This repo showcases using Terraform
- to automate provisioning AWS infrastructure
- modularizing the TF project
- to automate provisioning an Amazon EKS cluster
- configuring shared remote TF state
- a complete CI/CD pipeline with TF involved to provision infrastructure for deploying containers to
Terraform, AWS (incl. EKS, S3), Docker, Linux, Git, Java, Maven, DockerHub
- Created TF project to automate provisioning AWS Infrastructure and its components, such as: VPC, Subnet in one of VPC's availability zones, Route Table, Internet Gateway, EC2, Security Group, Key Pair
- Configured TF to use a script to automate deploying Docker container to EC2 instance
- Split Terraform resources into reusable modules (subnet and webserver)
- Added eks-vpc.tf to provision a VPC with public and private subnets (using AWS VPC Terraform Module), and eks-cluster.tf to provision an EKS cluster (using AWS EKS Terraform Module) including highly available Worker Node Groups across multiple availability zones.
- to connect using kubectl:
aws eks update-kubeconfig --name eks-cluster --region eu-central-1
- to connect using kubectl:
- Created SSH key-pair in AWS (EC2 - Key Pairs) and added saved .pem file contents as credential (SSH Username with private key, user
ec2-user) in Jenkins multibranch pipeline scope - Installed Terraform inside Jenkins container:
- SSHed into Jenkins server:
ssh devops@dropletIp - entered the container as root:
docker exec -u 0 -it containerId bash - followed instructions from https://developer.hashicorp.com/terraform/install to install Terraform
wget -O - https://apt.releases.hashicorp.com/gpg | gpg --dearmor -o /usr/share/keyrings/hashicorp-archive-keyring.gpg echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] https://apt.releases.hashicorp.com $(grep -oP '(?<=UBUNTU_CODENAME=).*' /etc/os-release || lsb_release -cs) main" | tee /etc/apt/sources.list.d/hashicorp.list apt update && apt install terraform
- SSHed into Jenkins server:
- Added Terraform configuration files to provision infrastructure on AWS necessary for an EC2 server
- Created Jenkinsfile pipeline to provision infrastructure and deploy to the provisioned server
- Created a bucket on AWS S3 - enabled versioning and blocked all public access (left the default encryption type and disabled Bucket Key)
- Before changing TF backend, ran
terraform destroyto destroy infrastructure (if created already) - Configured Amazon S3 as remote storage for Terraform state in main.tf
- afterwards, to access remote state, ran
terraform initandterraform state listshows resources created by Jenkins build
- afterwards, to access remote state, ran
.
├── eks-cluster.tf
├── eks-vpc.tf
├── entry-script.sh
├── java-maven-app
│ ├── docker-compose.yaml
│ ├── Dockerfile
│ ├── Jenkinsfile
│ ├── pom.xml
│ ├── server-cmds.sh
│ ├── src
│ │ └── main
│ │ ├── java
│ │ │ └── com
│ │ │ └── example
│ │ │ └── Application.java
│ │ └── resources
│ │ └── static
│ │ └── index.html
│ └── terraform
│ ├── entry-script.sh
│ ├── main.tf
│ ├── terraform.tfstate
│ └── variables.tf
├── main.tf
├── modules
│ ├── subnet
│ │ ├── main.tf
│ │ ├── outputs.tf
│ │ └── variables.tf
│ └── webserver
│ ├── main.tf
│ ├── outputs.tf
│ └── variables.tf
├── outputs.tf
├── providers.tf
├── readme.md
├── terraform.tfstate
├── terraform.tfstate.backup
├── terraform.tfvars
└── variables.tf