Skip to content

Commit

Permalink
add tfvas
Browse files Browse the repository at this point in the history
  • Loading branch information
badra001 committed Jan 12, 2023
1 parent 9393f73 commit 87ed80e
Show file tree
Hide file tree
Showing 36 changed files with 495 additions and 3 deletions.
3 changes: 0 additions & 3 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@
*.tfstate
*.tfstate.*

# .tfvars files
*.tfvars

.terraform/*
logs
common/README.md
Expand Down
3 changes: 3 additions & 0 deletions examples/cluster-assume-role/settings.auto.tfvars
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
admin_cluster_list = [
"edl-sa1",
]
2 changes: 2 additions & 0 deletions examples/efk/test1.auto.tfvars
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
cluster_name = "test1"
region = "us-east-1"
59 changes: 59 additions & 0 deletions examples/efk/variables.elk.auto.tfvars
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
image_config = [
{
enabled = true
dest_path = null
name = "elastic/elasticsearch"
source_image = "elasticsearch/elasticsearch"
source_registry = "docker.elastic.co"
source_tag = null
tag = "7.14.0"
},
{
enabled = true
dest_path = null
name = "elastic/kibana"
source_image = "kibana/kibana"
source_registry = "docker.elastic.co"
source_tag = null
tag = "7.14.0"
},
{
enabled = true
dest_path = null
name = "fluent/fluentd-kubernetes-daemonset"
source_image = "fluent/fluentd-kubernetes-daemonset"
source_registry = "docker.io"
source_tag = null
tag = "v1.13.3-debian-elasticsearch7-1.2"
},
]

chart_config = [
{
name = "elasticsearch"
chart_name = "elasticsearch"
chart_version = "7.14.0"
source_repository = "https://helm.elastic.co"
image_reference = "elastic/elasticsearch"
image_tag = "7.14.0"
enabled = true
},
{
name = "kinbana"
chart_name = "kinbana"
chart_version = "7.14.0"
source_repository = "https://helm.elastic.co"
image_reference = "elastic/kibana"
image_tag = "7.14.0"
enabled = true
},
{
name = "fluentd"
chart_name = "fluentd"
chart_version = "09.2.10"
source_repository = "https://fluent.github.io/helm-charts"
image_reference = "fluent/fluentd-kubernetes-daemonset"
image_tag = "v1.13.3-debian-elasticsearch7-1.2"
enabled = true
},
]
28 changes: 28 additions & 0 deletions examples/full-cluster-tf-upgrade.old/aws-auth/aws-auth.auto.tfvars
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
aws_auth_users = [
{
userarn = ""
aws_username = "a-ashle001"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
{
userarn = ""
aws_username = "a-badra001"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
]
aws_auth_roles = [
{
rolearn = ""
aws_rolename = "r-inf-cloud-admin"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
{
rolearn = ""
aws_rolename = "r-inf-terraform"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
]
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
istio_installed_namespace = "istio-system"
# enable only for cicd needs
cicd_k8s_group_name = "cicd-deployer"
cicd_k8s_user_name = "cicd-deployer"
cicd_managed_namespaces = []
deployer_application_istio_role_name = "deployer-application-istio-role"
deployer_application_istio_rolebinding_name = "deployer-application-istio-rolebinding"
deployer_application_role_name = "deployer-application-role"
deployer_application_rolebinding_name = "deployer-application-rolebinding"
deployer_istiosystem_role_name = "deployer-istiosystem-role"
# enable only for dba account needs (most likely, not needed)
dba_admin_rolebinding_name = "dba-admin-rolebinding"
dba_administrator_role_name = "dba-admin-role"
dba_k8s_group_name = "dba-admin"
dba_k8s_user_name = "dba-admin"
dba_managed_namespaces = []
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
#tls_crt_file = "certs/pki.test4.sandbox.csp2.census.gov.bundle.crt"
#tls_key_file = "certs/pki.test4.sandbox.csp2.census.gov.key"
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
cert_manager_cainjector_tag = "v1.4.3"
cert_manager_controller_tag = "v1.4.3"
cert_manager_webhook_tag = "v1.4.3"
cluster_autoscaler_tag = "v1.21.0"
istio_tag = "1.10.1"
metrics_server_tag = "0.6.2-debian-11-r0"
tls_crt_b64 = ""
tls_crt_contents = ""
tls_crt_file = ""
tls_key_b64 = ""
tls_key_contents = ""
tls_key_file = ""
vault_approle_role_id = ""
vault_approle_role_path = ""
vault_approle_secret_id = ""
vault_authentication = ""
vault_ca_bundle_pem = ""
vault_ca_bundle_pem_b64 = ""
vault_ca_bundle_pem_file = ""
vault_path = ""
vault_serviceaccount_mountpath = ""
vault_serviceaccount_role = ""
vault_serviceaccount_sa = ""
vault_token = ""
vault_url = ""
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
namespace = "kube-system"
namespace_short = ""
name = "cluster-autoscaler"
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
name = "unknown"
namespace = "unknown"
namespace_short = ""
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
aws_auth_users = [
{
userarn = ""
aws_username = "a-ashle001"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
{
userarn = ""
aws_username = "a-badra001"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
]
aws_auth_roles = [
{
rolearn = ""
aws_rolename = "r-inf-cloud-admin"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
{
rolearn = ""
aws_rolename = "r-inf-terraform"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
]
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
istio_installed_namespace = "istio-system"
# enable only for cicd needs
cicd_k8s_group_name = "cicd-deployer"
cicd_k8s_user_name = "cicd-deployer"
cicd_managed_namespaces = []
deployer_application_istio_role_name = "deployer-application-istio-role"
deployer_application_istio_rolebinding_name = "deployer-application-istio-rolebinding"
deployer_application_role_name = "deployer-application-role"
deployer_application_rolebinding_name = "deployer-application-rolebinding"
deployer_istiosystem_role_name = "deployer-istiosystem-role"
# enable only for dba account needs (most likely, not needed)
dba_admin_rolebinding_name = "dba-admin-rolebinding"
dba_administrator_role_name = "dba-admin-role"
dba_k8s_group_name = "dba-admin"
dba_k8s_user_name = "dba-admin"
dba_managed_namespaces = []
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
#tls_crt_file = "certs/pki.test4.sandbox.csp2.census.gov.bundle.crt"
#tls_key_file = "certs/pki.test4.sandbox.csp2.census.gov.key"
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
cert_manager_cainjector_tag = "v1.4.3"
cert_manager_controller_tag = "v1.4.3"
cert_manager_webhook_tag = "v1.4.3"
cluster_autoscaler_tag = "v1.21.0"
istio_tag = "1.10.1"
metrics_server_tag = "0.6.2-debian-11-r0"
tls_crt_b64 = ""
tls_crt_contents = ""
tls_crt_file = ""
tls_key_b64 = ""
tls_key_contents = ""
tls_key_file = ""
vault_approle_role_id = ""
vault_approle_role_path = ""
vault_approle_secret_id = ""
vault_authentication = ""
vault_ca_bundle_pem = ""
vault_ca_bundle_pem_b64 = ""
vault_ca_bundle_pem_file = ""
vault_path = ""
vault_serviceaccount_mountpath = ""
vault_serviceaccount_role = ""
vault_serviceaccount_sa = ""
vault_token = ""
vault_url = ""
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
namespace = "kube-system"
namespace_short = ""
name = "cluster-autoscaler"
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
name = "unknown"
namespace = "unknown"
namespace_short = ""
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
aws_auth_users = [
{
userarn = ""
aws_username = "a-ashle001"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
{
userarn = ""
aws_username = "a-badra001"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
]
aws_auth_roles = [
{
rolearn = ""
aws_rolename = "r-inf-cloud-admin"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
{
rolearn = ""
aws_rolename = "r-inf-terraform"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
]
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
istio_installed_namespace = "istio-system"
# enable only for cicd needs
cicd_k8s_group_name = "cicd-deployer"
cicd_k8s_user_name = "cicd-deployer"
cicd_managed_namespaces = []
deployer_application_istio_role_name = "deployer-application-istio-role"
deployer_application_istio_rolebinding_name = "deployer-application-istio-rolebinding"
deployer_application_role_name = "deployer-application-role"
deployer_application_rolebinding_name = "deployer-application-rolebinding"
deployer_istiosystem_role_name = "deployer-istiosystem-role"
# enable only for dba account needs (most likely, not needed)
dba_admin_rolebinding_name = "dba-admin-rolebinding"
dba_administrator_role_name = "dba-admin-role"
dba_k8s_group_name = "dba-admin"
dba_k8s_user_name = "dba-admin"
dba_managed_namespaces = []
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
#tls_crt_file = "certs/pki.test4.sandbox.csp2.census.gov.bundle.crt"
#tls_key_file = "certs/pki.test4.sandbox.csp2.census.gov.key"
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
cert_manager_cainjector_tag = "v1.4.3"
cert_manager_controller_tag = "v1.4.3"
cert_manager_webhook_tag = "v1.4.3"
cluster_autoscaler_tag = "v1.21.0"
istio_tag = "1.10.1"
metrics_server_tag = "0.6.2-debian-11-r0"
tls_crt_b64 = ""
tls_crt_contents = ""
tls_crt_file = ""
tls_key_b64 = ""
tls_key_contents = ""
tls_key_file = ""
vault_approle_role_id = ""
vault_approle_role_path = ""
vault_approle_secret_id = ""
vault_authentication = ""
vault_ca_bundle_pem = ""
vault_ca_bundle_pem_b64 = ""
vault_ca_bundle_pem_file = ""
vault_path = ""
vault_serviceaccount_mountpath = ""
vault_serviceaccount_role = ""
vault_serviceaccount_sa = ""
vault_token = ""
vault_url = ""
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
namespace = "kube-system"
namespace_short = ""
name = "cluster-autoscaler"
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
name = "unknown"
namespace = "unknown"
namespace_short = ""
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
aws_auth_users = [
{
userarn = ""
aws_username = "a-ashle001"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
{
userarn = ""
aws_username = "a-badra001"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
]
aws_auth_roles = [
{
rolearn = ""
aws_rolename = "r-inf-cloud-admin"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
{
rolearn = ""
aws_rolename = "r-inf-terraform"
username = "admin"
groups = ["system:masters", "eks-console-dashboard-full-access-group"]
},
]
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
istio_installed_namespace = "istio-system"
# enable only for cicd needs
cicd_k8s_group_name = "cicd-deployer"
cicd_k8s_user_name = "cicd-deployer"
cicd_managed_namespaces = []
deployer_application_istio_role_name = "deployer-application-istio-role"
deployer_application_istio_rolebinding_name = "deployer-application-istio-rolebinding"
deployer_application_role_name = "deployer-application-role"
deployer_application_rolebinding_name = "deployer-application-rolebinding"
deployer_istiosystem_role_name = "deployer-istiosystem-role"
# enable only for dba account needs (most likely, not needed)
dba_admin_rolebinding_name = "dba-admin-rolebinding"
dba_administrator_role_name = "dba-admin-role"
dba_k8s_group_name = "dba-admin"
dba_k8s_user_name = "dba-admin"
dba_managed_namespaces = []
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
#tls_crt_file = "certs/pki.test4.sandbox.csp2.census.gov.bundle.crt"
#tls_key_file = "certs/pki.test4.sandbox.csp2.census.gov.key"
Loading

0 comments on commit 87ed80e

Please sign in to comment.