diff --git a/.terraform.lock.hcl b/.terraform.lock.hcl index db1d5f3..85c8ce9 100644 --- a/.terraform.lock.hcl +++ b/.terraform.lock.hcl @@ -2,25 +2,24 @@ # Manual edits may be lost in future updates. provider "registry.terraform.io/hashicorp/aws" { - version = "5.100.0" - constraints = "~> 5.0" + version = "6.35.0" + constraints = "~> 6.0" hashes = [ - "h1:Ijt7pOlB7Tr7maGQIqtsLFbl7pSMIj06TVdkoSBcYOw=", - "h1:edXOJWE4ORX8Fm+dpVpICzMZJat4AX0VRCAy/xkcOc0=", - "zh:054b8dd49f0549c9a7cc27d159e45327b7b65cf404da5e5a20da154b90b8a644", - "zh:0b97bf8d5e03d15d83cc40b0530a1f84b459354939ba6f135a0086c20ebbe6b2", - "zh:1589a2266af699cbd5d80737a0fe02e54ec9cf2ca54e7e00ac51c7359056f274", - "zh:6330766f1d85f01ae6ea90d1b214b8b74cc8c1badc4696b165b36ddd4cc15f7b", - "zh:7c8c2e30d8e55291b86fcb64bdf6c25489d538688545eb48fd74ad622e5d3862", - "zh:99b1003bd9bd32ee323544da897148f46a527f622dc3971af63ea3e251596342", + "h1:1iT6jfU18fnDQCUzsWGsT0EUfLm//UcTh3QVN//gv7k=", + "zh:0ae4d5a1fc094b173e0d47649981b6cb8d4f5a24182f08aeb0f1812071d5bacc", + "zh:21acdf0d5671df0aee7e9c6a226b08ce40d637d3f6d44cb33bd89a532e58ac81", + "zh:2706f83d54ee74d0c3238ef451a10aae94c25c275fff945f24c81cc8c3185c6f", + "zh:336fc3be04864e2cb326df3ba03523a23e17efc978d95a5b3622bc2a2051d56c", + "zh:399a05362eaa2e6ff1446b42350d6bcdfbd13c48e7e5bceeaec987e7145743b8", + "zh:402a326a938120a0d6d2839d1eacd6862e3a51679f53cbb41e400c6deb36bd7e", + "zh:74497cc6185fb8f7a7c916f35006413fc5852e5d7414dca25d25efca527f3721", + "zh:8afd2759d9355270def8fa345c8880ab52d35ec4aa5bc463c392afe740a67863", "zh:9b12af85486a96aedd8d7984b0ff811a4b42e3d88dad1a3fb4c0b580d04fa425", - "zh:9f8b909d3ec50ade83c8062290378b1ec553edef6a447c56dadc01a99f4eaa93", - "zh:aaef921ff9aabaf8b1869a86d692ebd24fbd4e12c21205034bb679b9caf883a2", - "zh:ac882313207aba00dd5a76dbd572a0ddc818bb9cbf5c9d61b28fe30efaec951e", - "zh:bb64e8aff37becab373a1a0cc1080990785304141af42ed6aa3dd4913b000421", - "zh:dfe495f6621df5540d9c92ad40b8067376350b005c637ea6efac5dc15028add4", - "zh:f0ddf0eaf052766cfe09dea8200a946519f653c384ab4336e2a4a64fdd6310e9", - "zh:f1b7e684f4c7ae1eed272b6de7d2049bb87a0275cb04dbb7cda6636f600699c9", - "zh:ff461571e3f233699bf690db319dfe46aec75e58726636a0d97dd9ac6e32fb70", + "zh:a69117698044b5e6eb0f178790f1166059ea009a82e60922309117751b75d9f3", + "zh:e8c12582c93a977a3082ca640f1b9d6050f2153dd27e8f337c8e0f1c47abb322", + "zh:e944e74e08b22ce7c5601cded1caa090e209d2ad550f945afd059c7098cfc28b", + "zh:edefaf9dc0e3c2a08e80b2ce0f8544ea433cbce2382bcb4913250ba71f4267dc", + "zh:eedd5a91f263b92092d1d174bcd60d8e3e5fe3588972c397664d36d548a77551", + "zh:f42d1289f85b1bc76de8a6f51f36fded9d933a313c5a28f61e5df0191398f4d8", ] } diff --git a/README.md b/README.md index 15b3197..7049e80 100644 --- a/README.md +++ b/README.md @@ -108,8 +108,6 @@ This is a core infrastructure repository that defines infrastructure related to * [DSO Infrastructure](https://github.com/MITLibraries/mitlib-tf-workloads-dso) * [DSpace Submission Composer Application](https://github.com/MITLibraries/dspace-submission-composer) * [DSpace Submission Service Application](https://github.com/MITLibraries/dspace-submission-service) -* **DEPRECATED**: [DSC](https://github.com/MITLibraries/mitlib-tf-workloads-dsc) -* **DEPRECATED**: [DSS](https://github.com/MITLibraries/mitlib-tf-workloads-dss) * [ETD Infrastructure](https://github.com/MITLibraries/mitlib-tf-workloads-etd) * [HRQB](https://github.com/MITLibraries/mitlib-tf-workloads-hrqb-loader) * [HRQB Client](https://github.com/MITLibraries/hrqb-client) @@ -120,17 +118,20 @@ This is a core infrastructure repository that defines infrastructure related to * [Matomo Application](https://github.com/MITLibraries/docker-matomo) * [PPOD](https://github.com/MITLibraries/mitlib-tf-workloads-ppod) * [PPOD Application](https://github.com/MITLibraries/ppod) +* [Quepid](https://github.com/MITLibraries/mitlib-tf-workloads-quepid) + * [Quepid Application](https://github.com/MITLibraries/quepid) * [TACOS](https://github.com/MITLibraries/mitlib-tf-workloads-tacos) * [tacos-detectors-lambdas](https://github.com/MITLibraries/tacos-detectors-lambdas) * [TIMDEX](https://github.com/MITLibraries/mitlib-tf-workloads-timdex-infrastructure) * [TIMDEX Application](https://github.com/MITLibraries/timdex) * [TIMDEX Dataset API](https://github.com/MITLibraries/timdex-dataset-api) + * [TIMDEX Embeddings](https://github.com/MITLibraries/timdex-embeddings) * [TIMDEX Index Manager](https://github.com/MITLibraries/timdex-index-manager) * [TIMDEX Pipeline Lambdas](https://github.com/MITLibraries/timdex-pipeline-lambdas) - * [TIMDEX UI](https://github.com/MITLibraries/timdex-ui) + * [TIMDEX Semantic Builder](https://github.com/MITLibraries/timdex-semantic-builder) * [TIMDEX Simulator](https://github.com/MITLibraries/timdex-simulator) * [TIMDEX Transmogrifier](https://github.com/MITLibraries/transmogrifier) - * [TIMDEX Embeddings](https://github.com/MITLibraries/timdex-embeddings) + * [TIMDEX UI](https://github.com/MITLibraries/timdex-ui) * [WCD2Reshare](https://github.com/MITLibraries/mitlib-tf-workloads-wcd2reshare) * [WCD2Reshare Application Container](https://github.com/MITLibraries/wcd2reshare) * **DEPRECATED**: [Wiley](https://github.com/MITLibraries/mitlib-tf-workloads-wiley) @@ -140,7 +141,7 @@ This is a core infrastructure repository that defines infrastructure related to * Owner: See [CODEOWNERS](./.github/CODEOWNERS) * Team: See [CODEOWNERS](./.github/CODEOWNERS) -* Last Maintenance: 2026-02 +* Last Maintenance: 2026-03 ## TF markdown is automatically inserted at the bottom of this file, nothing should be written beyond this point @@ -150,13 +151,13 @@ This is a core infrastructure repository that defines infrastructure related to | Name | Version | |------|---------| | terraform | ~> 1.14 | -| aws | ~> 5.0 | +| aws | ~> 6.0 | ## Providers | Name | Version | |------|---------| -| aws | 5.100.0 | +| aws | 6.35.0 | ## Modules @@ -179,6 +180,7 @@ This is a core infrastructure repository that defines infrastructure related to | ecr\_oaiharvester | ./modules/ecr | n/a | | ecr\_patronload | ./modules/ecr | n/a | | ecr\_ppod | ./modules/ecr | n/a | +| ecr\_quepid | ./modules/ecr | n/a | | ecr\_sapinvoices | ./modules/ecr | n/a | | ecr\_sapinvoices\_ui | ./modules/ecr | n/a | | ecr\_tacos\_detectors | ./modules/ecr | n/a | @@ -186,6 +188,7 @@ This is a core infrastructure repository that defines infrastructure related to | ecr\_timdex\_embeddings | ./modules/ecr | n/a | | ecr\_timdex\_geo | ./modules/ecr | n/a | | ecr\_timdex\_lambdas | ./modules/ecr | n/a | +| ecr\_timdex\_semantic\_builder | ./modules/ecr | n/a | | ecr\_timdex\_tim | ./modules/ecr | n/a | | ecr\_timdex\_transmogrifier | ./modules/ecr | n/a | | ecr\_wcd2reshare | ./modules/ecr | n/a | @@ -285,6 +288,10 @@ This is a core infrastructure repository that defines infrastructure related to | ppod\_makefile | Full contents of the Makefile for the ppod repo (allows devs to push to Dev account only) | | ppod\_prod\_promote\_workflow | Full contents of the prod-promote.yml for the ppod repo | | ppod\_stage\_build\_workflow | Full contents of the stage-build.yml for the ppod repo | +| quepid\_fargate\_dev\_build\_workflow | Full contents of the dev-build.yml for the quepid repo | +| quepid\_fargate\_makefile | Full contents of the Makefile for the quepid repo (allows devs to push to Dev account only) | +| quepid\_fargate\_prod\_promote\_workflow | Full contents of the prod-promote.yml for the quepid repo | +| quepid\_fargate\_stage\_build\_workflow | Full contents of the stage-build.yml for the quepid repo | | s3\_bagit\_validator\_dev\_build\_workflow | Full contents of the dev-build.yml for the s3-bagit-validator repo | | s3\_bagit\_validator\_dev\_build\_workflow\_west | Additional job for the dev-build.yml for the s3-bagit-validator repo to deploy in us-west-2 | | s3\_bagit\_validator\_makefile | Full contents of the Makefile for the s3-bagit-validator repo (allows devs to push to Dev account only) | @@ -317,6 +324,10 @@ This is a core infrastructure repository that defines infrastructure related to | timdex\_lambdas\_makefile | Full contents of the Makefile for the timdex-pipeline-lambdas repo (allows devs to push to Dev account only) | | timdex\_lambdas\_prod\_promote\_workflow | Full contents of the prod-promote.yml for the timdex-pipeline-lambdas repo | | timdex\_lambdas\_stage\_build\_workflow | Full contents of the stage-build.yml for the timdex-pipeline-lambdas repo | +| timdex\_semantic\_builder\_lambda\_dev\_build\_workflow | Full contents of the dev-build.yml for the timdex-semantic-builder repo | +| timdex\_semantic\_builder\_lambda\_makefile | Full contents of the Makefile for the timdex-semantic-builder repo (allows devs to push to Dev account only) | +| timdex\_semantic\_builder\_lambda\_prod\_promote\_workflow | Full contents of the prod-promote.yml for the timdex-semantic-builder repo | +| timdex\_semantic\_builder\_lambda\_stage\_build\_workflow | Full contents of the stage-build.yml for the timdex-semantic-builder repo | | transmogrifier\_dev\_build\_workflow | Full contents of the dev-build.yml for the transmogrifier repo | | transmogrifier\_makefile | Full contents of the Makefile for the transmogrifier repo (allows devs to push to Dev account only) | | transmogrifier\_prod\_promote\_workflow | Full contents of the prod-promote.yml for the transmogrifier repo | diff --git a/dsc_ecr.tf b/dsc_ecr.tf deleted file mode 100644 index 025b9b8..0000000 --- a/dsc_ecr.tf +++ /dev/null @@ -1,67 +0,0 @@ -# DSpace Submission Composer (dsc) containers -# This is a standard ECR for an ECS with a Fargate launch type -locals { - ecr_dsc = "dsc-${var.environment}" -} - -module "ecr_dsc" { - source = "./modules/ecr" - repo_name = "dspace-submission-composer" - login_policy_arn = aws_iam_policy.login.arn - oidc_arn = data.aws_ssm_parameter.oidc_arn.value - environment = var.environment - tfoutput_ssm_path = var.tfoutput_ssm_path - tags = { - app-repo = "dspace-submission-composer" - } -} - -## Outputs to Terraform Cloud for devs ## - -## For dsc application repo and ECR repository -# Outputs in dev -output "dsc_fargate_dev_build_workflow" { - value = var.environment == "prod" || var.environment == "stage" ? null : templatefile("${path.module}/files/dev-build-cpu-arch.tpl", { - region = var.aws_region - role = module.ecr_dsc.gha_role - ecr = module.ecr_dsc.repository_name - function = "" - } - ) - description = "Full contents of the dev-build.yml for the dsc repo" -} -output "dsc_fargate_makefile" { - value = var.environment == "prod" || var.environment == "stage" ? null : templatefile("${path.module}/files/makefile-cpu-arch.tpl", { - ecr_name = module.ecr_dsc.repository_name - ecr_url = module.ecr_dsc.repository_url - function = "" - } - ) - description = "Full contents of the Makefile for the dsc repo (allows devs to push to Dev account only)" -} - -# Outputs in stage -output "dsc_fargate_stage_build_workflow" { - value = var.environment == "prod" || var.environment == "dev" ? null : templatefile("${path.module}/files/stage-build-cpu-arch.tpl", { - region = var.aws_region - role = module.ecr_dsc.gha_role - ecr = module.ecr_dsc.repository_name - function = "" - } - ) - description = "Full contents of the stage-build.yml for the dsc repo" -} - -# Outputs after promotion to prod -output "dsc_fargate_prod_promote_workflow" { - value = var.environment == "stage" || var.environment == "dev" ? null : templatefile("${path.module}/files/prod-promote-cpu-arch.tpl", { - region = var.aws_region - role_stage = "${module.ecr_dsc.repo_name}-gha-stage" - role_prod = "${module.ecr_dsc.repo_name}-gha-prod" - ecr_stage = "${module.ecr_dsc.repo_name}-stage" - ecr_prod = "${module.ecr_dsc.repo_name}-prod" - function = "" - } - ) - description = "Full contents of the prod-promote.yml for the dsc repo" -} diff --git a/dso_ecrs.tf b/dso_ecrs.tf new file mode 100644 index 0000000..8079bed --- /dev/null +++ b/dso_ecrs.tf @@ -0,0 +1,141 @@ +# Containers related to DSpace Orchestrator + +############################################################################## +# DSpace Submission Composer (dsc) containers +# This is a standard ECR for an ECS with a Fargate launch type +locals { + ecr_dsc = "dsc-${var.environment}" +} + +module "ecr_dsc" { + source = "./modules/ecr" + repo_name = "dspace-submission-composer" + login_policy_arn = aws_iam_policy.login.arn + oidc_arn = data.aws_ssm_parameter.oidc_arn.value + environment = var.environment + tfoutput_ssm_path = var.tfoutput_ssm_path + tags = { + app-repo = "dspace-submission-composer" + } +} + +## Outputs to Terraform Cloud for devs ## + +## For dsc application repo and ECR repository +# Outputs in dev +output "dsc_fargate_dev_build_workflow" { + value = var.environment == "prod" || var.environment == "stage" ? null : templatefile("${path.module}/files/dev-build-cpu-arch.tpl", { + region = var.aws_region + role = module.ecr_dsc.gha_role + ecr = module.ecr_dsc.repository_name + function = "" + } + ) + description = "Full contents of the dev-build.yml for the dsc repo" +} +output "dsc_fargate_makefile" { + value = var.environment == "prod" || var.environment == "stage" ? null : templatefile("${path.module}/files/makefile-cpu-arch.tpl", { + ecr_name = module.ecr_dsc.repository_name + ecr_url = module.ecr_dsc.repository_url + function = "" + } + ) + description = "Full contents of the Makefile for the dsc repo (allows devs to push to Dev account only)" +} + +# Outputs in stage +output "dsc_fargate_stage_build_workflow" { + value = var.environment == "prod" || var.environment == "dev" ? null : templatefile("${path.module}/files/stage-build-cpu-arch.tpl", { + region = var.aws_region + role = module.ecr_dsc.gha_role + ecr = module.ecr_dsc.repository_name + function = "" + } + ) + description = "Full contents of the stage-build.yml for the dsc repo" +} + +# Outputs after promotion to prod +output "dsc_fargate_prod_promote_workflow" { + value = var.environment == "stage" || var.environment == "dev" ? null : templatefile("${path.module}/files/prod-promote-cpu-arch.tpl", { + region = var.aws_region + role_stage = "${module.ecr_dsc.repo_name}-gha-stage" + role_prod = "${module.ecr_dsc.repo_name}-gha-prod" + ecr_stage = "${module.ecr_dsc.repo_name}-stage" + ecr_prod = "${module.ecr_dsc.repo_name}-prod" + function = "" + } + ) + description = "Full contents of the prod-promote.yml for the dsc repo" +} + + +############################################################################## +# DSpace Submission Service (dss) containers +# This is a standard ECR for an ECS with a Fargate launch type + +locals { + ecr_dss = "dspace-submission-service-${var.environment}" +} + +module "ecr_dss" { + source = "./modules/ecr" + repo_name = "dspace-submission-service" + login_policy_arn = aws_iam_policy.login.arn + oidc_arn = data.aws_ssm_parameter.oidc_arn.value + environment = var.environment + tfoutput_ssm_path = var.tfoutput_ssm_path + tags = { + app-repo = "dspace-submission-service" + } +} + +## Outputs to Terraform Cloud for devs ## + +## For dss application repo and ECR repository +# Outputs in dev +output "dss_fargate_dev_build_workflow" { + value = var.environment == "prod" || var.environment == "stage" ? null : templatefile("${path.module}/files/dev-build-cpu-arch.tpl", { + region = var.aws_region + role = module.ecr_dss.gha_role + ecr = module.ecr_dss.repository_name + function = "" + } + ) + description = "Full contents of the dev-build.yml for the dss repo" +} +output "dss_fargate_makefile" { + value = var.environment == "prod" || var.environment == "stage" ? null : templatefile("${path.module}/files/makefile-cpu-arch.tpl", { + ecr_name = module.ecr_dss.repository_name + ecr_url = module.ecr_dss.repository_url + function = "" + } + ) + description = "Full contents of the Makefile for the dss repo (allows devs to push to Dev account only)" +} + +# Outputs in stage +output "dss_fargate_stage_build_workflow" { + value = var.environment == "prod" || var.environment == "dev" ? null : templatefile("${path.module}/files/stage-build-cpu-arch.tpl", { + region = var.aws_region + role = module.ecr_dss.gha_role + ecr = module.ecr_dss.repository_name + function = "" + } + ) + description = "Full contents of the stage-build.yml for the dss repo" +} + +# Outputs after promotion to prod +output "dss_fargate_prod_promote_workflow" { + value = var.environment == "stage" || var.environment == "dev" ? null : templatefile("${path.module}/files/prod-promote-cpu-arch.tpl", { + region = var.aws_region + role_stage = "${module.ecr_dss.repo_name}-gha-stage" + role_prod = "${module.ecr_dss.repo_name}-gha-prod" + ecr_stage = "${module.ecr_dss.repo_name}-stage" + ecr_prod = "${module.ecr_dss.repo_name}-prod" + function = "" + } + ) + description = "Full contents of the prod-promote.yml for the dss repo" +} diff --git a/dss_ecr.tf b/dss_ecr.tf deleted file mode 100644 index 0592cdd..0000000 --- a/dss_ecr.tf +++ /dev/null @@ -1,68 +0,0 @@ -# DSpace Submission Service (dss) containers -# This is a standard ECR for an ECS with a Fargate launch type - -locals { - ecr_dss = "dspace-submission-service-${var.environment}" -} - -module "ecr_dss" { - source = "./modules/ecr" - repo_name = "dspace-submission-service" - login_policy_arn = aws_iam_policy.login.arn - oidc_arn = data.aws_ssm_parameter.oidc_arn.value - environment = var.environment - tfoutput_ssm_path = var.tfoutput_ssm_path - tags = { - app-repo = "dspace-submission-service" - } -} - -## Outputs to Terraform Cloud for devs ## - -## For dss application repo and ECR repository -# Outputs in dev -output "dss_fargate_dev_build_workflow" { - value = var.environment == "prod" || var.environment == "stage" ? null : templatefile("${path.module}/files/dev-build-cpu-arch.tpl", { - region = var.aws_region - role = module.ecr_dss.gha_role - ecr = module.ecr_dss.repository_name - function = "" - } - ) - description = "Full contents of the dev-build.yml for the dss repo" -} -output "dss_fargate_makefile" { - value = var.environment == "prod" || var.environment == "stage" ? null : templatefile("${path.module}/files/makefile-cpu-arch.tpl", { - ecr_name = module.ecr_dss.repository_name - ecr_url = module.ecr_dss.repository_url - function = "" - } - ) - description = "Full contents of the Makefile for the dss repo (allows devs to push to Dev account only)" -} - -# Outputs in stage -output "dss_fargate_stage_build_workflow" { - value = var.environment == "prod" || var.environment == "dev" ? null : templatefile("${path.module}/files/stage-build-cpu-arch.tpl", { - region = var.aws_region - role = module.ecr_dss.gha_role - ecr = module.ecr_dss.repository_name - function = "" - } - ) - description = "Full contents of the stage-build.yml for the dss repo" -} - -# Outputs after promotion to prod -output "dss_fargate_prod_promote_workflow" { - value = var.environment == "stage" || var.environment == "dev" ? null : templatefile("${path.module}/files/prod-promote-cpu-arch.tpl", { - region = var.aws_region - role_stage = "${module.ecr_dss.repo_name}-gha-stage" - role_prod = "${module.ecr_dss.repo_name}-gha-prod" - ecr_stage = "${module.ecr_dss.repo_name}-stage" - ecr_prod = "${module.ecr_dss.repo_name}-prod" - function = "" - } - ) - description = "Full contents of the prod-promote.yml for the dss repo" -} diff --git a/modules/ecr/README.md b/modules/ecr/README.md index aabf935..24cc56e 100644 --- a/modules/ecr/README.md +++ b/modules/ecr/README.md @@ -16,8 +16,8 @@ The following resources are generated when this module is called | Name | Version | |------|---------| -| terraform | ~> 1.11 | -| aws | ~> 5.0 | +| terraform | ~> 1.14 | +| aws | ~> 6.0 | ## Providers diff --git a/modules/ecr/ecr.tf b/modules/ecr/ecr.tf index d42e78d..1baba11 100644 --- a/modules/ecr/ecr.tf +++ b/modules/ecr/ecr.tf @@ -40,7 +40,7 @@ resource "aws_ecr_lifecycle_policy" "this" { data "aws_iam_policy_document" "rw_this" { #checkov:skip=CKV_AWS_111:This policy needs unconstrained CreateRepository privileges #checkov:skip=CKV_AWS_356:This policy should allow "*" as a resource for restrictable actions - count = data.aws_region.current.name == "us-east-1" ? 1 : 0 + count = data.aws_region.current.region == "us-east-1" ? 1 : 0 statement { actions = [ "ecr:CreateRepository", @@ -75,7 +75,7 @@ data "aws_iam_policy_document" "rw_this" { } resource "aws_iam_policy" "rw_this" { - count = data.aws_region.current.name == "us-east-1" ? 1 : 0 + count = data.aws_region.current.region == "us-east-1" ? 1 : 0 name = "${var.repo_name}-ecr-rw-${var.environment}" description = "policy to allow read/write into ${var.repo_name} ECR" policy = data.aws_iam_policy_document.rw_this[0].json @@ -86,7 +86,7 @@ resource "aws_iam_policy" "rw_this" { # The trust policy that allows GitHub Actions OIDC-based connections from the # repository. The definition is explicitly linked to the name of the GitHub repo. data "aws_iam_policy_document" "gh_trust" { - count = data.aws_region.current.name == "us-east-1" ? 1 : 0 + count = data.aws_region.current.region == "us-east-1" ? 1 : 0 statement { actions = ["sts:AssumeRoleWithWebIdentity"] principals { @@ -108,7 +108,7 @@ data "aws_iam_policy_document" "gh_trust" { # Role for GitHub Action OIDC connections from the lambdas repository resource "aws_iam_role" "gha_this" { - count = data.aws_region.current.name == "us-east-1" ? 1 : 0 + count = data.aws_region.current.region == "us-east-1" ? 1 : 0 name = "${var.repo_name}-gha-${var.environment}" assume_role_policy = data.aws_iam_policy_document.gh_trust[0].json @@ -116,12 +116,12 @@ resource "aws_iam_role" "gha_this" { } resource "aws_iam_role_policy_attachment" "gha_ecr_rw" { - count = data.aws_region.current.name == "us-east-1" ? 1 : 0 + count = data.aws_region.current.region == "us-east-1" ? 1 : 0 role = aws_iam_role.gha_this[0].name policy_arn = aws_iam_policy.rw_this[0].arn } resource "aws_iam_role_policy_attachment" "gha_ecr_login" { - count = data.aws_region.current.name == "us-east-1" ? 1 : 0 + count = data.aws_region.current.region == "us-east-1" ? 1 : 0 role = aws_iam_role.gha_this[0].name policy_arn = var.login_policy_arn } diff --git a/modules/ecr/outputs.tf b/modules/ecr/outputs.tf index af80e2b..5f9380e 100644 --- a/modules/ecr/outputs.tf +++ b/modules/ecr/outputs.tf @@ -17,7 +17,7 @@ output "repository_url" { # ecr role so that we can add the updatefunctioncode to it after the lambda itself is created output "gha_role" { description = "Github action role used to update the ECR repository" - value = data.aws_region.current.name == "us-east-1" ? aws_iam_role.gha_this[0].name : null + value = data.aws_region.current.region == "us-east-1" ? aws_iam_role.gha_this[0].name : null sensitive = false } diff --git a/modules/ecr/ssm_outputs.tf b/modules/ecr/ssm_outputs.tf index f44f8c5..f12af22 100644 --- a/modules/ecr/ssm_outputs.tf +++ b/modules/ecr/ssm_outputs.tf @@ -29,7 +29,7 @@ resource "aws_ssm_parameter" "ecr_repository_url" { resource "aws_ssm_parameter" "gha_role" { #checkov:skip=CKV_AWS_337:By default we are not encrypting parameters in tfoutput_ssm_path #checkov:skip=CKV2_AWS_34:By default we are not encrypting parameters in tfoutput_ssm_path - count = data.aws_region.current.name == "us-east-1" ? 1 : 0 + count = data.aws_region.current.region == "us-east-1" ? 1 : 0 type = "String" name = "${var.tfoutput_ssm_path}/${var.repo_name}/gha-role" value = aws_iam_role.gha_this[0].name diff --git a/modules/ecr/versions.tf b/modules/ecr/versions.tf index 29dd2e1..bfea29d 100644 --- a/modules/ecr/versions.tf +++ b/modules/ecr/versions.tf @@ -3,12 +3,12 @@ # Providers themselves are set in the `providers.tf` file. terraform { - required_version = "~> 1.11" + required_version = "~> 1.14" required_providers { aws = { source = "hashicorp/aws" - version = "~> 5.0" + version = "~> 6.0" } } } diff --git a/quepid_ecr.tf b/quepid_ecr.tf new file mode 100644 index 0000000..4ec195a --- /dev/null +++ b/quepid_ecr.tf @@ -0,0 +1,70 @@ +# For the MITL fork of the quepid application + + +# quepid containers +# This is a standard ECR for an ECS with a Fargate launch type +locals { + ecr_quepid = "quepid-${var.environment}" +} +module "ecr_quepid" { + source = "./modules/ecr" + repo_name = "quepid" + login_policy_arn = aws_iam_policy.login.arn + oidc_arn = data.aws_ssm_parameter.oidc_arn.value + environment = var.environment + tfoutput_ssm_path = var.tfoutput_ssm_path + tags = { + app-repo = "quepid" + } +} + + +## Outputs to Terraform Cloud for devs ## + +## For quepid application repo and ECR repository +# Outputs in dev +output "quepid_fargate_dev_build_workflow" { + value = var.environment == "prod" || var.environment == "stage" ? null : templatefile("${path.module}/files/dev-build-cpu-arch.tpl", { + region = var.aws_region + role = module.ecr_quepid.gha_role + ecr = module.ecr_quepid.repository_name + function = "" + } + ) + description = "Full contents of the dev-build.yml for the quepid repo" +} +output "quepid_fargate_makefile" { + value = var.environment == "prod" || var.environment == "stage" ? null : templatefile("${path.module}/files/makefile-cpu-arch.tpl", { + ecr_name = module.ecr_quepid.repository_name + ecr_url = module.ecr_quepid.repository_url + function = "" + } + ) + description = "Full contents of the Makefile for the quepid repo (allows devs to push to Dev account only)" +} + +# Outputs in stage +output "quepid_fargate_stage_build_workflow" { + value = var.environment == "prod" || var.environment == "dev" ? null : templatefile("${path.module}/files/stage-build-cpu-arch.tpl", { + region = var.aws_region + role = module.ecr_quepid.gha_role + ecr = module.ecr_quepid.repository_name + function = "" + } + ) + description = "Full contents of the stage-build.yml for the quepid repo" +} + +# Outputs after promotion to prod +output "quepid_fargate_prod_promote_workflow" { + value = var.environment == "stage" || var.environment == "dev" ? null : templatefile("${path.module}/files/prod-promote-cpu-arch.tpl", { + region = var.aws_region + role_stage = "${module.ecr_quepid.repo_name}-gha-stage" + role_prod = "${module.ecr_quepid.repo_name}-gha-prod" + ecr_stage = "${module.ecr_quepid.repo_name}-stage" + ecr_prod = "${module.ecr_quepid.repo_name}-prod" + function = "" + } + ) + description = "Full contents of the prod-promote.yml for the quepid repo" +} diff --git a/timdex_ecrs.tf b/timdex_ecrs.tf index 8274709..c447414 100644 --- a/timdex_ecrs.tf +++ b/timdex_ecrs.tf @@ -2,6 +2,8 @@ ### Timdex related ECR's ### + +############################################################################## ## oaiharvester # oaiharvester ECR repo module "ecr_oaiharvester" { @@ -63,6 +65,7 @@ output "oaiharvester_prod_promote_workflow" { } +############################################################################## ## transmogrifier # transmogrifier ECR repository module "ecr_timdex_transmogrifier" { @@ -121,7 +124,7 @@ output "transmogrifier_prod_promote_workflow" { description = "Full contents of the prod-promote.yml for the transmogrifier repo" } - +############################################################################## ## timdex-pipeline-lambdas # Since this is a Lambda function, we need to set the function name now in order to build the correct files. locals { @@ -186,6 +189,7 @@ output "timdex_lambdas_prod_promote_workflow" { } +############################################################################## ## timdex-index-manager # timdex-index-manager ECR repository module "ecr_timdex_tim" { @@ -245,6 +249,7 @@ output "tim_prod_promote_workflow" { } +############################################################################## ## browsertrix-harvester # browsertrix-harvester ECR repository module "ecr_timdex_browsertrix" { @@ -308,6 +313,7 @@ output "browsertrix_prod_promote_workflow" { } +############################################################################## ## geo-harvester # geo-harvester ECR repository module "ecr_timdex_geo" { @@ -367,6 +373,7 @@ output "geo_prod_promote_workflow" { } +############################################################################## # timdex-embeddings containers # This is a standard ECR for an ECS with a Fargate launch type module "ecr_timdex_embeddings" { @@ -430,3 +437,68 @@ output "timdex_embeddings_fargate_prod_promote_workflow" { ) description = "Full contents of the prod-promote.yml for the timdex-embeddings repo" } + + +############################################################################## +# timdex-semantic-builder +# Since this is a Lambda function, we need to set the function name now in order to build the correct files. +locals { + ecr_timdex_semantic_builder_function_name = "timdex-semantic-builder-${var.environment}" +} +module "ecr_timdex_semantic_builder" { + source = "./modules/ecr" + repo_name = "timdex-semantic-builder" + login_policy_arn = aws_iam_policy.login.arn + oidc_arn = data.aws_ssm_parameter.oidc_arn.value + environment = var.environment + tfoutput_ssm_path = var.tfoutput_ssm_path + tags = { + app-repo = "timdex-infrastructure-timdex-semantic-builder" + } +} +# Outputs in dev +output "timdex_semantic_builder_lambda_dev_build_workflow" { + value = var.environment == "prod" || var.environment == "stage" ? null : templatefile("${path.module}/files/dev-build-cpu-arch.tpl", { + region = var.aws_region + role = module.ecr_timdex_semantic_builder.gha_role + ecr = module.ecr_timdex_semantic_builder.repository_name + function = local.ecr_timdex_semantic_builder_function_name + } + ) + description = "Full contents of the dev-build.yml for the timdex-semantic-builder repo" +} +output "timdex_semantic_builder_lambda_makefile" { + value = var.environment == "prod" || var.environment == "stage" ? null : templatefile("${path.module}/files/makefile-cpu-arch.tpl", { + ecr_name = module.ecr_timdex_semantic_builder.repository_name + ecr_url = module.ecr_timdex_semantic_builder.repository_url + function = local.ecr_timdex_semantic_builder_function_name + } + ) + description = "Full contents of the Makefile for the timdex-semantic-builder repo (allows devs to push to Dev account only)" +} + +# Outputs in stage +output "timdex_semantic_builder_lambda_stage_build_workflow" { + value = var.environment == "prod" || var.environment == "dev" ? null : templatefile("${path.module}/files/stage-build-cpu-arch.tpl", { + region = var.aws_region + role = module.ecr_timdex_semantic_builder.gha_role + ecr = module.ecr_timdex_semantic_builder.repository_name + function = local.ecr_timdex_semantic_builder_function_name + } + ) + description = "Full contents of the stage-build.yml for the timdex-semantic-builder repo" +} + +# Outputs after promotion to prod +output "timdex_semantic_builder_lambda_prod_promote_workflow" { + value = var.environment == "stage" || var.environment == "dev" ? null : templatefile("${path.module}/files/prod-promote-cpu-arch.tpl", { + region = var.aws_region + role_stage = "${module.ecr_timdex_semantic_builder.repo_name}-gha-stage" + role_prod = "${module.ecr_timdex_semantic_builder.repo_name}-gha-prod" + ecr_stage = "${module.ecr_timdex_semantic_builder.repo_name}-stage" + ecr_prod = "${module.ecr_timdex_semantic_builder.repo_name}-prod" + function = local.ecr_timdex_semantic_builder_function_name + } + ) + description = "Full contents of the prod-promote.yml for the timdex-semantic-builder repo" +} diff --git a/versions.tf b/versions.tf index bb54315..bfea29d 100644 --- a/versions.tf +++ b/versions.tf @@ -8,7 +8,7 @@ terraform { required_providers { aws = { source = "hashicorp/aws" - version = "~> 5.0" + version = "~> 6.0" } } }