Files
domain/share/gitea-tekton-org/auto-cd.tf
2024-04-21 13:45:02 +02:00

201 lines
6.4 KiB
HCL

locals {
create-labels = merge(local.common-labels, {
"type" = "repo-new"
})
activate-labels = merge(local.common-labels, {
"type" = "package-new"
})
delete-labels = merge(local.common-labels, {
"type" = "repo-delete"
})
}
resource "kubectl_manifest" "cd-trigger-create" {
count = var.autoCD?1:0
yaml_body = <<-EOF
apiVersion: triggers.tekton.dev/v1beta1
kind: Trigger
metadata:
metadata:
name: "${var.instance}-${var.component}-auto-create"
namespace: "${var.namespace}"
labels: ${jsonencode(local.create-labels)}
spec:
bindings:
- name: gitrepositoryname
value: $(body.repository.name)
- name: deployurl
value: $(extensions.deploy-url)
template:
spec:
params:
- name: gitrepositoryname
description: The git repository name
- name: deployurl
description: The git url for the deploy repository
resourcetemplates:
- apiVersion: tekton.dev/v1beta1
kind: PipelineRun
metadata:
generateName: $(tt.params.gitrepositoryname)-create-
annotations:
"mayfly.cloud.namecheap.com/expire": "336h" # 2 weeks
spec:
pipelineRef:
name: "${var.instance}-${var.component}-auto-create"
params:
- name: project-name
value: $(tt.params.gitrepositoryname)
- name: deploy-url
value: $(tt.params.deployurl)
workspaces:
- name: source
volumeClaimTemplate:
metadata:
annotations:
"mayfly.cloud.namecheap.com/expire": "2h"
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
- name: ssh
secret:
secretName: ssh-credentials
items:
- key: "known_hosts"
path: "known_hosts"
- key: "ssh-privatekey"
path: "id_rsa"
- key: "ssh-publickey"
path: "id_rsa.pub"
EOF
}
resource "kubectl_manifest" "cd-trigger-activate" {
count = var.autoCD?1:0
yaml_body = <<-EOF
apiVersion: triggers.tekton.dev/v1beta1
kind: Trigger
metadata:
metadata:
name: "${var.instance}-${var.component}-auto-activate"
namespace: "${var.namespace}"
labels: ${jsonencode(local.activate-labels)}
spec:
bindings:
- name: gitrepositoryname
value: $(body.repository.name)
- name: deployurl
value: $(extensions.deploy-url)
template:
spec:
params:
- name: gitrepositoryname
description: The git repository name
- name: deployurl
description: The git url for the deploy repository
resourcetemplates:
- apiVersion: tekton.dev/v1beta1
kind: PipelineRun
metadata:
generateName: $(tt.params.gitrepositoryname)-activate-
annotations:
"mayfly.cloud.namecheap.com/expire": "336h" # 2 weeks
spec:
pipelineRef:
name: "${var.instance}-${var.component}-auto-activate"
params:
- name: project-name
value: $(tt.params.gitrepositoryname)
- name: deploy-url
value: $(tt.params.deployurl)
workspaces:
- name: source
volumeClaimTemplate:
metadata:
annotations:
"mayfly.cloud.namecheap.com/expire": "2h"
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
- name: ssh
secret:
secretName: ssh-credentials
items:
- key: "known_hosts"
path: "known_hosts"
- key: "ssh-privatekey"
path: "id_rsa"
- key: "ssh-publickey"
path: "id_rsa.pub"
EOF
}
resource "kubectl_manifest" "ci-trigger-delete" {
count = var.autoCD?1:0
yaml_body = <<-EOF
apiVersion: triggers.tekton.dev/v1beta1
kind: Trigger
metadata:
metadata:
name: "${var.instance}-${var.component}-auto-delete"
namespace: "${var.namespace}"
labels: ${jsonencode(local.delete-labels)}
spec:
bindings:
- name: gitrepositoryname
value: $(body.repository.name)
- name: deployurl
value: $(extensions.deploy-url)
template:
spec:
params:
- name: gitrepositoryname
description: The git repository name
- name: deployurl
description: The git url for the deploy repository
resourcetemplates:
- apiVersion: tekton.dev/v1beta1
kind: PipelineRun
metadata:
generateName: $(tt.params.gitrepositoryname)-delete-
annotations:
"mayfly.cloud.namecheap.com/expire": "1440h" # 2 months
spec:
pipelineRef:
name: "${var.instance}-${var.component}-delete"
params:
- name: project-name
value: $(tt.params.gitrepositoryname)
- name: deploy-url
value: $(tt.params.deployurl)
workspaces:
- name: source
volumeClaimTemplate:
metadata:
annotations:
"mayfly.cloud.namecheap.com/expire": "2h"
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
- name: ssh
secret:
secretName: ssh-credentials
items:
- key: "known_hosts"
path: "known_hosts"
- key: "ssh-privatekey"
path: "id_rsa"
- key: "ssh-publickey"
path: "id_rsa.pub"
EOF
}