mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-09-11 00:50:43 +02:00
* terraform: add cloud-agnostic core renderer module Renders per-node weed argv, systemd units, config files, disk-mount and secret-fetch scripts, and cloud-init from an address map. Creates zero cloud resources. Flags verified against the weed binary: volume uses -mserver for the master list, gRPC is -port.grpc (auto http+10000), minFreeSpacePercent is a string, filer store via -defaultStoreDir. * terraform: add mTLS and JWT security module Generates the CA, per-component certs with distinct CNs, and JWT signing keys via the tls/random providers. Emits a core_security object plus PEMs for secret-store delivery. * terraform: add AWS deployment module and examples Reserves stable ENIs first, renders config via the core, then creates instances, prevent_destroy EBS data disks mounted at /data, and the cluster security group. With enable_security, generates certs/JWT, stores them in SSM SecureString, grants an instance role, and fetches them at boot so secrets stay out of user_data. Keyed for_each on every stateful tier. * terraform: add local cluster test harnesses run_local_cluster.sh and run_local_secure.sh render a cluster with the core and run real weed processes, asserting master quorum, volume registration, filer/s3 round-trips, mutual-TLS formation, and JWT enforcement. Use an isolated high port range with a guard so they never touch a cluster already running on the machine. The weed binary defaults to $(go env GOPATH)/bin/weed. * terraform: add CI workflow and README fmt/validate/tofu-test plus smoke jobs that build weed and run both harnesses. * terraform: guard against empty filesystem UUID in mount script An empty UUID made grep -q match any fstab line, skipping the fstab entry and breaking the mount. Fail fast when blkid returns no UUID. * terraform: sanitize cluster name in WEED_CLUSTER env keys Hyphens or spaces in cluster_name produced invalid systemd/bash env var names; map non-alphanumerics to underscores. * terraform: omit empty jwt.signing block from security.toml With enable_security and no JWT key, the template emitted [jwt.signing] key="". Gate the block on a non-empty key and cover it with a test. * terraform: mark core security input as sensitive The security object carries JWT signing keys; keep them out of plan output and known values. * terraform: enforce jwt_length minimum of 32 * terraform: note region/AZ coupling in HA example * terraform: guard WORKDIR before recursive delete in test harnesses * terraform: fix README fence language and test count * terraform: handle embedded s3 with no filer nodes Indexing sort(keys(var.filers))[0] errored at plan time when embedded S3 was enabled but no filers were defined; fall back to an empty config source. * terraform: scope kms:Decrypt to a configurable key arn Replace the hardcoded Resource="*" with a kms_key_arn variable (default "*") so production can restrict decrypt to a specific CMK. * terraform: encrypt EBS data volumes at rest Set encrypted = true on the volume/filer data disks and the all-in-one example disk. * terraform: protect filer instances from API termination Filers hold the leveldb2 metadata store, so they are stateful and get the same disable_api_termination as masters and volumes. * terraform: stop instance before detaching in all-in-one example * terraform: drop stale references to the removed plan doc * terraform: correct stale mount-step comment in aws module * terraform: mark Terraform support as experimental in README
101 lines
3.1 KiB
Terraform
101 lines
3.1 KiB
Terraform
# =============================================================================
|
|
# Local test harness: render a small SeaweedFS cluster with the core module
|
|
# and run it as real `weed` processes on 127.0.0.1 (no cloud, no docker).
|
|
#
|
|
# 3 masters (quorum) + 1 volume + 1 filer + 1 standalone S3, each on a distinct
|
|
# port. run_local_cluster.sh consumes the `cluster` output, launches the weed
|
|
# processes from the rendered argv, and asserts the cluster actually works.
|
|
# =============================================================================
|
|
|
|
terraform {
|
|
required_version = ">= 1.3.0"
|
|
}
|
|
|
|
variable "weed_binary" {
|
|
description = "Path to the weed executable used for the local cluster."
|
|
type = string
|
|
default = "/usr/bin/weed"
|
|
}
|
|
|
|
variable "workdir" {
|
|
description = "Scratch directory for per-node data dirs and config files."
|
|
type = string
|
|
default = "/tmp/seaweedfs-tftest"
|
|
}
|
|
|
|
module "core" {
|
|
source = "../../modules/core"
|
|
|
|
weed_binary = var.weed_binary
|
|
monitoring_enabled = false
|
|
enable_security = false
|
|
|
|
# High port range so the harness does not collide with a SeaweedFS cluster
|
|
# that may already be running on this dev machine (default 9333/8080/8888/8333).
|
|
master = {
|
|
nodes = {
|
|
m0 = { address = "127.0.0.1", port = 29333, data_dir = "${var.workdir}/master-m0" }
|
|
m1 = { address = "127.0.0.1", port = 29334, data_dir = "${var.workdir}/master-m1" }
|
|
m2 = { address = "127.0.0.1", port = 29335, data_dir = "${var.workdir}/master-m2" }
|
|
}
|
|
# Tighten election so a 3-node local quorum converges quickly.
|
|
election_timeout = "3s"
|
|
heartbeat_interval = "200ms"
|
|
}
|
|
|
|
volume = {
|
|
nodes = {
|
|
v0 = {
|
|
address = "127.0.0.1"
|
|
port = 28080
|
|
rack = "rack-a"
|
|
data_dirs = [{ path = "${var.workdir}/volume-v0", max_volumes = 20 }]
|
|
}
|
|
}
|
|
}
|
|
|
|
filer = {
|
|
nodes = {
|
|
f0 = { address = "127.0.0.1", port = 28888, data_dir = "${var.workdir}/filer-f0" }
|
|
}
|
|
}
|
|
|
|
s3 = {
|
|
enabled = true
|
|
nodes = { s0 = { address = "127.0.0.1", port = 28333 } }
|
|
# this weed build starts an Iceberg REST catalog on 8181 by default; disable
|
|
# it so the test does not collide with a cluster already using that port.
|
|
iceberg_port = 0
|
|
config_path = "${var.workdir}/s3_config.json"
|
|
}
|
|
|
|
# Anonymous identity so the smoke test can PUT/GET without sigv4 signing.
|
|
s3_identities = [{
|
|
name = "anonymous"
|
|
access_key = ""
|
|
secret_key = ""
|
|
actions = ["Admin", "Read", "Write", "List", "Tagging"]
|
|
}]
|
|
}
|
|
|
|
output "cluster" {
|
|
description = "Node specs consumed by run_local_cluster.sh (read via `tofu output -json`, which emits values even when sensitive)."
|
|
sensitive = true
|
|
value = {
|
|
for name, n in module.core.nodes : name => {
|
|
role = n.role
|
|
address = n.address
|
|
http_port = n.ports.http
|
|
data_dirs = n.data_dirs
|
|
argv = n.argv
|
|
env = n.env
|
|
config_files = n.config_files
|
|
exec_start = n.exec_start
|
|
}
|
|
}
|
|
}
|
|
|
|
output "master_peers" {
|
|
value = module.core.master_peers
|
|
}
|