You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

190 lines
5.6 KiB

  1. terraform {
  2. required_version = ">= 0.8.7"
  3. }
  4. provider "aws" {
  5. access_key = "${var.AWS_ACCESS_KEY_ID}"
  6. secret_key = "${var.AWS_SECRET_ACCESS_KEY}"
  7. region = "${var.AWS_DEFAULT_REGION}"
  8. }
  9. /*
  10. * Calling modules who create the initial AWS VPC / AWS ELB
  11. * and AWS IAM Roles for Kubernetes Deployment
  12. */
  13. module "aws-vpc" {
  14. source = "modules/vpc"
  15. aws_cluster_name = "${var.aws_cluster_name}"
  16. aws_vpc_cidr_block = "${var.aws_vpc_cidr_block}"
  17. aws_avail_zones="${var.aws_avail_zones}"
  18. aws_cidr_subnets_private="${var.aws_cidr_subnets_private}"
  19. aws_cidr_subnets_public="${var.aws_cidr_subnets_public}"
  20. default_tags="${var.default_tags}"
  21. }
  22. module "aws-elb" {
  23. source = "modules/elb"
  24. aws_cluster_name="${var.aws_cluster_name}"
  25. aws_vpc_id="${module.aws-vpc.aws_vpc_id}"
  26. aws_avail_zones="${var.aws_avail_zones}"
  27. aws_subnet_ids_public="${module.aws-vpc.aws_subnet_ids_public}"
  28. aws_elb_api_port = "${var.aws_elb_api_port}"
  29. k8s_secure_api_port = "${var.k8s_secure_api_port}"
  30. default_tags="${var.default_tags}"
  31. }
  32. module "aws-iam" {
  33. source = "modules/iam"
  34. aws_cluster_name="${var.aws_cluster_name}"
  35. }
  36. /*
  37. * Create Bastion Instances in AWS
  38. *
  39. */
  40. resource "aws_instance" "bastion-server" {
  41. ami = "${var.aws_bastion_ami}"
  42. instance_type = "${var.aws_bastion_size}"
  43. count = "${length(var.aws_cidr_subnets_public)}"
  44. associate_public_ip_address = true
  45. availability_zone = "${element(var.aws_avail_zones,count.index)}"
  46. subnet_id = "${element(module.aws-vpc.aws_subnet_ids_public,count.index)}"
  47. vpc_security_group_ids = [ "${module.aws-vpc.aws_security_group}" ]
  48. key_name = "${var.AWS_SSH_KEY_NAME}"
  49. tags = "${merge(var.default_tags, map(
  50. "Name", "kubernetes-${var.aws_cluster_name}-bastion-${count.index}",
  51. "Cluster", "${var.aws_cluster_name}",
  52. "Role", "bastion-${var.aws_cluster_name}-${count.index}"
  53. ))}"
  54. }
  55. /*
  56. * Create K8s Master and worker nodes and etcd instances
  57. *
  58. */
  59. resource "aws_instance" "k8s-master" {
  60. ami = "${var.aws_cluster_ami}"
  61. instance_type = "${var.aws_kube_master_size}"
  62. count = "${var.aws_kube_master_num}"
  63. availability_zone = "${element(var.aws_avail_zones,count.index)}"
  64. subnet_id = "${element(module.aws-vpc.aws_subnet_ids_private,count.index)}"
  65. vpc_security_group_ids = [ "${module.aws-vpc.aws_security_group}" ]
  66. iam_instance_profile = "${module.aws-iam.kube-master-profile}"
  67. key_name = "${var.AWS_SSH_KEY_NAME}"
  68. tags = "${merge(var.default_tags, map(
  69. "Name", "kubernetes-${var.aws_cluster_name}-master${count.index}",
  70. "Cluster", "${var.aws_cluster_name}",
  71. "Role", "master"
  72. ))}"
  73. }
  74. resource "aws_elb_attachment" "attach_master_nodes" {
  75. count = "${var.aws_kube_master_num}"
  76. elb = "${module.aws-elb.aws_elb_api_id}"
  77. instance = "${element(aws_instance.k8s-master.*.id,count.index)}"
  78. }
  79. resource "aws_instance" "k8s-etcd" {
  80. ami = "${var.aws_cluster_ami}"
  81. instance_type = "${var.aws_etcd_size}"
  82. count = "${var.aws_etcd_num}"
  83. availability_zone = "${element(var.aws_avail_zones,count.index)}"
  84. subnet_id = "${element(module.aws-vpc.aws_subnet_ids_private,count.index)}"
  85. vpc_security_group_ids = [ "${module.aws-vpc.aws_security_group}" ]
  86. key_name = "${var.AWS_SSH_KEY_NAME}"
  87. tags = "${merge(var.default_tags, map(
  88. "Name", "kubernetes-${var.aws_cluster_name}-etcd${count.index}",
  89. "Cluster", "${var.aws_cluster_name}",
  90. "Role", "etcd"
  91. ))}"
  92. }
  93. resource "aws_instance" "k8s-worker" {
  94. ami = "${var.aws_cluster_ami}"
  95. instance_type = "${var.aws_kube_worker_size}"
  96. count = "${var.aws_kube_worker_num}"
  97. availability_zone = "${element(var.aws_avail_zones,count.index)}"
  98. subnet_id = "${element(module.aws-vpc.aws_subnet_ids_private,count.index)}"
  99. vpc_security_group_ids = [ "${module.aws-vpc.aws_security_group}" ]
  100. iam_instance_profile = "${module.aws-iam.kube-worker-profile}"
  101. key_name = "${var.AWS_SSH_KEY_NAME}"
  102. tags = "${merge(var.default_tags, map(
  103. "Name", "kubernetes-${var.aws_cluster_name}-worker${count.index}",
  104. "Cluster", "${var.aws_cluster_name}",
  105. "Role", "worker"
  106. ))}"
  107. }
  108. /*
  109. * Create Kubespray Inventory File
  110. *
  111. */
  112. data "template_file" "inventory" {
  113. template = "${file("${path.module}/templates/inventory.tpl")}"
  114. vars {
  115. public_ip_address_bastion = "${join("\n",formatlist("bastion ansible_host=%s" , aws_instance.bastion-server.*.public_ip))}"
  116. connection_strings_master = "${join("\n",formatlist("%s ansible_host=%s",aws_instance.k8s-master.*.tags.Name, aws_instance.k8s-master.*.private_ip))}"
  117. connection_strings_node = "${join("\n", formatlist("%s ansible_host=%s", aws_instance.k8s-worker.*.tags.Name, aws_instance.k8s-worker.*.private_ip))}"
  118. connection_strings_etcd = "${join("\n",formatlist("%s ansible_host=%s", aws_instance.k8s-etcd.*.tags.Name, aws_instance.k8s-etcd.*.private_ip))}"
  119. list_master = "${join("\n",aws_instance.k8s-master.*.tags.Name)}"
  120. list_node = "${join("\n",aws_instance.k8s-worker.*.tags.Name)}"
  121. list_etcd = "${join("\n",aws_instance.k8s-etcd.*.tags.Name)}"
  122. elb_api_fqdn = "apiserver_loadbalancer_domain_name=\"${module.aws-elb.aws_elb_api_fqdn}\""
  123. elb_api_port = "loadbalancer_apiserver.port=${var.aws_elb_api_port}"
  124. loadbalancer_apiserver_address = "loadbalancer_apiserver.address=${var.loadbalancer_apiserver_address}"
  125. }
  126. }
  127. resource "null_resource" "inventories" {
  128. provisioner "local-exec" {
  129. command = "echo '${data.template_file.inventory.rendered}' > ../../../inventory/hosts"
  130. }
  131. triggers {
  132. template = "${data.template_file.inventory.rendered}"
  133. }
  134. }