diff --git a/copy_images.tf b/copy_images.tf index 84a61ab..794a3a9 100644 --- a/copy_images.tf +++ b/copy_images.tf @@ -7,39 +7,40 @@ locals { image_config = [ { - enabled = true - dest_path = null - name = "keycloak/keycloak" - source_image = "keycloak/keycloak" - source_registry = format("%v/%v", local.ent_ecr_source, "quay") - source_tag = var.keycloak_tag - tag = var.keycloak_tag - source_username = data.aws_ecr_authorization_token.ecr_token.user_name - source_password = data.aws_ecr_authorization_token.ecr_token.password - destination_username = data.aws_ecr_authorization_token.token.user_name - destination_password = data.aws_ecr_authorization_token.token.password + enabled = true + dest_path = null + name = "keycloak/keycloak" + source_image = "keycloak/keycloak" + source_registry = format("%v/%v", local.ent_ecr_source, "quay") + source_tag = var.keycloak_tag + tag = var.keycloak_tag }, { enabled = true dest_path = null name = "bitnami/postgresql" source_image = "bitnami/postgresql" - source_registry = "public.ecr.aws" + source_registry = format("%v/%v", local.ent_ecr_source, "docker-io") + source_tag = var.postgresql_tag + tag = var.postgresql_tag + }, + { + enabled = true + dest_path = null + name = "bitnami/postgres-exporter" + source_image = "bitnami/postgres-exporter" + source_registry = format("%v/%v", local.ent_ecr_source, "docker-io") source_tag = var.postgresql_tag tag = var.postgresql_tag }, { - enabled = true - dest_path = null - name = "bitnami/kubectl-debian" - source_image = "big-bang/utilities" - source_registry = format("%v/%v", local.ent_ecr_source, "ironbank") - source_tag = var.utilities_tag - tag = var.utilities_tag - source_username = data.aws_ecr_authorization_token.ecr_token.user_name - source_password = data.aws_ecr_authorization_token.ecr_token.password - destination_username = data.aws_ecr_authorization_token.token.user_name - destination_password = data.aws_ecr_authorization_token.token.password + enabled = true + dest_path = null + name = "bitnami/kubectl-debian" + source_image = "big-bang/utilities" + source_registry = format("%v/%v", local.ent_ecr_source, "ironbank") + source_tag = var.utilities_tag + tag = var.utilities_tag }, ] } @@ -56,6 +57,12 @@ module "images" { lifecycle_policy_all = true force_delete = true lifecycle_policy_keep_count = 5 + + source_username = data.aws_ecr_authorization_token.ecr_token.user_name + source_password = data.aws_ecr_authorization_token.ecr_token.password + + destination_username = data.aws_ecr_authorization_token.token.user_name + destination_password = data.aws_ecr_authorization_token.token.password } data "aws_ecr_authorization_token" "token" { diff --git a/keycloak-db-values.yaml b/keycloak-db-values.yaml index 849d847..fbed636 100644 --- a/keycloak-db-values.yaml +++ b/keycloak-db-values.yaml @@ -33,7 +33,7 @@ readReplicas: memory: 2Gi # To enable metrics we need to pull in the posgresql-exporter image metrics: - enabled: false + enabled: true persistence: enabled: true diff --git a/terraform-release.yaml b/terraform-release.yaml new file mode 100644 index 0000000..3f67574 --- /dev/null +++ b/terraform-release.yaml @@ -0,0 +1,40 @@ +name: Terraform Module Release +on: + workflow_dispatch: + pull_request: + types: [closed] + branches: + - main +jobs: + terraform-release: + runs-on: "229685449397" + permissions: + contents: write + + steps: + - name: Checkout code + uses: CSVD/gh-actions-checkout@v4 + + - name: Setup GITHUB Credentials + id: github_credentials + uses: CSVD/gh-auth@main + with: + github_app_pem_file: ${{ secrets.GH_APP_PEM_FILE }} + github_app_installation_id: ${{ vars.GH_APP_INSTALLATION_ID }} + github_app_id: ${{ vars.GH_APP_ID }} + + - name: Setup GitHub CLI + run: | + # Force manual authentication since setup-git might not work with GitHub Enterprise + echo "${{ steps.github_credentials.outputs.github_token }}" > /tmp/token.txt + gh auth login --with-token --hostname "github.e.it.census.gov" < /tmp/token.txt + rm /tmp/token.txt + + # Test GitHub CLI auth status + gh auth status || echo "GitHub CLI authentication failed" + + - name: Run Release Action + uses: CSVD/releaser@main + with: + github-token: ${{ steps.github_credentials.outputs.github_token }} + working-directory: '.' diff --git a/terraform-validate.yaml b/terraform-validate.yaml new file mode 100644 index 0000000..ac349eb --- /dev/null +++ b/terraform-validate.yaml @@ -0,0 +1,42 @@ +name: Terraform Validate +on: + pull_request: + workflow_dispatch: + +jobs: + + terraform-validate: + runs-on: "229685449397" + permissions: + contents: write + steps: + - name: Checkout code + uses: CSVD/gh-actions-checkout@v4 + + - name: Setup Terraform + uses: CSVD/gh-actions-setup-terraform@v2 + with: + terraform_version: '1.10.5' + + - name: Validate Terraform Configuration + id: validate + uses: CSVD/terraform-validate@main + + - name: Check Validation/Test Results + if: always() + run: | + # Set default values if outputs are empty + IS_VALID="${{ steps.validate.outputs.is_valid }}" + TESTS_PASSED="${{ steps.validate.outputs.tests_passed }}" + + # If outputs are empty, set them to false + [ -z "$IS_VALID" ] && IS_VALID="false" + [ -z "$TESTS_PASSED" ] && TESTS_PASSED="false" + + if [[ "$IS_VALID" != "true" || "$TESTS_PASSED" != "true" ]]; then + echo "Validation or test errors found:" + echo "${{ steps.validate.outputs.stderr }}" + exit 1 + else + echo "All validations and tests passed successfully!" + fi