diff --git a/.gitignore b/.gitignore index 801e4a2..5d432f9 100644 --- a/.gitignore +++ b/.gitignore @@ -38,3 +38,5 @@ terraform.rc ghe-runner **/terraform.tfstate **/terraform.tfvars + +downloads/*.rpm \ No newline at end of file diff --git a/.terraform.lock.hcl b/.terraform.lock.hcl index a5a344c..1b00b7e 100644 --- a/.terraform.lock.hcl +++ b/.terraform.lock.hcl @@ -24,6 +24,63 @@ provider "registry.terraform.io/hashicorp/aws" { ] } +provider "registry.terraform.io/hashicorp/external" { + version = "2.3.4" + hashes = [ + "h1:XWkRZOLKMjci9/JAtE8X8fWOt7A4u+9mgXSUjc4Wuyo=", + "zh:037fd82cd86227359bc010672cd174235e2d337601d4686f526d0f53c87447cb", + "zh:0ea1db63d6173d01f2fa8eb8989f0809a55135a0d8d424b08ba5dabad73095fa", + "zh:17a4d0a306566f2e45778fbac48744b6fd9c958aaa359e79f144c6358cb93af0", + "zh:298e5408ab17fd2e90d2cd6d406c6d02344fe610de5b7dae943a58b958e76691", + "zh:38ecfd29ee0785fd93164812dcbe0664ebbe5417473f3b2658087ca5a0286ecb", + "zh:59f6a6f31acf66f4ea3667a555a70eba5d406c6e6d93c2c641b81d63261eeace", + "zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3", + "zh:ad0279dfd09d713db0c18469f585e58d04748ca72d9ada83883492e0dd13bd58", + "zh:c69f66fd21f5e2c8ecf7ca68d9091c40f19ad913aef21e3ce23836e91b8cbb5f", + "zh:d4a56f8c48aa86fc8e0c233d56850f5783f322d6336f3bf1916e293246b6b5d4", + "zh:f2b394ebd4af33f343835517e80fc876f79361f4688220833bc3c77655dd2202", + "zh:f31982f29f12834e5d21e010856eddd19d59cd8f449adf470655bfd19354377e", + ] +} + +provider "registry.terraform.io/hashicorp/local" { + version = "2.5.2" + hashes = [ + "h1:JlMZD6nYqJ8sSrFfEAH0Vk/SL8WLZRmFaMUF9PJK5wM=", + "zh:136299545178ce281c56f36965bf91c35407c11897f7082b3b983d86cb79b511", + "zh:3b4486858aa9cb8163378722b642c57c529b6c64bfbfc9461d940a84cd66ebea", + "zh:4855ee628ead847741aa4f4fc9bed50cfdbf197f2912775dd9fe7bc43fa077c0", + "zh:4b8cd2583d1edcac4011caafe8afb7a95e8110a607a1d5fb87d921178074a69b", + "zh:52084ddaff8c8cd3f9e7bcb7ce4dc1eab00602912c96da43c29b4762dc376038", + "zh:71562d330d3f92d79b2952ffdda0dad167e952e46200c767dd30c6af8d7c0ed3", + "zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3", + "zh:805f81ade06ff68fa8b908d31892eaed5c180ae031c77ad35f82cb7a74b97cf4", + "zh:8b6b3ebeaaa8e38dd04e56996abe80db9be6f4c1df75ac3cccc77642899bd464", + "zh:ad07750576b99248037b897de71113cc19b1a8d0bc235eb99173cc83d0de3b1b", + "zh:b9f1c3bfadb74068f5c205292badb0661e17ac05eb23bfe8bd809691e4583d0e", + "zh:cc4cbcd67414fefb111c1bf7ab0bc4beb8c0b553d01719ad17de9a047adff4d1", + ] +} + +provider "registry.terraform.io/hashicorp/null" { + version = "3.2.3" + hashes = [ + "h1:+AnORRgFbRO6qqcfaQyeX80W0eX3VmjadjnUFUJTiXo=", + "zh:22d062e5278d872fe7aed834f5577ba0a5afe34a3bdac2b81f828d8d3e6706d2", + "zh:23dead00493ad863729495dc212fd6c29b8293e707b055ce5ba21ee453ce552d", + "zh:28299accf21763ca1ca144d8f660688d7c2ad0b105b7202554ca60b02a3856d3", + "zh:55c9e8a9ac25a7652df8c51a8a9a422bd67d784061b1de2dc9fe6c3cb4e77f2f", + "zh:756586535d11698a216291c06b9ed8a5cc6a4ec43eee1ee09ecd5c6a9e297ac1", + "zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3", + "zh:9d5eea62fdb587eeb96a8c4d782459f4e6b73baeece4d04b4a40e44faaee9301", + "zh:a6355f596a3fb8fc85c2fb054ab14e722991533f87f928e7169a486462c74670", + "zh:b5a65a789cff4ada58a5baffc76cb9767dc26ec6b45c00d2ec8b1b027f6db4ed", + "zh:db5ab669cf11d0e9f81dc380a6fdfcac437aea3d69109c7aef1a5426639d2d65", + "zh:de655d251c470197bcbb5ac45d289595295acb8f829f6c781d4a75c8c8b7c7dd", + "zh:f5c68199f2e6076bce92a12230434782bf768103a427e9bb9abee99b116af7b5", + ] +} + provider "registry.terraform.io/hashicorp/random" { version = "3.6.3" hashes = [ diff --git a/downloads.tf b/downloads.tf new file mode 100644 index 0000000..db687e5 --- /dev/null +++ b/downloads.tf @@ -0,0 +1,39 @@ +locals { + # Define a set of Morpheus binaries to be downloaded + morpheus_binaries = [ + { + name = "morpheus-appliance-fips-7.0.10-1.el8.x86_64.rpm" + url = "https://downloads.morpheusdata.com/files/morpheus-appliance-fips-7.0.10-1.el8.x86_64.rpm" + path_prefix = "morpheus" + output_path = "${path.root}/downloads" + }, + { + name = "morpheus-appliance-7.0.10-1.el8.x86_64.rpm" + url = "https://downloads.morpheusdata.com/files/morpheus-appliance-7.0.10-1.el8.x86_64.rpm" + path_prefix = "morpheus" + output_path = "${path.root}/downloads" + } + ] + + # Create a set of download configurations for each binary + downloads = concat( + local.morpheus_binaries + ) +} + +module downloader { + # Iterate over each download configuration + for_each = tomap({ for download in local.downloads : download.name => download }) + source = "HappyPathway/downloader/url" + url = each.value.url + output_path = "${each.value.output_path}/${each.key}" +} + + +resource "aws_s3_bucket_object" "morpheus_rpms" { + for_each = tomap({ for download in local.downloads : download.name => download }) + bucket = aws_s3_bucket.assets_bucket.bucket + key = "${each.value.path_prefix}/${each.key}" + source = "${each.value.output_path}/${each.key}" + depends_on = [module.downloader] +} diff --git a/imports.tf b/imports.tf new file mode 100644 index 0000000..09fdd93 --- /dev/null +++ b/imports.tf @@ -0,0 +1,11 @@ +# module.morpheus.module.build_user[0].aws_secretsmanager_secret.credentials +import { + to = module.morpheus.module.build_user[0].aws_secretsmanager_secret.credentials + id = "arn:aws-us-gov:secretsmanager:us-gov-west-1:229685449397:secret:/image-pipeline/morpheus-app/build_user_credentials-BF4y0w" +} + +# module.morpheus.aws_secretsmanager_secret.ssh_key +import { + to = module.morpheus.aws_secretsmanager_secret.ssh_key + id = "arn:aws-us-gov:secretsmanager:us-gov-west-1:229685449397:secret:/image-pipeline/morpheus-app/ssh-private-key-FCQtUR" +} \ No newline at end of file diff --git a/linux-images.code-workspace b/linux-images.code-workspace index 9c90941..9df4b75 100644 --- a/linux-images.code-workspace +++ b/linux-images.code-workspace @@ -8,13 +8,16 @@ }, { "path": ".", - "name": "aws-image-pipeline" + "name": "aws-image-pipeline" }, { "path": "../terraform-aws-image-pipeline" }, { "path": "../image-pipeline-goss-testing" + }, + { + "path": "../terraform-url-downloader" } ], "settings": { diff --git a/locals.tf b/locals.tf index ca323de..cbbd440 100644 --- a/locals.tf +++ b/locals.tf @@ -3,9 +3,28 @@ data "aws_security_group" "it_linux_base" { } locals { + domains_list = [ + ".census.gov", + "169.254.169.254", + "148.129.*", + "10.*", + "172.18.*", + "172.22.*", + "172.23.*", + "172.24.*", + "172.25.*", + ".eks.amazonaws.com", + ".s3.amazonaws.com", + ".amazonaws.com", + ".gcr.io", + ".pkg.dev", + "${local._vpc_config.region}.compute.internal", + ".${local._vpc_config.region}.compute.internal", + "downloads.morpheusdata.com" + ] proxy_env_vars = { HTTP_PROXY = "http://proxy.tco.census.gov:3128" - NO_PROXY = ".census.gov,169.254.169.254,148.129.*,10.*,172.18.*,172.22.*,172.23.*,172.24.*,172.25.*,.eks.amazonaws.com,.s3.amazonaws.com,.amazonaws.com,.gcr.io,.pkg.dev,${local._vpc_config.region}.compute.internal,.${local._vpc_config.region}.compute.internal" + NO_PROXY = join(",", local.domains_list) HTTPS_PROXY = "http://proxy.tco.census.gov:3128" } source_repo = "linux-image-pipeline" diff --git a/morpheus.tf b/morpheus.tf index 670fe3b..9b1bb6a 100644 --- a/morpheus.tf +++ b/morpheus.tf @@ -43,6 +43,9 @@ module "morpheus" { source_ami = var.use_rhel9_ami ? one(data.aws_ssm_parameter.rhel9_ami).value : local.morpheus_ami instance_type = "m5.xlarge" # x86_64 compatible instance type } + extra_parameters = { + morpheus_version = "7.0.10-1" + } image_volume_mapping = [ { device_name = "/dev/sda1"