locals { annotations = { "vynil.solidite.fr/meta" = var.component "vynil.solidite.fr/name" = var.namespace } annotations_default = { "default.vynil.solidite.fr/sso_vynil" = var.sso_vynil "default.vynil.solidite.fr/domain_name" = var.domain_name "default.vynil.solidite.fr/timezone" = var.timezone "default.vynil.solidite.fr/language" = var.language "default.vynil.solidite.fr/domain" = var.domain "default.vynil.solidite.fr/issuer" = var.issuer "default.vynil.solidite.fr/ingress_class" = var.ingress_class "default.vynil.solidite.fr/app_group" = var.app_group "default.vynil.solidite.fr/backups.enable" = var.backups.enable "default.vynil.solidite.fr/backups.use_barman" = var.backups.use_barman "default.vynil.solidite.fr/backups.endpoint" = var.backups.endpoint "default.vynil.solidite.fr/backups.secret_name" = var.backups.secret_name "default.vynil.solidite.fr/backups.key_id_key" = var.backups.key_id_key "default.vynil.solidite.fr/backups.secret_key" = var.backups.secret_key "default.vynil.solidite.fr/backups.restic_key" = var.backups.restic_key "default.vynil.solidite.fr/storage.volume.accessMode" = var.storage.volume.accessMode "default.vynil.solidite.fr/storage.volume.class" = var.storage.volume.class } global = { "sso_vynil" = var.sso_vynil "domain_name" = var.domain_name "timezone" = var.timezone "language" = var.language "domain" = var.domain "issuer" = var.issuer "ingress_class" = var.ingress_class "app_group" = var.app_group } global-backups = { "enable" = var.backups.enable "use_barman" = var.backups.use_barman "endpoint" = var.backups.endpoint "secret_name" = var.backups.secret_name "key_id_key" = var.backups.key_id_key "secret_key" = var.backups.secret_key "restic_key" = var.backups.restic_key } global-volume = { "accessMode" = var.storage.volume.accessMode "class" = var.storage.volume.class } grafana = merge(local.global,{ for k, v in var.grafana : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.grafana, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.grafana, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.grafana, "storage", {}), "volume", {}), local.global-volume) }) }) prometheus = merge(local.global,{ for k, v in var.prometheus : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.prometheus, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.prometheus, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.prometheus, "storage", {}), "volume", {}), local.global-volume) }) }) alertmanager = merge(local.global,{ for k, v in var.alertmanager : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.alertmanager, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.alertmanager, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.alertmanager, "storage", {}), "volume", {}), local.global-volume) }) }) loki = merge(local.global,{ for k, v in var.loki : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.loki, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.loki, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.loki, "storage", {}), "volume", {}), local.global-volume) }) }) promtail = merge(local.global,{ for k, v in var.promtail : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.promtail, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.promtail, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.promtail, "storage", {}), "volume", {}), local.global-volume) }) }) alerts-core = merge(local.global,{ for k, v in var.alerts-core : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.alerts-core, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.alerts-core, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.alerts-core, "storage", {}), "volume", {}), local.global-volume) }) }) alerts-containers = merge(local.global,{ for k, v in var.alerts-containers : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.alerts-containers, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.alerts-containers, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.alerts-containers, "storage", {}), "volume", {}), local.global-volume) }) }) nodeExporter = { for k, v in var.node-exporter : k => v if k!="enable" } nodeExporter = merge(local.global,{ for k, v in var.node-exporter : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.node-exporter, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.node-exporter, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.node-exporter, "storage", {}), "volume", {}), local.global-volume) }) }) kubeStateMetrics = merge(local.global,{ for k, v in var.kube-state-metrics : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.kube-state-metrics, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.kube-state-metrics, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.kube-state-metrics, "storage", {}), "volume", {}), local.global-volume) }) }) monitorControlPlan = merge(local.global,{ for k, v in var.monitor-control-plan : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.monitor-control-plan, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.monitor-control-plan, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.monitor-control-plan, "storage", {}), "volume", {}), local.global-volume) }) }) dashboards-cluster = merge(local.global,{ for k, v in var.dashboards-cluster : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.dashboards-cluster, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.dashboards-cluster, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.dashboards-cluster, "storage", {}), "volume", {}), local.global-volume) }) }) dashboards-minimal = merge(local.global,{ for k, v in var.dashboards-minimal : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.dashboards-minimal, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.dashboards-minimal, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.dashboards-minimal, "storage", {}), "volume", {}), local.global-volume) }) }) dashboards-namespace = merge(local.global,{ for k, v in var.dashboards-namespace : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.dashboards-namespace, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.dashboards-namespace, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.dashboards-namespace, "storage", {}), "volume", {}), local.global-volume) }) }) dashboards-workload = merge(local.global,{ for k, v in var.dashboards-workload : k => v if !contains(["enable","storage","backups"],k) },{ backups = merge(lookup(var.dashboards-workload, "backups", {}), local.global-backups) storage = merge({ for k, v in lookup(var.dashboards-workload, "storage", {}) : k => v if !contains(["volume"],k) }, { volume = merge(lookup(lookup(var.dashboards-workload, "storage", {}), "volume", {}), local.global-volume) }) }) } resource "kubernetes_namespace_v1" "monitor-ns" { count = ( var.grafana.enable || var.loki.enable || var.promtail.enable || var.prometheus.enable || var.alertmanager.enable || var.node-exporter.enable || var.kube-state-metrics.enable || var.monitor-control-plan.enable )? 1 : 0 metadata { annotations = merge(local.annotations, local.annotations_default) labels = merge(local.common-labels, local.annotations) name = "${var.namespace}-monitor" } } resource "kubectl_manifest" "alertmanager" { count = var.alertmanager.enable ? 1 : 0 depends_on = [kubernetes_namespace_v1.monitor-ns] yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "alertmanager" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "alertmanager" options: ${jsonencode(local.alertmanager)} EOF } resource "kubectl_manifest" "prometheus" { count = var.prometheus.enable ? 1 : 0 yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "prometheus" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "prometheus" options: ${jsonencode(local.prometheus)} EOF } resource "kubectl_manifest" "nodeExporter" { count = var.node-exporter.enable ? 1 : 0 yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "node-exporter" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "node-exporter" options: ${jsonencode(local.nodeExporter)} EOF } resource "kubectl_manifest" "kubeStateMetrics" { count = var.kube-state-metrics.enable ? 1 : 0 depends_on = [kubernetes_namespace_v1.monitor-ns] yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "kube-state-metrics" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "kube-state-metrics" options: ${jsonencode(local.kubeStateMetrics)} EOF } resource "kubectl_manifest" "monitorControlPlan" { count = var.monitor-control-plan.enable ? 1 : 0 depends_on = [kubernetes_namespace_v1.monitor-ns] yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "monitor-control-plan" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "monitor-control-plan" options: ${jsonencode(local.monitorControlPlan)} EOF } resource "kubectl_manifest" "alerts-core" { count = var.alerts-core.enable ? 1 : 0 depends_on = [kubernetes_namespace_v1.monitor-ns] yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "alerts-core" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "alerts-core" options: ${jsonencode(local.alerts-core)} EOF } resource "kubectl_manifest" "alerts-containers" { count = var.alerts-containers.enable ? 1 : 0 depends_on = [kubernetes_namespace_v1.monitor-ns] yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "alerts-containers" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "alerts-containers" options: ${jsonencode(local.alerts-containers)} EOF } resource "kubectl_manifest" "dashboards-cluster" { count = var.dashboards-cluster.enable ? 1 : 0 yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "dashboards-cluster" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "dashboards-cluster" options: ${jsonencode(local.dashboards-cluster)} EOF } resource "kubectl_manifest" "dashboards-minimal" { count = var.dashboards-minimal.enable ? 1 : 0 yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "dashboards-minimal" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "dashboards-minimal" options: ${jsonencode(local.dashboards-minimal)} EOF } resource "kubectl_manifest" "dashboards-namespace" { count = var.dashboards-namespace.enable ? 1 : 0 yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "dashboards-namespace" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "dashboards-namespace" options: ${jsonencode(local.dashboards-namespace)} EOF } resource "kubectl_manifest" "dashboards-workload" { count = var.dashboards-workload.enable ? 1 : 0 yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "dashboards-workload" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "dashboards-workload" options: ${jsonencode(local.dashboards-workload)} EOF } resource "kubectl_manifest" "grafana" { count = var.grafana.enable ? 1 : 0 yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "grafana" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "grafana" options: ${jsonencode(local.grafana)} EOF } resource "kubectl_manifest" "promtail" { count = var.promtail.enable ? 1 : 0 yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "promtail" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "promtail" options: ${jsonencode(local.promtail)} EOF } resource "kubectl_manifest" "loki" { count = var.loki.enable ? 1 : 0 yaml_body = <<-EOF apiVersion: "vynil.solidite.fr/v1" kind: "Install" metadata: name: "loki" namespace: "${kubernetes_namespace_v1.monitor-ns[0].metadata[0].name}" labels: ${jsonencode(local.common-labels)} spec: distrib: "${var.distributions.domain}" category: "monitor" component: "loki" options: ${jsonencode(local.loki)} EOF }