diff --git a/.gitattributes b/.gitattributes new file mode 100644 index 0000000..285b615 --- /dev/null +++ b/.gitattributes @@ -0,0 +1,2 @@ +*.yaml linguist-detectable +*.sh text eol=lf \ No newline at end of file diff --git a/.gitignore b/.gitignore index 3a0dfe2..cd939a0 100644 --- a/.gitignore +++ b/.gitignore @@ -2,6 +2,8 @@ local/*.env testes/ *.terraform -*.tfstate +*.tfstate* +*.tfplan terraform.tfvars -.aws/ \ No newline at end of file +.aws/ +.terraform/ \ No newline at end of file diff --git a/apps/config/pg-api-secrets.yaml b/apps/config/pg-api-secrets.yaml index 6df8781..68ee68b 100644 --- a/apps/config/pg-api-secrets.yaml +++ b/apps/config/pg-api-secrets.yaml @@ -6,10 +6,7 @@ metadata: spec: hostAPI: https://app.infisical.com/api - - syncConfig: - resyncInterval: 60s - instantUpdates: false + resyncInterval: 60 authentication: universalAuth: diff --git a/apps/pg-api.yaml b/apps/pg-api.yaml index e71c2a8..b256cfb 100644 --- a/apps/pg-api.yaml +++ b/apps/pg-api.yaml @@ -11,8 +11,8 @@ metadata: app.kubernetes.io/part-of: acta spec: - replicas: 3 - revisionHistoryLimit: 3 + replicas: 1 + revisionHistoryLimit: 1 selector: matchLabels: @@ -52,7 +52,7 @@ spec: startupProbe: tcpSocket: port: http - periodSeconds: 5 + periodSeconds: 10 failureThreshold: 60 readinessProbe: diff --git a/argocd/prod.yaml b/argocd/prod.yaml index 2fdca2c..0542581 100644 --- a/argocd/prod.yaml +++ b/argocd/prod.yaml @@ -17,6 +17,13 @@ spec: server: https://kubernetes.default.svc namespace: acta-prod + # a versão atual do operador remove o bloco antigo syncConfig + ignoreDifferences: + - group: secrets.infisical.com + kind: InfisicalSecret + jsonPointers: + - /spec/syncConfig + syncPolicy: automated: prune: true diff --git a/infra/aws/.terraform.lock.hcl b/infra/aws/.terraform.lock.hcl new file mode 100644 index 0000000..92a2bcc --- /dev/null +++ b/infra/aws/.terraform.lock.hcl @@ -0,0 +1,25 @@ +# This file is maintained automatically by "terraform init". +# Manual edits may be lost in future updates. + +provider "registry.terraform.io/hashicorp/aws" { + version = "5.100.0" + constraints = "~> 5.0" + hashes = [ + "h1:H3mU/7URhP0uCRGK8jeQRKxx2XFzEqLiOq/L2Bbiaxs=", + "zh:054b8dd49f0549c9a7cc27d159e45327b7b65cf404da5e5a20da154b90b8a644", + "zh:0b97bf8d5e03d15d83cc40b0530a1f84b459354939ba6f135a0086c20ebbe6b2", + "zh:1589a2266af699cbd5d80737a0fe02e54ec9cf2ca54e7e00ac51c7359056f274", + "zh:6330766f1d85f01ae6ea90d1b214b8b74cc8c1badc4696b165b36ddd4cc15f7b", + "zh:7c8c2e30d8e55291b86fcb64bdf6c25489d538688545eb48fd74ad622e5d3862", + "zh:99b1003bd9bd32ee323544da897148f46a527f622dc3971af63ea3e251596342", + "zh:9b12af85486a96aedd8d7984b0ff811a4b42e3d88dad1a3fb4c0b580d04fa425", + "zh:9f8b909d3ec50ade83c8062290378b1ec553edef6a447c56dadc01a99f4eaa93", + "zh:aaef921ff9aabaf8b1869a86d692ebd24fbd4e12c21205034bb679b9caf883a2", + "zh:ac882313207aba00dd5a76dbd572a0ddc818bb9cbf5c9d61b28fe30efaec951e", + "zh:bb64e8aff37becab373a1a0cc1080990785304141af42ed6aa3dd4913b000421", + "zh:dfe495f6621df5540d9c92ad40b8067376350b005c637ea6efac5dc15028add4", + "zh:f0ddf0eaf052766cfe09dea8200a946519f653c384ab4336e2a4a64fdd6310e9", + "zh:f1b7e684f4c7ae1eed272b6de7d2049bb87a0275cb04dbb7cda6636f600699c9", + "zh:ff461571e3f233699bf690db319dfe46aec75e58726636a0d97dd9ac6e32fb70", + ] +} diff --git a/infra/aws/bootstrap-k3s.sh b/infra/aws/bootstrap-k3s.sh new file mode 100644 index 0000000..8656f1e --- /dev/null +++ b/infra/aws/bootstrap-k3s.sh @@ -0,0 +1,36 @@ +#!/usr/bin/env bash + +# para o bootstrap se algum comando falhar +set -e + +# usa o kubectl instalado junto com o k3s +export KUBECONFIG=/etc/rancher/k3s/k3s.yaml +export PATH="/snap/bin:${PATH}" + +# o ssh pode abrir antes do k3s terminar de iniciar +until kubectl get nodes >/dev/null 2>&1; do + sleep 5 +done + +# instala o argocd dentro do cluster +kubectl create namespace argocd + +kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.2/manifests/install.yaml + +# espera os componentes do argocd ficarem disponiveis +kubectl wait --for=condition=Available deployment --all -n argocd --timeout=10m + +kubectl rollout status statefulset/argocd-application-controller -n argocd --timeout=10m + +# instala o helm usado pelo operador do infisical +snap install helm --classic + +helm repo add infisical-helm-charts https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/ --force-update + +helm repo update + +# instala o infisical para o k8s +helm install infisical-operator infisical-helm-charts/secrets-operator --version 0.10.11 -n infisical-operator-system --create-namespace --wait --timeout 10m + +# namespace recebe a api e suas credenciais +kubectl create namespace acta-prod \ No newline at end of file diff --git a/infra/aws/deploy.ps1 b/infra/aws/deploy.ps1 new file mode 100644 index 0000000..d2cf19a --- /dev/null +++ b/infra/aws/deploy.ps1 @@ -0,0 +1,84 @@ +# faz o script parar se algum comando falhar +$ErrorActionPreference = "Stop" +$PSNativeCommandUseErrorActionPreference = $true + +# confirma a conta da aws e prepara o terraform +aws sts get-caller-identity +if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } + +Set-Location .\infra\aws + +terraform init +terraform validate +terraform plan -out acta.tfplan +if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } + +$confirmation = Read-Host "Digite APLICAR para criar os recursos na AWS" + +if ($confirmation -cne "APLICAR") { + Set-Location ..\.. + Write-Host "Implantacao cancelada" + exit +} + +terraform apply acta.tfplan +if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } + +$publicIp = (terraform output -raw public_ip).Trim() + +Set-Location ..\.. + +# espera a ec2 liberar o acesso ssh +while (-not (Test-NetConnection $publicIp -Port 22 -InformationLevel Quiet)) { + Start-Sleep -Seconds 10 +} + +# instala o argocd e o infisical dentro da ec2 +Get-Content .\infra\aws\bootstrap-k3s.sh -Raw | + ssh -i .\.aws\labsuser.pem -o StrictHostKeyChecking=accept-new "ubuntu@$publicIp" "tr -d '\r' | sudo bash -s" + +if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } + +# baixa o kubeconfig do k3s +$kubeconfigPath = "$env:USERPROFILE\.kube\acta-aws.yaml" + +New-Item "$env:USERPROFILE\.kube" -ItemType Directory -Force | Out-Null + +$kubeconfig = ssh -i .\.aws\labsuser.pem "ubuntu@$publicIp" "sudo cat /etc/rancher/k3s/k3s.yaml" +if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } + +$kubeconfig | Set-Content $kubeconfigPath -Encoding utf8 + +(Get-Content $kubeconfigPath -Raw).Replace( + "https://127.0.0.1:6443", + "https://${publicIp}:6443" +) | Set-Content $kubeconfigPath -Encoding utf8 + +$env:KUBECONFIG = $kubeconfigPath +kubectl get nodes + +# cria a credencial usada pelo infisical +$clientId = Read-Host "Client ID do Infisical" +$clientSecret = Read-Host "Client Secret do Infisical" -AsSecureString +$clientSecret = [Net.NetworkCredential]::new("", $clientSecret).Password + +kubectl create secret generic infisical-universal-auth ` + -n acta-prod ` + --from-literal="clientId=$clientId" ` + --from-literal="clientSecret=$clientSecret" + +$clientSecret = $null + +# entrega a aplicacao para o argocd +kubectl apply -f .\argocd\prod.yaml + +Write-Host "Aguardando o Argo CD e o Infisical..." +Start-Sleep -Seconds 90 + +kubectl rollout status deployment/acta-pg-api -n acta-prod --timeout=15m +kubectl get applications -n argocd +kubectl get pods -n acta-prod + +Write-Host "Implantação concluída" +Write-Host "Para abrir o Argo CD:" +Write-Host "kubectl port-forward svc/argocd-server -n argocd 9000:443" diff --git a/infra/aws/variables.tf b/infra/aws/variables.tf index 20ba3e2..305366c 100644 --- a/infra/aws/variables.tf +++ b/infra/aws/variables.tf @@ -49,7 +49,7 @@ variable "instance_type" { variable "vpc_cidr" { description = "CIDR privado da VPC." type = string - default = "10.42.0.0/16" + default = "10.50.0.0/16" validation { condition = can(cidrhost(var.vpc_cidr, 0)) @@ -62,7 +62,7 @@ variable "vpc_cidr" { variable "public_subnet_cidr" { description = "CIDR da subnet pública. Deve estar contido em vpc_cidr." type = string - default = "10.42.1.0/24" + default = "10.50.1.0/24" validation { condition = can(cidrhost(var.public_subnet_cidr, 0))