Skip to content

Commit 72e8f88

Browse files
authored
feat(scaletest/terraform): add cert-manager, otel, and TLS (#9894)
1 parent 0878381 commit 72e8f88

File tree

4 files changed

+167
-10
lines changed

4 files changed

+167
-10
lines changed
Lines changed: 67 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,67 @@
1+
# Terraform configuration for cert-manaer
2+
3+
locals {
4+
cert_manager_namespace = "cert-manager"
5+
cert_manager_helm_repo = "https://charts.jetstack.io"
6+
cert_manager_helm_chart = "cert-manager"
7+
cert_manager_release_name = "cert-manager"
8+
cert_manager_chart_version = "1.12.2"
9+
cloudflare_issuer_private_key_secret_name = "cloudflare-issuer-private-key"
10+
}
11+
12+
resource "kubernetes_secret" "cloudflare-api-key" {
13+
metadata {
14+
name = "cloudflare-api-key-secret"
15+
namespace = local.cert_manager_namespace
16+
}
17+
data = {
18+
api-token = var.cloudflare_api_token
19+
}
20+
}
21+
22+
resource "kubernetes_namespace" "cert-manager-namespace" {
23+
metadata {
24+
name = local.cert_manager_namespace
25+
}
26+
}
27+
28+
resource "helm_release" "cert-manager" {
29+
repository = local.cert_manager_helm_repo
30+
chart = local.cert_manager_helm_chart
31+
name = local.cert_manager_release_name
32+
namespace = kubernetes_namespace.cert-manager-namespace.metadata.0.name
33+
values = [<<EOF
34+
installCRDs: true
35+
EOF
36+
]
37+
}
38+
39+
resource "kubernetes_manifest" "cloudflare-cluster-issuer" {
40+
manifest = {
41+
apiVersion = "cert-manager.io/v1"
42+
kind = "ClusterIssuer"
43+
metadata = {
44+
name = "cloudflare-issuer"
45+
}
46+
spec = {
47+
acme = {
48+
email = var.cloudflare_email
49+
privateKeySecretRef = {
50+
name = local.cloudflare_issuer_private_key_secret_name
51+
}
52+
solvers = [
53+
{
54+
dns01 = {
55+
cloudflare = {
56+
apiTokenSecretRef = {
57+
name = kubernetes_secret.cloudflare-api-key.metadata.0.name
58+
key = "api-token"
59+
}
60+
}
61+
}
62+
}
63+
]
64+
}
65+
}
66+
}
67+
}

scaletest/terraform/k8s/coder.tf

Lines changed: 21 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
data "google_client_config" "default" {}
22

33
locals {
4-
coder_url = var.coder_access_url == "" ? "http://${var.coder_address}" : var.coder_access_url
4+
coder_url = var.coder_access_url
55
coder_admin_email = "admin@coder.com"
66
coder_admin_user = "coder"
77
coder_helm_repo = "https://helm.coder.com/v2"
@@ -61,20 +61,31 @@ data "kubernetes_secret" "coder_oidc" {
6161
}
6262
}
6363

64-
# TLS needs to be provisioned manually for now.
65-
data "kubernetes_secret" "coder_tls" {
66-
metadata {
67-
namespace = kubernetes_namespace.coder_namespace.metadata.0.name
68-
name = "${var.name}-tls"
64+
resource "kubernetes_manifest" "coder_certificate" {
65+
manifest = {
66+
apiVersion = "cert-manager.io/v1"
67+
kind = "Certificate"
68+
metadata = {
69+
name = "${var.name}"
70+
namespace = kubernetes_namespace.coder_namespace.metadata.0.name
71+
}
72+
spec = {
73+
secretName = "${var.name}-tls"
74+
dnsNames = regex("https?://([^/]+)", local.coder_url)
75+
issuerRef = {
76+
name = kubernetes_manifest.cloudflare-cluster-issuer.manifest.metadata.name
77+
kind = "ClusterIssuer"
78+
}
79+
}
6980
}
7081
}
7182

72-
# Also need an OTEL collector deployed. Manual for now.
73-
data "kubernetes_service" "otel_collector" {
83+
data "kubernetes_secret" "coder_tls" {
7484
metadata {
7585
namespace = kubernetes_namespace.coder_namespace.metadata.0.name
76-
name = "otel-collector"
86+
name = "${var.name}-tls"
7787
}
88+
depends_on = [kubernetes_manifest.coder_certificate]
7889
}
7990

8091
resource "helm_release" "coder-chart" {
@@ -164,7 +175,7 @@ coder:
164175
name: "${data.kubernetes_secret.coder_oidc.metadata.0.name}"
165176
# Send OTEL traces to the cluster-local collector to sample 10%
166177
- name: "OTEL_EXPORTER_OTLP_ENDPOINT"
167-
value: "http://${data.kubernetes_service.otel_collector.metadata.0.name}.${kubernetes_namespace.coder_namespace.metadata.0.name}.svc.cluster.local:4317"
178+
value: "http://${kubernetes_manifest.otel-collector.manifest.metadata.name}-collector.${kubernetes_namespace.coder_namespace.metadata.0.name}.svc.cluster.local:4317"
168179
- name: "OTEL_TRACES_SAMPLER"
169180
value: parentbased_traceidratio
170181
- name: "OTEL_TRACES_SAMPLER_ARG"

scaletest/terraform/k8s/otel.tf

Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
# Terraform configuration for OpenTelemetry Operator
2+
3+
locals {
4+
otel_namespace = "opentelemetry-operator-system"
5+
otel_operator_helm_repo = "https://open-telemetry.github.io/opentelemetry-helm-charts"
6+
otel_operator_helm_chart = "opentelemtry-operator"
7+
otel_operator_release_name = "opentelemetry-operator"
8+
otel_operator_chart_version = "0.34.1"
9+
}
10+
11+
resource "kubernetes_namespace" "otel-namespace" {
12+
metadata {
13+
name = local.otel_namespace
14+
}
15+
lifecycle {
16+
ignore_changes = [timeouts, wait_for_default_service_account]
17+
}
18+
}
19+
20+
resource "helm_release" "otel-operator" {
21+
repository = local.otel_operator_helm_repo
22+
chart = local.otel_operator_helm_chart
23+
name = local.otel_operator_release_name
24+
namespace = kubernetes_namespace.otel-namespace.metadata.0.name
25+
# Default values
26+
values = []
27+
}
28+
29+
resource "kubernetes_manifest" "otel-collector" {
30+
manifest = {
31+
apiVersion = "opentelemetry.io/v1alpha1"
32+
kind = "OpenTelemetryCollector"
33+
metadata = {
34+
namespace = kubernetes_namespace.coder_namespace.metadata.0.name
35+
name = "otel"
36+
}
37+
spec = {
38+
config = jsonencode({
39+
receivers = {
40+
otlp = {
41+
protocols : {
42+
grpc : {}
43+
http : {}
44+
}
45+
}
46+
}
47+
exporters = {
48+
googlecloud = {
49+
logging = {
50+
loglevel = "debug"
51+
}
52+
}
53+
}
54+
service = {
55+
pipelines = {
56+
traces = {
57+
receivers = ["otlp"]
58+
processors = []
59+
exporters = ["logging", "googlecloud"]
60+
}
61+
}
62+
}
63+
image = "otel/open-telemetry-collector-contrib:latest"
64+
mode = "deployment"
65+
replicas = 1
66+
})
67+
}
68+
}
69+
}

scaletest/terraform/k8s/vars.tf

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -207,3 +207,13 @@ variable "prometheus_remote_write_send_interval" {
207207
description = "Prometheus remote write interval."
208208
default = "15s"
209209
}
210+
211+
variable "cloudflare_api_token" {
212+
description = "Cloudflare API token."
213+
sensitive = true
214+
}
215+
216+
variable "cloudflare_email" {
217+
description = "Cloudflare email address."
218+
sensitive = true
219+
}

0 commit comments

Comments
 (0)