From d57f269d13145f1d82e7b0bfb485dd8fa5cf4dcb Mon Sep 17 00:00:00 2001 From: Kashan Ali Date: Fri, 22 Sep 2023 17:24:48 +0500 Subject: [PATCH 01/13] Link: https://github.com/XgridInc/xc3/issues/77 [PS-2] - Added licence
[PS-1] - Crating PR of codepipeline. Issues: - This code pipeline is used to automate the deployment of xc3 infrastructure through codepipeline.
- [ ] Added tests that cover your change (if possible) - [ ] Added/modified documentation as required (such as the `README.md`, or the `docs` directory) - [x] Manually tested - [x] Every function, interface, class has a comment describing what it does and input/output parameters Signed-off-by: Kashan Ali [ kashan.ali@xgrid.co ] --- .../buildspec_yml/apply_buildspec.yml | 37 +++ .../buildspec_yml/destroy_buildspec.yml | 38 +++ .../buildspec_yml/init_buildspec.yml | 46 +++ .../buildspec_yml/plan_buildspec.yml | 39 +++ .../buildspec_yml/unit_test_buildspec.yml | 42 +++ codepipeline-tf/main.tf | 45 +++ .../modules/xc3_codepipeline/main.tf | 306 ++++++++++++++++++ .../modules/xc3_codepipeline/output.tf | 1 + .../modules/xc3_codepipeline/providers.tf | 9 + .../modules/xc3_codepipeline/readme.md | 1 + .../modules/xc3_codepipeline/variables.tf | 122 +++++++ codepipeline-tf/providers.tf | 9 + codepipeline-tf/readme.md | 82 +++++ codepipeline-tf/terraform.auto.tfvars | 44 +++ codepipeline-tf/variable.tf | 122 +++++++ 15 files changed, 943 insertions(+) create mode 100755 codepipeline-tf/buildspec_yml/apply_buildspec.yml create mode 100644 codepipeline-tf/buildspec_yml/destroy_buildspec.yml create mode 100644 codepipeline-tf/buildspec_yml/init_buildspec.yml create mode 100644 codepipeline-tf/buildspec_yml/plan_buildspec.yml create mode 100644 codepipeline-tf/buildspec_yml/unit_test_buildspec.yml create mode 100644 codepipeline-tf/main.tf create mode 100644 codepipeline-tf/modules/xc3_codepipeline/main.tf create mode 100644 codepipeline-tf/modules/xc3_codepipeline/output.tf create mode 100755 codepipeline-tf/modules/xc3_codepipeline/providers.tf create mode 100644 codepipeline-tf/modules/xc3_codepipeline/readme.md create mode 100644 codepipeline-tf/modules/xc3_codepipeline/variables.tf create mode 100755 codepipeline-tf/providers.tf create mode 100644 codepipeline-tf/readme.md create mode 100644 codepipeline-tf/terraform.auto.tfvars create mode 100644 codepipeline-tf/variable.tf diff --git a/codepipeline-tf/buildspec_yml/apply_buildspec.yml b/codepipeline-tf/buildspec_yml/apply_buildspec.yml new file mode 100755 index 00000000..6b61cc13 --- /dev/null +++ b/codepipeline-tf/buildspec_yml/apply_buildspec.yml @@ -0,0 +1,37 @@ +/* +Copyright (c) 2023, Xgrid Inc, https://xgrid.co + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. + +SPDX-License-Identifier:Apache-2.0 +*/ + +version: 0.2 + +phases: + pre_build: + commands: + - echo $0 + - ls + - cd infrastructure + - cat backend.tf + - | + terraform workspace select ${namespace} + build: + commands: + - echo "Applying XC3 Infratructure" + - terraform apply -auto-approve || echo "Terraform apply failed, but continuing the pipeline..." + +artifacts: + files: + - '**/*' diff --git a/codepipeline-tf/buildspec_yml/destroy_buildspec.yml b/codepipeline-tf/buildspec_yml/destroy_buildspec.yml new file mode 100644 index 00000000..4530e033 --- /dev/null +++ b/codepipeline-tf/buildspec_yml/destroy_buildspec.yml @@ -0,0 +1,38 @@ +/* +Copyright (c) 2023, Xgrid Inc, https://xgrid.co + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. + +SPDX-License-Identifier:Apache-2.0 +*/ + +version: 0.2 + +phases: + pre_build: + commands: + - echo $0 + - ls + - cd infrastructure + - cat backend.tf + - | + terraform workspace select ${namespace} + build: + commands: + - echo "Destroying the XC3 Infratructure" + - terraform destroy --auto-approve + + +artifacts: + files: + - '**/*' diff --git a/codepipeline-tf/buildspec_yml/init_buildspec.yml b/codepipeline-tf/buildspec_yml/init_buildspec.yml new file mode 100644 index 00000000..18e0dd6f --- /dev/null +++ b/codepipeline-tf/buildspec_yml/init_buildspec.yml @@ -0,0 +1,46 @@ +/* +Copyright (c) 2023, Xgrid Inc, https://xgrid.co + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. + +SPDX-License-Identifier:Apache-2.0 +*/ + +version: 0.2 + +phases: + pre_build: + commands: + - echo $0 + - echo "Initalizing the XC3 Infratructure" + - ls + - cd infrastructure + - sed -i 's/namespace\s*=\s*"example"/namespace = ${namespace}/' terraform.auto.tfvars + - sed -i 's/account_id\s*=\s*"123456789"/account_id = ${account_id}/' terraform.auto.tfvars + - sed -i 's/domain_name\s*=\s*""/domain_name = ${domain_name}/' terraform.auto.tfvars + - cat backend.tf + - terraform init + - | + if ! terraform workspace select ${namespace}; then + terraform workspace new ${namespace} + terraform workspace select ${namespace} + fi + + build: + commands: + - terraform validate + + +artifacts: + files: + - '**/*' diff --git a/codepipeline-tf/buildspec_yml/plan_buildspec.yml b/codepipeline-tf/buildspec_yml/plan_buildspec.yml new file mode 100644 index 00000000..6ea50dc1 --- /dev/null +++ b/codepipeline-tf/buildspec_yml/plan_buildspec.yml @@ -0,0 +1,39 @@ +/* +Copyright (c) 2023, Xgrid Inc, https://xgrid.co + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. + +SPDX-License-Identifier:Apache-2.0 +*/ + +version: 0.2 + +phases: + pre_build: + commands: + - echo $0 + - ls + - cd infrastructure + - cat backend.tf + - | + terraform workspace select ${namespace} + build: + commands: + - echo "Plan Run of XC3 Infratructure" + - terraform plan + + + +artifacts: + files: + - '**/*' diff --git a/codepipeline-tf/buildspec_yml/unit_test_buildspec.yml b/codepipeline-tf/buildspec_yml/unit_test_buildspec.yml new file mode 100644 index 00000000..08e0b190 --- /dev/null +++ b/codepipeline-tf/buildspec_yml/unit_test_buildspec.yml @@ -0,0 +1,42 @@ +/* +Copyright (c) 2023, Xgrid Inc, https://xgrid.co + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. + +SPDX-License-Identifier:Apache-2.0 +*/ + +version: 0.2 + +phases: + install: + commands: + - echo Installing Python Services + - apk update && apk upgrade + - apk add python3 + - apk add py3-pip + + build: + commands: + - ls + - cd infrastructure + - ls + - terraform workspace select ${namespace} + - cd ../tests/unit_test + - ls + - pytest *.py && echo "Tests passed" || echo "Tests failed" + - cd ../../infrastructure/ + +artifacts: + files: + - '**/*' diff --git a/codepipeline-tf/main.tf b/codepipeline-tf/main.tf new file mode 100644 index 00000000..f49bbd5b --- /dev/null +++ b/codepipeline-tf/main.tf @@ -0,0 +1,45 @@ +/* +Copyright (c) 2023, Xgrid Inc, https://xgrid.co + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. + +SPDX-License-Identifier: Apache-2.0 +*/ + +# code pipeline module +module "xc3_pipeline" { + + source = "./modules/xc3_codepipeline" + tags = var.tags + + namespace_name = var.namespace_name + account_id = var.account_id + domain_name = var.domain_name + xc3_codepipeline_role = var.xc3_codepipeline_role + codebuild_service_role = var.codebuild_service_role + codestar_connections = var.codestar_connections + approve_comment_for_apply = var.approve_comment_for_apply + approve_comment_for_destroy = var.approve_comment_for_destroy + buildspec_folder_path = var.buildspec_folder_path + init_buildspec = var.init_buildspec + plan_buildspec = var.plan_buildspec + test_buildspec = var.test_buildspec + apply_buildspec = var.apply_buildspec + destroy_buildspec = var.destroy_buildspec + compute_type_for_building = var.compute_type_for_building + os_type = var.os_type + docker_image_used = var.docker_image_used + s3_bucket_name = var.s3_bucket_name + full_repository_id = var.full_repository_id + full_branch_name = var.full_branch_name +} diff --git a/codepipeline-tf/modules/xc3_codepipeline/main.tf b/codepipeline-tf/modules/xc3_codepipeline/main.tf new file mode 100644 index 00000000..f67e97bf --- /dev/null +++ b/codepipeline-tf/modules/xc3_codepipeline/main.tf @@ -0,0 +1,306 @@ +/* +Copyright (c) 2023, Xgrid Inc, https://xgrid.co + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. + +SPDX-License-Identifier: Apache-2.0 +*/ + +#creating S3 bucket +resource "aws_s3_bucket" "this" { + bucket = var.s3_bucket_name + tags = var.tags +} + +# codepipeline main resource +resource "aws_codepipeline" "this" { + name = "${var.tags.app}-${var.tags.environment}-tf-pipeline" + role_arn = var.xc3_codepipeline_role + artifact_store { + location = aws_s3_bucket.this.bucket + type = "S3" + } + + stage { + name = "Source_Stage" + + action { + name = "Source" + category = "Source" + owner = "AWS" + provider = "CodeStarSourceConnection" + version = "1" + output_artifacts = ["xc3_infra_code"] + + configuration = { + ConnectionArn = var.codestar_connections + FullRepositoryId = var.full_repository_id + BranchName = var.full_branch_name + } + } + } + + stage { + name = "Terraform_Init_Stage" + + action { + name = "Init_and_Validate" + category = "Build" + owner = "AWS" + provider = "CodeBuild" + input_artifacts = ["xc3_infra_code"] + output_artifacts = ["xc3_infra_init"] + version = "1" + + configuration = { + ProjectName = aws_codebuild_project.codebuild_project_init_stage.name + } + } + } + stage { + name = "Terraform_Plan_Stage" + + action { + name = "Plan" + category = "Build" + owner = "AWS" + provider = "CodeBuild" + input_artifacts = ["xc3_infra_init"] + output_artifacts = ["xc3_infra_plan"] + version = "1" + + configuration = { + ProjectName = aws_codebuild_project.codebuild_project_plan_stage.name + } + } + } + stage { + name = "Terraform_Testing_Stage" + + action { + name = "Testing" + category = "Build" + owner = "AWS" + provider = "CodeBuild" + input_artifacts = ["xc3_infra_plan"] + version = "1" + + configuration = { + ProjectName = aws_codebuild_project.codebuild_project_test_stage.name + } + } + } + stage { + name = "Manual_Approval_for_Apply" + + action { + name = "Approval" + category = "Approval" + owner = "AWS" + provider = "Manual" + version = "1" + + configuration = { + CustomData = var.approve_comment_for_apply + } + } + } + stage { + name = "Terraform_Apply_Stage" + + action { + name = "Deploy" + category = "Build" + owner = "AWS" + provider = "CodeBuild" + input_artifacts = ["xc3_infra_plan"] + output_artifacts = ["xc3_infra_deploy"] + version = "1" + + configuration = { + ProjectName = aws_codebuild_project.codebuild_project_apply_stage.name + } + } + } + stage { + name = "Approval_for_Destroy" + + action { + name = "Destroy_XC3_Infra" + category = "Approval" + owner = "AWS" + provider = "Manual" + version = "1" + + configuration = { + CustomData = var.approve_comment_for_destroy + } + } + } + stage { + name = "Destroy" + + action { + name = "Destroy" + category = "Build" + owner = "AWS" + provider = "CodeBuild" + input_artifacts = ["xc3_infra_deploy"] + version = "1" + + configuration = { + ProjectName = aws_codebuild_project.codebuild_project_destroy_stage.name + } + } + } + + tags = var.tags +} + +##################################################################################################################################################### +### Projects resources +#stage 1 +resource "aws_codebuild_project" "codebuild_project_init_stage" { + name = "${var.tags.app}-${var.tags.environment}-init-project" + description = "Terraform Init and Validate Stage for infra XC3" + service_role = var.codebuild_service_role + + artifacts { + type = "CODEPIPELINE" + } + + environment { + compute_type = var.compute_type_for_building + type = var.os_type + image = var.docker_image_used + environment_variable { + name = "namespace" + value = var.namespace_name + } + } + + source { + type = "CODEPIPELINE" + buildspec = file("${var.buildspec_folder_path}${var.init_buildspec}") + } +} +#stage 2 +resource "aws_codebuild_project" "codebuild_project_plan_stage" { + name = "${var.tags.app}_${var.tags.environment}-plan-project" + description = "Terraform Plan Stage for infra XC3" + service_role = var.codebuild_service_role + + + artifacts { + type = "CODEPIPELINE" + } + + environment { + compute_type = var.compute_type_for_building + type = var.os_type + image = var.docker_image_used + environment_variable { + name = "namespace" + value = var.namespace_name + } + environment_variable { + name = "account_id" + value = var.account_id + } + environment_variable { + name = "domain_name" + value = var.domain_name + } + } + + source { + type = "CODEPIPELINE" + buildspec = file("${var.buildspec_folder_path}${var.plan_buildspec}") + } +} +#stage unit test +resource "aws_codebuild_project" "codebuild_project_test_stage" { + name = "${var.tags.app}-${var.tags.environment}-test-project" + description = "Terraform Test Stage for infra XC3" + service_role = var.codebuild_service_role + + + artifacts { + type = "CODEPIPELINE" + } + + environment { + compute_type = var.compute_type_for_building + type = var.os_type + image = var.docker_image_used + environment_variable { + name = "namespace" + value = var.namespace_name + } + } + + source { + type = "CODEPIPELINE" + buildspec = file("${var.buildspec_folder_path}${var.test_buildspec}") + } +} +#stage 3 +resource "aws_codebuild_project" "codebuild_project_apply_stage" { + name = "${var.tags.app}-${var.tags.environment}-apply-project" + description = "Terraform Apply Stage for infra XC3" + service_role = var.codebuild_service_role + + artifacts { + type = "CODEPIPELINE" + } + + environment { + compute_type = var.compute_type_for_building + type = var.os_type + image = var.docker_image_used + environment_variable { + name = "namespace" + value = var.namespace_name + } + } + + source { + type = "CODEPIPELINE" + buildspec = file("${var.buildspec_folder_path}${var.apply_buildspec}") + } +} +#stage 4 +resource "aws_codebuild_project" "codebuild_project_destroy_stage" { + name = "${var.tags.app}-${var.tags.environment}-destroy-project" + description = "Terraform Apply Stage for infra XC3" + service_role = var.codebuild_service_role + + artifacts { + type = "CODEPIPELINE" + } + + environment { + compute_type = var.compute_type_for_building + type = var.os_type + image = var.docker_image_used + environment_variable { + name = "namespace" + value = var.namespace_name + } + } + + source { + type = "CODEPIPELINE" + buildspec = file("${var.buildspec_folder_path}${var.destroy_buildspec}") + } +} diff --git a/codepipeline-tf/modules/xc3_codepipeline/output.tf b/codepipeline-tf/modules/xc3_codepipeline/output.tf new file mode 100644 index 00000000..28307dae --- /dev/null +++ b/codepipeline-tf/modules/xc3_codepipeline/output.tf @@ -0,0 +1 @@ +# No outputs included, currently empty. diff --git a/codepipeline-tf/modules/xc3_codepipeline/providers.tf b/codepipeline-tf/modules/xc3_codepipeline/providers.tf new file mode 100755 index 00000000..f32ed9da --- /dev/null +++ b/codepipeline-tf/modules/xc3_codepipeline/providers.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} diff --git a/codepipeline-tf/modules/xc3_codepipeline/readme.md b/codepipeline-tf/modules/xc3_codepipeline/readme.md new file mode 100644 index 00000000..28034d0e --- /dev/null +++ b/codepipeline-tf/modules/xc3_codepipeline/readme.md @@ -0,0 +1 @@ +This pipeline has currently different stages to Source, Build, Deploy and destroy the code. diff --git a/codepipeline-tf/modules/xc3_codepipeline/variables.tf b/codepipeline-tf/modules/xc3_codepipeline/variables.tf new file mode 100644 index 00000000..1dbdd147 --- /dev/null +++ b/codepipeline-tf/modules/xc3_codepipeline/variables.tf @@ -0,0 +1,122 @@ +/* +Copyright (c) 2023, Xgrid Inc, https://xgrid.co + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. + +SPDX-License-Identifier: Apache-2.0 +*/ + +################ Tags Portion ################ +variable "tags" { + description = "Tags used in this module." + type = map(any) +} + +variable "namespace_name" { + description = "Namespace used in project." + type = string +} +variable "account_id" { + description = "AWS account ID used in module." + type = string +} +variable "domain_name" { + description = "domain name used in module." + type = string +} +################ S3 Bucket Variables ################ +variable "s3_bucket_name" { + description = "S3 bucket varibale" + type = string +} + +################ Senstive Values Variables ################ +variable "xc3_codepipeline_role" { + description = "This is the main role to run codepipelin." + type = string + +} + +variable "codebuild_service_role" { + description = "This is the service role, used to create projects for codepipeline." + type = string +} + +variable "codestar_connections" { + description = "This is the service role, used to create projects for codepipeline." + type = string +} +################ Github Variables ################ +variable "full_repository_id" { + description = "Repository identity used codepipeline module." + type = string + +} +variable "full_branch_name" { + description = "Branch name used in codepipeline module." + type = string +} +################ Comments and Description Variables ################ +variable "approve_comment_for_apply" { + description = "" + type = string + +} +variable "approve_comment_for_destroy" { + description = "" + type = string +} +################ Build Spec File Name Variables ################ +variable "buildspec_folder_path" { + description = "Buildspec folder path used in codepipeline module." + type = string +} + +variable "init_buildspec" { + description = "" + type = string +} + +variable "plan_buildspec" { + description = "" + type = string +} +variable "test_buildspec" { + description = "" + type = string +} +variable "apply_buildspec" { + description = "" + type = string +} + +variable "destroy_buildspec" { + description = "" + type = string +} +################ Compute Environment Variables ################ + +variable "compute_type_for_building" { + description = "Build environment compute type variable." + type = string +} + +variable "os_type" { + description = "Operating system variable." + type = string +} + +variable "docker_image_used" { + description = "Docker image used in project variable." + type = string +} diff --git a/codepipeline-tf/providers.tf b/codepipeline-tf/providers.tf new file mode 100755 index 00000000..f32ed9da --- /dev/null +++ b/codepipeline-tf/providers.tf @@ -0,0 +1,9 @@ +terraform { + required_version = ">= 1.0" + required_providers { + aws = { + source = "hashicorp/aws" + version = ">= 5.0" + } + } +} diff --git a/codepipeline-tf/readme.md b/codepipeline-tf/readme.md new file mode 100644 index 00000000..b567e3b1 --- /dev/null +++ b/codepipeline-tf/readme.md @@ -0,0 +1,82 @@ +# Terraform Module: xc3_pipeline + +## Overview + +This Terraform module, named `xc3_pipeline`, is designed to create and manage an AWS CodePipeline for a project. It automates the process of setting up continuous integration and continuous deployment (CI/CD) pipelines. This README provides an overview of the module, its configuration options, and how to use it. + +## Module Structure + +The `xc3_pipeline` module consists of the following components: + +- **Source**: This module references another module named `xc3_codepipeline`, located in the `./modules/xc3_codepipeline` directory. The sub-module is responsible for defining the AWS CodePipeline resources and their configurations. + +- **Input Variables**: Various input variables are provided to customize the behavior of the CodePipeline. These variables include configuration options for AWS resources, GitHub repository information, comments for approvals, and build specifications. + +- **Providers**: The module specifies the required Terraform provider, in this case, the `hashicorp/aws` provider with a version constraint of `>= 5.0`. + +## Configuration Options + +### Tags + +- `tags` (Map): A map of tags to apply to the AWS resources created by the module. + +- `namespace_name` (String): A namespace identifier used within the project. + +### Sensitive Values Variables + +- `xc3_codepipeline_role` (String): The IAM role used to execute the CodePipeline. + +- `codebuild_service_role` (String): The IAM role used to create projects for the CodePipeline. + +- `codestar_connections` (String): A service role used in the CodePipeline configuration. + +### GitHub Variables + +- `full_repository_id` (String): The full ID of the GitHub repository. + +- `full_branch_name` (String): The full name of the GitHub branch to monitor for changes. + +### Comments and Description Variables + +- `approve_comment_for_apply` (String): A comment to request manual approval before applying changes. + +- `approve_comment_for_destroy` (String): A comment to request manual approval before destroying resources. + +### Build Spec File Name Variables + +- `buildspec_folder_path` (String): The path to the directory containing build specifications. + +- `init_buildspec` (String): The name of the build specification for the initialization phase. + +- `plan_buildspec` (String): The name of the build specification for the planning phase. + +- `test_buildspec` (String): The name of the build specification for the testing phase. + +- `apply_buildspec` (String): The name of the build specification for the applying phase. + +- `destroy_buildspec` (String): The name of the build specification for the destroying phase. + +### Compute Environment Variables + +- `compute_type_for_building` (String): The type of compute environment for building. + +- `os_type` (String): The operating system used in the build environment. + +- `docker_image_used` (String): The Docker image used in the project. + +## How to Use + +To use this Terraform module, include it in your Terraform configuration, and provide values for the required variables. Here's an example of how to use it: + +```hcl +module "my_codepipeline" { + source = "./modules/xc3_pipeline" + + tags = { + Project = "MyProject" + Environment = "Dev" + } + + namespace_name = "my_namespace" + # ... Provide values for other variables ... +} diff --git a/codepipeline-tf/terraform.auto.tfvars b/codepipeline-tf/terraform.auto.tfvars new file mode 100644 index 00000000..ba1fef03 --- /dev/null +++ b/codepipeline-tf/terraform.auto.tfvars @@ -0,0 +1,44 @@ +################################################## +# tfvars +################################################## + + +namespace_name = "example" +account_id = "your-account-id" +domain_name = "your-domain" + +s3_bucket_name = "terraform-state-xc3-example-pipeline" + + +xc3_codepipeline_role = "arn:aws:iam::201635854701:role/xccc-pipeline-role" +codebuild_service_role = "arn:aws:iam::201635854701:role/service-role/codebuild-test-service-role" +codestar_connections = "arn:aws:codestar-connections:eu-west-1:201635854701:connection/68b68fa1-9687-405a-b75c-cbf1f5ca6de5" + +approve_comment_for_apply = "This approval needs to create XC3 infrastructure." +approve_comment_for_destroy = "This approval needs to destroy XC3 infrastructure." + +full_repository_id = "your full repo id" +full_branch_name = "feature/pipeline-testing-example" + +buildspec_folder_path = "./buildspec_yml/" +init_buildspec = "init_buildspec.yml" +plan_buildspec = "plan_buildspec.yml" +test_buildspec = "unit_test_buildspec.yml" +apply_buildspec = "apply_buildspec.yml" +destroy_buildspec = "destroy_buildspec.yml" + +compute_type_for_building = "BUILD_GENERAL1_SMALL" +os_type = "LINUX_CONTAINER" +docker_image_used = "hashicorp/terraform:latest" + + +tags = { + app = "Codepipeline", + created-by = "Terraform", + environment = "dev", + name = "example", + project = "test", + owner = "example@example.co", + creator = "example@example.co", + team = "team" +} diff --git a/codepipeline-tf/variable.tf b/codepipeline-tf/variable.tf new file mode 100644 index 00000000..f8446cab --- /dev/null +++ b/codepipeline-tf/variable.tf @@ -0,0 +1,122 @@ +/* +Copyright (c) 2023, Xgrid Inc, https://xgrid.co + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. + +SPDX-License-Identifier: Apache-2.0 +*/ + +################ Tags Portion ################ +variable "tags" { + description = "Tags used in this module." + type = map(any) +} + +variable "namespace_name" { + description = "Namespace used in project." + type = string +} +variable "account_id" { + description = "AWS account ID used in module." + type = string +} +variable "domain_name" { + description = "domain name used in module." + type = string +} +################ S3 Bucket Variables ################ +variable "s3_bucket_name" { + description = "S3 bucket varibale" + type = string +} + +################ Senstive Values Variables ################ +variable "xc3_codepipeline_role" { + description = "This is the main role to run codepipelin." + type = string + +} + +variable "codebuild_service_role" { + description = "This is the service role, used to create projects for codepipeline." + type = string +} + +variable "codestar_connections" { + description = "This is the service role, used to create projects for codepipeline." + type = string +} +################ Github Variables ################ +variable "full_repository_id" { + description = "Repository identity used codepipeline module." + type = string + +} +variable "full_branch_name" { + description = "Branch name used in codepipeline module." + type = string +} +################ Comments and Description Variables ################ +variable "approve_comment_for_apply" { + description = "" + type = string + +} +variable "approve_comment_for_destroy" { + description = "" + type = string +} +################ Build Spec File Name Variables ################ +variable "buildspec_folder_path" { + description = "Buildspec folder path used in codepipeline module." + type = string +} + +variable "init_buildspec" { + description = "" + type = string +} + +variable "plan_buildspec" { + description = "" + type = string +} +variable "test_buildspec" { + description = "" + type = string +} +variable "apply_buildspec" { + description = "" + type = string +} + +variable "destroy_buildspec" { + description = "" + type = string +} +################ Compute Environment Variables ################ + +variable "compute_type_for_building" { + description = "Build environment compute type variable." + type = string +} + +variable "os_type" { + description = "Operating system variable." + type = string +} + +variable "docker_image_used" { + description = "Docker image used in project variable." + type = string +} From c2eb92bedfc635b3e9fe4795845c33bb22566d22 Mon Sep 17 00:00:00 2001 From: kashan-ali_snlabs Date: Thu, 25 Jan 2024 16:19:37 +0500 Subject: [PATCH 02/13] Codepipeline xc3 - Module Link: https://github.com/XgridInc/xc3/issues/77 [PS-1] - Crating PR of codepipeline. Issues: - This code pipeline is used to automate the deployment of xc3 infrastructure through codepipeline.
- [ ] Added tests that cover your change (if possible) - [ ] Added/modified documentation as required (such as the `README.md`, or the `docs` directory) - [x] Manually tested - [x] Every function, interface, class has a comment describing what it does and input/output parameters Signed-off-by: Kashan Ali [ kashan.ali@xgrid.co ] Signed-off-by: kashan-ali_snlabs --- .../buildspec_yml/apply_buildspec.yml | 34 +++++++------ .../buildspec_yml/destroy_buildspec.yml | 27 +++++----- .../buildspec_yml/init_buildspec.yml | 49 +++++++++++-------- .../buildspec_yml/plan_buildspec.yml | 27 +++++----- .../buildspec_yml/unit_test_buildspec.yml | 25 +++++----- codepipeline-tf/main.tf | 1 + .../modules/xc3_codepipeline/main.tf | 32 ++++++++---- .../modules/xc3_codepipeline/variables.tf | 5 ++ codepipeline-tf/providers.tf | 4 ++ codepipeline-tf/terraform.auto.tfvars | 11 +++-- codepipeline-tf/variable.tf | 9 ++++ 11 files changed, 136 insertions(+), 88 deletions(-) diff --git a/codepipeline-tf/buildspec_yml/apply_buildspec.yml b/codepipeline-tf/buildspec_yml/apply_buildspec.yml index 6b61cc13..fb8a4965 100755 --- a/codepipeline-tf/buildspec_yml/apply_buildspec.yml +++ b/codepipeline-tf/buildspec_yml/apply_buildspec.yml @@ -1,20 +1,18 @@ -/* -Copyright (c) 2023, Xgrid Inc, https://xgrid.co +#Copyright (c) 2023, Xgrid Inc, https://xgrid.co -Licensed under the Apache License, Version 2.0 (the "License"); -you may not use this file except in compliance with the License. -You may obtain a copy of the License at +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at - http://www.apache.org/licenses/LICENSE-2.0 +# http://www.apache.org/licenses/LICENSE-2.0 -Unless required by applicable law or agreed to in writing, software -distributed under the License is distributed on an "AS IS" BASIS, -WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -See the License for the specific language governing permissions and -limitations under the License. +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. -SPDX-License-Identifier:Apache-2.0 -*/ +# SPDX-License-Identifier:Apache-2.0 version: 0.2 @@ -22,6 +20,7 @@ phases: pre_build: commands: - echo $0 + - apk --update add aws-cli - ls - cd infrastructure - cat backend.tf @@ -29,7 +28,14 @@ phases: terraform workspace select ${namespace} build: commands: - - echo "Applying XC3 Infratructure" + - cat backend.tf + - mkdir python + - apk add python3 + - apk add py3-pip + - apk add zip + - pip3 install -t python/ prometheus-client + - zip -r python.zip ./python + - echo "Applying XC3 Infrastructure" - terraform apply -auto-approve || echo "Terraform apply failed, but continuing the pipeline..." artifacts: diff --git a/codepipeline-tf/buildspec_yml/destroy_buildspec.yml b/codepipeline-tf/buildspec_yml/destroy_buildspec.yml index 4530e033..4b617412 100644 --- a/codepipeline-tf/buildspec_yml/destroy_buildspec.yml +++ b/codepipeline-tf/buildspec_yml/destroy_buildspec.yml @@ -1,20 +1,19 @@ -/* -Copyright (c) 2023, Xgrid Inc, https://xgrid.co +#Copyright (c) 2023, Xgrid Inc, https://xgrid.co -Licensed under the Apache License, Version 2.0 (the "License"); -you may not use this file except in compliance with the License. -You may obtain a copy of the License at +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at - http://www.apache.org/licenses/LICENSE-2.0 +# http://www.apache.org/licenses/LICENSE-2.0 -Unless required by applicable law or agreed to in writing, software -distributed under the License is distributed on an "AS IS" BASIS, -WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -See the License for the specific language governing permissions and -limitations under the License. +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +# SPDX-License-Identifier:Apache-2.0 -SPDX-License-Identifier:Apache-2.0 -*/ version: 0.2 @@ -29,7 +28,7 @@ phases: terraform workspace select ${namespace} build: commands: - - echo "Destroying the XC3 Infratructure" + - echo "Destroying the XC3 Infrastructure" - terraform destroy --auto-approve diff --git a/codepipeline-tf/buildspec_yml/init_buildspec.yml b/codepipeline-tf/buildspec_yml/init_buildspec.yml index 18e0dd6f..62838e9a 100644 --- a/codepipeline-tf/buildspec_yml/init_buildspec.yml +++ b/codepipeline-tf/buildspec_yml/init_buildspec.yml @@ -1,20 +1,18 @@ -/* -Copyright (c) 2023, Xgrid Inc, https://xgrid.co +#Copyright (c) 2023, Xgrid Inc, https://xgrid.co -Licensed under the Apache License, Version 2.0 (the "License"); -you may not use this file except in compliance with the License. -You may obtain a copy of the License at +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at - http://www.apache.org/licenses/LICENSE-2.0 +# http://www.apache.org/licenses/LICENSE-2.0 -Unless required by applicable law or agreed to in writing, software -distributed under the License is distributed on an "AS IS" BASIS, -WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -See the License for the specific language governing permissions and -limitations under the License. +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. -SPDX-License-Identifier:Apache-2.0 -*/ +# SPDX-License-Identifier:Apache-2.0 version: 0.2 @@ -22,22 +20,33 @@ phases: pre_build: commands: - echo $0 - - echo "Initalizing the XC3 Infratructure" + - echo "Initializing the XC3 Infrastructure" - ls - cd infrastructure - - sed -i 's/namespace\s*=\s*"example"/namespace = ${namespace}/' terraform.auto.tfvars - - sed -i 's/account_id\s*=\s*"123456789"/account_id = ${account_id}/' terraform.auto.tfvars - - sed -i 's/domain_name\s*=\s*""/domain_name = ${domain_name}/' terraform.auto.tfvars + - ls + - echo ${s3_bucket_name} + - sed -i "s/\"terraform-state-xc3\"/\"$s3_bucket_name\"/g" backend.tf + - sed -i 's/xc3\/xc3.tfstate/'${key}'/g' backend.tf - cat backend.tf + - sed -i "s/\"testing\"/\"$namespace\"/g" terraform.auto.tfvars + - sed -i "s/\"123456789\"/\"$account_id\"/g" terraform.auto.tfvars + - sed -i "s/\"\"/\"$domain_name\"/g" terraform.auto.tfvars + + - sed -i 's/"testing"/'${namespace}'/g' terraform.auto.tfvars + - sed -i 's/"123456789"/'${account_id}'/g' terraform.auto.tfvars + - sed -i 's/""/'${domain_name}'/g' terraform.auto.tfvars + - cat terraform.auto.tfvars + + + + build: + commands: - terraform init - | if ! terraform workspace select ${namespace}; then terraform workspace new ${namespace} terraform workspace select ${namespace} fi - - build: - commands: - terraform validate diff --git a/codepipeline-tf/buildspec_yml/plan_buildspec.yml b/codepipeline-tf/buildspec_yml/plan_buildspec.yml index 6ea50dc1..e31dfb5c 100644 --- a/codepipeline-tf/buildspec_yml/plan_buildspec.yml +++ b/codepipeline-tf/buildspec_yml/plan_buildspec.yml @@ -1,20 +1,18 @@ -/* -Copyright (c) 2023, Xgrid Inc, https://xgrid.co +#Copyright (c) 2023, Xgrid Inc, https://xgrid.co -Licensed under the Apache License, Version 2.0 (the "License"); -you may not use this file except in compliance with the License. -You may obtain a copy of the License at +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at - http://www.apache.org/licenses/LICENSE-2.0 +# http://www.apache.org/licenses/LICENSE-2.0 -Unless required by applicable law or agreed to in writing, software -distributed under the License is distributed on an "AS IS" BASIS, -WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -See the License for the specific language governing permissions and -limitations under the License. +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. -SPDX-License-Identifier:Apache-2.0 -*/ +# SPDX-License-Identifier:Apache-2.0 version: 0.2 @@ -25,11 +23,12 @@ phases: - ls - cd infrastructure - cat backend.tf + - cat terraform.auto.tfvars - | terraform workspace select ${namespace} build: commands: - - echo "Plan Run of XC3 Infratructure" + - echo "Plan Run of XC3 Infrastructure" - terraform plan diff --git a/codepipeline-tf/buildspec_yml/unit_test_buildspec.yml b/codepipeline-tf/buildspec_yml/unit_test_buildspec.yml index 08e0b190..b0e7a471 100644 --- a/codepipeline-tf/buildspec_yml/unit_test_buildspec.yml +++ b/codepipeline-tf/buildspec_yml/unit_test_buildspec.yml @@ -1,20 +1,19 @@ -/* -Copyright (c) 2023, Xgrid Inc, https://xgrid.co +#Copyright (c) 2023, Xgrid Inc, https://xgrid.co -Licensed under the Apache License, Version 2.0 (the "License"); -you may not use this file except in compliance with the License. -You may obtain a copy of the License at +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at - http://www.apache.org/licenses/LICENSE-2.0 +# http://www.apache.org/licenses/LICENSE-2.0 -Unless required by applicable law or agreed to in writing, software -distributed under the License is distributed on an "AS IS" BASIS, -WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -See the License for the specific language governing permissions and -limitations under the License. +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +# SPDX-License-Identifier:Apache-2.0 -SPDX-License-Identifier:Apache-2.0 -*/ version: 0.2 diff --git a/codepipeline-tf/main.tf b/codepipeline-tf/main.tf index f49bbd5b..98573119 100644 --- a/codepipeline-tf/main.tf +++ b/codepipeline-tf/main.tf @@ -42,4 +42,5 @@ module "xc3_pipeline" { s3_bucket_name = var.s3_bucket_name full_repository_id = var.full_repository_id full_branch_name = var.full_branch_name + key = var.key } diff --git a/codepipeline-tf/modules/xc3_codepipeline/main.tf b/codepipeline-tf/modules/xc3_codepipeline/main.tf index f67e97bf..9fa7cfa6 100644 --- a/codepipeline-tf/modules/xc3_codepipeline/main.tf +++ b/codepipeline-tf/modules/xc3_codepipeline/main.tf @@ -19,9 +19,15 @@ SPDX-License-Identifier: Apache-2.0 #creating S3 bucket resource "aws_s3_bucket" "this" { bucket = var.s3_bucket_name + force_destroy = true tags = var.tags } - +resource "aws_s3_bucket_versioning" "this" { + bucket = aws_s3_bucket.this.id + versioning_configuration { + status = "Enabled" + } +} # codepipeline main resource resource "aws_codepipeline" "this" { name = "${var.tags.app}-${var.tags.environment}-tf-pipeline" @@ -187,6 +193,22 @@ resource "aws_codebuild_project" "codebuild_project_init_stage" { name = "namespace" value = var.namespace_name } + environment_variable { + name = "account_id" + value = var.account_id + } + environment_variable { + name = "domain_name" + value = var.domain_name + } + environment_variable { + name = "s3_bucket_name" + value = var.s3_bucket_name + } + environment_variable { + name = "key" + value = var.key + } } source { @@ -213,14 +235,6 @@ resource "aws_codebuild_project" "codebuild_project_plan_stage" { name = "namespace" value = var.namespace_name } - environment_variable { - name = "account_id" - value = var.account_id - } - environment_variable { - name = "domain_name" - value = var.domain_name - } } source { diff --git a/codepipeline-tf/modules/xc3_codepipeline/variables.tf b/codepipeline-tf/modules/xc3_codepipeline/variables.tf index 1dbdd147..cefbabcc 100644 --- a/codepipeline-tf/modules/xc3_codepipeline/variables.tf +++ b/codepipeline-tf/modules/xc3_codepipeline/variables.tf @@ -120,3 +120,8 @@ variable "docker_image_used" { description = "Docker image used in project variable." type = string } + +variable "key" { + description = "key used in codepipeline(state file key)." + type = string +} \ No newline at end of file diff --git a/codepipeline-tf/providers.tf b/codepipeline-tf/providers.tf index f32ed9da..b09baa3a 100755 --- a/codepipeline-tf/providers.tf +++ b/codepipeline-tf/providers.tf @@ -7,3 +7,7 @@ terraform { } } } + +provider "aws" { + region = "eu-west-1" +} \ No newline at end of file diff --git a/codepipeline-tf/terraform.auto.tfvars b/codepipeline-tf/terraform.auto.tfvars index ba1fef03..b2e41f8f 100644 --- a/codepipeline-tf/terraform.auto.tfvars +++ b/codepipeline-tf/terraform.auto.tfvars @@ -6,19 +6,22 @@ namespace_name = "example" account_id = "your-account-id" domain_name = "your-domain" +region = "eu-west-1" s3_bucket_name = "terraform-state-xc3-example-pipeline" +//delete after deployment +key = "example\\/example.tfstate" -xc3_codepipeline_role = "arn:aws:iam::201635854701:role/xccc-pipeline-role" -codebuild_service_role = "arn:aws:iam::201635854701:role/service-role/codebuild-test-service-role" -codestar_connections = "arn:aws:codestar-connections:eu-west-1:201635854701:connection/68b68fa1-9687-405a-b75c-cbf1f5ca6de5" +xc3_codepipeline_role = "arn:aws:iam::test:role/xccc-pipeline-role" +codebuild_service_role = "arn:aws:iam::test:role/service-role/codebuild-test-service-role" +codestar_connections = "arn:aws:codestar-connections:eu-west-1:test:connection/code-star-connection-role" approve_comment_for_apply = "This approval needs to create XC3 infrastructure." approve_comment_for_destroy = "This approval needs to destroy XC3 infrastructure." full_repository_id = "your full repo id" -full_branch_name = "feature/pipeline-testing-example" +full_branch_name = "main" buildspec_folder_path = "./buildspec_yml/" init_buildspec = "init_buildspec.yml" diff --git a/codepipeline-tf/variable.tf b/codepipeline-tf/variable.tf index f8446cab..632d8867 100644 --- a/codepipeline-tf/variable.tf +++ b/codepipeline-tf/variable.tf @@ -120,3 +120,12 @@ variable "docker_image_used" { description = "Docker image used in project variable." type = string } + +variable "region" { + description = "Region used for pipeline testing." + type = string +} +variable "key" { + description = "key used in codepipeline(state file key)." + type = string +} \ No newline at end of file From 6355f426b989351e609e53488a3274cb71870cd7 Mon Sep 17 00:00:00 2001 From: kashan-ali_snlabs Date: Thu, 25 Jan 2024 17:52:31 +0500 Subject: [PATCH 03/13] Added new changes Signed-off-by: kashan-ali_snlabs --- codepipeline-tf/buildspec_yml/apply_buildspec.yml | 7 +------ codepipeline-tf/buildspec_yml/destroy_buildspec.yml | 7 +------ codepipeline-tf/buildspec_yml/init_buildspec.yml | 9 --------- codepipeline-tf/buildspec_yml/plan_buildspec.yml | 7 ------- codepipeline-tf/buildspec_yml/unit_test_buildspec.yml | 7 ------- codepipeline-tf/main.tf | 1 + codepipeline-tf/modules/xc3_codepipeline/variables.tf | 5 +++++ codepipeline-tf/providers.tf | 2 +- codepipeline-tf/terraform.auto.tfvars | 2 +- codepipeline-tf/variable.tf | 2 +- 10 files changed, 11 insertions(+), 38 deletions(-) diff --git a/codepipeline-tf/buildspec_yml/apply_buildspec.yml b/codepipeline-tf/buildspec_yml/apply_buildspec.yml index fb8a4965..65c91aaa 100755 --- a/codepipeline-tf/buildspec_yml/apply_buildspec.yml +++ b/codepipeline-tf/buildspec_yml/apply_buildspec.yml @@ -1,17 +1,13 @@ #Copyright (c) 2023, Xgrid Inc, https://xgrid.co - # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at - # http://www.apache.org/licenses/LICENSE-2.0 - # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. - # SPDX-License-Identifier:Apache-2.0 version: 0.2 @@ -36,8 +32,7 @@ phases: - pip3 install -t python/ prometheus-client - zip -r python.zip ./python - echo "Applying XC3 Infrastructure" - - terraform apply -auto-approve || echo "Terraform apply failed, but continuing the pipeline..." - + - terraform apply -auto-approve || echo "Terraform apply failed, but continuing the pipeline....." artifacts: files: - '**/*' diff --git a/codepipeline-tf/buildspec_yml/destroy_buildspec.yml b/codepipeline-tf/buildspec_yml/destroy_buildspec.yml index 4b617412..f7798686 100644 --- a/codepipeline-tf/buildspec_yml/destroy_buildspec.yml +++ b/codepipeline-tf/buildspec_yml/destroy_buildspec.yml @@ -1,20 +1,15 @@ #Copyright (c) 2023, Xgrid Inc, https://xgrid.co - # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at - # http://www.apache.org/licenses/LICENSE-2.0 - # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. - # SPDX-License-Identifier:Apache-2.0 - version: 0.2 phases: @@ -31,7 +26,7 @@ phases: - echo "Destroying the XC3 Infrastructure" - terraform destroy --auto-approve - + artifacts: files: - '**/*' diff --git a/codepipeline-tf/buildspec_yml/init_buildspec.yml b/codepipeline-tf/buildspec_yml/init_buildspec.yml index 62838e9a..a64096c9 100644 --- a/codepipeline-tf/buildspec_yml/init_buildspec.yml +++ b/codepipeline-tf/buildspec_yml/init_buildspec.yml @@ -1,17 +1,13 @@ #Copyright (c) 2023, Xgrid Inc, https://xgrid.co - # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at - # http://www.apache.org/licenses/LICENSE-2.0 - # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. - # SPDX-License-Identifier:Apache-2.0 version: 0.2 @@ -36,9 +32,6 @@ phases: - sed -i 's/"123456789"/'${account_id}'/g' terraform.auto.tfvars - sed -i 's/""/'${domain_name}'/g' terraform.auto.tfvars - cat terraform.auto.tfvars - - - build: commands: - terraform init @@ -48,8 +41,6 @@ phases: terraform workspace select ${namespace} fi - terraform validate - - artifacts: files: - '**/*' diff --git a/codepipeline-tf/buildspec_yml/plan_buildspec.yml b/codepipeline-tf/buildspec_yml/plan_buildspec.yml index e31dfb5c..1105af6c 100644 --- a/codepipeline-tf/buildspec_yml/plan_buildspec.yml +++ b/codepipeline-tf/buildspec_yml/plan_buildspec.yml @@ -1,17 +1,13 @@ #Copyright (c) 2023, Xgrid Inc, https://xgrid.co - # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at - # http://www.apache.org/licenses/LICENSE-2.0 - # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. - # SPDX-License-Identifier:Apache-2.0 version: 0.2 @@ -30,9 +26,6 @@ phases: commands: - echo "Plan Run of XC3 Infrastructure" - terraform plan - - - artifacts: files: - '**/*' diff --git a/codepipeline-tf/buildspec_yml/unit_test_buildspec.yml b/codepipeline-tf/buildspec_yml/unit_test_buildspec.yml index b0e7a471..3bb7354a 100644 --- a/codepipeline-tf/buildspec_yml/unit_test_buildspec.yml +++ b/codepipeline-tf/buildspec_yml/unit_test_buildspec.yml @@ -1,20 +1,15 @@ #Copyright (c) 2023, Xgrid Inc, https://xgrid.co - # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at - # http://www.apache.org/licenses/LICENSE-2.0 - # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. - # SPDX-License-Identifier:Apache-2.0 - version: 0.2 phases: @@ -24,7 +19,6 @@ phases: - apk update && apk upgrade - apk add python3 - apk add py3-pip - build: commands: - ls @@ -35,7 +29,6 @@ phases: - ls - pytest *.py && echo "Tests passed" || echo "Tests failed" - cd ../../infrastructure/ - artifacts: files: - '**/*' diff --git a/codepipeline-tf/main.tf b/codepipeline-tf/main.tf index 98573119..e535dd32 100644 --- a/codepipeline-tf/main.tf +++ b/codepipeline-tf/main.tf @@ -42,5 +42,6 @@ module "xc3_pipeline" { s3_bucket_name = var.s3_bucket_name full_repository_id = var.full_repository_id full_branch_name = var.full_branch_name + region = var.region key = var.key } diff --git a/codepipeline-tf/modules/xc3_codepipeline/variables.tf b/codepipeline-tf/modules/xc3_codepipeline/variables.tf index cefbabcc..7d5cc6a5 100644 --- a/codepipeline-tf/modules/xc3_codepipeline/variables.tf +++ b/codepipeline-tf/modules/xc3_codepipeline/variables.tf @@ -121,6 +121,11 @@ variable "docker_image_used" { type = string } +variable "region" { + description = "Region used for pipeline testing." + type = string +} + variable "key" { description = "key used in codepipeline(state file key)." type = string diff --git a/codepipeline-tf/providers.tf b/codepipeline-tf/providers.tf index b09baa3a..520d29b2 100755 --- a/codepipeline-tf/providers.tf +++ b/codepipeline-tf/providers.tf @@ -10,4 +10,4 @@ terraform { provider "aws" { region = "eu-west-1" -} \ No newline at end of file +} diff --git a/codepipeline-tf/terraform.auto.tfvars b/codepipeline-tf/terraform.auto.tfvars index b2e41f8f..036a8d48 100644 --- a/codepipeline-tf/terraform.auto.tfvars +++ b/codepipeline-tf/terraform.auto.tfvars @@ -11,7 +11,7 @@ region = "eu-west-1" s3_bucket_name = "terraform-state-xc3-example-pipeline" //delete after deployment -key = "example\\/example.tfstate" +key = var.namespace_name+"\\/"+var.namespace_name+".tfstate" xc3_codepipeline_role = "arn:aws:iam::test:role/xccc-pipeline-role" codebuild_service_role = "arn:aws:iam::test:role/service-role/codebuild-test-service-role" diff --git a/codepipeline-tf/variable.tf b/codepipeline-tf/variable.tf index 632d8867..756004ee 100644 --- a/codepipeline-tf/variable.tf +++ b/codepipeline-tf/variable.tf @@ -128,4 +128,4 @@ variable "region" { variable "key" { description = "key used in codepipeline(state file key)." type = string -} \ No newline at end of file +} From 59e3b2ec7ecff1b0becac5d8919051420632c97f Mon Sep 17 00:00:00 2001 From: irfan-hassan Date: Tue, 27 Feb 2024 14:28:40 +0500 Subject: [PATCH 04/13] added roles and updated the init_buildspec.yml file to bash backend.tf --- .../buildspec_yml/init_buildspec.yml | 9 + .../modules/xc3_codepipeline/main.tf | 181 +++++++++++++++++- codepipeline-tf/terraform.auto.tfvars | 6 +- 3 files changed, 187 insertions(+), 9 deletions(-) diff --git a/codepipeline-tf/buildspec_yml/init_buildspec.yml b/codepipeline-tf/buildspec_yml/init_buildspec.yml index a64096c9..62838e9a 100644 --- a/codepipeline-tf/buildspec_yml/init_buildspec.yml +++ b/codepipeline-tf/buildspec_yml/init_buildspec.yml @@ -1,13 +1,17 @@ #Copyright (c) 2023, Xgrid Inc, https://xgrid.co + # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at + # http://www.apache.org/licenses/LICENSE-2.0 + # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. + # SPDX-License-Identifier:Apache-2.0 version: 0.2 @@ -32,6 +36,9 @@ phases: - sed -i 's/"123456789"/'${account_id}'/g' terraform.auto.tfvars - sed -i 's/""/'${domain_name}'/g' terraform.auto.tfvars - cat terraform.auto.tfvars + + + build: commands: - terraform init @@ -41,6 +48,8 @@ phases: terraform workspace select ${namespace} fi - terraform validate + + artifacts: files: - '**/*' diff --git a/codepipeline-tf/modules/xc3_codepipeline/main.tf b/codepipeline-tf/modules/xc3_codepipeline/main.tf index 9fa7cfa6..ba40a750 100644 --- a/codepipeline-tf/modules/xc3_codepipeline/main.tf +++ b/codepipeline-tf/modules/xc3_codepipeline/main.tf @@ -16,6 +16,173 @@ limitations under the License. SPDX-License-Identifier: Apache-2.0 */ +resource "aws_iam_policy" "codebuild_service_policy_FH" { + name = "xc3_codebuild_service_role_FH" + + # Adjust policy document as needed + policy = jsonencode({ + Version = "2012-10-17", + Statement = [ + { + Sid = "VisualEditor0", + Effect = "Allow", + Action = [ + "sqs:*", + "lambda:*", + "iam:*", + "ssm:*", + "codedeploy:*", + "sns:*", + "codestar:*", + "logs:*", + "events:*", + "codebuild:*", + "dynamodb:*", + "ses:*", + "sts:*", + "organizations:*", + "ce:*", + "aws-portal:*", + "apigateway:*", + "s3:*", + "elasticloadbalancing:*", + "acm:*", + "kms:*", + "route53:*", + "cognito-idp:*", + "cloudtrail:*", + "codestar-connections:*", + "ec2:*", + "opsworks:*", + "cloudwatch:*", + "wafv2:*" + ], + Resource = "*" + }, + { + Sid = "KMSPermissions", + Effect = "Allow", + Action = [ + "kms:ListAliases" + ], + Resource = "*" + }, + { + Sid = "EC2Permissions", + Effect = "Allow", + Action = [ + "ec2:DescribeImages", + "ec2:DescribeKeyPairs" + ], + Resource = "*" + }, + { + Sid = "ACMPermissions", + Effect = "Allow", + Action = [ + "acm:ListCertificates" + ], + Resource = "*" + } + ] + }) +} + + +# IAM Role for CodeBuild service role +resource "aws_iam_role" "codebuild_service_role" { + name = var.codebuild_service_role + assume_role_policy = jsonencode({ + Version = "2012-10-17", + Statement = [ + { + Action = "sts:AssumeRole", + Effect = "Allow", + Principal = { + Service = "codebuild.amazonaws.com" + } + } + ] + }) +} + +# Attach IAM policy to CodeBuild service role +resource "aws_iam_policy_attachment" "codebuild_service_policy_attachment_FH" { + name = "xc3_codebuild_service_policy_attachment_FH" + policy_arn = aws_iam_policy.codebuild_service_policy_FH.arn + roles = [aws_iam_role.codebuild_service_role.name] +} + +# Attach managed policy to CodeBuild service role +resource "aws_iam_policy_attachment" "codebuild_managed_policy_attachment" { + name = "xc3_codebuild_test_managed_policy_attachment" + policy_arn = "arn:aws:iam::aws:policy/CloudWatchReadOnlyAccess" + roles = [aws_iam_role.codebuild_service_role.name] +} + +# IAM Policy for pipeline role +resource "aws_iam_policy" "xc3_pipeline_policy" { + name = "xc3_pipeline_policy" + + # Adjust policy document as needed + policy = jsonencode({ + Version = "2012-10-17", + Statement = [ + { + Sid = "VisualEditor0", + Effect = "Allow", + Action = [ + "codedeploy:*", + "sns:*", + "codestar:*", + "logs:*", + "events:*", + "codebuild:*", + "dynamodb:*", + "s3:*", + "codestar-connections:*", + "codepipeline:*" + ], + Resource = "*" + } + ] + }) +} + +# IAM Role for pipeline role +resource "aws_iam_role" "xc3_pipeline_role" { + name = var.xc3_codepipeline_role + assume_role_policy = jsonencode({ + Version = "2012-10-17", + Statement = [ + { + Action = "sts:AssumeRole", + Effect = "Allow", + Principal = { + Service = [ + "codedeploy.amazonaws.com", + "codepipeline.amazonaws.com" + ] + } + } + ] + }) +} + +# Attach IAM policy to pipeline role +resource "aws_iam_policy_attachment" "xc3_pipeline_policy_attachment" { + name = "xc3_pipeline_policy_attachment" + policy_arn = aws_iam_policy.xc3_pipeline_policy.arn + roles = [aws_iam_role.xc3_pipeline_role.name] +} + +# Attach managed policy to pipeline role +resource "aws_iam_policy_attachment" "xc3_pipeline_managed_policy_attachment" { + name = "xc3_pipeline_managed_policy_attachment" + policy_arn = "arn:aws:iam::aws:policy/AWSCodeDeployDeployerAccess" + roles = [aws_iam_role.xc3_pipeline_role.name] +} + #creating S3 bucket resource "aws_s3_bucket" "this" { bucket = var.s3_bucket_name @@ -28,10 +195,12 @@ resource "aws_s3_bucket_versioning" "this" { status = "Enabled" } } + + # codepipeline main resource resource "aws_codepipeline" "this" { name = "${var.tags.app}-${var.tags.environment}-tf-pipeline" - role_arn = var.xc3_codepipeline_role + role_arn = aws_iam_role.xc3_pipeline_role.arn artifact_store { location = aws_s3_bucket.this.bucket type = "S3" @@ -179,7 +348,7 @@ resource "aws_codepipeline" "this" { resource "aws_codebuild_project" "codebuild_project_init_stage" { name = "${var.tags.app}-${var.tags.environment}-init-project" description = "Terraform Init and Validate Stage for infra XC3" - service_role = var.codebuild_service_role + service_role = aws_iam_role.codebuild_service_role.arn artifacts { type = "CODEPIPELINE" @@ -220,7 +389,7 @@ resource "aws_codebuild_project" "codebuild_project_init_stage" { resource "aws_codebuild_project" "codebuild_project_plan_stage" { name = "${var.tags.app}_${var.tags.environment}-plan-project" description = "Terraform Plan Stage for infra XC3" - service_role = var.codebuild_service_role + service_role = aws_iam_role.codebuild_service_role.arn artifacts { @@ -246,7 +415,7 @@ resource "aws_codebuild_project" "codebuild_project_plan_stage" { resource "aws_codebuild_project" "codebuild_project_test_stage" { name = "${var.tags.app}-${var.tags.environment}-test-project" description = "Terraform Test Stage for infra XC3" - service_role = var.codebuild_service_role + service_role = aws_iam_role.codebuild_service_role.arn artifacts { @@ -272,7 +441,7 @@ resource "aws_codebuild_project" "codebuild_project_test_stage" { resource "aws_codebuild_project" "codebuild_project_apply_stage" { name = "${var.tags.app}-${var.tags.environment}-apply-project" description = "Terraform Apply Stage for infra XC3" - service_role = var.codebuild_service_role + service_role = aws_iam_role.codebuild_service_role.arn artifacts { type = "CODEPIPELINE" @@ -297,7 +466,7 @@ resource "aws_codebuild_project" "codebuild_project_apply_stage" { resource "aws_codebuild_project" "codebuild_project_destroy_stage" { name = "${var.tags.app}-${var.tags.environment}-destroy-project" description = "Terraform Apply Stage for infra XC3" - service_role = var.codebuild_service_role + service_role = aws_iam_role.codebuild_service_role.arn artifacts { type = "CODEPIPELINE" diff --git a/codepipeline-tf/terraform.auto.tfvars b/codepipeline-tf/terraform.auto.tfvars index 036a8d48..00830eab 100644 --- a/codepipeline-tf/terraform.auto.tfvars +++ b/codepipeline-tf/terraform.auto.tfvars @@ -13,9 +13,9 @@ s3_bucket_name = "terraform-state-xc3-example-pipeline" //delete after deployment key = var.namespace_name+"\\/"+var.namespace_name+".tfstate" -xc3_codepipeline_role = "arn:aws:iam::test:role/xccc-pipeline-role" -codebuild_service_role = "arn:aws:iam::test:role/service-role/codebuild-test-service-role" -codestar_connections = "arn:aws:codestar-connections:eu-west-1:test:connection/code-star-connection-role" +xc3_codepipeline_role = "irfan-pipeline-role" +codebuild_service_role = "codebuild-irfan-service" +codestar_connections = "code-star-connection-role" approve_comment_for_apply = "This approval needs to create XC3 infrastructure." approve_comment_for_destroy = "This approval needs to destroy XC3 infrastructure." From bbfac672cc0a08f9faa9425ec4dd544d77b43343 Mon Sep 17 00:00:00 2001 From: irfan-hassan Date: Wed, 6 Mar 2024 17:36:32 +0500 Subject: [PATCH 05/13] remove variables and update added command in initbuildsepc file --- .../buildspec_yml/init_buildspec.yml | 22 ++++++++++++++----- codepipeline-tf/terraform.auto.tfvars | 6 ++--- 2 files changed, 20 insertions(+), 8 deletions(-) diff --git a/codepipeline-tf/buildspec_yml/init_buildspec.yml b/codepipeline-tf/buildspec_yml/init_buildspec.yml index 62838e9a..a3208dd6 100644 --- a/codepipeline-tf/buildspec_yml/init_buildspec.yml +++ b/codepipeline-tf/buildspec_yml/init_buildspec.yml @@ -25,8 +25,21 @@ phases: - cd infrastructure - ls - echo ${s3_bucket_name} + + - sed -i "s/export bucket_name=.*/export bucket_name=\"$s3_bucket_name\"/" config.sh + - sed -i "s/export project=.*/export project=\"$namespace\"/" config.sh + - sed -i "s/export domain=.*/export domain=\"${domain_name}\"/" config.sh + - sed -i "s/export namespace=.*/export namespace=\"$namespace\"/" config.sh + - sed -i "s/export env=.*/export env=\"prod\"/" config.sh + + - cat config.sh + - apk --update add bash + - apk --update add aws-cli + - bash pre_req.sh + - sed -i "s/\"terraform-state-xc3\"/\"$s3_bucket_name\"/g" backend.tf - sed -i 's/xc3\/xc3.tfstate/'${key}'/g' backend.tf + - cat backend.tf - sed -i "s/\"testing\"/\"$namespace\"/g" terraform.auto.tfvars - sed -i "s/\"123456789\"/\"$account_id\"/g" terraform.auto.tfvars @@ -35,10 +48,11 @@ phases: - sed -i 's/"testing"/'${namespace}'/g' terraform.auto.tfvars - sed -i 's/"123456789"/'${account_id}'/g' terraform.auto.tfvars - sed -i 's/""/'${domain_name}'/g' terraform.auto.tfvars - - cat terraform.auto.tfvars - - + - sed -i 's/create_cloudtrail_kms\s*=\s*true/create_cloudtrail_kms = false/g' terraform.auto.tfvars + - sed -i 's/create_cloudtrail\s*=\s*true/create_cloudtrail = false/g' terraform.auto.tfvars + - sed -i 's/create_cloudtrail_s3_bucket\s*=\s*true/create_cloudtrail_s3_bucket = false/g' terraform.auto.tfvars + - cat terraform.auto.tfvars build: commands: - terraform init @@ -48,8 +62,6 @@ phases: terraform workspace select ${namespace} fi - terraform validate - - artifacts: files: - '**/*' diff --git a/codepipeline-tf/terraform.auto.tfvars b/codepipeline-tf/terraform.auto.tfvars index 00830eab..187a9396 100644 --- a/codepipeline-tf/terraform.auto.tfvars +++ b/codepipeline-tf/terraform.auto.tfvars @@ -11,10 +11,10 @@ region = "eu-west-1" s3_bucket_name = "terraform-state-xc3-example-pipeline" //delete after deployment -key = var.namespace_name+"\\/"+var.namespace_name+".tfstate" +key = "xc3\\/xc3.tfstate" -xc3_codepipeline_role = "irfan-pipeline-role" -codebuild_service_role = "codebuild-irfan-service" +xc3_codepipeline_role = "example-pipeline-role" +codebuild_service_role = "codebuild-example-service" codestar_connections = "code-star-connection-role" approve_comment_for_apply = "This approval needs to create XC3 infrastructure." From fadf9afc0739afcb193e3be9d80eb4c55635f866 Mon Sep 17 00:00:00 2001 From: irfan-hassan Date: Tue, 26 Mar 2024 11:07:44 +0500 Subject: [PATCH 06/13] updated readme and change region in provider file to make it dynamic theough avriable file --- .../modules/xc3_codepipeline/variables.tf | 2 +- codepipeline-tf/providers.tf | 2 +- codepipeline-tf/readme.md | 32 +++++++++++++++++++ codepipeline-tf/terraform.auto.tfvars | 17 ++++++++++ codepipeline-tf/variable.tf | 1 + 5 files changed, 52 insertions(+), 2 deletions(-) diff --git a/codepipeline-tf/modules/xc3_codepipeline/variables.tf b/codepipeline-tf/modules/xc3_codepipeline/variables.tf index 7d5cc6a5..7761c428 100644 --- a/codepipeline-tf/modules/xc3_codepipeline/variables.tf +++ b/codepipeline-tf/modules/xc3_codepipeline/variables.tf @@ -129,4 +129,4 @@ variable "region" { variable "key" { description = "key used in codepipeline(state file key)." type = string -} \ No newline at end of file +} diff --git a/codepipeline-tf/providers.tf b/codepipeline-tf/providers.tf index 520d29b2..5a7ea3fd 100755 --- a/codepipeline-tf/providers.tf +++ b/codepipeline-tf/providers.tf @@ -9,5 +9,5 @@ terraform { } provider "aws" { - region = "eu-west-1" + region = var.region } diff --git a/codepipeline-tf/readme.md b/codepipeline-tf/readme.md index b567e3b1..768bb8ae 100644 --- a/codepipeline-tf/readme.md +++ b/codepipeline-tf/readme.md @@ -80,3 +80,35 @@ module "my_codepipeline" { namespace_name = "my_namespace" # ... Provide values for other variables ... } +``` + +## Deploying CodePipeline +To deploy the CodePipeline defined by this module, follow these steps: + +- ### Defined the pipeline configuration: + Change the variable from terraform auto.tf.var file to defined the pipeline configuration. + +- ### Deploy Pipeline: + Once you've defined the pipeline configuration, use Terraform to deploy it. Ensure that you have configured your AWS credentials properly and have the necessary permissions to create CodePipeline resources. + + +## Codepipeline Satges +The CodePipeline consists of multiple stages, each representing a phase of the CI/CD process. Here are the stages typically included in this pipeline: + +- ### Source Stage: + Fetches changes from the GitHub repository specified in the auto.tfvars file. + +- ### Initialization Stage: + Initializes the environment by creating necessary resources such as S3 buckets, DynamoDB tables, keys, and certificates. + +- ### Plan Stage: + Checks the proposed changes for any issues without actually applying them. + +- ### Approval Stage: + Requires manual approval before proceeding with applying changes. + +- ### Apply Stage: + Deploys the changes using Terraform after approval. + +- ### Destroy Stage: + Requires manual approval before destroying infrastructure. \ No newline at end of file diff --git a/codepipeline-tf/terraform.auto.tfvars b/codepipeline-tf/terraform.auto.tfvars index 187a9396..5efb162a 100644 --- a/codepipeline-tf/terraform.auto.tfvars +++ b/codepipeline-tf/terraform.auto.tfvars @@ -1,3 +1,20 @@ +/* +Copyright (c) 2023, Xgrid Inc, https://xgrid.co + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. + +SPDX-License-Identifier: Apache-2.0 +*/ ################################################## # tfvars ################################################## diff --git a/codepipeline-tf/variable.tf b/codepipeline-tf/variable.tf index 756004ee..d07ce56c 100644 --- a/codepipeline-tf/variable.tf +++ b/codepipeline-tf/variable.tf @@ -125,6 +125,7 @@ variable "region" { description = "Region used for pipeline testing." type = string } + variable "key" { description = "key used in codepipeline(state file key)." type = string From 1493a78945f64a0ed6122e3b477f9fd1e26885f0 Mon Sep 17 00:00:00 2001 From: irfan-hassan Date: Tue, 2 Apr 2024 12:38:48 +0500 Subject: [PATCH 07/13] updated readme for codepipelien module --- .../modules/xc3_codepipeline/readme.md | 90 ++++++++++++++++++- 1 file changed, 89 insertions(+), 1 deletion(-) diff --git a/codepipeline-tf/modules/xc3_codepipeline/readme.md b/codepipeline-tf/modules/xc3_codepipeline/readme.md index 28034d0e..18fb8e34 100644 --- a/codepipeline-tf/modules/xc3_codepipeline/readme.md +++ b/codepipeline-tf/modules/xc3_codepipeline/readme.md @@ -1 +1,89 @@ -This pipeline has currently different stages to Source, Build, Deploy and destroy the code. +# Terraform CodePipeline Module + +This Terraform module sets up a continuous integration and continuous deployment (CI/CD) pipeline using AWS CodePipeline and AWS CodeBuild. + +## Table of Contents + +- [Prerequisites](#prerequisites) +- [Usage](#usage) + - [Inputs](#inputs) + - [Outputs](#outputs) +- [Example](#example) +- [License](#license) + +## Prerequisites + +Before using this module, ensure you have: + +- An AWS account +- Terraform installed locally +- Basic knowledge of AWS services like CodePipeline, CodeBuild, IAM, and S3 + +## Usage + +To use this module, follow these steps: + +1. **Module Installation**: Include this module in your Terraform configuration files. + +```hcl +module "codepipeline" { + source = "git::https://github.com/your-repo/path-to-module" + + # Input variables + tags = var.tags + namespace_name = var.namespace_name + account_id = var.account_id + domain_name = var.domain_name + s3_bucket_name = var.s3_bucket_name + xc3_codepipeline_role = var.xc3_codepipeline_role + codebuild_service_role = var.codebuild_service_role + codestar_connections = var.codestar_connections + full_repository_id = var.full_repository_id + full_branch_name = var.full_branch_name + approve_comment_for_apply = var.approve_comment_for_apply + approve_comment_for_destroy = var.approve_comment_for_destroy + buildspec_folder_path = var.buildspec_folder_path + init_buildspec = var.init_buildspec + plan_buildspec = var.plan_buildspec + test_buildspec = var.test_buildspec + apply_buildspec = var.apply_buildspec + destroy_buildspec = var.destroy_buildspec + compute_type_for_building = var.compute_type_for_building + os_type = var.os_type + docker_image_used = var.docker_image_used + region = var.region + key = var.key +} +``` + +2. **Configuration**: Set the input variables according to your project requirements. Refer to the [Inputs](#inputs) section for details on each variable. + +3. **Terraform Apply**: Run `terraform init` and `terraform apply` to provision the resources. + +### Inputs + +- **tags**: (Map) Tags used in this module. +- **namespace_name**: (String) Namespace used in the project. +- **account_id**: (String) AWS account ID used in the module. +- **domain_name**: (String) Domain name used in the module. +- **s3_bucket_name**: (String) S3 bucket name variable. +- ... (continue for all input variables) + +### Outputs + +- Outputs, if any, can be documented here. + +## Example + +```hcl +# Example usage of the codepipeline module +module "codepipeline" { + source = "git::https://github.com/your-repo/path-to-module" + + # Input variables... +} +``` + +## License + +This module is licensed under the Apache License, Version 2.0. See the [LICENSE](LICENSE) file for details. From b0add372d0a010279b4c658e52035625073420c4 Mon Sep 17 00:00:00 2001 From: shehroz-khan-xgrid Date: Tue, 23 Apr 2024 16:17:15 +0500 Subject: [PATCH 08/13] update terraform version, fix indentation and add description --- codepipeline-tf/main.tf | 8 ++-- .../modules/xc3_codepipeline/readme.md | 48 +++++++++---------- .../modules/xc3_codepipeline/variables.tf | 31 +++++++----- codepipeline-tf/providers.tf | 2 +- codepipeline-tf/terraform.auto.tfvars | 2 +- codepipeline-tf/variable.tf | 31 +++++++----- 6 files changed, 68 insertions(+), 54 deletions(-) diff --git a/codepipeline-tf/main.tf b/codepipeline-tf/main.tf index e535dd32..8f651255 100644 --- a/codepipeline-tf/main.tf +++ b/codepipeline-tf/main.tf @@ -20,8 +20,8 @@ SPDX-License-Identifier: Apache-2.0 module "xc3_pipeline" { source = "./modules/xc3_codepipeline" - tags = var.tags - + tags = var.tags + namespace_name = var.namespace_name account_id = var.account_id domain_name = var.domain_name @@ -42,6 +42,6 @@ module "xc3_pipeline" { s3_bucket_name = var.s3_bucket_name full_repository_id = var.full_repository_id full_branch_name = var.full_branch_name - region = var.region - key = var.key + region = var.region + key = var.key } diff --git a/codepipeline-tf/modules/xc3_codepipeline/readme.md b/codepipeline-tf/modules/xc3_codepipeline/readme.md index 18fb8e34..7aa94bd6 100644 --- a/codepipeline-tf/modules/xc3_codepipeline/readme.md +++ b/codepipeline-tf/modules/xc3_codepipeline/readme.md @@ -28,31 +28,31 @@ To use this module, follow these steps: ```hcl module "codepipeline" { source = "git::https://github.com/your-repo/path-to-module" - + # Input variables - tags = var.tags - namespace_name = var.namespace_name - account_id = var.account_id - domain_name = var.domain_name - s3_bucket_name = var.s3_bucket_name - xc3_codepipeline_role = var.xc3_codepipeline_role - codebuild_service_role = var.codebuild_service_role - codestar_connections = var.codestar_connections - full_repository_id = var.full_repository_id - full_branch_name = var.full_branch_name - approve_comment_for_apply = var.approve_comment_for_apply + tags = var.tags + namespace_name = var.namespace_name + account_id = var.account_id + domain_name = var.domain_name + s3_bucket_name = var.s3_bucket_name + xc3_codepipeline_role = var.xc3_codepipeline_role + codebuild_service_role = var.codebuild_service_role + codestar_connections = var.codestar_connections + full_repository_id = var.full_repository_id + full_branch_name = var.full_branch_name + approve_comment_for_apply = var.approve_comment_for_apply approve_comment_for_destroy = var.approve_comment_for_destroy - buildspec_folder_path = var.buildspec_folder_path - init_buildspec = var.init_buildspec - plan_buildspec = var.plan_buildspec - test_buildspec = var.test_buildspec - apply_buildspec = var.apply_buildspec - destroy_buildspec = var.destroy_buildspec - compute_type_for_building = var.compute_type_for_building - os_type = var.os_type - docker_image_used = var.docker_image_used - region = var.region - key = var.key + buildspec_folder_path = var.buildspec_folder_path + init_buildspec = var.init_buildspec + plan_buildspec = var.plan_buildspec + test_buildspec = var.test_buildspec + apply_buildspec = var.apply_buildspec + destroy_buildspec = var.destroy_buildspec + compute_type_for_building = var.compute_type_for_building + os_type = var.os_type + docker_image_used = var.docker_image_used + region = var.region + key = var.key } ``` @@ -79,7 +79,7 @@ module "codepipeline" { # Example usage of the codepipeline module module "codepipeline" { source = "git::https://github.com/your-repo/path-to-module" - + # Input variables... } ``` diff --git a/codepipeline-tf/modules/xc3_codepipeline/variables.tf b/codepipeline-tf/modules/xc3_codepipeline/variables.tf index 7761c428..01f01027 100644 --- a/codepipeline-tf/modules/xc3_codepipeline/variables.tf +++ b/codepipeline-tf/modules/xc3_codepipeline/variables.tf @@ -26,14 +26,17 @@ variable "namespace_name" { description = "Namespace used in project." type = string } + variable "account_id" { description = "AWS account ID used in module." type = string } + variable "domain_name" { description = "domain name used in module." type = string } + ################ S3 Bucket Variables ################ variable "s3_bucket_name" { description = "S3 bucket varibale" @@ -44,7 +47,6 @@ variable "s3_bucket_name" { variable "xc3_codepipeline_role" { description = "This is the main role to run codepipelin." type = string - } variable "codebuild_service_role" { @@ -56,26 +58,29 @@ variable "codestar_connections" { description = "This is the service role, used to create projects for codepipeline." type = string } + ################ Github Variables ################ variable "full_repository_id" { description = "Repository identity used codepipeline module." type = string - } + variable "full_branch_name" { description = "Branch name used in codepipeline module." type = string } + ################ Comments and Description Variables ################ variable "approve_comment_for_apply" { - description = "" + description = "Comment to create the XC3 infrastructure" type = string - } + variable "approve_comment_for_destroy" { - description = "" + description = "Comment to destroy the XC3 infrastructure" type = string } + ################ Build Spec File Name Variables ################ variable "buildspec_folder_path" { description = "Buildspec folder path used in codepipeline module." @@ -83,29 +88,31 @@ variable "buildspec_folder_path" { } variable "init_buildspec" { - description = "" + description = "Initialize and validate terraform configuration file variable" type = string } variable "plan_buildspec" { - description = "" + description = "Plan run of XC3 infrastructure file variable" type = string } + variable "test_buildspec" { - description = "" + description = "Unit testing file variable" type = string } + variable "apply_buildspec" { - description = "" + description = "Create XC3 infrastructure file variable" type = string } variable "destroy_buildspec" { - description = "" + description = "Destroy XC3 infrastructure file variable" type = string } -################ Compute Environment Variables ################ +################ Compute Environment Variables ################ variable "compute_type_for_building" { description = "Build environment compute type variable." type = string @@ -123,7 +130,7 @@ variable "docker_image_used" { variable "region" { description = "Region used for pipeline testing." - type = string + type = string } variable "key" { diff --git a/codepipeline-tf/providers.tf b/codepipeline-tf/providers.tf index 5a7ea3fd..a8b29c0e 100755 --- a/codepipeline-tf/providers.tf +++ b/codepipeline-tf/providers.tf @@ -1,5 +1,5 @@ terraform { - required_version = ">= 1.0" + required_version = ">= 1.7" required_providers { aws = { source = "hashicorp/aws" diff --git a/codepipeline-tf/terraform.auto.tfvars b/codepipeline-tf/terraform.auto.tfvars index 5efb162a..4cec2605 100644 --- a/codepipeline-tf/terraform.auto.tfvars +++ b/codepipeline-tf/terraform.auto.tfvars @@ -30,7 +30,7 @@ s3_bucket_name = "terraform-state-xc3-example-pipeline" //delete after deployment key = "xc3\\/xc3.tfstate" -xc3_codepipeline_role = "example-pipeline-role" +xc3_codepipeline_role = "example-pipeline-role" codebuild_service_role = "codebuild-example-service" codestar_connections = "code-star-connection-role" diff --git a/codepipeline-tf/variable.tf b/codepipeline-tf/variable.tf index d07ce56c..7ea46a05 100644 --- a/codepipeline-tf/variable.tf +++ b/codepipeline-tf/variable.tf @@ -26,14 +26,17 @@ variable "namespace_name" { description = "Namespace used in project." type = string } + variable "account_id" { description = "AWS account ID used in module." type = string } + variable "domain_name" { description = "domain name used in module." type = string } + ################ S3 Bucket Variables ################ variable "s3_bucket_name" { description = "S3 bucket varibale" @@ -44,7 +47,6 @@ variable "s3_bucket_name" { variable "xc3_codepipeline_role" { description = "This is the main role to run codepipelin." type = string - } variable "codebuild_service_role" { @@ -56,26 +58,29 @@ variable "codestar_connections" { description = "This is the service role, used to create projects for codepipeline." type = string } + ################ Github Variables ################ variable "full_repository_id" { description = "Repository identity used codepipeline module." type = string - } + variable "full_branch_name" { description = "Branch name used in codepipeline module." type = string } + ################ Comments and Description Variables ################ variable "approve_comment_for_apply" { - description = "" + description = "Comment to create the XC3 infrastructure" type = string - } + variable "approve_comment_for_destroy" { - description = "" + description = "Comment to destroy the XC3 infrastructure" type = string } + ################ Build Spec File Name Variables ################ variable "buildspec_folder_path" { description = "Buildspec folder path used in codepipeline module." @@ -83,29 +88,31 @@ variable "buildspec_folder_path" { } variable "init_buildspec" { - description = "" + description = "Initialize and validate terraform configuration file variable" type = string } variable "plan_buildspec" { - description = "" + description = "Plan run of XC3 infrastructure file variable" type = string } + variable "test_buildspec" { - description = "" + description = "Unit testing file variable" type = string } + variable "apply_buildspec" { - description = "" + description = "Create XC3 infrastructure file variable" type = string } variable "destroy_buildspec" { - description = "" + description = "Destroy XC3 infrastructure file variable" type = string } -################ Compute Environment Variables ################ +################ Compute Environment Variables ################ variable "compute_type_for_building" { description = "Build environment compute type variable." type = string @@ -123,7 +130,7 @@ variable "docker_image_used" { variable "region" { description = "Region used for pipeline testing." - type = string + type = string } variable "key" { From 960febd2b85026231c91298d23647018fa8eabcf Mon Sep 17 00:00:00 2001 From: shehroz-khan-xgrid Date: Tue, 23 Apr 2024 18:24:52 +0500 Subject: [PATCH 09/13] remove region variable --- codepipeline-tf/modules/xc3_codepipeline/variables.tf | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/codepipeline-tf/modules/xc3_codepipeline/variables.tf b/codepipeline-tf/modules/xc3_codepipeline/variables.tf index 01f01027..9be39bdb 100644 --- a/codepipeline-tf/modules/xc3_codepipeline/variables.tf +++ b/codepipeline-tf/modules/xc3_codepipeline/variables.tf @@ -128,10 +128,10 @@ variable "docker_image_used" { type = string } -variable "region" { - description = "Region used for pipeline testing." - type = string -} +# variable "region" { +# description = "Region used for pipeline testing." +# type = string +# } variable "key" { description = "key used in codepipeline(state file key)." From 1ffd5b0f750514c9b9864c621c934cae56c809a0 Mon Sep 17 00:00:00 2001 From: shehroz-khan-xgrid Date: Fri, 3 May 2024 17:47:06 +0500 Subject: [PATCH 10/13] fix region variable error by deleting it --- codepipeline-tf/main.tf | 1 - codepipeline-tf/modules/xc3_codepipeline/variables.tf | 5 ----- 2 files changed, 6 deletions(-) diff --git a/codepipeline-tf/main.tf b/codepipeline-tf/main.tf index 8f651255..eef9d61d 100644 --- a/codepipeline-tf/main.tf +++ b/codepipeline-tf/main.tf @@ -42,6 +42,5 @@ module "xc3_pipeline" { s3_bucket_name = var.s3_bucket_name full_repository_id = var.full_repository_id full_branch_name = var.full_branch_name - region = var.region key = var.key } diff --git a/codepipeline-tf/modules/xc3_codepipeline/variables.tf b/codepipeline-tf/modules/xc3_codepipeline/variables.tf index 9be39bdb..4b7990f8 100644 --- a/codepipeline-tf/modules/xc3_codepipeline/variables.tf +++ b/codepipeline-tf/modules/xc3_codepipeline/variables.tf @@ -128,11 +128,6 @@ variable "docker_image_used" { type = string } -# variable "region" { -# description = "Region used for pipeline testing." -# type = string -# } - variable "key" { description = "key used in codepipeline(state file key)." type = string From 068a9cda5b1921ca24c0024b2d03030a70ef80f7 Mon Sep 17 00:00:00 2001 From: shehroz-khan-xgrid Date: Wed, 29 May 2024 14:50:30 +0500 Subject: [PATCH 11/13] update terraform version and fix most expensive services panel issue --- codepipeline-tf/modules/xc3_codepipeline/providers.tf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/codepipeline-tf/modules/xc3_codepipeline/providers.tf b/codepipeline-tf/modules/xc3_codepipeline/providers.tf index f32ed9da..fa06ddea 100755 --- a/codepipeline-tf/modules/xc3_codepipeline/providers.tf +++ b/codepipeline-tf/modules/xc3_codepipeline/providers.tf @@ -1,5 +1,5 @@ terraform { - required_version = ">= 1.0" + required_version = ">= 1.7" required_providers { aws = { source = "hashicorp/aws" From 6d9e011aa1c240687ad45cb1f3cc03d2fecc9ff5 Mon Sep 17 00:00:00 2001 From: shehroz-khan-xgrid Date: Wed, 29 May 2024 14:51:31 +0500 Subject: [PATCH 12/13] update terraform version and fix most expensive services panel issue --- custom_dashboard/grafana_dashboards/home-dashboard.json | 2 +- infrastructure/modules/networking/provider.tf | 2 +- infrastructure/modules/serverless/data.tf | 1 - infrastructure/modules/serverless/providers.tf | 2 +- infrastructure/modules/xc3/provider.tf | 2 +- infrastructure/providers.tf | 2 +- pre_requirement/providers.tf | 2 +- .../cost_metrics_of_expensive_services.py | 2 +- 8 files changed, 7 insertions(+), 8 deletions(-) diff --git a/custom_dashboard/grafana_dashboards/home-dashboard.json b/custom_dashboard/grafana_dashboards/home-dashboard.json index 49e6c1cd..1ece0e69 100644 --- a/custom_dashboard/grafana_dashboards/home-dashboard.json +++ b/custom_dashboard/grafana_dashboards/home-dashboard.json @@ -415,7 +415,7 @@ }, "editorMode": "builder", "exemplar": false, - "expr": "Expensive_Services_Detail{job=\"Most_Expensive_Services\", region=\"$region\", account=\"$Account\"}", + "expr": "Expensive_Services_Detail{job=\"$Account\", region=\"$region\"}", "format": "table", "instant": true, "legendFormat": "__auto", diff --git a/infrastructure/modules/networking/provider.tf b/infrastructure/modules/networking/provider.tf index 15e26bd8..e80031df 100644 --- a/infrastructure/modules/networking/provider.tf +++ b/infrastructure/modules/networking/provider.tf @@ -14,7 +14,7 @@ terraform { - required_version = ">= 1.0" + required_version = ">= 1.7" required_providers { aws = { diff --git a/infrastructure/modules/serverless/data.tf b/infrastructure/modules/serverless/data.tf index 2daff849..3de94bc0 100644 --- a/infrastructure/modules/serverless/data.tf +++ b/infrastructure/modules/serverless/data.tf @@ -15,5 +15,4 @@ # tflint-ignore: terraform_unused_declarations data "aws_kms_alias" "check_existing_kms" { name = "alias/${var.namespace}-kms-key" - } \ No newline at end of file diff --git a/infrastructure/modules/serverless/providers.tf b/infrastructure/modules/serverless/providers.tf index cf16efd3..148bad68 100644 --- a/infrastructure/modules/serverless/providers.tf +++ b/infrastructure/modules/serverless/providers.tf @@ -1,5 +1,5 @@ terraform { - required_version = ">= 1.0" + required_version = ">= 1.7" required_providers { aws = { diff --git a/infrastructure/modules/xc3/provider.tf b/infrastructure/modules/xc3/provider.tf index 466f829d..bf0197c9 100644 --- a/infrastructure/modules/xc3/provider.tf +++ b/infrastructure/modules/xc3/provider.tf @@ -13,7 +13,7 @@ # limitations under the License. terraform { - required_version = ">= 1.0" + required_version = ">= 1.7" required_providers { aws = { diff --git a/infrastructure/providers.tf b/infrastructure/providers.tf index 2ee22363..6f7f800f 100644 --- a/infrastructure/providers.tf +++ b/infrastructure/providers.tf @@ -19,7 +19,7 @@ provider "aws" { } terraform { - required_version = ">= 1.0" + required_version = ">= 1.7" required_providers { aws = { diff --git a/pre_requirement/providers.tf b/pre_requirement/providers.tf index 717e07f3..9695577e 100644 --- a/pre_requirement/providers.tf +++ b/pre_requirement/providers.tf @@ -19,7 +19,7 @@ provider "aws" { } terraform { - required_version = ">= 1.0" + required_version = ">= 1.7" required_providers { aws = { diff --git a/src/expensive_services_detail/cost_metrics_of_expensive_services.py b/src/expensive_services_detail/cost_metrics_of_expensive_services.py index 068dd740..3f234f6e 100644 --- a/src/expensive_services_detail/cost_metrics_of_expensive_services.py +++ b/src/expensive_services_detail/cost_metrics_of_expensive_services.py @@ -173,7 +173,7 @@ def lambda_handler(event, context): for resource in top_5_resources: resourcedata = { "Account": account_detail, - "Region": f"{region} ({region_names.get(region, 'unknown region name')})", + "Region": f"{region}-{region_names.get(region, 'unknown region name')}", "Service": resource["Keys"][0], "Cost": resource["Metrics"]["UnblendedCost"]["Amount"], } From 4f621a0e969d3b3c3504c13d2f12bca9a2bdd9a3 Mon Sep 17 00:00:00 2001 From: shehroz-khan-xgrid Date: Wed, 29 May 2024 16:38:12 +0500 Subject: [PATCH 13/13] update terraform version and fix most expensive services panel issue --- infrastructure/modules/serverless/data.tf | 1 + 1 file changed, 1 insertion(+) diff --git a/infrastructure/modules/serverless/data.tf b/infrastructure/modules/serverless/data.tf index 3de94bc0..2daff849 100644 --- a/infrastructure/modules/serverless/data.tf +++ b/infrastructure/modules/serverless/data.tf @@ -15,4 +15,5 @@ # tflint-ignore: terraform_unused_declarations data "aws_kms_alias" "check_existing_kms" { name = "alias/${var.namespace}-kms-key" + } \ No newline at end of file