-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathcharts.tf
106 lines (84 loc) · 2.45 KB
/
charts.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
# ---------------------------------------------------------------------------------------------------------------------
# DEPLOY A SAMPLE CHART
# A chart repository is a location where packaged charts can be stored and shared. Define Bitnami Helm repository location,
# so Helm can install the nginx chart.
#
# We also install sysdig, gremlind, and opa gatekeeper
# ---------------------------------------------------------------------------------------------------------------------
#resource "helm_release" "_name_" {
# depends_on = [google_container_node_pool.node_pool]
#
# repository = "https://_repo_"
# name = "_name_"
# chart = "_name_"
# create_namespace = true
# namespace = "_namespace_"
#}
# Prevents misconfig and acts as a security tool plus IAM
resource "helm_release" "gatekeeper" {
depends_on = [google_container_node_pool.node_pool]
repository = "https://open-policy-agent.github.io/gatekeeper/charts"
name = "gatekeeper"
chart = "gatekeeper/gatekeeper"
namespace = "gatekeeper-system"
#create_namespace = true
}
resource "helm_release" "sysdig" {
depends_on = [google_container_node_pool.node_pool]
repository = "https://charts.sysdig.com/"
name = "sysdig"
chart = "sysdig"
namespace = "sysdig-agent"
#create_namespace = true
set {
name = "sysdig.accessKey"
value = var.sysdig_accessKey
}
set {
name = "sysdig.settings.collector"
value = var.sysdig_collector
}
set {
name = "sysdig.settings.collector_port"
value = var.sysdig_collector_port
}
set {
name = "nodeAnalyzer.apiEndpoint"
value = var.sysdig_collector
}
}
## Chaos Agent
resource "helm_release" "gremlind" {
depends_on = [google_container_node_pool.node_pool]
repository = "https://helm.gremlin.com"
name = "gremlin"
chart = "gremlin/gremlin"
namespace = "gremlin"
#create_namespace = true
set {
name = "gremlin.secret.managed"
value = "true"
}
set {
name = "gremlin.secret.type"
value = "secret"
}
set {
name = "gremlin.secret.teamID"
value = var.gremlin_teamID
}
set {
name = "gremlin.secret.clusterID"
value = var.gremlin_clusterID
}
set {
name = "gremlin.secret.teamSecret"
value = var.gremlin_teamSecret
}
}
resource "helm_release" "nginx" {
depends_on = [google_container_node_pool.node_pool]
repository = "https://charts.bitnami.com/bitnami"
name = "nginx"
chart = "nginx"
}