Skip to main content

4. Extras | Modules

This document briefly discusses the various modules defined in the Terraform code.

cloudfunction​

The module sets up the Cloud Function that calls the webhook notifying the GitHub Actions that a new image has been published on the Artifact Registry. The function itself is defined in infrastructure/functions directory.

Inputs:

  • run_images: List of images that are to be tracked. These have to be passed with tags, so you can pass the images from the configurations stored in app/config/<env>.tfvars.json.
  • github_settings: Some GitHub config to define how the webhook will be published and the authorization for it to do so.

Outputs: none.

cloudrun​

This module defines the running Cloud Run instances. It does not store environment variables, the current running image, etc.

Inputs:

  • serilog_envs: List of environment variables passed as Serilog configuration.
  • run_images: List of images to be deployed on each Cloud Run instance. Format is demonstrated in app/config/<env>.tfvars.json.
  • run_instance_environment_variables: Environment variables passed to each Cloud Run instances, grouped by the Run instance they are passed to. Format is demonstrated in infrastructure/environments/<env>/terraform.tfvars.json.
  • run_instance_secrets: Secrets passed to each Cloud Run instance. Format similar to run_instance_environment_variables, but there is additionally a common group that is passed to all instances accepting secrets.
  • access_connector_ids: IDs of serverless access connectors. Pass the identically named output of the VPC module.

Outputs:

  • run_urls: Map of URLs of Run instances.

google_apis​

Initialises the APIs used for the project.

Inputs: none.

Outputs: none.

pubsub​

Sets up the PubSub topics and subscriptions for various Cloud Run instances.

Inputs:

  • run_urls: Map of URLs of Run instances. Pass identically named output from the Cloud Run module.

Outputs:

  • topic_ids: Map of IDs of created topics.

secret_manager​

Loads secrets stored on Google Secret Manager for the use of other infrastructure.

Inputs: none.

Outputs:

  • run_instance_secrets: Map of maps of secrets for each Cloud Run instance. Format similar to run_instance_environment_variables, demonstrated in infrastructure/environments/<env>/terraform.tfvars.json. List of groups can be found in local.secrets_list defined in the same module.

vpc_network​

Sets up the entire network infrastructure, including VPC nets, subnets, firewalls, static IPs, serverless access connectors and routers.

Inputs: none.

Outputs:

  • access_connector_ids: List of IDs of serverless access connectors.
  • static_addresses: List of static external IP addresses.
  • network_ids: List of IDs of VPC networks.

database​

Imported current database from acceptance environment

Note: need to match the import from production too so that it doesn’t change a single field and try to destroy it

Inputs:

  • ip_whitelist: List of IP addresses to allow to connect to the database outside google cloud

Outputs: none