Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dev #20

Merged
merged 2 commits into from
Jun 15, 2024
Merged

Dev #20

merged 2 commits into from
Jun 15, 2024

Conversation

enricogoerlitz
Copy link
Owner

No description provided.

@enricogoerlitz enricogoerlitz merged commit 7d53a49 into main Jun 15, 2024
2 of 3 checks passed
Copy link

Terraform Format and Style 🖌failure

Terraform Initialization ⚙️success

Terraform Validation 🤖success

Validation Output

Success! The configuration is valid.


Terraform Plan 📖success

Show Plan

terraform
aws_lb_target_group.tg_bp2_hosting_backend: Refreshing state... [id=arn:aws:elasticloadbalancing:eu-central-1:533267024986:targetgroup/tg-bp2-hosting-backend/fc494915fd12f323]
aws_security_group.bp2_hosting_backend_sg: Refreshing state... [id=sg-0d9fd3f8e5654871d]

Note: Objects have changed outside of Terraform

Terraform detected the following changes made outside of Terraform since the
last "terraform apply" which may have affected this plan:

  # aws_lb_target_group.tg_bp2_hosting_backend has changed
  ~ resource "aws_lb_target_group" "tg_bp2_hosting_backend" {
      + arn                                = "arn:aws:elasticloadbalancing:eu-central-1:533267024986:targetgroup/tg-bp2-hosting-backend/fc494915fd12f323"
        id                                 = "arn:aws:elasticloadbalancing:eu-central-1:533267024986:targetgroup/tg-bp2-hosting-backend/fc494915fd12f323"
        name                               = "tg-bp2-hosting-backend"
        # (9 unchanged attributes hidden)
    }


Unless you have made equivalent changes to your configuration, or ignored the
relevant attributes using ignore_changes, the following plan may include
actions to undo or respond to these changes.

─────────────────────────────────────────────────────────────────────────────

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  + create
-/+ destroy and then create replacement

Terraform will perform the following actions:

  # aws_autoscaling_group.asg_bp2_hosting_backend will be created
  + resource "aws_autoscaling_group" "asg_bp2_hosting_backend" {
      + arn                              = (known after apply)
      + availability_zones               = (known after apply)
      + default_cooldown                 = (known after apply)
      + desired_capacity                 = 4
      + force_delete                     = false
      + force_delete_warm_pool           = false
      + health_check_grace_period        = 300
      + health_check_type                = (known after apply)
      + id                               = (known after apply)
      + ignore_failed_scaling_activities = false
      + load_balancers                   = (known after apply)
      + max_size                         = 5
      + metrics_granularity              = "1Minute"
      + min_size                         = 3
      + name                             = (known after apply)
      + name_prefix                      = (known after apply)
      + predicted_capacity               = (known after apply)
      + protect_from_scale_in            = false
      + service_linked_role_arn          = (known after apply)
      + target_group_arns                = (known after apply)
      + vpc_zone_identifier              = [
          + "subnet-01120a3503e1fe9a4",
          + "subnet-075437f53bad1c0e3",
          + "subnet-0f5bbc4112f613d16",
        ]
      + wait_for_capacity_timeout        = "10m"
      + warm_pool_size                   = (known after apply)

      + launch_template {
          + id      = (known after apply)
          + name    = (known after apply)
          + version = "$Latest"
        }
    }

  # aws_launch_template.ect_bp2_hosting_backend will be created
  + resource "aws_launch_template" "ect_bp2_hosting_backend" {
      + arn                    = (known after apply)
      + default_version        = (known after apply)
      + id                     = (known after apply)
      + image_id               = "ami-00cf59bc9978eb266"
      + instance_type          = "t2.micro"
      + key_name               = "tmp-key-pair"
      + latest_version         = (known after apply)
      + name                   = "ec2t-bp2-hosting-backend"
      + name_prefix            = (known after apply)
      + tags_all               = (known after apply)
      + user_data              = "IyEvYmluL2Jhc2gKCnN1ZG8geXVtIHVwZGF0ZSAteQoKc3VkbyB5dW0gaW5zdGFsbCBkb2NrZXIgLXkKc3VkbyBzZXJ2aWNlIGRvY2tlciBzdGFydApzdWRvIHVzZXJtb2QgLWEgLUcgZG9ja2VyIGVjMi11c2VyCgpzdWRvIGRuZiBpbnN0YWxsIGxpYnhjcnlwdC1jb21wYXQgLXkKCnN1ZG8gY3VybCAtTCAiaHR0cHM6Ly9naXRodWIuY29tL2RvY2tlci9jb21wb3NlL3JlbGVhc2VzL2Rvd25sb2FkL3YyLjI3LjEvZG9ja2VyLWNvbXBvc2UtJCh1bmFtZSAtcyktJCh1bmFtZSAtbSkiIC1vIC91c3IvbG9jYWwvYmluL2RvY2tlci1jb21wb3NlCgpzdWRvIGNobW9kICt4IC91c3IvbG9jYWwvYmluL2RvY2tlci1jb21wb3NlCgojIENyZWF0ZSBhIHN5bWJvbGljIGxpbmsgdG8gL3Vzci9iaW4Kc3VkbyBsbiAtcyAvdXNyL2xvY2FsL2Jpbi9kb2NrZXItY29tcG9zZSAvdXNyL2Jpbi9kb2NrZXItY29tcG9zZQoKY2QgL2hvbWUvZWMyLXVzZXIvCm1rZGlyIHByb2plY3QKY2QgLi9wcm9qZWN0CmN1cmwgLUwgImh0dHBzOi8vcmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbS9lbnJpY29nb2VybGl0ei9hd3MtYnAtMi1ob3N0aW5nLWJhY2tlbmQtb24tZWMyLWFzZy1hbGIvbWFpbi9kb2NrZXIvcHJvZC9kb2NrZXItY29tcG9zZS55bWwiIC1vIGRvY2tlci1jb21wb3NlLnltbAoKc3VkbyBkb2NrZXItY29tcG9zZSB1cCAtZAo="
      + vpc_security_group_ids = (known after apply)
    }

  # aws_lb.alb_bp2_hosting_backend will be created
  + resource "aws_lb" "alb_bp2_hosting_backend" {
      + arn                                                          = (known after apply)
      + arn_suffix                                                   = (known after apply)
      + client_keep_alive                                            = 3600
      + desync_mitigation_mode                                       = "defensive"
      + dns_name                                                     = (known after apply)
      + drop_invalid_header_fields                                   = false
      + enable_deletion_protection                                   = false
      + enable_http2                                                 = true
      + enable_tls_version_and_cipher_suite_headers                  = false
      + enable_waf_fail_open                                         = false
      + enable_xff_client_port                                       = false
      + enforce_security_group_inbound_rules_on_private_link_traffic = (known after apply)
      + id                                                           = (known after apply)
      + idle_timeout                                                 = 60
      + internal                                                     = false
      + ip_address_type                                              = (known after apply)
      + load_balancer_type                                           = "application"
      + name                                                         = "alb-bp2-hosting-backend"
      + name_prefix                                                  = (known after apply)
      + preserve_host_header                                         = false
      + security_groups                                              = (known after apply)
      + subnets                                                      = [
          + "subnet-01120a3503e1fe9a4",
          + "subnet-075437f53bad1c0e3",
          + "subnet-0f5bbc4112f613d16",
        ]
      + tags_all                                                     = (known after apply)
      + vpc_id                                                       = (known after apply)
      + xff_header_processing_mode                                   = "append"
      + zone_id                                                      = (known after apply)
    }

  # aws_lb_listener.listener_http_bp2_hosting_backend will be created
  + resource "aws_lb_listener" "listener_http_bp2_hosting_backend" {
      + arn               = (known after apply)
      + id                = (known after apply)
      + load_balancer_arn = (known after apply)
      + port              = 80
      + protocol          = "HTTP"
      + ssl_policy        = (known after apply)
      + tags_all          = (known after apply)

      + default_action {
          + order            = (known after apply)
          + target_group_arn = (known after apply)
          + type             = "forward"
        }
    }

  # aws_lb_listener.listener_https_bp2_hosting_backend will be created
  + resource "aws_lb_listener" "listener_https_bp2_hosting_backend" {
      + arn               = (known after apply)
      + certificate_arn   = "arn:aws:acm:eu-central-1:533267024986:certificate/2412b429-1dd0-4850-a11d-6692007d62b9"
      + id                = (known after apply)
      + load_balancer_arn = (known after apply)
      + port              = 443
      + protocol          = "HTTPS"
      + ssl_policy        = "ELBSecurityPolicy-2016-08"
      + tags_all          = (known after apply)

      + default_action {
          + order            = (known after apply)
          + target_group_arn = (known after apply)
          + type             = "forward"
        }
    }

  # aws_lb_target_group.tg_bp2_hosting_backend is tainted, so must be replaced
-/+ resource "aws_lb_target_group" "tg_bp2_hosting_backend" {
      ~ arn                                = "arn:aws:elasticloadbalancing:eu-central-1:533267024986:targetgroup/tg-bp2-hosting-backend/fc494915fd12f323" -> (known after apply)
      ~ arn_suffix                         = "targetgroup/tg-bp2-hosting-backend/fc494915fd12f323" -> (known after apply)
      + connection_termination             = (known after apply)
      ~ id                                 = "arn:aws:elasticloadbalancing:eu-central-1:533267024986:targetgroup/tg-bp2-hosting-backend/fc494915fd12f323" -> (known after apply)
      ~ ip_address_type                    = "ipv4" -> (known after apply)
      ~ load_balancer_arns                 = [] -> (known after apply)
      ~ load_balancing_algorithm_type      = "round_robin" -> (known after apply)
      ~ load_balancing_anomaly_mitigation  = "off" -> (known after apply)
      ~ load_balancing_cross_zone_enabled  = "use_load_balancer_configuration" -> (known after apply)
        name                               = "tg-bp2-hosting-backend"
      + name_prefix                        = (known after apply)
      + preserve_client_ip                 = (known after apply)
      ~ protocol_version                   = "HTTP1" -> (known after apply)
      - tags                               = {} -> null
      ~ tags_all                           = {} -> (known after apply)
        # (8 unchanged attributes hidden)

      - health_check {
          - enabled             = true -> null
          - healthy_threshold   = 5 -> null
          - interval            = 30 -> null
          - matcher             = "200" -> null
          - path                = "/" -> null
          - port                = "traffic-port" -> null
          - protocol            = "HTTP" -> null
          - timeout             = 5 -> null
          - unhealthy_threshold = 2 -> null
        }

      - stickiness {
          - cookie_duration = 86400 -> null
          - enabled         = false -> null
          - type            = "lb_cookie" -> null
        }

      - target_failover {}

      - target_health_state {}
    }

  # aws_route53_record.bp2_hosting_backend will be created
  + resource "aws_route53_record" "bp2_hosting_backend" {
      + allow_overwrite = (known after apply)
      + fqdn            = (known after apply)
      + id              = (known after apply)
      + name            = "bp2.enricogoerlitz.com"
      + type            = "A"
      + zone_id         = "Z0537675234U5T8AE6L76"

      + alias {
          + evaluate_target_health = true
          + name                   = (known after apply)
          + zone_id                = (known after apply)
        }
    }

  # aws_security_group.bp2_hosting_backend_sg is tainted, so must be replaced
-/+ resource "aws_security_group" "bp2_hosting_backend_sg" {
      ~ arn                    = "arn:aws:ec2:eu-central-1:533267024986:security-group/sg-0d9fd3f8e5654871d" -> (known after apply)
      ~ id                     = "sg-0d9fd3f8e5654871d" -> (known after apply)
      ~ ingress                = [
          + {
              + cidr_blocks      = [
                  + "0.0.0.0/0",
                ]
              + description      = "Allow HTTP"
              + from_port        = 80
              + ipv6_cidr_blocks = []
              + prefix_list_ids  = []
              + protocol         = "tcp"
              + security_groups  = []
              + self             = false
              + to_port          = 80
            },
          + {
              + cidr_blocks      = [
                  + "0.0.0.0/0",
                ]
              + description      = "Allow HTTPS"
              + from_port        = 443
              + ipv6_cidr_blocks = []
              + prefix_list_ids  = []
              + protocol         = "tcp"
              + security_groups  = []
              + self             = false
              + to_port          = 443
            },
          + {
              + cidr_blocks      = [
                  + "0.0.0.0/0",
                ]
              + description      = "Allow SSH"
              + from_port        = 22
              + ipv6_cidr_blocks = []
              + prefix_list_ids  = []
              + protocol         = "tcp"
              + security_groups  = []
              + self             = false
              + to_port          = 22
            },
        ]
        name                   = "bp2-hosting-backend-sg"
      + name_prefix            = (known after apply)
      ~ owner_id               = "533267024986" -> (known after apply)
      - tags                   = {} -> null
      ~ tags_all               = {} -> (known after apply)
        # (4 unchanged attributes hidden)
    }

Plan: 8 to add, 0 to change, 2 to destroy.

─────────────────────────────────────────────────────────────────────────────

Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.

Pushed by: @enricogoerlitz, Action: pull_request

Copy link

Terraform Format and Style 🖌failure

Terraform Initialization ⚙️success

Terraform Validation 🤖success

Validation Output

Success! The configuration is valid.


Terraform Plan 📖success

Show Plan

terraform

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  + create

Terraform will perform the following actions:

  # aws_autoscaling_group.asg_bp2_hosting_backend will be created
  + resource "aws_autoscaling_group" "asg_bp2_hosting_backend" {
      + arn                              = (known after apply)
      + availability_zones               = (known after apply)
      + default_cooldown                 = (known after apply)
      + desired_capacity                 = 4
      + force_delete                     = false
      + force_delete_warm_pool           = false
      + health_check_grace_period        = 300
      + health_check_type                = (known after apply)
      + id                               = (known after apply)
      + ignore_failed_scaling_activities = false
      + load_balancers                   = (known after apply)
      + max_size                         = 5
      + metrics_granularity              = "1Minute"
      + min_size                         = 3
      + name                             = (known after apply)
      + name_prefix                      = (known after apply)
      + predicted_capacity               = (known after apply)
      + protect_from_scale_in            = false
      + service_linked_role_arn          = (known after apply)
      + target_group_arns                = (known after apply)
      + vpc_zone_identifier              = [
          + "subnet-01120a3503e1fe9a4",
          + "subnet-075437f53bad1c0e3",
          + "subnet-0f5bbc4112f613d16",
        ]
      + wait_for_capacity_timeout        = "10m"
      + warm_pool_size                   = (known after apply)

      + launch_template {
          + id      = (known after apply)
          + name    = (known after apply)
          + version = "$Latest"
        }
    }

  # aws_launch_template.ect_bp2_hosting_backend will be created
  + resource "aws_launch_template" "ect_bp2_hosting_backend" {
      + arn                    = (known after apply)
      + default_version        = (known after apply)
      + id                     = (known after apply)
      + image_id               = "ami-00cf59bc9978eb266"
      + instance_type          = "t2.micro"
      + key_name               = "tmp-key-pair"
      + latest_version         = (known after apply)
      + name                   = "ec2t-bp2-hosting-backend"
      + name_prefix            = (known after apply)
      + tags_all               = (known after apply)
      + user_data              = "IyEvYmluL2Jhc2gKCnN1ZG8geXVtIHVwZGF0ZSAteQoKc3VkbyB5dW0gaW5zdGFsbCBkb2NrZXIgLXkKc3VkbyBzZXJ2aWNlIGRvY2tlciBzdGFydApzdWRvIHVzZXJtb2QgLWEgLUcgZG9ja2VyIGVjMi11c2VyCgpzdWRvIGRuZiBpbnN0YWxsIGxpYnhjcnlwdC1jb21wYXQgLXkKCnN1ZG8gY3VybCAtTCAiaHR0cHM6Ly9naXRodWIuY29tL2RvY2tlci9jb21wb3NlL3JlbGVhc2VzL2Rvd25sb2FkL3YyLjI3LjEvZG9ja2VyLWNvbXBvc2UtJCh1bmFtZSAtcyktJCh1bmFtZSAtbSkiIC1vIC91c3IvbG9jYWwvYmluL2RvY2tlci1jb21wb3NlCgpzdWRvIGNobW9kICt4IC91c3IvbG9jYWwvYmluL2RvY2tlci1jb21wb3NlCgojIENyZWF0ZSBhIHN5bWJvbGljIGxpbmsgdG8gL3Vzci9iaW4Kc3VkbyBsbiAtcyAvdXNyL2xvY2FsL2Jpbi9kb2NrZXItY29tcG9zZSAvdXNyL2Jpbi9kb2NrZXItY29tcG9zZQoKY2QgL2hvbWUvZWMyLXVzZXIvCm1rZGlyIHByb2plY3QKY2QgLi9wcm9qZWN0CmN1cmwgLUwgImh0dHBzOi8vcmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbS9lbnJpY29nb2VybGl0ei9hd3MtYnAtMi1ob3N0aW5nLWJhY2tlbmQtb24tZWMyLWFzZy1hbGIvbWFpbi9kb2NrZXIvcHJvZC9kb2NrZXItY29tcG9zZS55bWwiIC1vIGRvY2tlci1jb21wb3NlLnltbAoKc3VkbyBkb2NrZXItY29tcG9zZSB1cCAtZAo="
      + vpc_security_group_ids = (known after apply)
    }

  # aws_lb.alb_bp2_hosting_backend will be created
  + resource "aws_lb" "alb_bp2_hosting_backend" {
      + arn                                                          = (known after apply)
      + arn_suffix                                                   = (known after apply)
      + client_keep_alive                                            = 3600
      + desync_mitigation_mode                                       = "defensive"
      + dns_name                                                     = (known after apply)
      + drop_invalid_header_fields                                   = false
      + enable_deletion_protection                                   = false
      + enable_http2                                                 = true
      + enable_tls_version_and_cipher_suite_headers                  = false
      + enable_waf_fail_open                                         = false
      + enable_xff_client_port                                       = false
      + enforce_security_group_inbound_rules_on_private_link_traffic = (known after apply)
      + id                                                           = (known after apply)
      + idle_timeout                                                 = 60
      + internal                                                     = false
      + ip_address_type                                              = (known after apply)
      + load_balancer_type                                           = "application"
      + name                                                         = "alb-bp2-hosting-backend"
      + name_prefix                                                  = (known after apply)
      + preserve_host_header                                         = false
      + security_groups                                              = (known after apply)
      + subnets                                                      = [
          + "subnet-01120a3503e1fe9a4",
          + "subnet-075437f53bad1c0e3",
          + "subnet-0f5bbc4112f613d16",
        ]
      + tags_all                                                     = (known after apply)
      + vpc_id                                                       = (known after apply)
      + xff_header_processing_mode                                   = "append"
      + zone_id                                                      = (known after apply)
    }

  # aws_lb_listener.listener_http_bp2_hosting_backend will be created
  + resource "aws_lb_listener" "listener_http_bp2_hosting_backend" {
      + arn               = (known after apply)
      + id                = (known after apply)
      + load_balancer_arn = (known after apply)
      + port              = 80
      + protocol          = "HTTP"
      + ssl_policy        = (known after apply)
      + tags_all          = (known after apply)

      + default_action {
          + order            = (known after apply)
          + target_group_arn = (known after apply)
          + type             = "forward"
        }
    }

  # aws_lb_listener.listener_https_bp2_hosting_backend will be created
  + resource "aws_lb_listener" "listener_https_bp2_hosting_backend" {
      + arn               = (known after apply)
      + certificate_arn   = "arn:aws:acm:eu-central-1:533267024986:certificate/2412b429-1dd0-4850-a11d-6692007d62b9"
      + id                = (known after apply)
      + load_balancer_arn = (known after apply)
      + port              = 443
      + protocol          = "HTTPS"
      + ssl_policy        = "ELBSecurityPolicy-2016-08"
      + tags_all          = (known after apply)

      + default_action {
          + order            = (known after apply)
          + target_group_arn = (known after apply)
          + type             = "forward"
        }
    }

  # aws_lb_target_group.tg_bp2_hosting_backend will be created
  + resource "aws_lb_target_group" "tg_bp2_hosting_backend" {
      + arn                                = (known after apply)
      + arn_suffix                         = (known after apply)
      + connection_termination             = (known after apply)
      + deregistration_delay               = "300"
      + id                                 = (known after apply)
      + ip_address_type                    = (known after apply)
      + lambda_multi_value_headers_enabled = false
      + load_balancer_arns                 = (known after apply)
      + load_balancing_algorithm_type      = (known after apply)
      + load_balancing_anomaly_mitigation  = (known after apply)
      + load_balancing_cross_zone_enabled  = (known after apply)
      + name                               = "tg-bp2-hosting-backend"
      + name_prefix                        = (known after apply)
      + port                               = 80
      + preserve_client_ip                 = (known after apply)
      + protocol                           = "HTTP"
      + protocol_version                   = (known after apply)
      + proxy_protocol_v2                  = false
      + slow_start                         = 0
      + tags_all                           = (known after apply)
      + target_type                        = "instance"
      + vpc_id                             = "vpc-09e61af5bb6aafa26"
    }

  # aws_route53_record.bp2_hosting_backend will be created
  + resource "aws_route53_record" "bp2_hosting_backend" {
      + allow_overwrite = (known after apply)
      + fqdn            = (known after apply)
      + id              = (known after apply)
      + name            = "bp2.enricogoerlitz.com"
      + type            = "A"
      + zone_id         = "Z0537675234U5T8AE6L76"

      + alias {
          + evaluate_target_health = true
          + name                   = (known after apply)
          + zone_id                = (known after apply)
        }
    }

  # aws_security_group.bp2_hosting_backend_sg will be created
  + resource "aws_security_group" "bp2_hosting_backend_sg" {
      + arn                    = (known after apply)
      + description            = "Allow HTTP, HTTPS and SSH traffic"
      + egress                 = [
          + {
              + cidr_blocks      = [
                  + "0.0.0.0/0",
                ]
              + description      = ""
              + from_port        = 0
              + ipv6_cidr_blocks = []
              + prefix_list_ids  = []
              + protocol         = "-1"
              + security_groups  = []
              + self             = false
              + to_port          = 0
            },
        ]
      + id                     = (known after apply)
      + ingress                = [
          + {
              + cidr_blocks      = [
                  + "0.0.0.0/0",
                ]
              + description      = "Allow HTTP"
              + from_port        = 80
              + ipv6_cidr_blocks = []
              + prefix_list_ids  = []
              + protocol         = "tcp"
              + security_groups  = []
              + self             = false
              + to_port          = 80
            },
          + {
              + cidr_blocks      = [
                  + "0.0.0.0/0",
                ]
              + description      = "Allow HTTPS"
              + from_port        = 443
              + ipv6_cidr_blocks = []
              + prefix_list_ids  = []
              + protocol         = "tcp"
              + security_groups  = []
              + self             = false
              + to_port          = 443
            },
          + {
              + cidr_blocks      = [
                  + "0.0.0.0/0",
                ]
              + description      = "Allow SSH"
              + from_port        = 22
              + ipv6_cidr_blocks = []
              + prefix_list_ids  = []
              + protocol         = "tcp"
              + security_groups  = []
              + self             = false
              + to_port          = 22
            },
        ]
      + name                   = "bp2-hosting-backend-sg"
      + name_prefix            = (known after apply)
      + owner_id               = (known after apply)
      + revoke_rules_on_delete = false
      + tags_all               = (known after apply)
      + vpc_id                 = "vpc-09e61af5bb6aafa26"
    }

Plan: 8 to add, 0 to change, 0 to destroy.

─────────────────────────────────────────────────────────────────────────────

Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.

Pushed by: @enricogoerlitz, Action: pull_request

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant