openstack-infrastructure-te.../modules/dmarc_reports/dmarc-reports.tf

134 lines
4.5 KiB
HCL

#
# DMARC reports service: parsedmarc reads the aggregate and forensic reports
# from the IMAP mailbox, OpenSearch stores them, OpenSearch Dashboards shows
# them. All three on one VM.
#
# One interface, on the main private network: the L7 load balancers reach
# Dashboards there, and the VM reaches the IMAP server through the router of
# the project. No floating IP.
#
locals {
# One rule per (load balancer, service port) pair
dmarc_reports_service_rules = {
for pair in setproduct(var.haproxy_l7_ip, var.dmarc_reports_data.service_ports) :
"${pair[0]}-${pair[1]}" => { address = pair[0], port = pair[1] }
}
}
#
# Traffic from the main L7 load balancers
#
resource "openstack_networking_secgroup_v2" "traffic_to_dmarc_reports" {
name = "traffic_to_dmarc_reports_from_the_main_load_balancers"
delete_default_rules = "true"
description = "Traffic from the main L7 HAPROXY load balancers to OpenSearch Dashboards"
}
resource "openstack_networking_secgroup_rule_v2" "haproxy_to_dmarc_reports" {
for_each = local.dmarc_reports_service_rules
security_group_id = openstack_networking_secgroup_v2.traffic_to_dmarc_reports.id
description = "Traffic from the HAPROXY L7 ${each.value.address} to the port ${each.value.port}"
direction = "ingress"
ethertype = "IPv4"
protocol = "tcp"
port_range_min = each.value.port
port_range_max = each.value.port
remote_ip_prefix = "${each.value.address}/32"
}
#
# Data volume: the OpenSearch indexes. Online resize enabled, like every other
# additional volume of the project
#
resource "openstack_blockstorage_volume_v3" "dmarc_reports_data_vol" {
name = var.dmarc_reports_data.vol_data_name
description = "OpenSearch data directory of the DMARC reports service"
size = var.dmarc_reports_data.vol_data_size
volume_type = var.dmarc_reports_data.volume_type
enable_online_resize = true
}
#
# Port, declared outside the instance
#
resource "openstack_networking_port_v2" "dmarc_reports_main_port" {
name = "${var.dmarc_reports_data.name}-main-port"
description = "Port of the DMARC reports service on the main private network"
admin_state_up = true
network_id = var.main_private_network_id
security_group_ids = [
var.default_security_group_id,
openstack_networking_secgroup_v2.traffic_to_dmarc_reports.id,
]
fixed_ip {
subnet_id = var.main_private_subnet_id
ip_address = var.dmarc_reports_main_ip
}
}
#
# Instance
#
resource "openstack_compute_instance_v2" "dmarc_reports" {
name = var.dmarc_reports_data.name
availability_zone_hints = var.availability_zone
flavor_name = var.dmarc_reports_data.flavor
key_pair = var.ssh_key_name
block_device {
uuid = var.image.uuid
source_type = "image"
volume_size = var.dmarc_reports_data.boot_vol_size
boot_index = 0
destination_type = "volume"
delete_on_termination = false
}
network {
port = openstack_networking_port_v2.dmarc_reports_main_port.id
}
user_data = file(var.image.user_data_file)
# Do not replace the instance when the ssh key or the user data change
lifecycle {
ignore_changes = [
key_pair, user_data, network
]
}
}
resource "openstack_compute_volume_attach_v2" "dmarc_reports_data_attach" {
instance_id = openstack_compute_instance_v2.dmarc_reports.id
volume_id = openstack_blockstorage_volume_v3.dmarc_reports_data_vol.id
device = var.dmarc_reports_data.vol_data_device
}
#
# A record on the main network address, so that the name can be used by the
# playbooks and by the load balancer configuration
#
resource "openstack_dns_recordset_v2" "dmarc_reports_recordset" {
zone_id = var.dns_zone_id
name = "${var.dmarc_reports_data.name}.${var.dns_zone_name}"
description = "Address of the DMARC reports service on the main private network"
ttl = 8600
type = "A"
records = [var.dmarc_reports_main_ip]
}
#
# Public name of the service, a CNAME of the main load balancer that publishes
# it
#
resource "openstack_dns_recordset_v2" "dmarc_reports_public_recordset" {
count = length(var.dmarc_reports_public_name) > 0 ? 1 : 0
zone_id = var.dns_zone_id
name = "${var.dmarc_reports_public_name}.${var.dns_zone_name}"
description = "DMARC reports, published by the main load balancer"
ttl = 8600
type = "CNAME"
records = [var.dmarc_reports_cname_target]
}