-
Notifications
You must be signed in to change notification settings - Fork 30
/
ec2-launch-templates.tf
144 lines (119 loc) · 4.36 KB
/
ec2-launch-templates.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
# Generate Consul gossip encryption key
resource "random_id" "gossip_key" {
byte_length = 32
}
## Set bootstrap ACL token
resource "random_uuid" "consul_bootstrap_token" {}
# Consul Server Launch Template
resource "aws_launch_template" "consul_server" {
name_prefix = "${var.main_project_tag}-server-lt-"
image_id = var.use_latest_ami ? data.aws_ssm_parameter.ubuntu_1804_ami_id.value : var.ami_id
instance_type = "t3.micro"
key_name = var.ec2_key_pair_name
vpc_security_group_ids = [aws_security_group.consul_server.id]
iam_instance_profile {
name = aws_iam_instance_profile.consul_instance_profile.name
}
tag_specifications {
resource_type = "instance"
tags = merge(
{ "Name" = "${var.main_project_tag}-server" },
{ "Project" = var.main_project_tag }
)
}
tag_specifications {
resource_type = "volume"
tags = merge(
{ "Name" = "${var.main_project_tag}-server-volume" },
{ "Project" = var.main_project_tag }
)
}
tags = merge(
{ "Name" = "${var.main_project_tag}-server-lt" },
{ "Project" = var.main_project_tag }
)
user_data = base64encode(templatefile("${path.module}/scripts/server.sh", {
PROJECT_TAG = "Project"
PROJECT_VALUE = var.main_project_tag
BOOTSTRAP_NUMBER = var.server_min_count
GOSSIP_KEY = random_id.gossip_key.b64_std
CA_PUBLIC_KEY = tls_self_signed_cert.ca_cert.cert_pem
SERVER_PUBLIC_KEY = tls_locally_signed_cert.server_signed_cert.cert_pem
SERVER_PRIVATE_KEY = tls_private_key.server_key.private_key_pem
BOOTSTRAP_TOKEN = random_uuid.consul_bootstrap_token.result
}))
}
# Consul Client Web Launch Template
resource "aws_launch_template" "consul_client_web" {
name_prefix = "${var.main_project_tag}-web-lt-"
image_id = var.use_latest_ami ? data.aws_ssm_parameter.ubuntu_1804_ami_id.value : var.ami_id
instance_type = "t3.micro"
key_name = var.ec2_key_pair_name
vpc_security_group_ids = [aws_security_group.consul_client.id]
iam_instance_profile {
name = aws_iam_instance_profile.consul_instance_profile.name
}
tag_specifications {
resource_type = "instance"
tags = merge(
{ "Name" = "${var.main_project_tag}-web" },
{ "Project" = var.main_project_tag }
)
}
tag_specifications {
resource_type = "volume"
tags = merge(
{ "Name" = "${var.main_project_tag}-web-volume" },
{ "Project" = var.main_project_tag }
)
}
tags = merge(
{ "Name" = "${var.main_project_tag}-web-lt" },
{ "Project" = var.main_project_tag }
)
user_data = base64encode(templatefile("${path.module}/scripts/client-web.sh", {
PROJECT_TAG = "Project"
PROJECT_VALUE = var.main_project_tag
GOSSIP_KEY = random_id.gossip_key.b64_std
CA_PUBLIC_KEY = tls_self_signed_cert.ca_cert.cert_pem
CLIENT_PUBLIC_KEY = tls_locally_signed_cert.client_web_signed_cert.cert_pem
CLIENT_PRIVATE_KEY = tls_private_key.client_web_key.private_key_pem
}))
}
# Consul Client API Launch Template
resource "aws_launch_template" "consul_client_api" {
name_prefix = "${var.main_project_tag}-api-lt-"
image_id = var.use_latest_ami ? data.aws_ssm_parameter.ubuntu_1804_ami_id.value : var.ami_id
instance_type = "t3.micro"
key_name = var.ec2_key_pair_name
vpc_security_group_ids = [aws_security_group.consul_client.id]
iam_instance_profile {
name = aws_iam_instance_profile.consul_instance_profile.name
}
tag_specifications {
resource_type = "instance"
tags = merge(
{ "Name" = "${var.main_project_tag}-api" },
{ "Project" = var.main_project_tag }
)
}
tag_specifications {
resource_type = "volume"
tags = merge(
{ "Name" = "${var.main_project_tag}-api-volume" },
{ "Project" = var.main_project_tag }
)
}
tags = merge(
{ "Name" = "${var.main_project_tag}-api-lt" },
{ "Project" = var.main_project_tag }
)
user_data = base64encode(templatefile("${path.module}/scripts/client-api.sh", {
PROJECT_TAG = "Project"
PROJECT_VALUE = var.main_project_tag
GOSSIP_KEY = random_id.gossip_key.b64_std
CA_PUBLIC_KEY = tls_self_signed_cert.ca_cert.cert_pem
CLIENT_PUBLIC_KEY = tls_locally_signed_cert.client_api_signed_cert.cert_pem
CLIENT_PRIVATE_KEY = tls_private_key.client_api_key.private_key_pem
}))
}