fix
This commit is contained in:
@@ -1,31 +1,54 @@
|
||||
locals {
|
||||
pg_vars = merge([for pg in var.pg: {
|
||||
join("_",["LABEL_pg", pg.namespace, pg.name, pg.dbname]) = join("|",["pg", pg.namespace, pg.name, pg.dbname])
|
||||
join("_",["LABEL_pg", pg.namespace, pg.name, pg.dbname]) = join(" | ",["pg", pg.namespace, pg.name, pg.dbname])
|
||||
join("_",["ENGINE_pg", pg.namespace, pg.name, pg.dbname]) = "postgres@dbgate-plugin-postgres"
|
||||
join("_",["SERVER_pg", pg.namespace, pg.name, pg.dbname]) = join(".",[pg.name, pg.namespace, "svc"])
|
||||
join("_",["SERVER_pg", pg.namespace, pg.name, pg.dbname]) = join(".",["${pg.name}-rw", pg.namespace, "svc"])
|
||||
join("_",["PORT_pg", pg.namespace, pg.name, pg.dbname]) = "5432"
|
||||
join("_",["DATABASE_pg", pg.namespace, pg.name, pg.dbname]) = pg.dbname
|
||||
join("_",["USER_pg", pg.namespace, pg.name, pg.dbname]) = pg.username
|
||||
}]...)
|
||||
pg_secrets = merge([for pg in var.pg: {
|
||||
join("_",["PASSWORD_pg", pg.namespace, pg.name, pg.dbname]) = join("|",["pg", pg.namespace, pg.name, pg.dbname])
|
||||
join("_",["PASSWORD_pg", pg.namespace, pg.name, pg.dbname]) = data.kubernetes_secret_v1.pgs[index].data[var.pgs[index].secret.key]
|
||||
}]...)
|
||||
pg_conns = [for pg in var.pg: join("_",["pg", pg.namespace, pg.name, pg.dbname])]
|
||||
|
||||
maria_vars = merge([for m in var.maria: {
|
||||
join("_",["LABEL_maria", m.namespace, m.name]) = join("|",["maria", m.namespace, m.name])
|
||||
join("_",["LABEL_maria", m.namespace, m.name]) = join(" | ",["maria", m.namespace, m.name])
|
||||
join("_",["ENGINE_maria", m.namespace, m.name]) = "mysql@dbgate-plugin-mysql"
|
||||
join("_",["SERVER_maria", m.namespace, m.name]) = join(".",[m.name, m.namespace, "svc"])
|
||||
join("_",["SERVER_maria", m.namespace, m.name]) = join(".",["${m.name}-svc", m.namespace, "svc"])
|
||||
join("_",["PORT_maria", m.namespace, m.name]) = "3306"
|
||||
join("_",["DATABASE_maria", m.namespace, m.name]) = m.dbname
|
||||
join("_",["USER_maria", m.namespace, m.name]) = m.username
|
||||
}]...)
|
||||
maria_secrets = merge([for m in var.maria: {
|
||||
join("_",["PASSWORD_maria", m.namespace, m.name]) = join("|",["maria", m.namespace, m.name, m.dbname])
|
||||
maria_secrets = merge([for index, m in var.maria: {
|
||||
join("_",["PASSWORD_maria", m.namespace, m.name]) = "unimplemented"
|
||||
}]...)
|
||||
maria_conns = [for m in var.maria: join("_",["maria", m.namespace, m.name])]
|
||||
|
||||
connections = join(",",concat(local.pg_conns, local.maria_conns))
|
||||
connection_vars = merge(local.pg_vars, local.maria_vars)
|
||||
connection_secrets = merge(local.pg_secrets,local.maria_secrets)
|
||||
mongo_vars = merge([for m in var.mongo: {
|
||||
join("_",["LABEL_mongo", m.namespace, m.name]) = join(" | ",["mongo", m.namespace, m.name])
|
||||
join("_",["ENGINE_mongo", m.namespace, m.name]) = "mongo@dbgate-plugin-mongo"
|
||||
join("_",["SERVER_mongo", m.namespace, m.name]) = join(".",["${m.name}-svc", m.namespace, "svc"])
|
||||
join("_",["PORT_mongo", m.namespace, m.name]) = "3306"
|
||||
join("_",["DATABASE_mongo", m.namespace, m.name]) = m.dbname
|
||||
join("_",["USER_mongo", m.namespace, m.name]) = m.username
|
||||
}]...)
|
||||
mongo_secrets = merge([for index, m in var.mongo: {
|
||||
join("_",["PASSWORD_mongo", m.namespace, m.name]) = join(" | ",["mongo", m.namespace, m.name, m.dbname])
|
||||
}]...)
|
||||
mongo_conns = [for m in var.mongo: join("_",["mongo", m.namespace, m.name])]
|
||||
oauth_config = {
|
||||
"OAUTH_AUTH" = "https://${data.kubernetes_ingress_v1.authentik.spec[0].rule[0].host}/application/o/authorize/"
|
||||
"OAUTH_TOKEN" = "https://${data.kubernetes_ingress_v1.authentik.spec[0].rule[0].host}/application/o/token/"
|
||||
"OAUTH_LOGOUT" = "https://${data.kubernetes_ingress_v1.authentik.spec[0].rule[0].host}/application/o/${var.component}-${var.instance}/end-session/"
|
||||
"OAUTH_LOGIN_FIELD" = "nickname"
|
||||
"OAUTH_SCOPE" = "email"
|
||||
}
|
||||
|
||||
|
||||
connections = join(",",concat(local.pg_conns, local.maria_conns, local.mongo_conns))
|
||||
connection_vars = merge(local.pg_vars, local.maria_vars, local.mongo_vars)
|
||||
connection_secrets = merge(local.pg_secrets,local.mongo_secrets)
|
||||
}
|
||||
|
||||
resource "kubectl_manifest" "dbgate-config" {
|
||||
@@ -36,7 +59,7 @@ resource "kubectl_manifest" "dbgate-config" {
|
||||
name: "${var.component}-${var.instance}"
|
||||
namespace: "${var.namespace}"
|
||||
labels: ${jsonencode(local.common-labels)}
|
||||
data: ${jsonencode(local.connection_vars)}
|
||||
data: ${jsonencode(merge(local.oauth_config, local.connection_vars))}
|
||||
EOF
|
||||
}
|
||||
|
||||
@@ -47,3 +70,20 @@ resource "kubernetes_secret_v1" "dbgate-config-secret" {
|
||||
}
|
||||
data = local.connection_secrets
|
||||
}
|
||||
|
||||
|
||||
data "kubernetes_secret_v1" "pgs" {
|
||||
count = length(var.pg)
|
||||
metadata {
|
||||
name = "${var.pgs[count.index].secret.name}"
|
||||
namespace = "${var.pgs[count.index].namespace}"
|
||||
}
|
||||
}
|
||||
|
||||
data "kubernetes_secret_v1" "mongos" {
|
||||
count = length(var.mongo)
|
||||
metadata {
|
||||
name = "${var.pgs[count.index].secret.name}"
|
||||
namespace = "${var.pgs[count.index].namespace}"
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user