main.tf 2.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133
  1. terraform {
  2. required_providers {
  3. aws = {
  4. source = "hashicorp/aws"
  5. version = "~> 4.16"
  6. }
  7. }
  8. required_version = ">= 1.2.0"
  9. }
  10. provider "aws" {
  11. profile = "weseek"
  12. region = "ap-northeast-1"
  13. }
  14. resource "aws_iam_role" "iam_role" {
  15. name = "growi-official-image-builder"
  16. assume_role_policy = <<EOF
  17. {
  18. "Version": "2012-10-17",
  19. "Statement": [
  20. {
  21. "Effect": "Allow",
  22. "Principal": {
  23. "Service": "codebuild.amazonaws.com"
  24. },
  25. "Action": "sts:AssumeRole"
  26. }
  27. ]
  28. }
  29. EOF
  30. }
  31. resource "aws_secretsmanager_secret" "secret" {
  32. name = "growi/official-image-builder"
  33. }
  34. resource "aws_secretsmanager_secret_version" "main" {
  35. secret_id = aws_secretsmanager_secret.secret.id
  36. secret_string = "CHANGE THIS"
  37. lifecycle {
  38. ignore_changes = [secret_string, version_stages]
  39. }
  40. }
  41. resource "aws_iam_role_policy" "growi-official-image-builder" {
  42. role = aws_iam_role.iam_role.name
  43. policy = <<POLICY
  44. {
  45. "Version": "2012-10-17",
  46. "Statement": [
  47. {
  48. "Effect": "Allow",
  49. "Resource": [
  50. "*"
  51. ],
  52. "Action": [
  53. "logs:CreateLogGroup",
  54. "logs:CreateLogStream",
  55. "logs:PutLogEvents"
  56. ]
  57. },
  58. {
  59. "Effect": "Allow",
  60. "Action": [
  61. "secretsmanager:GetResourcePolicy",
  62. "secretsmanager:GetSecretValue",
  63. "secretsmanager:DescribeSecret",
  64. "secretsmanager:ListSecretVersionIds"
  65. ],
  66. "Resource": [
  67. "${aws_secretsmanager_secret.secret.arn}"
  68. ]
  69. },
  70. {
  71. "Effect": "Allow",
  72. "Action": [
  73. "codebuild:StartBuild",
  74. "codebuild:StopBuild",
  75. "codebuild:RetryBuild",
  76. "codebuild:CreateReportGroup",
  77. "codebuild:CreateReport",
  78. "codebuild:UpdateReport",
  79. "codebuild:BatchPutTestCases",
  80. "codebuild:BatchPutCodeCoverages"
  81. ],
  82. "Resource": [
  83. "*"
  84. ]
  85. }
  86. ]
  87. }
  88. POLICY
  89. }
  90. resource "aws_codebuild_project" "codebuild" {
  91. name = "growi-official-image-builder"
  92. description = "The CodeBuild Project for GROWI official docker image"
  93. service_role = aws_iam_role.iam_role.arn
  94. build_batch_config {
  95. service_role = aws_iam_role.iam_role.arn
  96. }
  97. artifacts {
  98. type = "NO_ARTIFACTS"
  99. }
  100. environment {
  101. compute_type = "BUILD_GENERAL1_LARGE"
  102. image = "aws/codebuild/standard:6.0"
  103. type = "LINUX_CONTAINER"
  104. privileged_mode = true
  105. }
  106. source {
  107. # type = "NO_SOURCE"
  108. type = "GITHUB"
  109. location = "https://github.com/weseek/growi.git"
  110. git_clone_depth = 1
  111. buildspec = "packages/app/docker/codebuild/buildspec.yml"
  112. }
  113. source_version = "refs/heads/support/build-with-codebuild"
  114. cache {
  115. type = "LOCAL"
  116. modes = ["LOCAL_DOCKER_LAYER_CACHE", "LOCAL_CUSTOM_CACHE"]
  117. }
  118. }