Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
37 changes: 36 additions & 1 deletion .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -9,4 +9,39 @@ __pycache__
app.log
Dockerfile
chromedriver.exe
Vagrantfile
Vagrantfile

# Local .terraform directories
**/.terraform/*

# .tfstate files
*.tfstate
*.tfstate.*

# Crash log files
crash.log

# Exclude all .tfvars files, which are likely to contain sentitive data, such as
# password, private keys, and other secrets. These should not be part of version
# control as they are data points which are potentially sensitive and subject
# to change depending on the environment.
#
*.tfvars

# Ignore override files as they are usually used to override resources locally and so
# are not checked in
override.tf
override.tf.json
*_override.tf
*_override.tf.json

# Include override files you do wish to add to version control using negated pattern
#
# !example_override.tf

# Include tfplan files to ignore the plan output of command: terraform plan -out=tfplan
# example: *tfplan*

# Ignore CLI configuration files
.terraformrc
terraform.rc
37 changes: 36 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -125,4 +125,39 @@ chromedriver.exe
### vagrant
.vagrant

app.log
app.log

# Local .terraform directories
**/.terraform/*

# .tfstate files
*.tfstate
*.tfstate.*

# Crash log files
crash.log

# Exclude all .tfvars files, which are likely to contain sentitive data, such as
# password, private keys, and other secrets. These should not be part of version
# control as they are data points which are potentially sensitive and subject
# to change depending on the environment.
#
*.tfvars

# Ignore override files as they are usually used to override resources locally and so
# are not checked in
override.tf
override.tf.json
*_override.tf
*_override.tf.json

# Include override files you do wish to add to version control using negated pattern
#
# !example_override.tf

# Include tfplan files to ignore the plan output of command: terraform plan -out=tfplan
# example: *tfplan*

# Ignore CLI configuration files
.terraformrc
terraform.rc
39 changes: 39 additions & 0 deletions .terraform.lock.hcl

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

17 changes: 16 additions & 1 deletion .travis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,29 @@ script:
- docker build --target test --tag todo-app:test .
- docker run todo-app:test tests
- docker run -e MONGODB_CONNECTION_STRING todo-app:test e2e_tests
before_deploy:
- wget https://releases.hashicorp.com/terraform/"$TF_VERSION"/terraform_"$TF_VERSION"_linux_amd64.zip
- unzip terraform_"$TF_VERSION"_linux_amd64.zip
- sudo mv terraform /usr/local/bin/
- rm terraform_"$TF_VERSION"_linux_amd64.zip
- terraform init
- terraform apply -var AUTH_CLIENT_ID=$AUTH_CLIENT_ID -var AUTH_CLIENT_SECRET=$AUTH_CLIENT_SECRET -var SECRET_KEY=$SECRET_KEY -auto-approve
deploy:
provider: script
script: bash deploy.sh
on:
branch: main
env:
global:
- TF_VERSION=0.14.7
- DOCKER_USERNAME=charliecumber
- secure: CPAHjkwOZo2p3E1W3+KaR13yZ4RAF5OlNwdugM8KbcmvF9p8B0tpTzkdBAYuBqOmp0OGkrMrHcUs31fY5g5/cH2KZ9n6xsFPRvHPTJui6i3h9UGQI4IA5hEa6TPo9qwx/6B7kKWfqlrvE5iWbzDMKXnT4M90Zx2JVNQA2ltsiBhDMEsOpl+qfStvhoTuI9EYexh2pgBXID6UVGZruM262r8ScmgIhZ12YHIt2rhMY4De+EWmvRBMrgbyMGQYU2FDQpYraQY837R/E7t5UFwzu6bqTkAd5ZeHiwO81zgEWB+xhoJqQxKuD9HVLK1qO0xfZYO1geiMS08kWZ8STGiAiKYFaW054qToStzu5r8QTw2A8ZN75cpDSvgg4Ki2/r1kVvvsvip5OUESfOIta22jn9+WMfTKDd+4IMYrWbbDQgcaKp+AQhOlYo2jhHNVIn308LivJQXqhAT/XR/hW36EKp0zZgUt2wlSgghHRQ3Is/frMeLDEKvaJMV4Cq8YQM/nqW0BKkGkaTYoLQClpstkzRjcY3ZUDAyxRDZtvD7E/Rfr7/MO/LCQ6XLUjiQB+st8rCFcASHRo7S44CKbGo+H/ocWXOnBnBwCO4b4L+EBYm7YdoYOtj25AqursTC6yLkKa0d1XtGqX4L0+tLMGgZrjaEbe3Zx2apVatLSQT4V1to=
- secure: hvfecANUp71801mNDCCOcANgTukXmvQayeTwD9sme5UBDOnbv8uCK/6TMhn5Mn8B9P9v44M+jV0dIxp/QcsQAOIENKp0OdFOYCwYafIByEG6T5AEKfC8oto6DmyybakMzZtuhgUcyPS5BGoKrANE/06StU3UsmvRA9gLuBikaM08VK2Y9FzytcsqShyMnMqvbsqlGpXN7tTIZcs9FQM1f35smc61m+DrZeOTY2spVNUOE9z6SDp3rYAflh7KWMSHD5s2P1ZBF4qqa76la8zxEIb4QZRgCrjGcIzy/GikYaPA43AjqC06999pXqjy4/lPCbYqr1W/91LSzDEbXgwQyxPaYi6cItPuGFmt/xzoVdkfb/JsR4UE0kUII2fXIOgPHl33wgB14naEqlYAxo4OTfji6g6B3nX1yyYFuB5a3KhPaSIQ7ZHQ+7hrq/Y+Jgxa4BafK4NsQhPplXirRXxrPKU2F0EbeKuia1FliIP/lOZyRPRPwkN/ve3gEOmB8Y9pldPyKgi8mvRlLchwQY8WiBmRI63Ku+o8ji15aqBo7nNLSI9NZ6gmWxyw8U7IwMK71uqPFcePbyxdGD0wUw2BCQpL9nZJTRGvOBbJfs/FHOkcCE4Ra8hctgeRIxWre5ACqBvgSZHLdUxIARXlEdRz9vH8tfics6iMWC6Y4k6pbgI=
- secure: de6os6dNL52E1bwQV9XjsbPHKrRGaDkI7bAe4B9CJifPlcunKr0bFnmc7EJvTVKBD/alHB7uJmhgf7Xdjh6jfGXcp1t6BRlDTpB9YQIwTu+SHcEd4M5apZ0G465J/sSz9R4DEuWHhgfauJGqoc+qXfPPEVW0Yl1xZLTMuaPXrGCyr3G3MRfUC3D99P4NuMjj8NB0pQmDSFOunKvQgBhD7PVzqmkSdNECcyGecMO8Y9DRXv+1Jf4NXeWUH5N6IbEUpEL2L6vy9rJUFQDNx9PCMww9QiOLyAxGcavWoFNDXbOb4CkKTXS3ByEPza9b5f9/xKb7oDecXFne2FYDWH9+NayWdBGvApbfNliN65CMJvtTma+geQn5YyaErYJLfdZs6PShjxCAw0wJmRF1aXjbTksyzLJ6WdvWFRwQzgfxurUYLzdMEaAVnsH2X0Pa6OTW4SxVXjb17DByd1cdTg0uebs+ZTpYmC4Fpwn5xLgS//+KFY2P89DMPqbu20vTpAvM3ViTOAsP1UATSwnK0wp+2J2V0lTpi4JzEUEitqGK/FrXhA9BlsgTCp1WtzvaAy+TkX5v7fMz66emWiqEOXW94SVP6E5HmyigT9j6b6GbvRRtMVoFsMLc5qI5tUWpTThZRrRTPaVCUGe32sxMlv+/L7PnoXg6y0mKjt9E9wnN//U=
- secure: hQFReQwF0OkTLHZuEQu7uQiHOlRhozMd0eMKCAqz6zflaWl1wxH4tUlY3CFQgmJ+Fize0NsUwU+yGKaLyhcxxCbiqkPVYEivsvSrcR/JRDFIS27UKn1zWu4aEEprd0W/ZsDGdZYDOxbXbkUEpxczG1nZ5sLJURAEKpT5ul0ERq7b3e4JlGE7HaAY8fA05+rtpCYWyS9j9CWwZ8kQ/tRep7oPVCxnoitOPRfrxhl8R6FYTxfM+tKP3wHw8eXV2tinRBMP326mdFBHTvrVHvvZQuANVkHyMZmdQNgDaVysMFmJvHJsBjdTtWjzUxFt0l37NFHBuKOotlcpCKUMBRoQ41TSLPbex2JTzfBg/7yC6jvm2fYT4CzQvlArrA4n6SI1PPF+CXEemUTPQJISjq1JgPtjR6LoEHpqmpoqhHnjuVjTgx5cxhGImhZCT1mY3SBDc7rgc6D+4pLVP19/k/rp7ENdqXs66PsDQf4+kWIr0nCSTjr/bGt1S42zWsg/jAq6895EZyiAr4dBrqTzBH4045VYKW6Ao+FJOG4j0p2w+DvsMOCn9zUlpahL7BbcQeD1VYvMfAZbYq7aXenKgpiVY2lxDpgxwbOWdSIZlPF54oHSs3EL52OtYE4rPOs9IuVlSISrG/dnBTPst4Iqi0oHY03SUoqFCD5Dv8sn/7mmYHY=
- secure: XSDu8u64mvwUDeDgF19CVGRW7sS6dGO+BMFJO5Epkch06fs0/dLwEZpIdHFdLJjhMmEs76WM7MCfbTGzTS32Dnzhw/MtWEIttf5Aeei869w0lJfNhyRGxZxLSor4ghElXzHXCUHSmHb28Mv2KmiQmxKM0FGOSg6orv692nTIJLdQzuv3FyFkxE0lNeo0EzEsrjDxNBH6CVYc/0KYgyVd6cP5t7EfYVItpa08WUc6YMHQ43EKv7QgjbYE61DjkpPYP/Fi0JYOnTne3LwW72K9pTYFri95x3JnyiVos8t9zm4lmSkbsPgqCfPcb/lF3KFMzqYutgn5pmml9krHXpN68Bv3f0d96tyftunJWf1tGayBWgFYJ5FKaygJXySwcerGwLWIAisvR/oskoPSPBbV4NvN76zlGHONpzyuPLvBeMzTAZS2LdAhCvwbDpmeoOQlu+Pxkis4rIHo+IEiyxLT3oA+fLuAtJAf2reTU4+g5Txzd/8tOWX+9wHvXUs+uOohymjXqnVItogh6RGu9Kdd3MgGCjQW2MQSlf4enePsDxU9MMgXCbPJ1Alb5x/+9W01RSIy/xw7DWWaSqtLLKVVSd/EyLOM81B+BlqhgJqIHQq5Bik+MBwaQ7Kx99v6i+zcirmOH8bhDNbYj5AO0Rqdbr8yplsCPlj9TdWOyyYr6JI=
- secure: NyNY55y8Es4vroH3Lc2tDaDzjl7hJzWJKXWqel+q/zp4vLPq51GX+UF+u0Tlgna4F41xJhRjDcxFY3+bIidzawd0+wAPkPauNA6IffV+NleuQ6Ehx8Xvj8lBtWJ9aUlSMZHqAVdDSNQjWjkMp956BKe5t9S2SSbow7Jx41RBnvM37zDcswYpZmg5z26975JGV1L0iqVvPLhXmBMyol6aLt31PWcHX61i6OR6Gb2O1j1kqMxbEaF5/Y3EdbMSaDxrG1SQ6uLsnIn2qlRFTCW3Z85ilvySbTcSXy1txwhgDLy68drqC9Y22GD1xMezUQGAeDZcITa51CqGimDa3oEXuINwE2SVWa2hgU4CZr8r/XXjkyPVR+00agtuAvZeVKUwzuK9eEyjIcHRmOZ4KN4DSCQ/LN65VXfc6NBhIuNOVralDKiAGEBg1HxEMs5qfUI9xnqabSJ4nvg1U4ZnvQ+epdjrJw1cqaz7wXEeA9JXoTL1XdWTXfoA0g149E8zh9m/tizoeeUIV3rAoZWDzG3huE7DWtRAKRyRwmrWm6R6L0lnlVa0/z05s6aBC200Y+mN/GNpWtxaBQvGLroVayRmSJzA4MHrigF4IDqD0KSXO50HmI9MmLMPkTVZpf4ZHcNIQZPDlQGP48O2xd2huLn5t9G7Wq7Ygx+wEaV2rCjNkKA=
- secure: l/c5O1Wdt1jt7D+vhhTn7XI3klJVkCl9ptiDMoJog48Lw4fpM+sGHNvb2/D184g5Ts1o+ZRd2wwcgzUR1Hy6tPwcJ9ka4X+qLh/hljC/i8qLOg0KtFk+hJXcNaT5XDoYwnTt5Cwtd3jgmB/sY5BBJRy/uR7rIkytYxCYzwXn4UKpSLPFF6Gu1McGhYlGD5myvEvbp2NLtuRDq3/AdZOGQzNDADPIWYQbkP3itbgDAGTSEVWmLFrQQNdxj8kg0ceBmF+MQGKMNbdD1lRCUwo05xRYh3YgrklsYRfnk8hFbrsIRHt6/S9Dotjl6Hp6U73Gaw7JlI2VEHN/ex3L1ZYDRhDlCOyrDBq4IpDyqTGiIYKwnqbfTIDnxIKZEsLvw9CPJqsTL1dCEe74hOW9avoGN390k8FQURJK1CSSJOZPRsZDEtaO8TkPPzcoSosyxjbMziau/CsrWWbjn4+S2mJevvRfsXaFDYCA4paSdr8dNZIOrlWTWILJGs6P4DUPM5f4SD0rQlJ5V6RcAr8o2Xq5Tx+22z7y/2UOzUeaFyUW6cWhMQrJFN5vEOyCIJMZFnYeaQageUAjjMg9hYZlZyVCaPyOVrWHdDmfFgIx0xiDS5zl9ISkm4f5123yw3lFtnGGURMF6B6KrWJnA9pHwJ4kOVw/hizJlZwWDjjO4KKasx8=
- secure: F7AFMhniVM5KgXB2NbG+l9XQ4g5fVRrjTjkDKCGVHTLcr0n67P2A9I3H4nTp5f9sPZpcK1Ln9aTr2yTFoCQkgxzMcRIQHbY7M3RldlBXxMjW0gCZYozr2tdeH3KYN6lGVR3Ng/HsMw9g0Z6dO5BfAcowxHvG4ExogSe2VX6i6q5BVvYtGzJAE7DozjCN9qP4kK5vVqyvdjKsmp8E/v+waL5NKghsSyHnCO2Nrj6WeACAGzcqUvI7Yafe8eibxrW+1BUFfba9b8xOKa3rPLRxKAsClG8odGCUva8bEkR5fNjY0qz4U0kl/gUwtozpTrBnxbUcwgNm1izK0xquRFJBybLgFeU/quaWrwzXty9H4icYhAaqX97fdpnAXQp21FamUHefbwhKIvDcDq53c4sv3u2RtAe1UvkMispJrWisEM2uhzEF2ENFLvS2HIO3zfOjllkQYMdH0GE89NU5LnOdsBtBoBfI87eyvfiSMFalIPqv3H5WgyQOBghBlPLrQtEUh5Io/47IH1qFIPnljcT14HxNfVtGpXS3yXAc4zZ2jkDKFU40cAe0qwY0oqE6QP7VNbo8avTAueTdi5oV4X5yPc+f59q9fiopiE9+5pGsx/9Ro/Qn+EWWCBG7utnSceuK20B0DID0x0NZRtcTu/lheevw6/wqmd3rb7ZDxXi4XgE=
- secure: XDlwoi/3Cgb2nWPD24/Ioq/RNLr3gQwAgdchSfil7VfAR7k2O+xHGnI50A9caOmoChd4FeIsBdppErX0xNe+nFEddjJlh2JXhUrd2xkf8juv6qVYJ+IoRh2oKWkTSDFxH8y/Om81ycd1NbSJ2g+qCrIPBKFVc0qpYTTlcXf2GoTsUrwMJcHTqoqhhd0QSWRQgiB+IlMQCJ3Ixm2G3Wark0XOSd/TB3W5Jz9+XnKFfIuqiBq7a2UxlBm0fy08tzYd8b+VFtd8nS2rtqwWaTLtpiXyqMJlrwgXsfML05GI3ig1ZoMm8YgvJwIa//C/IYqD/JiwfeIPxFXIekpM+abZXHJhn40I0dEkPBBEcFAvcMxo6b7n3cW8fu2JOZSxmUEwS+FULiLUMrTuxuQHHRh3wJCetrl4QRgvMoVqSfvMUtyrYKGsG+QyczZTVvD6+W9bkH2y4JafJAg0npbxOtvbyPVeDGeK8N9F89z0GoBYxQOubMx8wh5Xj84GCk94trwXsVI0jPffN9r64PS+Tofj7HHosgze3nmcw09a6/yi7akiScWxKiq/NFUgZuVYzcW6LX2nwe6PrGSLQrHCffwCZEg+pvM4xeApQ/rs9XTcmTenA4Ny786TEb+/kkXSFtklvBQs46dBRnCCzOk5LYHimo1B0XZigJ7P/y5XGmQIv30=
- secure: amUsFIN93YQwaq24tgGMKJgox2/96hL09RDxpXP90PlwuiIlp7V2fBKtdc2g73FwEBffXffK/ZVJCrrn/OvP2qR+PyDQSiaKTs76tVjpWdRTFJbvte3TFX4NPl+XsdCA3UuiwccNRTTJ+OIK1Xzhua2KT/wAFwVkbgdTzSWjVkRymVZJUWm+Nec6H0zuh1DaqCdIV1ZFiKf2CnH4FPJe2kIPX95qTdS203h0uiZjzRnt5asbMNs7CxowISgbTH3hwAQo2YPckWQZbfEEPft8zZWprW/YrW6YQrvFRTiTyydg8qQkMN3ai0bmPTp4Hs+pyFEZWkRaNGqI5r+97en/7X4AEL6R/Yzz1+q3vPE6h7SVAQ39Fxq5NuM2M8eWPUCC35z8SwzAj2UYh5QnrMdIj19J27RhrvQVLOs8ebKUjiRVSB2ZjwwFUBOOQWzCi3DZLpgSj1pR1q/xRC2OUhjLNEMSi1Bwz+/t/QwNVKUG8aJPAVBbsh5M5NKzuNr1Bot+wUhHZX2ZrUAVt2J4SK6g17EmTMz0veNhf8bQ9ezkTIWkkM+IvugJ0XwzMKlDNMFBO32lP/aRm+uZ+3+n/4OZTzSHh3IniwKsIBD5Zegbxjp1IkWk/IGFYEU7PaHZeIQmyo82GzJS0KLg9/2O6e0AcbZBZN0lItNNgIbRHY3yZeg=
- secure: pifLS+4pJDZmnx1TwSr349RoF0xbQwQLPDTvl6PSUGwnAtFX8s7OyC61hTN247ISl3GdEUml87b7dRZ5zkGy8FaxgRaQFRgo2BJOyvC99sn6DL65Yh5xLn/MZl9xIM6roHBtFtuFBrQco5YLnmV1i8kHD9k3QLMbBke2JSZR2l/l2aFFkM1PDTsNUM0A3w3VvtPrMq8UVyY3H1WNV/h5l4Vf8a1l9sJd8LgcSBuToAGcSFu/EQxC/lIxOdZgUH/4JF/ETw8XbulEqA5aaqsyNsSe+Gtg31YEjbVbF3Pjh70qRc+LFy6nu0hPMN0wfVJBziNIs8QUJ5rQVCBECURzRnkayBUAZuwyeJmGXWsTzf7FZxCRXpJBsOLRIn202dGy26pfMKMoDGXJ5Y29GeLqRPvosvJpTJ/dTQWpztdpS028KpAFN6aKCbM6yBwPfQ2UtXoseJVdkf/NaqNa9luWD2r2blDbZl1mdAkbxkc/wCqtuiIz4E/2GrMPL6rIo7W+axN0rQiqEs2Ai8peSUBw4ZTIux1ZSijvbszX+gp0shiUHfHtxmeao48gIZ3DsZ5Te4YCszY6xYfFbs5clFsio5ZG0A/xdZm971rJK7yfPb5tDXeqBpr5MNNIvjCDujjDLAVY0/VD4+akgTfaXiMwuL6xi++oHNYCzsuutZF5XyA=
10 changes: 9 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -106,6 +106,14 @@ $ docker run --env-file .env todo-app:test e2e_tests

# Deploying the application

The application is deployed with azure and is accessible at https://charlie-devops-to-do.azurewebsites.net/
The application is deployed with azure and is accessible at https://prod-charlie-devops-to-do.azurewebsites.net/

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not sure if you changed your plan, but I was actually able to access it at:
http://charlie-devops-to-do-terraform.azurewebsites.net/


New deployments are automatically triggered when commits are made to the main branch.

# Terraform

Running terraform locally requires that an access secret is first loaded from the keyvault. This can be done as follows:
```bash
$ az login
$ export ARM_ACCESS_KEY=$(az keyvault secret show --name terraform-backend-key --vault-name to-do-app --query value -o tsv)
```
4 changes: 3 additions & 1 deletion deploy.sh
Original file line number Diff line number Diff line change
Expand Up @@ -4,4 +4,6 @@ docker image tag todo-app "${DOCKER_USERNAME}/todo-app:${TRAVIS_COMMIT}"
echo "$DOCKER_PASSWORD" | docker login -u "$DOCKER_USERNAME" --password-stdin
docker push "${DOCKER_USERNAME}/todo-app:latest"
docker push "${DOCKER_USERNAME}/todo-app:${TRAVIS_COMMIT}"
curl -dH -X POST "$DEPLOY_WEBHOOK"

set -e
curl -dH -X POST "$(terraform output -raw cd_webhook)"
85 changes: 85 additions & 0 deletions main.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
terraform {
required_providers {
azurerm = {
source = "hashicorp/azurerm"
version = ">= 2.49"
}
}
backend "azurerm" {
resource_group_name = "SoftwirePilot_CharlieCumber_ProjectExercise"
storage_account_name = "tfstater1khr"
container_name = "tfstate"
key = "terraform.tfstate"
}
}

provider "azurerm" {
features {}
}

data "azurerm_resource_group" "main" {
name = "SoftwirePilot_CharlieCumber_ProjectExercise"
}

resource "azurerm_app_service_plan" "main" {
name = "${var.prefix}terraformed-asp"
location = data.azurerm_resource_group.main.location
resource_group_name = data.azurerm_resource_group.main.name
kind = "Linux"
reserved = true
sku {
tier = "Basic"
size = "B1"
}
}

resource "azurerm_cosmosdb_account" "main" {
name = "${var.prefix}charlie-devops-cosmosdb-account"
resource_group_name = data.azurerm_resource_group.main.name
kind = "MongoDB"
location = data.azurerm_resource_group.main.location
geo_location {
location = data.azurerm_resource_group.main.location
failover_priority = 0
}
consistency_policy {
consistency_level = "Session"
}
offer_type = "Standard"
capabilities {
name = "EnableServerless"
}
capabilities {
name = "EnableMongo"
}
lifecycle {
prevent_destroy = true
}
}

resource "azurerm_cosmosdb_mongo_database" "main" {
name = "${var.prefix}charlie-devops-cosmos-mongo-db"
resource_group_name = data.azurerm_resource_group.main.name
account_name = azurerm_cosmosdb_account.main.name
}

resource "azurerm_app_service" "main" {
name = "charlie-devops-to-do-terraform"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's good practice to prefix everything, that way you can tell what's terraformed and can have multiple instances of the infrastructure.

location = data.azurerm_resource_group.main.location
resource_group_name = data.azurerm_resource_group.main.name
app_service_plan_id = azurerm_app_service_plan.main.id
site_config {
app_command_line = ""
linux_fx_version = "DOCKER|charliecumber/todo-app:latest"
}
app_settings = {
MONGODB_CONNECTION_STRING = "mongodb://${azurerm_cosmosdb_account.main.name}:${azurerm_cosmosdb_account.main.primary_key}@${azurerm_cosmosdb_account.main.name}.mongo.cosmos.azure.com:10255"
MONGODB_DATABASE_NAME = var.MONGODB_DATABASE_NAME
DOCKER_REGISTRY_SERVER_URL = "https://index.docker.io/v1"
DOCKER_ENABLE_CI = true
AUTH_CLIENT_ID = var.AUTH_CLIENT_ID
AUTH_CLIENT_SECRET = var.AUTH_CLIENT_SECRET
SECRET_KEY = var.SECRET_KEY
OAUTHLIB_INSECURE_TRANSPORT = 1
}
}
7 changes: 7 additions & 0 deletions outputs.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
output "cd_webhook" {
value = "https://${azurerm_app_service.main.site_credential[0].username}:${azurerm_app_service.main.site_credential[0].password}@${azurerm_app_service.main.name}.scm.azurewebsites.net/docker/hook"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should mark this output as sensitive since it contains a password - that way Terraform will avoid logging it unless explicitly told to

}
Comment on lines +1 to +3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should be marked as sensitive = true so Terraform doesn't print it out, it has your App Service's deployment password in.

https://app.travis-ci.com/github/CharlieCumber1/DevOps-Course-Starter-Module-3/builds/233145846#L2025

You can change the password in the Azure portal, go to the App Service -> Container settings (Classic) -> FTPS credentials -> Application scope and reset the password.


output "webapp_url" {
value = "https://${azurerm_app_service.main.default_site_hostname}"
}
20 changes: 20 additions & 0 deletions remote-state.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
resource "random_string" "resource_code" {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We wouldn't usually track the storage account for the terraform state in terraform - you can't safely create the account until there's somewhere to store state, and obviously you can't create the state until the storage account exists. If you now tried to rename one of these resources, causing a destroy/recreate, then we'd lose the existing state. Curious to know if you disagree and there is some clever workaround/solution for this

length = 5
special = false
upper = false
}

resource "azurerm_storage_account" "tfstate" {
name = "tfstate${random_string.resource_code.result}"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You don't normally manage Terraform's backend state with Terraform. It means you can't recreate everything with one terraform apply, and can't use workspaces for different environments.

If you delete this file you'll need to remove these objects from the state so Terraform doesn't destroy them, e.g. terraform state rm 'azurerm_storage_account.tfstate'.

resource_group_name = data.azurerm_resource_group.main.name
location = data.azurerm_resource_group.main.location
account_tier = "Standard"
account_replication_type = "LRS"
allow_blob_public_access = true
}

resource "azurerm_storage_container" "tfstate" {
name = "tfstate"
storage_account_name = azurerm_storage_account.tfstate.name
container_access_type = "blob"
}
1 change: 0 additions & 1 deletion todo_app/app.py
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,6 @@ def load_user(user_id):

@app.route('/login/')
def login():
code = request.args.get('code')
token_request_url, token_request_headers, token_request_body = auth_client.prepare_token_request(token_url, authorization_response=request.url, client_secret=client_secret)
token_request_response = requests.post(token_request_url, headers=token_request_headers, data=token_request_body)
auth_client.parse_request_body_response(token_request_response.content.decode())
Expand Down
26 changes: 26 additions & 0 deletions variables.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
variable "prefix" {
description = "The prefix used for all resources in this environment"
default = "prod-"
}

variable "location" {
description = "The Azure location where all resources in this deployment should be created"
default = "uksouth"
}

variable "AUTH_CLIENT_ID" {
description = "GitHub client ID for authentication."
}

variable "AUTH_CLIENT_SECRET" {
description = "GitHub client secret for authentication."

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As with the outputs, we should mark any sensitive input variables as such to avoid them potentially being printed out in logging anywhere

}

variable "SECRET_KEY" {
description = "The Azure secret key"
}
Comment on lines +15 to +21

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These should both be marked as sensitive = true so they don't get printed in terraform plan output.

(Also the SECRET_KEY is for signing Flask's session cookies, not really Azure related)


variable "MONGODB_DATABASE_NAME" {
description = "Name of default database"
default = "main"
}