codebuild.tf 2.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117
  1. resource "aws_iam_role" "iam_role" {
  2. name = "growi-official-image-builder"
  3. assume_role_policy = <<EOF
  4. {
  5. "Version": "2012-10-17",
  6. "Statement": [
  7. {
  8. "Effect": "Allow",
  9. "Principal": {
  10. "Service": "codebuild.amazonaws.com"
  11. },
  12. "Action": "sts:AssumeRole"
  13. }
  14. ]
  15. }
  16. EOF
  17. }
  18. resource "aws_secretsmanager_secret" "secret" {
  19. name = "growi/official-image-builder"
  20. }
  21. resource "aws_secretsmanager_secret_version" "main" {
  22. secret_id = aws_secretsmanager_secret.secret.id
  23. secret_string = "CHANGE THIS"
  24. lifecycle {
  25. ignore_changes = [secret_string, version_stages]
  26. }
  27. }
  28. resource "aws_iam_role_policy" "growi-official-image-builder" {
  29. role = aws_iam_role.iam_role.name
  30. policy = <<POLICY
  31. {
  32. "Version": "2012-10-17",
  33. "Statement": [
  34. {
  35. "Effect": "Allow",
  36. "Resource": [
  37. "*"
  38. ],
  39. "Action": [
  40. "logs:CreateLogGroup",
  41. "logs:CreateLogStream",
  42. "logs:PutLogEvents"
  43. ]
  44. },
  45. {
  46. "Effect": "Allow",
  47. "Action": [
  48. "secretsmanager:GetResourcePolicy",
  49. "secretsmanager:GetSecretValue",
  50. "secretsmanager:DescribeSecret",
  51. "secretsmanager:ListSecretVersionIds"
  52. ],
  53. "Resource": [
  54. "${aws_secretsmanager_secret.secret.arn}"
  55. ]
  56. },
  57. {
  58. "Effect": "Allow",
  59. "Action": [
  60. "codebuild:StartBuild",
  61. "codebuild:StopBuild",
  62. "codebuild:RetryBuild",
  63. "codebuild:CreateReportGroup",
  64. "codebuild:CreateReport",
  65. "codebuild:UpdateReport",
  66. "codebuild:BatchPutTestCases",
  67. "codebuild:BatchPutCodeCoverages"
  68. ],
  69. "Resource": [
  70. "*"
  71. ]
  72. }
  73. ]
  74. }
  75. POLICY
  76. }
  77. resource "aws_codebuild_project" "codebuild" {
  78. name = "growi-official-image-builder"
  79. description = "The CodeBuild Project for GROWI official docker image"
  80. service_role = aws_iam_role.iam_role.arn
  81. build_batch_config {
  82. service_role = aws_iam_role.iam_role.arn
  83. }
  84. artifacts {
  85. type = "NO_ARTIFACTS"
  86. }
  87. environment {
  88. compute_type = "BUILD_GENERAL1_LARGE"
  89. image = "aws/codebuild/standard:6.0"
  90. type = "LINUX_CONTAINER"
  91. privileged_mode = true
  92. }
  93. source {
  94. # type = "NO_SOURCE"
  95. type = "GITHUB"
  96. location = "https://github.com/weseek/growi.git"
  97. git_clone_depth = 1
  98. buildspec = "packages/app/docker/codebuild/buildspec/root.yml"
  99. }
  100. source_version = "refs/heads/support/build-with-codebuild"
  101. cache {
  102. type = "LOCAL"
  103. modes = ["LOCAL_DOCKER_LAYER_CACHE", "LOCAL_CUSTOM_CACHE"]
  104. }
  105. }