Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
*.yaml linguist-detectable
*.sh text eol=lf
6 changes: 4 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@
local/*.env
testes/
*.terraform
*.tfstate
*.tfstate*
*.tfplan
terraform.tfvars
.aws/
.aws/
.terraform/
5 changes: 1 addition & 4 deletions apps/config/pg-api-secrets.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,7 @@ metadata:

spec:
hostAPI: https://app.infisical.com/api

syncConfig:
resyncInterval: 60s
instantUpdates: false
resyncInterval: 60

authentication:
universalAuth:
Expand Down
6 changes: 3 additions & 3 deletions apps/pg-api.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,8 +11,8 @@ metadata:
app.kubernetes.io/part-of: acta

spec:
replicas: 3
revisionHistoryLimit: 3
replicas: 1
revisionHistoryLimit: 1

selector:
matchLabels:
Expand Down Expand Up @@ -52,7 +52,7 @@ spec:
startupProbe:
tcpSocket:
port: http
periodSeconds: 5
periodSeconds: 10
failureThreshold: 60

readinessProbe:
Expand Down
7 changes: 7 additions & 0 deletions argocd/prod.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,13 @@ spec:
server: https://kubernetes.default.svc
namespace: acta-prod

# a versão atual do operador remove o bloco antigo syncConfig
ignoreDifferences:
- group: secrets.infisical.com
kind: InfisicalSecret
jsonPointers:
- /spec/syncConfig

syncPolicy:
automated:
prune: true
Expand Down
25 changes: 25 additions & 0 deletions infra/aws/.terraform.lock.hcl

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

36 changes: 36 additions & 0 deletions infra/aws/bootstrap-k3s.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
#!/usr/bin/env bash

# para o bootstrap se algum comando falhar
set -e

# usa o kubectl instalado junto com o k3s
export KUBECONFIG=/etc/rancher/k3s/k3s.yaml
export PATH="/snap/bin:${PATH}"

# o ssh pode abrir antes do k3s terminar de iniciar
until kubectl get nodes >/dev/null 2>&1; do
sleep 5
done

# instala o argocd dentro do cluster
kubectl create namespace argocd

kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.2/manifests/install.yaml

# espera os componentes do argocd ficarem disponiveis
kubectl wait --for=condition=Available deployment --all -n argocd --timeout=10m

kubectl rollout status statefulset/argocd-application-controller -n argocd --timeout=10m

# instala o helm usado pelo operador do infisical
snap install helm --classic

helm repo add infisical-helm-charts https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/ --force-update

helm repo update

# instala o infisical para o k8s
helm install infisical-operator infisical-helm-charts/secrets-operator --version 0.10.11 -n infisical-operator-system --create-namespace --wait --timeout 10m

# namespace recebe a api e suas credenciais
kubectl create namespace acta-prod
84 changes: 84 additions & 0 deletions infra/aws/deploy.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1,84 @@
# faz o script parar se algum comando falhar
$ErrorActionPreference = "Stop"
$PSNativeCommandUseErrorActionPreference = $true

# confirma a conta da aws e prepara o terraform
aws sts get-caller-identity
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }

Set-Location .\infra\aws

terraform init
terraform validate
terraform plan -out acta.tfplan
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }

$confirmation = Read-Host "Digite APLICAR para criar os recursos na AWS"

if ($confirmation -cne "APLICAR") {
Set-Location ..\..
Write-Host "Implantacao cancelada"
exit
}

terraform apply acta.tfplan
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }

$publicIp = (terraform output -raw public_ip).Trim()

Set-Location ..\..

# espera a ec2 liberar o acesso ssh
while (-not (Test-NetConnection $publicIp -Port 22 -InformationLevel Quiet)) {
Start-Sleep -Seconds 10
}

# instala o argocd e o infisical dentro da ec2
Get-Content .\infra\aws\bootstrap-k3s.sh -Raw |
ssh -i .\.aws\labsuser.pem -o StrictHostKeyChecking=accept-new "ubuntu@$publicIp" "tr -d '\r' | sudo bash -s"

if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }

# baixa o kubeconfig do k3s
$kubeconfigPath = "$env:USERPROFILE\.kube\acta-aws.yaml"

New-Item "$env:USERPROFILE\.kube" -ItemType Directory -Force | Out-Null

$kubeconfig = ssh -i .\.aws\labsuser.pem "ubuntu@$publicIp" "sudo cat /etc/rancher/k3s/k3s.yaml"
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }

$kubeconfig | Set-Content $kubeconfigPath -Encoding utf8

(Get-Content $kubeconfigPath -Raw).Replace(
"https://127.0.0.1:6443",
"https://${publicIp}:6443"
) | Set-Content $kubeconfigPath -Encoding utf8

$env:KUBECONFIG = $kubeconfigPath
kubectl get nodes

# cria a credencial usada pelo infisical
$clientId = Read-Host "Client ID do Infisical"
$clientSecret = Read-Host "Client Secret do Infisical" -AsSecureString
$clientSecret = [Net.NetworkCredential]::new("", $clientSecret).Password

kubectl create secret generic infisical-universal-auth `
-n acta-prod `
--from-literal="clientId=$clientId" `
--from-literal="clientSecret=$clientSecret"

$clientSecret = $null

# entrega a aplicacao para o argocd
kubectl apply -f .\argocd\prod.yaml

Write-Host "Aguardando o Argo CD e o Infisical..."
Start-Sleep -Seconds 90

kubectl rollout status deployment/acta-pg-api -n acta-prod --timeout=15m
kubectl get applications -n argocd
kubectl get pods -n acta-prod

Write-Host "Implantação concluída"
Write-Host "Para abrir o Argo CD:"
Write-Host "kubectl port-forward svc/argocd-server -n argocd 9000:443"
4 changes: 2 additions & 2 deletions infra/aws/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ variable "instance_type" {
variable "vpc_cidr" {
description = "CIDR privado da VPC."
type = string
default = "10.42.0.0/16"
default = "10.50.0.0/16"

validation {
condition = can(cidrhost(var.vpc_cidr, 0))
Expand All @@ -62,7 +62,7 @@ variable "vpc_cidr" {
variable "public_subnet_cidr" {
description = "CIDR da subnet pública. Deve estar contido em vpc_cidr."
type = string
default = "10.42.1.0/24"
default = "10.50.1.0/24"

validation {
condition = can(cidrhost(var.public_subnet_cidr, 0))
Expand Down
Loading