117 lines
5.4 KiB
HCL
117 lines
5.4 KiB
HCL
locals {
|
|
pg = concat(var.pg, var.detected.pgs)
|
|
pg_vars = merge([for pg in local.pg: {
|
|
join("_",["LABEL_pg", pg.namespace, pg.name, pg.dbname]) = join(" | ",[pg.namespace, pg.name, pg.dbname])
|
|
join("_",["ENGINE_pg", pg.namespace, pg.name, pg.dbname]) = "postgres@dbgate-plugin-postgres"
|
|
join("_",["SERVER_pg", pg.namespace, pg.name, pg.dbname]) = join(".",["${pg.name}-rw", pg.namespace, "svc"])
|
|
join("_",["PORT_pg", pg.namespace, pg.name, pg.dbname]) = "5432"
|
|
join("_",["DATABASE_pg", pg.namespace, pg.name, pg.dbname]) = pg.dbname
|
|
join("_",["USER_pg", pg.namespace, pg.name, pg.dbname]) = pg.username
|
|
}]...)
|
|
pg_secrets = merge([for index, pg in local.pg: {
|
|
join("_",["PASSWORD_pg", pg.namespace, pg.name, pg.dbname]) = lookup(coalesce(data.kubernetes_secret_v1.pgs[index].data,{}),lookup(pg.secret,"key", "password"), "not-found")
|
|
}]...)
|
|
pg_conns = [for pg in local.pg: join("_",["pg", pg.namespace, pg.name, pg.dbname])]
|
|
|
|
ndb = concat(var.ndb, var.detected.ndbs)
|
|
ndb_vars = merge([for m in local.ndb: {
|
|
join("_",["LABEL_ndb", m.namespace, m.name]) = join(" | ",[m.namespace, m.name])
|
|
join("_",["ENGINE_ndb", m.namespace, m.name]) = "mysql@dbgate-plugin-mysql"
|
|
join("_",["SERVER_ndb", m.namespace, m.name]) = join(".",["${m.name}-svc", m.namespace, "svc"])
|
|
join("_",["PORT_ndb", m.namespace, m.name]) = "3306"
|
|
join("_",["DATABASE_ndb", m.namespace, m.name]) = m.dbname
|
|
join("_",["USER_ndb", m.namespace, m.name]) = m.username
|
|
}]...)
|
|
ndb_secrets = merge([for index, m in local.ndb: {
|
|
join("_",["PASSWORD_ndb", m.namespace, m.name]) = lookup(coalesce(data.kubernetes_secret_v1.ndbs[index].data,{}),lookup(m.secret,"key", "password"), "not-found")
|
|
}]...)
|
|
ndb_conns = [for m in local.ndb: join("_",["ndb", m.namespace, m.name])]
|
|
|
|
redis = concat(var.redis, var.detected.rediss)
|
|
redis_vars = merge([for m in local.redis: {
|
|
join("_",["LABEL_redis", m.namespace, m.name]) = join(" | ",[m.namespace, m.name])
|
|
join("_",["ENGINE_redis", m.namespace, m.name]) = "redis@dbgate-plugin-redis"
|
|
join("_",["SERVER_redis", m.namespace, m.name]) = join(".",[m.name, m.namespace, "svc"])
|
|
join("_",["PORT_redis", m.namespace, m.name]) = "6379"
|
|
}]...)
|
|
redis-privs = [for m in local.redis: merge({secret = lookup(m,"secret",{})},m) if contains(keys(m),"secret")]
|
|
redis_secrets = merge([for index, m in local.redis-privs: {
|
|
join("_",["PASSWORD_redis", m.namespace, m.name]) = data.kubernetes_secret_v1.redis[index].data[lookup(m.secret,"key", "password")]
|
|
}]...)
|
|
redis_conns = [for m in local.redis: join("_",["redis", m.namespace, m.name])]
|
|
|
|
mongo = concat(var.mongo, var.detected.mongos)
|
|
mongo_vars = merge([for m in local.mongo: {
|
|
join("_",["LABEL_mongo", m.namespace, m.name]) = join(" | ",[m.namespace, m.name])
|
|
join("_",["ENGINE_mongo", m.namespace, m.name]) = "mongo@dbgate-plugin-mongo"
|
|
join("_",["DATABASE_mongo", m.namespace, m.name]) = m.dbname
|
|
}]...)
|
|
mongo_secrets = merge([for index, m in local.mongo: {
|
|
join("_",["URL_mongo", m.namespace, m.name]) = "mongodb://${m.username}:${urlencode(data.kubernetes_secret_v1.mongos[index].data[m.secret.key])}@${join(".",["${m.name}-svc", m.namespace, "svc"])}:27017/${m.dbname}"
|
|
}]...)
|
|
mongo_conns = [for m in local.mongo: join("_",["mongo", m.namespace, m.name])]
|
|
oauth_config = {
|
|
"OAUTH_AUTH" = "https://${data.kubernetes_ingress_v1.authentik.spec[0].rule[0].host}/application/o/authorize/"
|
|
"OAUTH_TOKEN" = "https://${data.kubernetes_ingress_v1.authentik.spec[0].rule[0].host}/application/o/token/"
|
|
"OAUTH_LOGOUT" = "https://${data.kubernetes_ingress_v1.authentik.spec[0].rule[0].host}/application/o/${var.component}-${var.instance}/end-session/"
|
|
"OAUTH_LOGIN_FIELD" = "nickname"
|
|
"OAUTH_SCOPE" = "email"
|
|
"NODE_EXTRA_CA_CERTS" = "/etc/local-ca/ca.crt"
|
|
}
|
|
connections = join(",", concat(local.pg_conns, local.ndb_conns, local.mongo_conns, local.redis_conns))
|
|
connection_vars = merge(local.pg_vars, local.ndb_vars, local.mongo_vars, local.redis_vars)
|
|
connection_secrets = merge(local.pg_secrets, local.mongo_secrets, local.redis_secrets)
|
|
}
|
|
|
|
resource "kubectl_manifest" "dbgate-config" {
|
|
yaml_body = <<-EOF
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: "${var.component}-${var.instance}"
|
|
namespace: "${var.namespace}"
|
|
labels: ${jsonencode(local.common_labels)}
|
|
data: ${jsonencode(merge(local.oauth_config, local.connection_vars))}
|
|
EOF
|
|
}
|
|
|
|
resource "kubernetes_secret_v1" "dbgate-config-secret" {
|
|
metadata {
|
|
name = "${var.component}-${var.instance}"
|
|
namespace = var.namespace
|
|
}
|
|
data = local.connection_secrets
|
|
}
|
|
|
|
|
|
data "kubernetes_secret_v1" "pgs" {
|
|
count = length(local.pg)
|
|
metadata {
|
|
name = "${local.pg[count.index].secret.name}"
|
|
namespace = "${local.pg[count.index].namespace}"
|
|
}
|
|
}
|
|
|
|
data "kubernetes_secret_v1" "ndbs" {
|
|
count = length(local.ndb)
|
|
metadata {
|
|
name = "${local.ndb[count.index].secret.name}"
|
|
namespace = "${local.ndb[count.index].namespace}"
|
|
}
|
|
}
|
|
|
|
data "kubernetes_secret_v1" "mongos" {
|
|
count = length(local.mongo)
|
|
metadata {
|
|
name = "${local.mongo[count.index].secret.name}"
|
|
namespace = "${local.mongo[count.index].namespace}"
|
|
}
|
|
}
|
|
data "kubernetes_secret_v1" "redis" {
|
|
count = length(local.redis-privs)
|
|
metadata {
|
|
name = "${lookup(local.redis-privs[count.index].secret, "name", local.redis-privs[count.index].name)}"
|
|
namespace = "${local.redis-privs[count.index].namespace}"
|
|
}
|
|
}
|