404 lines
17 KiB
HCL
404 lines
17 KiB
HCL
locals {
|
|
annotations = {
|
|
"vynil.solidite.fr/meta" = var.component
|
|
"vynil.solidite.fr/name" = var.namespace
|
|
}
|
|
annotations_default = {
|
|
"default.vynil.solidite.fr/sso_vynil" = var.sso_vynil
|
|
"default.vynil.solidite.fr/domain_name" = var.domain_name
|
|
"default.vynil.solidite.fr/timezone" = var.timezone
|
|
"default.vynil.solidite.fr/language" = var.language
|
|
"default.vynil.solidite.fr/domain" = var.domain
|
|
"default.vynil.solidite.fr/issuer" = var.issuer
|
|
"default.vynil.solidite.fr/ingress_class" = var.ingress_class
|
|
"default.vynil.solidite.fr/app_group" = var.app_group
|
|
"default.vynil.solidite.fr/backups.enable" = var.backups.enable
|
|
"default.vynil.solidite.fr/backups.use_barman" = var.backups.use_barman
|
|
"default.vynil.solidite.fr/backups.endpoint" = var.backups.endpoint
|
|
"default.vynil.solidite.fr/backups.secret_name" = var.backups.secret_name
|
|
"default.vynil.solidite.fr/backups.key_id_key" = var.backups.key_id_key
|
|
"default.vynil.solidite.fr/backups.secret_key" = var.backups.secret_key
|
|
"default.vynil.solidite.fr/backups.restic_key" = var.backups.restic_key
|
|
"default.vynil.solidite.fr/storage.volume.accessMode" = var.storage.volume.accessMode
|
|
"default.vynil.solidite.fr/storage.volume.class" = var.storage.volume.class
|
|
}
|
|
global = {
|
|
"sso_vynil" = var.sso_vynil
|
|
"domain_name" = var.domain_name
|
|
"timezone" = var.timezone
|
|
"language" = var.language
|
|
"domain" = var.domain
|
|
"issuer" = var.issuer
|
|
"ingress_class" = var.ingress_class
|
|
"app_group" = var.app_group
|
|
}
|
|
global-backups = {
|
|
"enable" = var.backups.enable
|
|
"use_barman" = var.backups.use_barman
|
|
"endpoint" = var.backups.endpoint
|
|
"secret_name" = var.backups.secret_name
|
|
"key_id_key" = var.backups.key_id_key
|
|
"secret_key" = var.backups.secret_key
|
|
"restic_key" = var.backups.restic_key
|
|
}
|
|
global-volume = {
|
|
"accessMode" = var.storage.volume.accessMode
|
|
"class" = var.storage.volume.class
|
|
}
|
|
grafana = merge(local.global,{ for k, v in var.grafana : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.grafana, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.grafana, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.grafana, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
prometheus = merge(local.global,{ for k, v in var.prometheus : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.prometheus, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.prometheus, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.prometheus, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
alertmanager = merge(local.global,{ for k, v in var.alertmanager : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.alertmanager, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.alertmanager, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.alertmanager, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
loki = merge(local.global,{ for k, v in var.loki : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.loki, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.loki, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.loki, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
promtail = merge(local.global,{ for k, v in var.promtail : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.promtail, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.promtail, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.promtail, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
alerts-core = merge(local.global,{ for k, v in var.alerts-core : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.alerts-core, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.alerts-core, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.alerts-core, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
alerts-containers = merge(local.global,{ for k, v in var.alerts-containers : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.alerts-containers, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.alerts-containers, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.alerts-containers, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
nodeExporter = merge(local.global,{ for k, v in var.node-exporter : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.node-exporter, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.node-exporter, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.node-exporter, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
kubeStateMetrics = merge(local.global,{ for k, v in var.kube-state-metrics : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.kube-state-metrics, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.kube-state-metrics, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.kube-state-metrics, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
monitorControlPlan = merge(local.global,{ for k, v in var.monitor-control-plan : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.monitor-control-plan, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.monitor-control-plan, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.monitor-control-plan, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
dashboards-cluster = merge(local.global,{ for k, v in var.dashboards-cluster : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.dashboards-cluster, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.dashboards-cluster, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.dashboards-cluster, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
dashboards-minimal = merge(local.global,{ for k, v in var.dashboards-minimal : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.dashboards-minimal, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.dashboards-minimal, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.dashboards-minimal, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
dashboards-namespace = merge(local.global,{ for k, v in var.dashboards-namespace : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.dashboards-namespace, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.dashboards-namespace, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.dashboards-namespace, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
dashboards-workload = merge(local.global,{ for k, v in var.dashboards-workload : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.dashboards-workload, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.dashboards-workload, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.dashboards-workload, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
pvc-autoresizer = merge(local.global,{ for k, v in var.pvc-autoresizer : k => v if !contains(["enable","storage","backups"],k) },{
|
|
backups = merge(local.global-backups, lookup(var.pvc-autoresizer, "backups", {}))
|
|
storage = merge({ for k, v in lookup(var.pvc-autoresizer, "storage", {}) : k => v if !contains(["volume"],k) }, {
|
|
volume = merge(local.global-volume, lookup(lookup(var.pvc-autoresizer, "storage", {}), "volume", {}))
|
|
})
|
|
})
|
|
}
|
|
|
|
resource "kubernetes_namespace_v1" "monitor-ns" {
|
|
count = ( var.grafana.enable || var.loki.enable || var.promtail.enable || var.prometheus.enable || var.alertmanager.enable || var.node-exporter.enable || var.kube-state-metrics.enable || var.monitor-control-plan.enable )? 1 : 0
|
|
metadata {
|
|
annotations = merge(local.annotations, local.annotations_default)
|
|
labels = merge(local.common_labels, local.annotations)
|
|
name = "${var.namespace}-monitor"
|
|
}
|
|
}
|
|
|
|
resource "kubectl_manifest" "alertmanager" {
|
|
count = var.alertmanager.enable ? 1 : 0
|
|
depends_on = [kubernetes_namespace_v1.monitor-ns]
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "alertmanager"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "alertmanager"
|
|
options: ${jsonencode(local.alertmanager)}
|
|
EOF
|
|
}
|
|
|
|
resource "kubectl_manifest" "prometheus" {
|
|
count = var.prometheus.enable ? 1 : 0
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "prometheus"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "prometheus"
|
|
options: ${jsonencode(local.prometheus)}
|
|
EOF
|
|
}
|
|
|
|
resource "kubectl_manifest" "nodeExporter" {
|
|
count = var.node-exporter.enable ? 1 : 0
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "node-exporter"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "node-exporter"
|
|
options: ${jsonencode(local.nodeExporter)}
|
|
EOF
|
|
}
|
|
|
|
resource "kubectl_manifest" "kubeStateMetrics" {
|
|
count = var.kube-state-metrics.enable ? 1 : 0
|
|
depends_on = [kubernetes_namespace_v1.monitor-ns]
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "kube-state-metrics"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "kube-state-metrics"
|
|
options: ${jsonencode(local.kubeStateMetrics)}
|
|
EOF
|
|
}
|
|
|
|
resource "kubectl_manifest" "monitorControlPlan" {
|
|
count = var.monitor-control-plan.enable ? 1 : 0
|
|
depends_on = [kubernetes_namespace_v1.monitor-ns]
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "monitor-control-plan"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "monitor-control-plan"
|
|
options: ${jsonencode(local.monitorControlPlan)}
|
|
EOF
|
|
}
|
|
|
|
resource "kubectl_manifest" "alerts-core" {
|
|
count = var.alerts-core.enable ? 1 : 0
|
|
depends_on = [kubernetes_namespace_v1.monitor-ns]
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "alerts-core"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "alerts-core"
|
|
options: ${jsonencode(local.alerts-core)}
|
|
EOF
|
|
}
|
|
resource "kubectl_manifest" "alerts-containers" {
|
|
count = var.alerts-containers.enable ? 1 : 0
|
|
depends_on = [kubernetes_namespace_v1.monitor-ns]
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "alerts-containers"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "alerts-containers"
|
|
options: ${jsonencode(local.alerts-containers)}
|
|
EOF
|
|
}
|
|
|
|
resource "kubectl_manifest" "dashboards-cluster" {
|
|
count = var.dashboards-cluster.enable ? 1 : 0
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "dashboards-cluster"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "dashboards-cluster"
|
|
options: ${jsonencode(local.dashboards-cluster)}
|
|
EOF
|
|
}
|
|
resource "kubectl_manifest" "dashboards-minimal" {
|
|
count = var.dashboards-minimal.enable ? 1 : 0
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "dashboards-minimal"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "dashboards-minimal"
|
|
options: ${jsonencode(local.dashboards-minimal)}
|
|
EOF
|
|
}
|
|
resource "kubectl_manifest" "dashboards-namespace" {
|
|
count = var.dashboards-namespace.enable ? 1 : 0
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "dashboards-namespace"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "dashboards-namespace"
|
|
options: ${jsonencode(local.dashboards-namespace)}
|
|
EOF
|
|
}
|
|
resource "kubectl_manifest" "dashboards-workload" {
|
|
count = var.dashboards-workload.enable ? 1 : 0
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "dashboards-workload"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "dashboards-workload"
|
|
options: ${jsonencode(local.dashboards-workload)}
|
|
EOF
|
|
}
|
|
|
|
resource "kubectl_manifest" "pvc-autoresizer" {
|
|
count = var.pvc-autoresizer.enable && ! var.conditions.only_localpath ? 1 : 0
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "pvc-autoresizer"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "pvc-autoresizer"
|
|
options: ${jsonencode(local.pvc-autoresizer)}
|
|
EOF
|
|
}
|
|
|
|
resource "kubectl_manifest" "grafana" {
|
|
count = var.grafana.enable ? 1 : 0
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "grafana"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "grafana"
|
|
options: ${jsonencode(local.grafana)}
|
|
EOF
|
|
}
|
|
|
|
resource "kubectl_manifest" "promtail" {
|
|
count = var.promtail.enable ? 1 : 0
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "promtail"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "promtail"
|
|
options: ${jsonencode(local.promtail)}
|
|
EOF
|
|
}
|
|
|
|
resource "kubectl_manifest" "loki" {
|
|
count = var.loki.enable ? 1 : 0
|
|
yaml_body = <<-EOF
|
|
apiVersion: "vynil.solidite.fr/v1"
|
|
kind: "Install"
|
|
metadata:
|
|
name: "loki"
|
|
namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
spec:
|
|
distrib: "${var.distributions.domain}"
|
|
category: "monitor"
|
|
component: "loki"
|
|
options: ${jsonencode(local.loki)}
|
|
EOF
|
|
}
|