west1"
|
||||||
tier = "db-g1-small"
|
tier = "db-g1-small"
|
||||||
database_version = "MYSQL_8_0"
|
database_version = "MYSQL_8_0"
|
||||||
ipv4_enabled = true
|
|
||||||
replicas = {
|
replicas = {
|
||||||
replica1 = { region = "europe-west3", encryption_key_name = null }
|
replica1 = { region = "europe-west3", encryption_key_name = null }
|
||||||
}
|
}
|
||||||
|
@ -173,7 +224,13 @@ Provide `insights_config` (can be just empty `{}`) to enable [Query Insights](ht
|
||||||
module "db" {
|
module "db" {
|
||||||
source = "./fabric/modules/cloudsql-instance"
|
source = "./fabric/modules/cloudsql-instance"
|
||||||
project_id = var.project_id
|
project_id = var.project_id
|
||||||
network = var.vpc.self_link
|
network_config = {
|
||||||
|
connectivity = {
|
||||||
|
psa_config = {
|
||||||
|
private_network = var.vpc.self_link
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
name = "db"
|
name = "db"
|
||||||
region = "europe-west1"
|
region = "europe-west1"
|
||||||
database_version = "POSTGRES_13"
|
database_version = "POSTGRES_13"
|
||||||
|
@ -190,37 +247,33 @@ module "db" {
|
||||||
|
|
||||||
| name | description | type | required | default |
|
| name | description | type | required | default |
|
||||||
|---|---|:---:|:---:|:---:|
|
|---|---|:---:|:---:|:---:|
|
||||||
| [database_version](variables.tf#L83) | Database type and version to create. | <code>string</code> | ✓ | |
|
| [database_version](variables.tf#L68) | Database type and version to create. | <code>string</code> | ✓ | |
|
||||||
| [name](variables.tf#L167) | Name of primary instance. | <code>string</code> | ✓ | |
|
| [name](variables.tf#L146) | Name of primary instance. | <code>string</code> | ✓ | |
|
||||||
| [network](variables.tf#L172) | VPC self link where the instances will be deployed. Private Service Networking must be enabled and configured in this VPC. | <code>string</code> | ✓ | |
|
| [network_config](variables.tf#L151) | Network configuration for the instance. Only one between private_network and psc_config can be used. | <code title="object({ authorized_networks = optional(map(string)) require_ssl = optional(bool) connectivity = object({ public_ipv4 = optional(bool, false) psa_config = optional(object({ private_network = string allocated_ip_ranges = optional(object({ primary = optional(string) replica = optional(string) })) })) psc_allowed_consumer_projects = optional(list(string)) }) })">object({…})</code> | ✓ | |
|
||||||
| [project_id](variables.tf#L193) | The ID of the project where this instances will be created. | <code>string</code> | ✓ | |
|
| [project_id](variables.tf#L190) | The ID of the project where this instances will be created. | <code>string</code> | ✓ | |
|
||||||
| [region](variables.tf#L198) | Region of the primary instance. | <code>string</code> | ✓ | |
|
| [region](variables.tf#L195) | Region of the primary instance. | <code>string</code> | ✓ | |
|
||||||
| [tier](variables.tf#L224) | The machine type to use for the instances. | <code>string</code> | ✓ | |
|
| [tier](variables.tf#L215) | The machine type to use for the instances. | <code>string</code> | ✓ | |
|
||||||
| [activation_policy](variables.tf#L16) | This variable specifies when the instance should be active. Can be either ALWAYS, NEVER or ON_DEMAND. Default is ALWAYS. | <code>string</code> | | <code>"ALWAYS"</code> |
|
| [activation_policy](variables.tf#L16) | This variable specifies when the instance should be active. Can be either ALWAYS, NEVER or ON_DEMAND. Default is ALWAYS. | <code>string</code> | | <code>"ALWAYS"</code> |
|
||||||
| [allocated_ip_ranges](variables.tf#L27) | (Optional)The name of the allocated ip range for the private ip CloudSQL instance. For example: \"google-managed-services-default\". If set, the instance ip will be created in the allocated range. The range name must comply with RFC 1035. Specifically, the name must be 1-63 characters long and match the regular expression a-z?. | <code title="object({ primary = optional(string) replica = optional(string) })">object({…})</code> | | <code>{}</code> |
|
| [availability_type](variables.tf#L27) | Availability type for the primary replica. Either `ZONAL` or `REGIONAL`. | <code>string</code> | | <code>"ZONAL"</code> |
|
||||||
| [authorized_networks](variables.tf#L36) | Map of NAME=>CIDR_RANGE to allow to connect to the database(s). | <code>map(string)</code> | | <code>null</code> |
|
| [backup_configuration](variables.tf#L33) | Backup settings for primary instance. Will be automatically enabled if using MySQL with one or more replicas. | <code title="object({ enabled = optional(bool, false) binary_log_enabled = optional(bool, false) start_time = optional(string, "23:00") location = optional(string) log_retention_days = optional(number, 7) point_in_time_recovery_enabled = optional(bool) retention_count = optional(number, 7) })">object({…})</code> | | <code title="{ enabled = false binary_log_enabled = false start_time = "23:00" location = null log_retention_days = 7 point_in_time_recovery_enabled = null retention_count = 7 }">{…}</code> |
|
||||||
| [availability_type](variables.tf#L42) | Availability type for the primary replica. Either `ZONAL` or `REGIONAL`. | <code>string</code> | | <code>"ZONAL"</code> |
|
| [collation](variables.tf#L56) | The name of server instance collation. | <code>string</code> | | <code>null</code> |
|
||||||
| [backup_configuration](variables.tf#L48) | Backup settings for primary instance. Will be automatically enabled if using MySQL with one or more replicas. | <code title="object({ enabled = optional(bool, false) binary_log_enabled = optional(bool, false) start_time = optional(string, "23:00") location = optional(string) log_retention_days = optional(number, 7) point_in_time_recovery_enabled = optional(bool) retention_count = optional(number, 7) })">object({…})</code> | | <code title="{ enabled = false binary_log_enabled = false start_time = "23:00" location = null log_retention_days = 7 point_in_time_recovery_enabled = null retention_count = 7 }">{…}</code> |
|
| [connector_enforcement](variables.tf#L62) | Specifies if connections must use Cloud SQL connectors. | <code>string</code> | | <code>null</code> |
|
||||||
| [collation](variables.tf#L71) | The name of server instance collation. | <code>string</code> | | <code>null</code> |
|
| [databases](variables.tf#L73) | Databases to create once the primary instance is created. | <code>list(string)</code> | | <code>null</code> |
|
||||||
| [connector_enforcement](variables.tf#L77) | Specifies if connections must use Cloud SQL connectors. | <code>string</code> | | <code>null</code> |
|
| [deletion_protection](variables.tf#L79) | Prevent terraform from deleting instances. | <code>bool</code> | | <code>true</code> |
|
||||||
| [databases](variables.tf#L88) | Databases to create once the primary instance is created. | <code>list(string)</code> | | <code>null</code> |
|
| [deletion_protection_enabled](variables.tf#L86) | Set Google's deletion protection attribute which applies across all surfaces (UI, API, & Terraform). | <code>bool</code> | | <code>true</code> |
|
||||||
| [deletion_protection](variables.tf#L94) | Prevent terraform from deleting instances. | <code>bool</code> | | <code>true</code> |
|
| [disk_autoresize_limit](variables.tf#L93) | The maximum size to which storage capacity can be automatically increased. The default value is 0, which specifies that there is no limit. | <code>number</code> | | <code>0</code> |
|
||||||
| [deletion_protection_enabled](variables.tf#L101) | Set Google's deletion protection attribute which applies across all surfaces (UI, API, & Terraform). | <code>bool</code> | | <code>true</code> |
|
| [disk_size](variables.tf#L99) | Disk size in GB. Set to null to enable autoresize. | <code>number</code> | | <code>null</code> |
|
||||||
| [disk_autoresize_limit](variables.tf#L108) | The maximum size to which storage capacity can be automatically increased. The default value is 0, which specifies that there is no limit. | <code>number</code> | | <code>0</code> |
|
| [disk_type](variables.tf#L105) | The type of data disk: `PD_SSD` or `PD_HDD`. | <code>string</code> | | <code>"PD_SSD"</code> |
|
||||||
| [disk_size](variables.tf#L114) | Disk size in GB. Set to null to enable autoresize. | <code>number</code> | | <code>null</code> |
|
| [edition](variables.tf#L111) | The edition of the instance, can be ENTERPRISE or ENTERPRISE_PLUS. | <code>string</code> | | <code>"ENTERPRISE"</code> |
|
||||||
| [disk_type](variables.tf#L120) | The type of data disk: `PD_SSD` or `PD_HDD`. | <code>string</code> | | <code>"PD_SSD"</code> |
|
| [encryption_key_name](variables.tf#L117) | The full path to the encryption key used for the CMEK disk encryption of the primary instance. | <code>string</code> | | <code>null</code> |
|
||||||
| [edition](variables.tf#L126) | The edition of the instance, can be ENTERPRISE or ENTERPRISE_PLUS. | <code>string</code> | | <code>"ENTERPRISE"</code> |
|
| [flags](variables.tf#L123) | Map FLAG_NAME=>VALUE for database-specific tuning. | <code>map(string)</code> | | <code>null</code> |
|
||||||
| [encryption_key_name](variables.tf#L132) | The full path to the encryption key used for the CMEK disk encryption of the primary instance. | <code>string</code> | | <code>null</code> |
|
| [insights_config](variables.tf#L129) | Query Insights configuration. Defaults to null which disables Query Insights. | <code title="object({ query_string_length = optional(number, 1024) record_application_tags = optional(bool, false) record_client_address = optional(bool, false) query_plans_per_minute = optional(number, 5) })">object({…})</code> | | <code>null</code> |
|
||||||
| [flags](variables.tf#L138) | Map FLAG_NAME=>VALUE for database-specific tuning. | <code>map(string)</code> | | <code>null</code> |
|
| [labels](variables.tf#L140) | Labels to be attached to all instances. | <code>map(string)</code> | | <code>null</code> |
|
||||||
| [insights_config](variables.tf#L144) | Query Insights configuration. Defaults to null which disables Query Insights. | <code title="object({ query_string_length = optional(number, 1024) record_application_tags = optional(bool, false) record_client_address = optional(bool, false) query_plans_per_minute = optional(number, 5) })">object({…})</code> | | <code>null</code> |
|
| [postgres_client_certificates](variables.tf#L174) | Map of cert keys connect to the application(s) using public IP. | <code>list(string)</code> | | <code>null</code> |
|
||||||
| [ipv4_enabled](variables.tf#L155) | Add a public IP address to database instance. | <code>bool</code> | | <code>false</code> |
|
| [prefix](variables.tf#L180) | Optional prefix used to generate instance names. | <code>string</code> | | <code>null</code> |
|
||||||
| [labels](variables.tf#L161) | Labels to be attached to all instances. | <code>map(string)</code> | | <code>null</code> |
|
| [replicas](variables.tf#L200) | Map of NAME=> {REGION, KMS_KEY} for additional read replicas. Set to null to disable replica creation. | <code title="map(object({ region = string encryption_key_name = string }))">map(object({…}))</code> | | <code>{}</code> |
|
||||||
| [postgres_client_certificates](variables.tf#L177) | Map of cert keys connect to the application(s) using public IP. | <code>list(string)</code> | | <code>null</code> |
|
| [root_password](variables.tf#L209) | Root password of the Cloud SQL instance. Required for MS SQL Server. | <code>string</code> | | <code>null</code> |
|
||||||
| [prefix](variables.tf#L183) | Optional prefix used to generate instance names. | <code>string</code> | | <code>null</code> |
|
| [users](variables.tf#L220) | Map of users to create in the primary instance (and replicated to other replicas). For MySQL, anything afterr the first `@` (if persent) will be used as the user's host. Set PASSWORD to null if you want to get an autogenerated password. The user types available are: 'BUILT_IN', 'CLOUD_IAM_USER' or 'CLOUD_IAM_SERVICE_ACCOUNT'. | <code title="map(object({ password = optional(string) type = optional(string) }))">map(object({…}))</code> | | <code>null</code> |
|
||||||
| [replicas](variables.tf#L203) | Map of NAME=> {REGION, KMS_KEY} for additional read replicas. Set to null to disable replica creation. | <code title="map(object({ region = string encryption_key_name = string }))">map(object({…}))</code> | | <code>{}</code> |
|
|
||||||
| [require_ssl](variables.tf#L212) | Enable SSL connections only. | <code>bool</code> | | <code>null</code> |
|
|
||||||
| [root_password](variables.tf#L218) | Root password of the Cloud SQL instance. Required for MS SQL Server. | <code>string</code> | | <code>null</code> |
|
|
||||||
| [users](variables.tf#L229) | Map of users to create in the primary instance (and replicated to other replicas). For MySQL, anything afterr the first `@` (if persent) will be used as the user's host. Set PASSWORD to null if you want to get an autogenerated password. The user types available are: 'BUILT_IN', 'CLOUD_IAM_USER' or 'CLOUD_IAM_SERVICE_ACCOUNT'. | <code title="map(object({ password = optional(string) type = optional(string) }))">map(object({…}))</code> | | <code>null</code> |
|
|
||||||
|
|
||||||
## Outputs
|
## Outputs
|
||||||
|
|
||||||
|
@ -228,15 +281,19 @@ module "db" {
|
||||||
|---|---|:---:|
|
|---|---|:---:|
|
||||||
| [connection_name](outputs.tf#L24) | Connection name of the primary instance. | |
|
| [connection_name](outputs.tf#L24) | Connection name of the primary instance. | |
|
||||||
| [connection_names](outputs.tf#L29) | Connection names of all instances. | |
|
| [connection_names](outputs.tf#L29) | Connection names of all instances. | |
|
||||||
| [id](outputs.tf#L37) | Fully qualified primary instance id. | |
|
| [dns_name](outputs.tf#L37) | The dns name of the instance. | |
|
||||||
| [ids](outputs.tf#L42) | Fully qualified ids of all instances. | |
|
| [dns_names](outputs.tf#L42) | Dns names of all instances. | |
|
||||||
| [instances](outputs.tf#L50) | Cloud SQL instance resources. | ✓ |
|
| [id](outputs.tf#L50) | Fully qualified primary instance id. | |
|
||||||
| [ip](outputs.tf#L56) | IP address of the primary instance. | |
|
| [ids](outputs.tf#L55) | Fully qualified ids of all instances. | |
|
||||||
| [ips](outputs.tf#L61) | IP addresses of all instances. | |
|
| [instances](outputs.tf#L63) | Cloud SQL instance resources. | ✓ |
|
||||||
| [name](outputs.tf#L69) | Name of the primary instance. | |
|
| [ip](outputs.tf#L69) | IP address of the primary instance. | |
|
||||||
| [names](outputs.tf#L74) | Names of all instances. | |
|
| [ips](outputs.tf#L74) | IP addresses of all instances. | |
|
||||||
| [postgres_client_certificates](outputs.tf#L82) | The CA Certificate used to connect to the SQL Instance via SSL. | ✓ |
|
| [name](outputs.tf#L82) | Name of the primary instance. | |
|
||||||
| [self_link](outputs.tf#L88) | Self link of the primary instance. | |
|
| [names](outputs.tf#L87) | Names of all instances. | |
|
||||||
| [self_links](outputs.tf#L93) | Self links of all instances. | |
|
| [postgres_client_certificates](outputs.tf#L95) | The CA Certificate used to connect to the SQL Instance via SSL. | ✓ |
|
||||||
| [user_passwords](outputs.tf#L101) | Map of containing the password of all users created through terraform. | ✓ |
|
| [psc_service_attachment_link](outputs.tf#L101) | The link to service attachment of PSC instance. | |
|
||||||
|
| [psc_service_attachment_links](outputs.tf#L106) | Links to service attachment of PSC instances. | |
|
||||||
|
| [self_link](outputs.tf#L114) | Self link of the primary instance. | |
|
||||||
|
| [self_links](outputs.tf#L119) | Self links of all instances. | |
|
||||||
|
| [user_passwords](outputs.tf#L127) | Map of containing the password of all users created through terraform. | ✓ |
|
||||||
<!-- END TFDOC -->
|
<!-- END TFDOC -->
|
||||||
|
|
|
@ -68,18 +68,25 @@ resource "google_sql_database_instance" "primary" {
|
||||||
connector_enforcement = var.connector_enforcement
|
connector_enforcement = var.connector_enforcement
|
||||||
|
|
||||||
ip_configuration {
|
ip_configuration {
|
||||||
ipv4_enabled = var.ipv4_enabled
|
ipv4_enabled = var.network_config.connectivity.public_ipv4
|
||||||
private_network = var.network
|
private_network = try(var.network_config.connectivity.psa_config.private_network, null)
|
||||||
allocated_ip_range = var.allocated_ip_ranges.primary
|
allocated_ip_range = try(var.network_config.connectivity.psa_config.allocated_ip_ranges.primary, null)
|
||||||
require_ssl = var.require_ssl
|
require_ssl = var.network_config.require_ssl
|
||||||
dynamic "authorized_networks" {
|
dynamic "authorized_networks" {
|
||||||
for_each = var.authorized_networks != null ? var.authorized_networks : {}
|
for_each = var.network_config.authorized_networks != null ? var.network_config.authorized_networks : {}
|
||||||
iterator = network
|
iterator = network
|
||||||
content {
|
content {
|
||||||
name = network.key
|
name = network.key
|
||||||
value = network.value
|
value = network.value
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
dynamic "psc_config" {
|
||||||
|
for_each = var.network_config.connectivity.psc_allowed_consumer_projects != null ? [""] : []
|
||||||
|
content {
|
||||||
|
psc_enabled = true
|
||||||
|
allowed_consumer_projects = var.network_config.connectivity.psc_allowed_consumer_projects
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
dynamic "backup_configuration" {
|
dynamic "backup_configuration" {
|
||||||
|
@ -149,17 +156,24 @@ resource "google_sql_database_instance" "replicas" {
|
||||||
activation_policy = var.activation_policy
|
activation_policy = var.activation_policy
|
||||||
|
|
||||||
ip_configuration {
|
ip_configuration {
|
||||||
ipv4_enabled = var.ipv4_enabled
|
ipv4_enabled = var.network_config.connectivity.public_ipv4
|
||||||
private_network = var.network
|
private_network = try(var.network_config.connectivity.psa_config.private_network, null)
|
||||||
allocated_ip_range = var.allocated_ip_ranges.replica
|
allocated_ip_range = try(var.network_config.connectivity.psa_config.allocated_ip_ranges.replica, null)
|
||||||
dynamic "authorized_networks" {
|
dynamic "authorized_networks" {
|
||||||
for_each = var.authorized_networks != null ? var.authorized_networks : {}
|
for_each = var.network_config.authorized_networks != null ? var.network_config.authorized_networks : {}
|
||||||
iterator = network
|
iterator = network
|
||||||
content {
|
content {
|
||||||
name = network.key
|
name = network.key
|
||||||
value = network.value
|
value = network.value
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
dynamic "psc_config" {
|
||||||
|
for_each = var.network_config.connectivity.psc_allowed_consumer_projects != null ? [""] : []
|
||||||
|
content {
|
||||||
|
psc_enabled = true
|
||||||
|
allowed_consumer_projects = var.network_config.connectivity.psc_allowed_consumer_projects
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
dynamic "database_flags" {
|
dynamic "database_flags" {
|
||||||
|
|
|
@ -34,6 +34,19 @@ output "connection_names" {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
output "dns_name" {
|
||||||
|
description = "The dns name of the instance."
|
||||||
|
value = google_sql_database_instance.primary.dns_name
|
||||||
|
}
|
||||||
|
|
||||||
|
output "dns_names" {
|
||||||
|
description = "Dns names of all instances."
|
||||||
|
value = {
|
||||||
|
for id, instance in local._all_instances :
|
||||||
|
id => instance.dns_name
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
output "id" {
|
output "id" {
|
||||||
description = "Fully qualified primary instance id."
|
description = "Fully qualified primary instance id."
|
||||||
value = google_sql_database_instance.primary.private_ip_address
|
value = google_sql_database_instance.primary.private_ip_address
|
||||||
|
@ -85,6 +98,19 @@ output "postgres_client_certificates" {
|
||||||
sensitive = true
|
sensitive = true
|
||||||
}
|
}
|
||||||
|
|
||||||
|
output "psc_service_attachment_link" {
|
||||||
|
description = "The link to service attachment of PSC instance."
|
||||||
|
value = google_sql_database_instance.primary.psc_service_attachment_link
|
||||||
|
}
|
||||||
|
|
||||||
|
output "psc_service_attachment_links" {
|
||||||
|
description = "Links to service attachment of PSC instances."
|
||||||
|
value = {
|
||||||
|
for id, instance in local._all_instances :
|
||||||
|
id => instance.psc_service_attachment_link
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
output "self_link" {
|
output "self_link" {
|
||||||
description = "Self link of the primary instance."
|
description = "Self link of the primary instance."
|
||||||
value = google_sql_database_instance.primary.self_link
|
value = google_sql_database_instance.primary.self_link
|
||||||
|
|
|
@ -24,21 +24,6 @@ variable "activation_policy" {
|
||||||
nullable = false
|
nullable = false
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "allocated_ip_ranges" {
|
|
||||||
description = "(Optional)The name of the allocated ip range for the private ip CloudSQL instance. For example: \"google-managed-services-default\". If set, the instance ip will be created in the allocated range. The range name must comply with RFC 1035. Specifically, the name must be 1-63 characters long and match the regular expression a-z?."
|
|
||||||
type = object({
|
|
||||||
primary = optional(string)
|
|
||||||
replica = optional(string)
|
|
||||||
})
|
|
||||||
default = {}
|
|
||||||
nullable = false
|
|
||||||
}
|
|
||||||
variable "authorized_networks" {
|
|
||||||
description = "Map of NAME=>CIDR_RANGE to allow to connect to the database(s)."
|
|
||||||
type = map(string)
|
|
||||||
default = null
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "availability_type" {
|
variable "availability_type" {
|
||||||
description = "Availability type for the primary replica. Either `ZONAL` or `REGIONAL`."
|
description = "Availability type for the primary replica. Either `ZONAL` or `REGIONAL`."
|
||||||
type = string
|
type = string
|
||||||
|
@ -152,12 +137,6 @@ variable "insights_config" {
|
||||||
default = null
|
default = null
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "ipv4_enabled" {
|
|
||||||
description = "Add a public IP address to database instance."
|
|
||||||
type = bool
|
|
||||||
default = false
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "labels" {
|
variable "labels" {
|
||||||
description = "Labels to be attached to all instances."
|
description = "Labels to be attached to all instances."
|
||||||
type = map(string)
|
type = map(string)
|
||||||
|
@ -169,9 +148,27 @@ variable "name" {
|
||||||
type = string
|
type = string
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "network" {
|
variable "network_config" {
|
||||||
description = "VPC self link where the instances will be deployed. Private Service Networking must be enabled and configured in this VPC."
|
description = "Network configuration for the instance. Only one between private_network and psc_config can be used."
|
||||||
type = string
|
type = object({
|
||||||
|
authorized_networks = optional(map(string))
|
||||||
|
require_ssl = optional(bool)
|
||||||
|
connectivity = object({
|
||||||
|
public_ipv4 = optional(bool, false)
|
||||||
|
psa_config = optional(object({
|
||||||
|
private_network = string
|
||||||
|
allocated_ip_ranges = optional(object({
|
||||||
|
primary = optional(string)
|
||||||
|
replica = optional(string)
|
||||||
|
}))
|
||||||
|
}))
|
||||||
|
psc_allowed_consumer_projects = optional(list(string))
|
||||||
|
})
|
||||||
|
})
|
||||||
|
validation {
|
||||||
|
condition = (var.network_config.connectivity.psa_config != null ? 1 : 0) + (var.network_config.connectivity.psc_allowed_consumer_projects != null ? 1 : 0) < 2
|
||||||
|
error_message = "Only one between private network and psc can be specified."
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "postgres_client_certificates" {
|
variable "postgres_client_certificates" {
|
||||||
|
@ -209,12 +206,6 @@ variable "replicas" {
|
||||||
default = {}
|
default = {}
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "require_ssl" {
|
|
||||||
description = "Enable SSL connections only."
|
|
||||||
type = bool
|
|
||||||
default = null
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "root_password" {
|
variable "root_password" {
|
||||||
description = "Root password of the Cloud SQL instance. Required for MS SQL Server."
|
description = "Root password of the Cloud SQL instance. Required for MS SQL Server."
|
||||||
type = string
|
type = string
|
||||||
|
|
Loading…
Reference in New Issue