main.tf 3.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143
  1. terraform {
  2. required_providers {
  3. aws = {
  4. source = "hashicorp/aws"
  5. version = "~> 4.16"
  6. }
  7. }
  8. required_version = ">= 1.2.0"
  9. }
  10. provider "aws" {
  11. profile = "weseek"
  12. region = "ap-northeast-1"
  13. }
  14. resource "aws_iam_role" "iam_role" {
  15. name = "growi-official-image-builder"
  16. assume_role_policy = <<EOF
  17. {
  18. "Version": "2012-10-17",
  19. "Statement": [
  20. {
  21. "Effect": "Allow",
  22. "Principal": {
  23. "Service": "codebuild.amazonaws.com"
  24. },
  25. "Action": "sts:AssumeRole"
  26. }
  27. ]
  28. }
  29. EOF
  30. }
  31. resource "aws_secretsmanager_secret" "secret" {
  32. name = "growi/official-image-builder"
  33. }
  34. resource "aws_secretsmanager_secret_version" "main" {
  35. secret_id = aws_secretsmanager_secret.secret.id
  36. secret_string = "CHANGE THIS"
  37. lifecycle {
  38. ignore_changes = [secret_string, version_stages]
  39. }
  40. }
  41. resource "aws_iam_role_policy" "growi-official-image-builder" {
  42. role = aws_iam_role.iam_role.name
  43. policy = <<POLICY
  44. {
  45. "Version": "2012-10-17",
  46. "Statement": [
  47. {
  48. "Effect": "Allow",
  49. "Resource": [
  50. "*"
  51. ],
  52. "Action": [
  53. "logs:CreateLogGroup",
  54. "logs:CreateLogStream",
  55. "logs:PutLogEvents"
  56. ]
  57. },
  58. {
  59. "Effect": "Allow",
  60. "Action": [
  61. "s3:*"
  62. ],
  63. "Resource": [
  64. "${aws_s3_bucket.s3_bucket.arn}",
  65. "${aws_s3_bucket.s3_bucket.arn}/*"
  66. ]
  67. },
  68. {
  69. "Effect": "Allow",
  70. "Action": [
  71. "secretsmanager:GetResourcePolicy",
  72. "secretsmanager:GetSecretValue",
  73. "secretsmanager:DescribeSecret",
  74. "secretsmanager:ListSecretVersionIds"
  75. ],
  76. "Resource": [
  77. "${aws_secretsmanager_secret.secret.arn}"
  78. ]
  79. },
  80. {
  81. "Effect": "Allow",
  82. "Action": [
  83. "codebuild:StartBuild",
  84. "codebuild:StopBuild",
  85. "codebuild:RetryBuild",
  86. "codebuild:CreateReportGroup",
  87. "codebuild:CreateReport",
  88. "codebuild:UpdateReport",
  89. "codebuild:BatchPutTestCases",
  90. "codebuild:BatchPutCodeCoverages"
  91. ],
  92. "Resource": [
  93. "*"
  94. ]
  95. }
  96. ]
  97. }
  98. POLICY
  99. }
  100. resource "aws_codebuild_project" "codebuild" {
  101. name = "growi-official-image-builder"
  102. description = "The CodeBuild Project for GROWI official docker image"
  103. service_role = aws_iam_role.iam_role.arn
  104. build_batch_config {
  105. service_role = aws_iam_role.iam_role.arn
  106. }
  107. artifacts {
  108. type = "NO_ARTIFACTS"
  109. }
  110. environment {
  111. compute_type = "BUILD_GENERAL1_LARGE"
  112. image = "aws/codebuild/standard:6.0"
  113. type = "LINUX_CONTAINER"
  114. privileged_mode = true
  115. }
  116. source {
  117. # type = "NO_SOURCE"
  118. type = "GITHUB"
  119. location = "https://github.com/weseek/growi.git"
  120. git_clone_depth = 1
  121. buildspec = "packages/app/docker/codebuild/buildspec.yml"
  122. }
  123. source_version = "refs/heads/support/build-with-codebuild"
  124. cache {
  125. type = "LOCAL"
  126. modes = ["LOCAL_DOCKER_LAYER_CACHE", "LOCAL_CUSTOM_CACHE"]
  127. }
  128. }