forked from rancher/quickstart
-
Notifications
You must be signed in to change notification settings - Fork 0
/
infra.tf
152 lines (124 loc) · 4.2 KB
/
infra.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
# GCP infrastructure resources
resource "tls_private_key" "global_key" {
algorithm = "RSA"
rsa_bits = 2048
}
resource "local_sensitive_file" "ssh_private_key_pem" {
filename = "${path.module}/id_rsa"
content = tls_private_key.global_key.private_key_pem
file_permission = "0600"
}
resource "local_file" "ssh_public_key_openssh" {
filename = "${path.module}/id_rsa.pub"
content = tls_private_key.global_key.public_key_openssh
}
# GCP Public Compute Address for rancher server node
resource "google_compute_address" "rancher_server_address" {
name = "rancher-server-ipv4-address"
}
# GCP Public Compute Address for quickstart node
resource "google_compute_address" "quickstart_node_address" {
name = "quickstart-node-ipv4-address"
}
# Firewall Rule to allow all traffic
resource "google_compute_firewall" "rancher_fw_allowall" {
name = "${var.prefix}-rancher-allowall"
network = "default"
allow {
protocol = "all"
}
source_ranges = ["0.0.0.0/0"]
}
# GCP Compute Instance for creating a single node RKE cluster and installing the Rancher server
resource "google_compute_instance" "rancher_server" {
depends_on = [
google_compute_firewall.rancher_fw_allowall,
]
name = "${var.prefix}-rancher-server"
machine_type = var.machine_type
zone = var.gcp_zone
boot_disk {
initialize_params {
image = data.google_compute_image.sles.self_link
}
}
network_interface {
network = "default"
access_config {
nat_ip = google_compute_address.rancher_server_address.address
}
}
metadata = {
ssh-keys = "${local.node_username}:${tls_private_key.global_key.public_key_openssh}"
enable-oslogin = "FALSE"
}
provisioner "remote-exec" {
inline = [
"echo 'SSH connection worked'",
]
connection {
type = "ssh"
host = self.network_interface.0.access_config.0.nat_ip
user = local.node_username
private_key = tls_private_key.global_key.private_key_pem
}
}
}
# Rancher resources
module "rancher_common" {
source = "../rancher-common"
node_public_ip = google_compute_instance.rancher_server.network_interface.0.access_config.0.nat_ip
node_internal_ip = google_compute_instance.rancher_server.network_interface.0.network_ip
node_username = local.node_username
ssh_private_key_pem = tls_private_key.global_key.private_key_pem
rancher_kubernetes_version = var.rancher_kubernetes_version
cert_manager_version = var.cert_manager_version
rancher_version = var.rancher_version
rancher_helm_repository = var.rancher_helm_repository
rancher_server_dns = join(".", ["rancher", google_compute_instance.rancher_server.network_interface.0.access_config.0.nat_ip, "sslip.io"])
admin_password = var.rancher_server_admin_password
workload_kubernetes_version = var.workload_kubernetes_version
workload_cluster_name = "quickstart-gcp-custom"
}
# GCP compute instance for creating a single node workload cluster
resource "google_compute_instance" "quickstart_node" {
depends_on = [
google_compute_firewall.rancher_fw_allowall,
]
name = "${var.prefix}-quickstart-node"
machine_type = var.machine_type
zone = var.gcp_zone
boot_disk {
initialize_params {
image = data.google_compute_image.sles.self_link
}
}
network_interface {
network = "default"
access_config {
nat_ip = google_compute_address.quickstart_node_address.address
}
}
metadata = {
ssh-keys = "${local.node_username}:${tls_private_key.global_key.public_key_openssh}"
enable-oslogin = "FALSE"
}
metadata_startup_script = templatefile(
"${path.module}/files/userdata_quickstart_node.template",
{
register_command = module.rancher_common.custom_cluster_command
public_ip = google_compute_address.quickstart_node_address.address
}
)
provisioner "remote-exec" {
inline = [
"echo 'SSH connection worked'",
]
connection {
type = "ssh"
host = self.network_interface.0.access_config.0.nat_ip
user = local.node_username
private_key = tls_private_key.global_key.private_key_pem
}
}
}