Skip to content

Commit

Permalink
Merge branch 'master' into master
Browse files Browse the repository at this point in the history
  • Loading branch information
prudnitskiy committed Nov 13, 2023
2 parents 8425f4a + a9de2d7 commit f7ef150
Show file tree
Hide file tree
Showing 8 changed files with 83 additions and 11 deletions.
4 changes: 3 additions & 1 deletion modules/asm/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ module "asm" {
```

Note that the [`mesh_id` label on the cluster](https://cloud.google.com/service-mesh/docs/managed/auto-control-plane-with-fleet#apply_the_mesh_id_label) is required for metrics to get displayed on the Anthos Service Mesh pages in the Cloud console (Topology, etc.). Illustrated with the full example mentioned above, here is an example of what your cluster should have:

```tf
module "gke" {
...
Expand All @@ -58,9 +59,10 @@ To deploy this config:
| enable\_cni | Determines whether to enable CNI for this ASM installation. Required to use Managed Data Plane (MDP). | `bool` | `false` | no |
| enable\_fleet\_registration | Determines whether the module registers the cluster to the fleet. | `bool` | `false` | no |
| enable\_mesh\_feature | Determines whether the module enables the mesh feature on the fleet. | `bool` | `false` | no |
| enable\_vpc\_sc | Determines whether to enable VPC-SC for this ASM installation. For more information read https://cloud.google.com/service-mesh/docs/managed/vpc-sc | `bool` | `false` | no |
| enable\_vpc\_sc | Determines whether to enable VPC-SC for this ASM installation. For more information read [VPC Service Controls for Managed Anthos Service Mesh](https://cloud.google.com/service-mesh/docs/managed/vpc-sc) | `bool` | `false` | no |
| fleet\_id | The fleet to use for this ASM installation. | `string` | `""` | no |
| internal\_ip | Use internal ip for the cluster endpoint when running kubectl commands. | `bool` | `false` | no |
| mesh\_management | ASM Management mode. For more information, see the [gke\_hub\_feature\_membership resource documentation](https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/gke_hub_feature_membership#nested_mesh) | `string` | `""` | no |
| module\_depends\_on | List of modules or resources this module depends on. If multiple, all items must be the same type. | `list(any)` | `[]` | no |
| multicluster\_mode | [Preview] Determines whether remote secrets should be autogenerated across fleet cluster. | `string` | `"manual"` | no |
| project\_id | The project in which the resource belongs. | `string` | n/a | yes |
Expand Down
12 changes: 12 additions & 0 deletions modules/asm/hub.tf
Original file line number Diff line number Diff line change
Expand Up @@ -33,3 +33,15 @@ resource "google_gke_hub_feature" "mesh" {
location = "global"
provider = google-beta
}

resource "google_gke_hub_feature_membership" "mesh_feature_membership" {
count = var.enable_fleet_registration && var.enable_mesh_feature && var.mesh_management != "" ? 1 : 0

location = "global"
feature = google_gke_hub_feature.mesh[0].name
membership = google_gke_hub_membership.membership[0].membership_id
mesh {
management = var.mesh_management
}
provider = google-beta
}
45 changes: 44 additions & 1 deletion modules/asm/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -34,14 +34,16 @@ data "google_container_cluster" "asm" {
}

resource "kubernetes_namespace" "system" {
count = var.create_system_namespace ? 1 : 0
count = var.create_system_namespace && var.mesh_management != "MANAGEMENT_AUTOMATIC" ? 1 : 0

metadata {
name = "istio-system"
}
}

resource "kubernetes_config_map" "asm_options" {
count = var.mesh_management != "MANAGEMENT_AUTOMATIC" ? 1 : 0

metadata {
name = "asm-options"
namespace = try(kubernetes_namespace.system[0].metadata[0].name, "istio-system")
Expand All @@ -56,6 +58,8 @@ resource "kubernetes_config_map" "asm_options" {
}

module "cpr" {
count = var.mesh_management != "MANAGEMENT_AUTOMATIC" ? 1 : 0

source = "terraform-google-modules/gcloud/google//modules/kubectl-wrapper"
version = "~> 3.1"

Expand All @@ -69,3 +73,42 @@ module "cpr" {

module_depends_on = [kubernetes_config_map.asm_options]
}

# Wait for the ControlPlaneRevision custom resource to be ready.
# Add an explicit "retry until the resource is created" until
module "kubectl_asm_wait_for_controlplanerevision_custom_resource_definition" {
count = var.mesh_management == "MANAGEMENT_AUTOMATIC" ? 1 : 0

source = "terraform-google-modules/gcloud/google//modules/kubectl-wrapper"
version = "~> 3.1"

project_id = var.project_id
cluster_name = var.cluster_name
cluster_location = var.cluster_location
kubectl_create_command = "/bin/sh -c 'while ! kubectl wait crd/controlplanerevisions.mesh.cloud.google.com --for condition=established --timeout=60m --all-namespaces; do echo \"crd/controlplanerevisions.mesh.cloud.google.com not yet available, waiting...\"; sleep 5; done'"
kubectl_destroy_command = ""

module_depends_on = [
google_gke_hub_feature_membership.mesh_feature_membership
]
}

# Wait for the ASM control plane revision to be ready so we can safely deploy resources that depend
# on ASM mutating webhooks.
# Add an explicit "retry until the resource is created" until
module "kubectl_asm_wait_for_controlplanerevision" {
count = var.mesh_management == "MANAGEMENT_AUTOMATIC" ? 1 : 0

source = "terraform-google-modules/gcloud/google//modules/kubectl-wrapper"
version = "~> 3.1"

project_id = var.project_id
cluster_name = var.cluster_name
cluster_location = var.cluster_location
kubectl_create_command = "/bin/sh -c 'while ! kubectl -n istio-system wait ControlPlaneRevision --all --timeout=60m --for condition=Reconciled; do echo \"ControlPlaneRevision not yet available, waiting...\"; sleep 5; done'"
kubectl_destroy_command = ""

module_depends_on = [
module.kubectl_asm_wait_for_controlplanerevision_custom_resource_definition[0].wait
]
}
2 changes: 1 addition & 1 deletion modules/asm/outputs.tf
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,6 @@ output "revision_name" {
}

output "wait" {
value = module.cpr.wait
value = var.mesh_management == "MANAGEMENT_AUTOMATIC" ? module.kubectl_asm_wait_for_controlplanerevision[0].wait : module.cpr[0].wait
description = "An output to use when depending on the ASM installation finishing."
}
17 changes: 16 additions & 1 deletion modules/asm/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,21 @@ variable "channel" {
default = ""
}

variable "mesh_management" {
default = ""
description = "ASM Management mode. For more information, see the [gke_hub_feature_membership resource documentation](https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/gke_hub_feature_membership#nested_mesh)"
type = string
validation {
condition = anytrue([
var.mesh_management == null,
var.mesh_management == "",
var.mesh_management == "MANAGEMENT_AUTOMATIC",
var.mesh_management == "MANAGEMENT_MANUAL",
])
error_message = "Must be null, empty, or one of MANAGEMENT_AUTOMATIC or MANAGEMENT_MANUAL."
}
}

variable "multicluster_mode" {
description = "[Preview] Determines whether remote secrets should be autogenerated across fleet cluster."
type = string
Expand All @@ -70,7 +85,7 @@ variable "enable_cni" {
}

variable "enable_vpc_sc" {
description = "Determines whether to enable VPC-SC for this ASM installation. For more information read https://cloud.google.com/service-mesh/docs/managed/vpc-sc"
description = "Determines whether to enable VPC-SC for this ASM installation. For more information read [VPC Service Controls for Managed Anthos Service Mesh](https://cloud.google.com/service-mesh/docs/managed/vpc-sc)"
type = bool
default = false
}
Expand Down
2 changes: 1 addition & 1 deletion modules/asm/versions.tf
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
*/

terraform {
required_version = ">= 0.14.0"
required_version = ">= 1.1"

required_providers {
kubernetes = {
Expand Down
4 changes: 2 additions & 2 deletions test/integration/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@ module github.com/terraform-google-modules/terraform-google-kubernetes-engine/te
go 1.20

require (
github.com/GoogleCloudPlatform/cloud-foundation-toolkit/infra/blueprint-test v0.9.2
github.com/gruntwork-io/terratest v0.46.1
github.com/GoogleCloudPlatform/cloud-foundation-toolkit/infra/blueprint-test v0.10.0
github.com/gruntwork-io/terratest v0.46.5
github.com/stretchr/testify v1.8.4
)

Expand Down
8 changes: 4 additions & 4 deletions test/integration/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -187,8 +187,8 @@ cloud.google.com/go/workflows v1.7.0/go.mod h1:JhSrZuVZWuiDfKEFxU0/F1PQjmpnpcoIS
dmitri.shuralyov.com/gpu/mtl v0.0.0-20190408044501-666a987793e9/go.mod h1:H6x//7gZCb22OMCxBHrMx7a5I7Hp++hsVxbQ4BYO7hU=
github.com/BurntSushi/toml v0.3.1/go.mod h1:xHWCNGjB5oqiDr8zfno3MHue2Ht5sIBksp03qcyfWMU=
github.com/BurntSushi/xgb v0.0.0-20160522181843-27f122750802/go.mod h1:IVnqGOEym/WlBOVXweHU+Q+/VP0lqqI8lqeDx9IjBqo=
github.com/GoogleCloudPlatform/cloud-foundation-toolkit/infra/blueprint-test v0.9.2 h1:7fdp02N9fd8itrSe/p7njaSKAUYJGgxn8ajgZfbFK+I=
github.com/GoogleCloudPlatform/cloud-foundation-toolkit/infra/blueprint-test v0.9.2/go.mod h1:yyde2qkA+GhCou8exSJwifnJlAcWCNcU1vs911CEOJg=
github.com/GoogleCloudPlatform/cloud-foundation-toolkit/infra/blueprint-test v0.10.0 h1:z3SfgfmUGWlmYPRl4YsEqyEexAYzPNos65401mppP+o=
github.com/GoogleCloudPlatform/cloud-foundation-toolkit/infra/blueprint-test v0.10.0/go.mod h1:yyde2qkA+GhCou8exSJwifnJlAcWCNcU1vs911CEOJg=
github.com/OneOfOne/xxhash v1.2.2/go.mod h1:HSdplMjZKSmBqAxg5vPj2TmRDmfkzw+cTzAElWljhcU=
github.com/agext/levenshtein v1.2.3 h1:YB2fHEn0UJagG8T1rrWknE3ZQzWM06O8AMAatNn7lmo=
github.com/agext/levenshtein v1.2.3/go.mod h1:JEDfjyjHDjOF/1e4FlBE/PkbqA9OfWu2ki2W0IB5558=
Expand Down Expand Up @@ -370,8 +370,8 @@ github.com/gorilla/websocket v1.4.2/go.mod h1:YR8l580nyteQvAITg2hZ9XVh4b55+EU/ad
github.com/grpc-ecosystem/grpc-gateway v1.16.0/go.mod h1:BDjrQk3hbvj6Nolgz8mAMFbcEtjT1g+wF4CSlocrBnw=
github.com/gruntwork-io/go-commons v0.17.1 h1:2KS9wAqrgeOTWj33DSHzDNJ1FCprptWdLFqej+wB8x0=
github.com/gruntwork-io/go-commons v0.17.1/go.mod h1:S98JcR7irPD1bcruSvnqupg+WSJEJ6xaM89fpUZVISk=
github.com/gruntwork-io/terratest v0.46.1 h1:dJ/y2/Li6yCDIc8KXY8PfydtrMRiXFb3UZm4LoPShPI=
github.com/gruntwork-io/terratest v0.46.1/go.mod h1:gl//tb5cLnbpQs1FTSNwhsrbhsoG00goCJPfOnyliiU=
github.com/gruntwork-io/terratest v0.46.5 h1:cmsIAKjM1Hqwy5tlZPb6EJQvaMCD4xRX1DN9fnTptBM=
github.com/gruntwork-io/terratest v0.46.5/go.mod h1:6gI5MlLeyF+SLwqocA5GBzcTix+XiuxCy1BPwKuT+WM=
github.com/hashicorp/errwrap v1.0.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
github.com/hashicorp/errwrap v1.1.0 h1:OxrOeh75EUXMY8TBjag2fzXGZ40LB6IKw45YeGUDY2I=
github.com/hashicorp/errwrap v1.1.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
Expand Down

0 comments on commit f7ef150

Please sign in to comment.