main.tf 3.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170
  1. terraform {
  2. required_providers {
  3. aws = {
  4. source = "hashicorp/aws"
  5. version = "~> 4.16"
  6. }
  7. }
  8. required_version = ">= 1.2.0"
  9. }
  10. provider "aws" {
  11. profile = "weseek"
  12. region = "ap-northeast-1"
  13. }
  14. resource "aws_s3_bucket" "s3_bucket" {
  15. bucket = "growi-official-image-builder-cache"
  16. }
  17. resource "aws_s3_bucket_acl" "s3_bucket_acl" {
  18. bucket = aws_s3_bucket.s3_bucket.id
  19. acl = "private"
  20. }
  21. resource "aws_s3_bucket_lifecycle_configuration" "s3_bucket_lifecycle" {
  22. bucket = aws_s3_bucket.s3_bucket.id
  23. rule {
  24. id = "auto-expire"
  25. status = "Enabled"
  26. expiration {
  27. days = 60
  28. }
  29. noncurrent_version_expiration {
  30. noncurrent_days = 3
  31. }
  32. }
  33. }
  34. resource "aws_iam_role" "iam_role" {
  35. name = "growi-official-image-builder"
  36. assume_role_policy = <<EOF
  37. {
  38. "Version": "2012-10-17",
  39. "Statement": [
  40. {
  41. "Effect": "Allow",
  42. "Principal": {
  43. "Service": "codebuild.amazonaws.com"
  44. },
  45. "Action": "sts:AssumeRole"
  46. }
  47. ]
  48. }
  49. EOF
  50. }
  51. resource "aws_secretsmanager_secret" "secret" {
  52. name = "growi/official-image-builder"
  53. }
  54. resource "aws_secretsmanager_secret_version" "main" {
  55. secret_id = aws_secretsmanager_secret.secret.id
  56. secret_string = "CHANGE THIS"
  57. lifecycle {
  58. ignore_changes = [secret_string, version_stages]
  59. }
  60. }
  61. resource "aws_iam_role_policy" "growi-official-image-builder" {
  62. role = aws_iam_role.iam_role.name
  63. policy = <<POLICY
  64. {
  65. "Version": "2012-10-17",
  66. "Statement": [
  67. {
  68. "Effect": "Allow",
  69. "Resource": [
  70. "*"
  71. ],
  72. "Action": [
  73. "logs:CreateLogGroup",
  74. "logs:CreateLogStream",
  75. "logs:PutLogEvents"
  76. ]
  77. },
  78. {
  79. "Effect": "Allow",
  80. "Action": [
  81. "s3:*"
  82. ],
  83. "Resource": [
  84. "${aws_s3_bucket.s3_bucket.arn}",
  85. "${aws_s3_bucket.s3_bucket.arn}/*"
  86. ]
  87. },
  88. {
  89. "Effect": "Allow",
  90. "Action": [
  91. "secretsmanager:GetResourcePolicy",
  92. "secretsmanager:GetSecretValue",
  93. "secretsmanager:DescribeSecret",
  94. "secretsmanager:ListSecretVersionIds"
  95. ],
  96. "Resource": [
  97. "${aws_secretsmanager_secret.secret.arn}"
  98. ]
  99. },
  100. {
  101. "Effect": "Allow",
  102. "Action": [
  103. "codebuild:StartBuild",
  104. "codebuild:StopBuild",
  105. "codebuild:RetryBuild",
  106. "codebuild:CreateReportGroup",
  107. "codebuild:CreateReport",
  108. "codebuild:UpdateReport",
  109. "codebuild:BatchPutTestCases",
  110. "codebuild:BatchPutCodeCoverages"
  111. ],
  112. "Resource": [
  113. "*"
  114. ]
  115. }
  116. ]
  117. }
  118. POLICY
  119. }
  120. resource "aws_codebuild_project" "codebuild" {
  121. name = "growi-official-image-builder"
  122. description = "The CodeBuild Project for GROWI official docker image"
  123. service_role = aws_iam_role.iam_role.arn
  124. build_batch_config {
  125. service_role = aws_iam_role.iam_role.arn
  126. }
  127. artifacts {
  128. type = "NO_ARTIFACTS"
  129. }
  130. environment {
  131. compute_type = "BUILD_GENERAL1_LARGE"
  132. image = "aws/codebuild/standard:6.0"
  133. type = "LINUX_CONTAINER"
  134. privileged_mode = true
  135. }
  136. source {
  137. # type = "NO_SOURCE"
  138. type = "GITHUB"
  139. location = "https://github.com/weseek/growi.git"
  140. git_clone_depth = 1
  141. buildspec = "packages/app/docker/codebuild/buildspec.yml"
  142. }
  143. source_version = "refs/heads/support/build-with-codebuild"
  144. cache {
  145. type = "S3"
  146. location = "${aws_s3_bucket.s3_bucket.id}"
  147. }
  148. }