Skip to content
Merged
Show file tree
Hide file tree
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -40,3 +40,8 @@
# Ignore vim swapfiles
*.swo
*.swp

# Ignore Terraform log files
.terraform
*.tfstate
*.tfstate.*
5 changes: 3 additions & 2 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
FROM phusion/passenger-ruby33 AS production

# Set correct environment variables.
ENV HOME /root
ENV HOME=/root

# Use baseimage-docker's init process.
RUN mkdir -p /etc/my_init.d
Expand All @@ -27,7 +27,8 @@ WORKDIR /home/app/scsbuster
COPY Gemfile /home/app/scsbuster
COPY Gemfile.lock /home/app/scsbuster
RUN gem update --system
RUN bundle install --without test development
RUN bundle config set without 'test development'
RUN bundle install
RUN RAILS_ENV=production bundle exec rake assets:precompile
RUN chown -R app:app /home/app/scsbuster/tmp/cache

Expand Down
10 changes: 10 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,3 +57,13 @@ Our branches (in order of stability are):
Merging `feature_branch` => `qa` automatically deploys to the qa environment.
Merging `qa` => `production` automatically deploys to the production environment.
After a release, please backmerge production to qa with a PR.

### Terraform

Most AWS infrastructure for SCSBuster is managed by the DevOps team through their Terraform configurations and state.

This repository contains a limited Terraform configuration used to manage application-specific monitoring resources owned by the Research Catalog team,
found in the `terraform/` directory.

Changes to application alarms should be made through this Terraform configuration. If changes to other core AWS infrastructure (ECS configuration,
load balancing, etc.) are necessary, DevOps must update their Terraform.
6 changes: 6 additions & 0 deletions terraform/base/alarms.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
/*
DevOps covers these metric alarms for the production and qa environments:
scsbuster-{env}-tf_cpu
scsbuster-{env}-tf_memory
scsbuster-{env}-tf_alb500_scale_up
*/
18 changes: 18 additions & 0 deletions terraform/base/resources.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
locals {
tags = {
Project = "SCSBuster"
BusinessUnit = "LSP"
Environment = var.environment
}
}

variable "environment" {
type = string
default = "qa"
description = "The name of the environment (qa, production). This controls the env vars loaded."

validation {
condition = contains(["qa", "production"], var.environment)
error_message = "The environment must be 'qa' or 'production'."
}
}
25 changes: 25 additions & 0 deletions terraform/production/.terraform.lock.hcl

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

42 changes: 42 additions & 0 deletions terraform/production/alarms.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
import {
to = aws_cloudwatch_metric_alarm.scsbuster_error_alarm
id = "SCSBusterErrorAlarm"
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Neat. I was not previously aware of import blocks. This seems maybe better than the import command since it documents that this was previously managed outside of terraform and how we imported it (because I always have to look up the right terraform import command).


data "aws_sns_topic" "rc_alarms" {
name = "research-catalog-team-alarms-production"
}

resource "aws_cloudwatch_log_metric_filter" "scsbuster_error" {
name = "SCSBusterError"
pattern = "{ $.level = FATAL }"
log_group_name = "/ecs/scsbuster-production-tf"

metric_transformation {
name = "SCSBusterError"
namespace = "LogMetrics"
value = "1"
}
}

resource "aws_cloudwatch_metric_alarm" "scsbuster_error_alarm" {
alarm_name = "SCSBusterErrorAlarm"

alarm_description = "Triggered when there's 1 or more fatal error log to SCSBuster within 5 minutes."

namespace = "LogMetrics"
metric_name = "SCSBusterError"

statistic = "Sum"

period = 300
evaluation_periods = 1
threshold = 1
comparison_operator = "GreaterThanOrEqualToThreshold"

datapoints_to_alarm = 1

treat_missing_data = "notBreaching"

alarm_actions = [data.aws_sns_topic.rc_alarms.arn]
}
18 changes: 18 additions & 0 deletions terraform/production/resources.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
provider "aws" {
region = "us-east-1"
}

terraform {
# Use s3 to store terraform state
backend "s3" {
bucket = "nypl-github-actions-builds-production"
key = "scsbuster-terraform-state"
region = "us-east-1"
}
}

module "base" {
source = "../base"

environment = "production"
}
Loading