diff --git a/.gitignore b/.gitignore index a7e2e29..11d9d52 100644 --- a/.gitignore +++ b/.gitignore @@ -40,3 +40,8 @@ # Ignore vim swapfiles *.swo *.swp + +# Terraform +.terraform* +*.hcl +*.tfstate diff --git a/Dockerfile b/Dockerfile index 83700bd..d28024d 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM phusion/passenger-ruby33 AS production # Set correct environment variables. -ENV HOME /root +ENV HOME=/root # Use baseimage-docker's init process. RUN mkdir -p /etc/my_init.d @@ -27,7 +27,8 @@ WORKDIR /home/app/scsbuster COPY Gemfile /home/app/scsbuster COPY Gemfile.lock /home/app/scsbuster RUN gem update --system -RUN bundle install --without test development +RUN bundle config set without 'test development' +RUN bundle install RUN RAILS_ENV=production bundle exec rake assets:precompile RUN chown -R app:app /home/app/scsbuster/tmp/cache diff --git a/README.md b/README.md index f14a3af..7779bb4 100644 --- a/README.md +++ b/README.md @@ -57,3 +57,13 @@ Our branches (in order of stability are): Merging `feature_branch` => `qa` automatically deploys to the qa environment. Merging `qa` => `production` automatically deploys to the production environment. After a release, please backmerge production to qa with a PR. + +### Terraform + +Most AWS infrastructure for SCSBuster is managed by the DevOps team through their Terraform configurations and state. + +This repository contains a limited Terraform configuration used to manage application-specific monitoring resources owned by the Research Catalog team, +found in the `terraform/` directory. + +Changes to application alarms should be made through this Terraform configuration. If changes to other core AWS infrastructure (ECS configuration, +load balancing, etc.) are necessary, DevOps must update their Terraform. diff --git a/terraform/base/alarms.tf b/terraform/base/alarms.tf new file mode 100644 index 0000000..f835750 --- /dev/null +++ b/terraform/base/alarms.tf @@ -0,0 +1,6 @@ +/* +DevOps covers these metric alarms for the production and qa environments: +scsbuster-{env}-tf_cpu +scsbuster-{env}-tf_memory +scsbuster-{env}-tf_alb500_scale_up +*/ diff --git a/terraform/base/resources.tf b/terraform/base/resources.tf new file mode 100644 index 0000000..6940b6d --- /dev/null +++ b/terraform/base/resources.tf @@ -0,0 +1,18 @@ +locals { + tags = { + Project = "SCSBuster" + BusinessUnit = "LSP" + Environment = var.environment + } +} + +variable "environment" { + type = string + default = "qa" + description = "The name of the environment (qa, production). This controls the env vars loaded." + + validation { + condition = contains(["qa", "production"], var.environment) + error_message = "The environment must be 'qa' or 'production'." + } +} diff --git a/terraform/production/alarms.tf b/terraform/production/alarms.tf new file mode 100644 index 0000000..671f833 --- /dev/null +++ b/terraform/production/alarms.tf @@ -0,0 +1,37 @@ +data "aws_sns_topic" "rc_alarms" { + name = "research-catalog-team-alarms-production" +} + +resource "aws_cloudwatch_log_metric_filter" "log_error" { + name = "SCSBusterLogError" + pattern = "{ $.level = \"FATAL\" }" + log_group_name = "/ecs/scsbuster-production-tf" + + metric_transformation { + name = "SCSBusterLogError" + namespace = "LogMetrics" + value = "1" + } +} + +resource "aws_cloudwatch_metric_alarm" "log_error_alarm" { + alarm_name = "SCSBusterLogErrorAlarm" + + alarm_description = "Triggered when there's 1 or more fatal error log to SCSBuster within 5 minutes." + + namespace = "LogMetrics" + metric_name = "SCSBusterLogError" + + statistic = "Sum" + + period = 300 + evaluation_periods = 1 + threshold = 1 + comparison_operator = "GreaterThanOrEqualToThreshold" + + datapoints_to_alarm = 1 + + treat_missing_data = "notBreaching" + + alarm_actions = [data.aws_sns_topic.rc_alarms.arn] +} diff --git a/terraform/production/resources.tf b/terraform/production/resources.tf new file mode 100644 index 0000000..97c6c9d --- /dev/null +++ b/terraform/production/resources.tf @@ -0,0 +1,18 @@ +provider "aws" { + region = "us-east-1" +} + +terraform { + # Use s3 to store terraform state + backend "s3" { + bucket = "nypl-github-actions-builds-production" + key = "scsbuster-terraform-state" + region = "us-east-1" + } +} + +module "base" { + source = "../base" + + environment = "production" +}