From 27b470aaabf13ebe278c142a141137871865ef3f Mon Sep 17 00:00:00 2001 From: Davi Aliaga Date: Fri, 11 Sep 2026 12:30:37 -0300 Subject: [PATCH 1/7] chore/yaml: adiciona gitattributes para identificar YAML --- .gitattributes | 1 + 1 file changed, 1 insertion(+) create mode 100644 .gitattributes diff --git a/.gitattributes b/.gitattributes new file mode 100644 index 0000000..47be97a --- /dev/null +++ b/.gitattributes @@ -0,0 +1 @@ +*.yaml linguist-detectable \ No newline at end of file From f58fee0c5c16e61549da6ede28a18f37004d6cc3 Mon Sep 17 00:00:00 2001 From: Davi Aliaga Date: Sun, 13 Sep 2026 16:31:03 -0300 Subject: [PATCH 2/7] =?UTF-8?q?chore/gitignore:=20atualiza=20.gitignore=20?= =?UTF-8?q?para=20excluir=20arquivos=20do=20terraform=20e=20o=20diret?= =?UTF-8?q?=C3=B3rio=20.aws.=20Atualiza=20.gitattributes=20para=20especifi?= =?UTF-8?q?car=20as=20quebras=20de=20linha=20para=20shell?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .gitattributes | 3 ++- .gitignore | 6 ++++-- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/.gitattributes b/.gitattributes index 47be97a..285b615 100644 --- a/.gitattributes +++ b/.gitattributes @@ -1 +1,2 @@ -*.yaml linguist-detectable \ No newline at end of file +*.yaml linguist-detectable +*.sh text eol=lf \ No newline at end of file diff --git a/.gitignore b/.gitignore index 3a0dfe2..cd939a0 100644 --- a/.gitignore +++ b/.gitignore @@ -2,6 +2,8 @@ local/*.env testes/ *.terraform -*.tfstate +*.tfstate* +*.tfplan terraform.tfvars -.aws/ \ No newline at end of file +.aws/ +.terraform/ \ No newline at end of file From e2606d9b0e12748a35808dcc95cc880d9ce74130 Mon Sep 17 00:00:00 2001 From: Davi Aliaga Date: Sun, 13 Sep 2026 16:32:38 -0300 Subject: [PATCH 3/7] =?UTF-8?q?fix/k8s:=20reduz=20r=C3=A9plicas=20da=20pg-?= =?UTF-8?q?api=20e=20o=20limite=20do=20hist=C3=B3rico=20de=20revis=C3=B5es?= =?UTF-8?q?.=20Aumenta=20o=20per=C3=ADodo=20de=20startup=20probe?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- apps/pg-api.yaml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/apps/pg-api.yaml b/apps/pg-api.yaml index e71c2a8..b256cfb 100644 --- a/apps/pg-api.yaml +++ b/apps/pg-api.yaml @@ -11,8 +11,8 @@ metadata: app.kubernetes.io/part-of: acta spec: - replicas: 3 - revisionHistoryLimit: 3 + replicas: 1 + revisionHistoryLimit: 1 selector: matchLabels: @@ -52,7 +52,7 @@ spec: startupProbe: tcpSocket: port: http - periodSeconds: 5 + periodSeconds: 10 failureThreshold: 60 readinessProbe: From d8d0ab263df4aa8bfe61a642097c257109d4db1d Mon Sep 17 00:00:00 2001 From: Davi Aliaga Date: Sun, 13 Sep 2026 16:33:13 -0300 Subject: [PATCH 4/7] =?UTF-8?q?fix/terraform:=20atualiza=20VPC=20e=20subne?= =?UTF-8?q?t=20p=C3=BAblica?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- infra/aws/variables.tf | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/infra/aws/variables.tf b/infra/aws/variables.tf index 20ba3e2..305366c 100644 --- a/infra/aws/variables.tf +++ b/infra/aws/variables.tf @@ -49,7 +49,7 @@ variable "instance_type" { variable "vpc_cidr" { description = "CIDR privado da VPC." type = string - default = "10.42.0.0/16" + default = "10.50.0.0/16" validation { condition = can(cidrhost(var.vpc_cidr, 0)) @@ -62,7 +62,7 @@ variable "vpc_cidr" { variable "public_subnet_cidr" { description = "CIDR da subnet pública. Deve estar contido em vpc_cidr." type = string - default = "10.42.1.0/24" + default = "10.50.1.0/24" validation { condition = can(cidrhost(var.public_subnet_cidr, 0)) From e746be8160b53804c1845c466673c062f49e1305 Mon Sep 17 00:00:00 2001 From: Davi Aliaga Date: Sun, 13 Sep 2026 16:33:23 -0300 Subject: [PATCH 5/7] =?UTF-8?q?chore/terraform:=20adiciona=20arquivo=20.te?= =?UTF-8?q?rraform.lock.hcl=20com=20depend=C3=AAncias=20do=20provider=20AW?= =?UTF-8?q?S?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- infra/aws/.terraform.lock.hcl | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 infra/aws/.terraform.lock.hcl diff --git a/infra/aws/.terraform.lock.hcl b/infra/aws/.terraform.lock.hcl new file mode 100644 index 0000000..92a2bcc --- /dev/null +++ b/infra/aws/.terraform.lock.hcl @@ -0,0 +1,25 @@ +# This file is maintained automatically by "terraform init". +# Manual edits may be lost in future updates. + +provider "registry.terraform.io/hashicorp/aws" { + version = "5.100.0" + constraints = "~> 5.0" + hashes = [ + "h1:H3mU/7URhP0uCRGK8jeQRKxx2XFzEqLiOq/L2Bbiaxs=", + "zh:054b8dd49f0549c9a7cc27d159e45327b7b65cf404da5e5a20da154b90b8a644", + "zh:0b97bf8d5e03d15d83cc40b0530a1f84b459354939ba6f135a0086c20ebbe6b2", + "zh:1589a2266af699cbd5d80737a0fe02e54ec9cf2ca54e7e00ac51c7359056f274", + "zh:6330766f1d85f01ae6ea90d1b214b8b74cc8c1badc4696b165b36ddd4cc15f7b", + "zh:7c8c2e30d8e55291b86fcb64bdf6c25489d538688545eb48fd74ad622e5d3862", + "zh:99b1003bd9bd32ee323544da897148f46a527f622dc3971af63ea3e251596342", + "zh:9b12af85486a96aedd8d7984b0ff811a4b42e3d88dad1a3fb4c0b580d04fa425", + "zh:9f8b909d3ec50ade83c8062290378b1ec553edef6a447c56dadc01a99f4eaa93", + "zh:aaef921ff9aabaf8b1869a86d692ebd24fbd4e12c21205034bb679b9caf883a2", + "zh:ac882313207aba00dd5a76dbd572a0ddc818bb9cbf5c9d61b28fe30efaec951e", + "zh:bb64e8aff37becab373a1a0cc1080990785304141af42ed6aa3dd4913b000421", + "zh:dfe495f6621df5540d9c92ad40b8067376350b005c637ea6efac5dc15028add4", + "zh:f0ddf0eaf052766cfe09dea8200a946519f653c384ab4336e2a4a64fdd6310e9", + "zh:f1b7e684f4c7ae1eed272b6de7d2049bb87a0275cb04dbb7cda6636f600699c9", + "zh:ff461571e3f233699bf690db319dfe46aec75e58726636a0d97dd9ac6e32fb70", + ] +} From df5382b8f6f867c0e84a1e305f28d9a4b2399d0f Mon Sep 17 00:00:00 2001 From: Davi Aliaga Date: Sun, 13 Sep 2026 16:34:03 -0300 Subject: [PATCH 6/7] =?UTF-8?q?chore/config:=20remove=20synConfig=20e=20ig?= =?UTF-8?q?nora=20diferen=C3=A7as=20do=20InfisicalSecret?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- apps/config/pg-api-secrets.yaml | 5 +---- argocd/prod.yaml | 7 +++++++ 2 files changed, 8 insertions(+), 4 deletions(-) diff --git a/apps/config/pg-api-secrets.yaml b/apps/config/pg-api-secrets.yaml index 6df8781..68ee68b 100644 --- a/apps/config/pg-api-secrets.yaml +++ b/apps/config/pg-api-secrets.yaml @@ -6,10 +6,7 @@ metadata: spec: hostAPI: https://app.infisical.com/api - - syncConfig: - resyncInterval: 60s - instantUpdates: false + resyncInterval: 60 authentication: universalAuth: diff --git a/argocd/prod.yaml b/argocd/prod.yaml index 2fdca2c..0542581 100644 --- a/argocd/prod.yaml +++ b/argocd/prod.yaml @@ -17,6 +17,13 @@ spec: server: https://kubernetes.default.svc namespace: acta-prod + # a versão atual do operador remove o bloco antigo syncConfig + ignoreDifferences: + - group: secrets.infisical.com + kind: InfisicalSecret + jsonPointers: + - /spec/syncConfig + syncPolicy: automated: prune: true From e8ce117d42744743f011635807efb543c1b2c1aa Mon Sep 17 00:00:00 2001 From: Davi Aliaga Date: Sun, 13 Sep 2026 16:34:16 -0300 Subject: [PATCH 7/7] feat/sh: adiciona scripts de bootstrap e deploy para configurar o k3s, instalar o Argo CD e o Infisical na infraestrutura AWS --- infra/aws/bootstrap-k3s.sh | 36 ++++++++++++++++ infra/aws/deploy.ps1 | 84 ++++++++++++++++++++++++++++++++++++++ 2 files changed, 120 insertions(+) create mode 100644 infra/aws/bootstrap-k3s.sh create mode 100644 infra/aws/deploy.ps1 diff --git a/infra/aws/bootstrap-k3s.sh b/infra/aws/bootstrap-k3s.sh new file mode 100644 index 0000000..8656f1e --- /dev/null +++ b/infra/aws/bootstrap-k3s.sh @@ -0,0 +1,36 @@ +#!/usr/bin/env bash + +# para o bootstrap se algum comando falhar +set -e + +# usa o kubectl instalado junto com o k3s +export KUBECONFIG=/etc/rancher/k3s/k3s.yaml +export PATH="/snap/bin:${PATH}" + +# o ssh pode abrir antes do k3s terminar de iniciar +until kubectl get nodes >/dev/null 2>&1; do + sleep 5 +done + +# instala o argocd dentro do cluster +kubectl create namespace argocd + +kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.2/manifests/install.yaml + +# espera os componentes do argocd ficarem disponiveis +kubectl wait --for=condition=Available deployment --all -n argocd --timeout=10m + +kubectl rollout status statefulset/argocd-application-controller -n argocd --timeout=10m + +# instala o helm usado pelo operador do infisical +snap install helm --classic + +helm repo add infisical-helm-charts https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/ --force-update + +helm repo update + +# instala o infisical para o k8s +helm install infisical-operator infisical-helm-charts/secrets-operator --version 0.10.11 -n infisical-operator-system --create-namespace --wait --timeout 10m + +# namespace recebe a api e suas credenciais +kubectl create namespace acta-prod \ No newline at end of file diff --git a/infra/aws/deploy.ps1 b/infra/aws/deploy.ps1 new file mode 100644 index 0000000..d2cf19a --- /dev/null +++ b/infra/aws/deploy.ps1 @@ -0,0 +1,84 @@ +# faz o script parar se algum comando falhar +$ErrorActionPreference = "Stop" +$PSNativeCommandUseErrorActionPreference = $true + +# confirma a conta da aws e prepara o terraform +aws sts get-caller-identity +if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } + +Set-Location .\infra\aws + +terraform init +terraform validate +terraform plan -out acta.tfplan +if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } + +$confirmation = Read-Host "Digite APLICAR para criar os recursos na AWS" + +if ($confirmation -cne "APLICAR") { + Set-Location ..\.. + Write-Host "Implantacao cancelada" + exit +} + +terraform apply acta.tfplan +if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } + +$publicIp = (terraform output -raw public_ip).Trim() + +Set-Location ..\.. + +# espera a ec2 liberar o acesso ssh +while (-not (Test-NetConnection $publicIp -Port 22 -InformationLevel Quiet)) { + Start-Sleep -Seconds 10 +} + +# instala o argocd e o infisical dentro da ec2 +Get-Content .\infra\aws\bootstrap-k3s.sh -Raw | + ssh -i .\.aws\labsuser.pem -o StrictHostKeyChecking=accept-new "ubuntu@$publicIp" "tr -d '\r' | sudo bash -s" + +if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } + +# baixa o kubeconfig do k3s +$kubeconfigPath = "$env:USERPROFILE\.kube\acta-aws.yaml" + +New-Item "$env:USERPROFILE\.kube" -ItemType Directory -Force | Out-Null + +$kubeconfig = ssh -i .\.aws\labsuser.pem "ubuntu@$publicIp" "sudo cat /etc/rancher/k3s/k3s.yaml" +if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } + +$kubeconfig | Set-Content $kubeconfigPath -Encoding utf8 + +(Get-Content $kubeconfigPath -Raw).Replace( + "https://127.0.0.1:6443", + "https://${publicIp}:6443" +) | Set-Content $kubeconfigPath -Encoding utf8 + +$env:KUBECONFIG = $kubeconfigPath +kubectl get nodes + +# cria a credencial usada pelo infisical +$clientId = Read-Host "Client ID do Infisical" +$clientSecret = Read-Host "Client Secret do Infisical" -AsSecureString +$clientSecret = [Net.NetworkCredential]::new("", $clientSecret).Password + +kubectl create secret generic infisical-universal-auth ` + -n acta-prod ` + --from-literal="clientId=$clientId" ` + --from-literal="clientSecret=$clientSecret" + +$clientSecret = $null + +# entrega a aplicacao para o argocd +kubectl apply -f .\argocd\prod.yaml + +Write-Host "Aguardando o Argo CD e o Infisical..." +Start-Sleep -Seconds 90 + +kubectl rollout status deployment/acta-pg-api -n acta-prod --timeout=15m +kubectl get applications -n argocd +kubectl get pods -n acta-prod + +Write-Host "Implantação concluída" +Write-Host "Para abrir o Argo CD:" +Write-Host "kubectl port-forward svc/argocd-server -n argocd 9000:443"