aboutsummaryrefslogtreecommitdiff
path: root/terraform/role/main.tf
blob: e85fd3bc3e7b381859728d4377c62f812e46fdc4 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
variable "host" {
  type = "string"
}

variable "id" {
  type = "string"
}

variable "roles" {
  type = "list"
}

variable "secret_cloudflare_token" {
  type = "string"
}

resource "tls_private_key" "private_key" {
  algorithm = "RSA"
}

resource "acme_registration" "reg" {
  account_key_pem = "${tls_private_key.private_key.private_key_pem}"
  email_address   = "jakob@odersky.com"
}

resource "acme_certificate" "certificate" {
  account_key_pem           = "${acme_registration.reg.account_key_pem}"
  common_name               = "${var.host}"
  subject_alternative_names = "${formatlist("%s.crashbox.io", var.roles)}"

  dns_challenge {
    provider = "cloudflare"

    config {
      CLOUDFLARE_EMAIL   = "jakob@odersky.com"
      CLOUDFLARE_API_KEY = "${var.secret_cloudflare_token}"
    }
  }
}

resource "cloudflare_record" "role_cname" {
  count = "${length(var.roles)}"

  domain = "crashbox.io"
  name   = "${element(var.roles, count.index)}"
  value  = "${var.host}"
  type   = "CNAME"
}

resource "null_resource" "role_config" {
  triggers = {
    host_id         = "${var.id}"
    config_packages = "${join(" ", sort(formatlist("crashbox-%s-config", var.roles)))}"
  }

  connection {
    host = "${var.host}"
  }

  provisioner "file" {
    content     = "${acme_certificate.certificate.certificate_pem}"
    destination = "/etc/ssl/server.cert.pem"
  }

  provisioner "file" {
    content     = "${acme_certificate.certificate.issuer_pem}"
    destination = "/etc/ssl/issuer.cert.pem"
  }

  provisioner "file" {
    content     = "${acme_certificate.certificate.private_key_pem}"
    destination = "/etc/ssl/private/server.key.pem"
  }

  provisioner "file" {
    source      = "${path.root}/../packages/target/archive"
    destination = "/usr/local/share/"
  }

  provisioner "remote-exec" {
    inline = [
      "echo deb [trusted=yes] file:/usr/local/share/archive ./ > /etc/apt/sources.list.d/local-archive.list",
      "apt update --quiet=2",
      "apt install --quiet=2 --yes ${null_resource.role_config.triggers.config_packages}",
    ]
  }
}

output "roles" {
  value = "${var.roles}"
}