4. Extras | Modules
This document briefly discusses the various modules defined in the Terraform code.
cloudfunction
The module sets up the Cloud Function that calls the webhook notifying the GitHub Actions that a new image has been published on the Artifact Registry. The function itself is defined in infrastructure/functions directory.
Inputs:
run_images: List of images that are to be tracked. These have to be passed with tags, so you can pass the images from the configurations stored inapp/config/<env>.tfvars.json.github_settings: Some GitHub config to define how the webhook will be published and the authorization for it to do so.
Outputs: none.
cloudrun
This module defines the running Cloud Run instances. It does not store environment variables, the current running image, etc.
Inputs:
serilog_envs: List of environment variables passed as Serilog configuration.run_images: List of images to be deployed on each Cloud Run instance. Format is demonstrated inapp/config/<env>.tfvars.json.run_instance_environment_variables: Environment variables passed to each Cloud Run instances, grouped by the Run instance they are passed to. Format is demonstrated ininfrastructure/environments/<env>/terraform.tfvars.json.run_instance_secrets: Secrets passed to each Cloud Run instance. Format similar torun_instance_environment_variables, but there is additionally acommongroup that is passed to all instances accepting secrets.access_connector_ids: IDs of serverless access connectors. Pass the identically named output of the VPC module.
Outputs:
run_urls: Map of URLs of Run instances.
google_apis
Initialises the APIs used for the project.
Inputs: none.
Outputs: none.
pubsub
Sets up the PubSub topics and subscriptions for various Cloud Run instances.
Inputs:
run_urls: Map of URLs of Run instances. Pass identically named output from the Cloud Run module.
Outputs:
topic_ids: Map of IDs of created topics.
secret_manager
Loads secrets stored on Google Secret Manager for the use of other infrastructure.
Inputs: none.
Outputs:
run_instance_secrets: Map of maps of secrets for each Cloud Run instance. Format similar torun_instance_environment_variables, demonstrated ininfrastructure/environments/<env>/terraform.tfvars.json. List of groups can be found inlocal.secrets_listdefined in the same module.
vpc_network
Sets up the entire network infrastructure, including VPC nets, subnets, firewalls, static IPs, serverless access connectors and routers.
Inputs: none.
Outputs:
access_connector_ids: List of IDs of serverless access connectors.static_addresses: List of static external IP addresses.network_ids: List of IDs of VPC networks.
database
Imported current database from acceptance environment
Note: need to match the import from production too so that it doesn’t change a single field and try to destroy it
Inputs:
ip_whitelist: List of IP addresses to allow to connect to the database outside google cloud
Outputs: none