Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Terraform at Wantedly (Tech-Circle #12)
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
Daisuke Fujita
January 29, 2016
Programming
840
2
Share
Terraform at Wantedly (Tech-Circle #12)
Tech-Circle #12 Terraform Handson での LT 発表資料です
http://techcircle.connpass.com/event/25496/
Daisuke Fujita
January 29, 2016
More Decks by Daisuke Fujita
See All by Daisuke Fujita
SREcon19 Asia/Pacific Recap
dtan4
0
220
Our Practices of Delegating Ownership in Microservices World
dtan4
4
9k
Kubernetes Cluster Upgrade / Mercari Meetup for Microservices Platform
dtan4
3
4.8k
KubeCon EU 2018 Recap: Multi-Tenancy in Kubernetes: Best Practices Today, and Future Directions / Kubernetes Meetup Tokyo 11 #k8sjp
dtan4
1
2k
Wantedly から Chef を一掃した話 / #chibadan
dtan4
24
11k
さようなら Chef こんにちは Dockerfile / Web Tech Tokyo #1
dtan4
6
7.3k
Docker をフル活用したインフラの紹介と成長し続けるためのインフラ戦略 / #abejameetup
dtan4
19
4.1k
Docker Compose PaaS の作り方、そして社内に導入した話 / #yapc8oji
dtan4
1
8.7k
Writing Kubenetes tools in Go
dtan4
1
3.8k
Other Decks in Programming
See All in Programming
net-httpのHTTP/2対応について
naruse
0
400
tsserverとは何だったのか、これからどうなるのか
nowaki28
1
430
脅威をエンジニアリングの糧にして――現場編 / Turning Threats into Engineering Fuel — Field Edition
nrslib
0
220
OCRを使ってゲームのアイテムをデータ化する
kishikawakatsumi
0
120
DynamoDBには集計系のクエリがないけどなんとかしたい
musan
1
110
運用エージェントは "作る" から "育てる" へ - 記憶と自己進化の3層設計パターン / self-evolving-agents-three-layer-agent-design
gawa
12
3.3k
気づいたらRubyで100作品 ー クリエイティブコーディングが生活の一部になるまで / 100 Ruby Sketches Later: How Creative Coding Became Part of My Life
chobishiba
3
520
密結合なバックエンドから TypeScript のコードを生成する
kemuridama
1
430
Inside Stream API
skrb
1
490
New "Type" system on PicoRuby
pocke
1
400
AIエージェントと協働するCLI開発 — BunとOpenClawで学んだこと
yoshikouki
1
230
ビジネスモデルから紐解く、AI+型駆動開発
hirokiomote
2
5.1k
Featured
See All Featured
The MySQL Ecosystem @ GitHub 2015
samlambert
251
13k
Darren the Foodie - Storyboard
khoart
PRO
3
3.4k
Ethics towards AI in product and experience design
skipperchong
2
290
Money Talks: Using Revenue to Get Sh*t Done
nikkihalliwell
0
240
Everyday Curiosity
cassininazir
0
220
Visual Storytelling: How to be a Superhuman Communicator
reverentgeek
2
540
Abbi's Birthday
coloredviolet
2
7.8k
Lightning talk: Run Django tests with GitHub Actions
sabderemane
0
190
SEOcharity - Dark patterns in SEO and UX: How to avoid them and build a more ethical web
sarafernandez
0
190
Six Lessons from altMBA
skipperchong
29
4.3k
Agile that works and the tools we love
rasmusluckow
331
21k
From π to Pie charts
rasagy
0
200
Transcript
TERRAFORM at WANTEDLY 2016-01-29 Tech-Circle #12 Terraform Handson @dtan4
Daisuke Fujita @dtan4 Πϯλʔϯ @ΠϯϑϥνʔϜ
None
None
Terraform flow @ Wantedly since May 2015
Terraform Ͱཧ͍ͯ͠Δ 28 resource types aws_customer_gateway aws_db_instance aws_db_parameter_group aws_db_security_group aws_db_subnet_group
aws_elasticache_cluster aws_elasticache_subnet_group aws_elb aws_iam_group aws_iam_group_membership aws_iam_group_policy aws_iam_role aws_iam_role_policy aws_iam_user aws_iam_user_policy aws_instance aws_internet_gateway aws_network_acl aws_route_table aws_route_table_association aws_s3_bucket aws_security_group aws_subnet aws_vpc aws_vpn_connection aws_vpn_connection_route aws_vpn_gateway dnsimple_record
Terraform Ͱཧ͍ͯ͠Δ AWS 224 DNSimple 169 393 resources
Terraform ڥ GitHub wercker S3 remote backend Vagrant CoreOS Docker
quay.io/wantedly/terraform 3FNPUF -PDBM
Terraform flow Terraform ίʔυΛॻ͍ͯ Pull Request Λग़͢
Terraform flow Terraform ίʔυΛॻ͍ͯ Pull Request Λग़͢
Terraform flow CI Ͱςετ (terraform plan) ͕Δ
Terraform flow CI Ͱςετ (terraform plan) ͕Δ
Terraform flow ΠϯϑϥνʔϜ͕ϨϏϡʔͯ͠ Merge
Terraform flow CI Ͱ࣮ڥͷద༻ (terraform apply) ͕ߦΘΕΔ
e.g. DNS ϨίʔυՃ
e.g. IAM ϢʔβՃ ৽͍͠։ൃϝϯόʔͷ௨աّྱ
e.g. GitHub ্Ͱ֬ೝͰ͖ͯศར
Terraform ಋೖͷաఔ
ಋೖͨ͠ܦҢ • Management Console ϙνϙνۀ͔Βͷ٫ • ΠϯϑϥνʔϜͷ࡞ۀूத͔Βͷ٫ • ߏங࡞ۀͷཤྺΛ͍ͨ͠ •
ϦιʔεҰཡΛ ͩΕͰ؆୯ʹݟΒΕΔΑ͏ʹ͍ͨ͠ • ϦιʔεෳΛָʹ͍ͨ͠ • AWS ͱ DNSimple Ұॹʹѻ͑ͯศར
Ұ͔ΒΠϯϑϥߏஙϦϓϨʔεͰͳ͘ɺ ͍·ಈ͍͍ͯΔΠϯϑϥϦιʔε ΛίʔυԽ͍ͨ͠ resource "aws_instance" "app" { count = 4
ami = "ami-408c7f28" instance_type = "t1.micro" } resource "aws_instance" "app" { count = 4 ami = "ami-408c7f28" instance_type = "t1.micro" }
ݱߦڥͷ Terraform ಋೖ https://github.com/hashicorp/terraform/issues/581
ݱߦڥͷ Terraform ಋೖ https://github.com/hashicorp/terraform/issues/581 طଘϦιʔε͔Β Terraform ίʔυ Λੜ͢Δػೳ࣮͞Ε͍ͯͳ͍
ݱߦڥͷ Terraform ಋೖ ex: hoge ͱ͍͏ S3 bucket ͕͋ͬͨͱ͖ resource
"aws_s3_bucket" "hoge" { bucket = "hoge" acl = "private" } { "version": 1, "serial": 1, "modules": { "path": [ "root" ], "outputs": { }, "resources": { "aws_s3_bucket.hoge": { "type": "aws_s3_bucket", "primary": { "id": "hoge", "attributes": { "acl": "private", "bucket": "hoge", "id": "hoge" } } } } } } TUG UFSSBGPSNUGTUBUF
ݱߦڥͷ Terraform ಋೖ ex: hoge ͱ͍͏ S3 bucket ͕͋ͬͨͱ͖ resource
"aws_s3_bucket" "hoge" { bucket = "hoge" acl = "private" } { "version": 1, "serial": 1, "modules": { "path": [ "root" ], "outputs": { }, "resources": { "aws_s3_bucket.hoge": { "type": "aws_s3_bucket", "primary": { "id": "hoge", "attributes": { "acl": "private", "bucket": "hoge", "id": "hoge" } } } } } } TUG UFSSBGPSNUGTUBUF tfstate (JSON) ਓྗͰॻ͘ͷݫ͍͠
Export existing AWS resources to Terraform style (tf, tfstate) dtan4/terraforming
Terraforming • طଘͷ AWS / DNSimple Ϧιʔε͔Β Terraform ͷίʔυ (tf,
tfstate) Λੜ͢Δ ίϚϯυϥΠϯπʔϧ • 29छྨͷ AWS ϦιʔεʹରԠ • Wantedly ͷ Terraform ίʔυͷେΛੜ • Issue & Pull Request ͓·ͪͯ͠·͢ʂ dtan4/terraforming $ gem install terraforming # or $ docker pull quay.io/dtan4/terraforming
None
Terraforming • S3 buckets ͷ tf Λੜ • S3 buckets
ͷ tfstate Λੜ • S3 buckets ͷ tfstate Λੜ͠ɺ طଘͷ terraform.tfstate ͱϚʔδ $ terraforming s3 $ terraforming s3 --tfstate \ --merge=/path/to/terraform.tfstate $ terraforming s3 --tfstate dtan4/terraforming
http://qiita.com/dtan4/items/345c56281ab0e87d6646
ૺ۰ͨ͠
terraform plan ͕৴༻ग़དྷͳ͍ • HCL ͷγϯλοΫενΣοΫͱ Terraform ύϥϝʔλͷνΣοΫͷΈɺ API ͷ
dry-run ͠ͳ͍ • terraform plan ͕௨ͬͯɺύϥϝʔλ͕ AWS తʹෆਖ਼Ͱ terraform apply ʹࣦഊ͢Δ • CI Ͱʮςετʯ͍ͯ͠Δҙຯ͕…
terraform plan ͕৴༻ग़དྷͳ͍ • AWS ͷυΩϡϝϯτಡ·ͳ͍ͱ͍͚ͳ͍ • terraform apply ࣦഊͯ͠ϦΧόϦͰ͖Δ
ΈΛ࡞Δ • खݩͰ apply Ͱ͖Δڥ
ELB ԼͷΠϯελϯε͕ ҙਤͤͣஔ͖ΘΔ • Terraform ͷ ELB resource Δ͢ΠϯελϯεΛ໌ࣔతʹॻ͘ඞཁ͋Γ
• Wantedly ͰࣗલπʔϧͰ Πϯελϯεͷ૿ݮɺELB ͷΔ͠Λߦ͏ • Terraform ίʔυͱ࣮ࡍͷڥʹࠩҟ͕ग़Δ
ELB ԼͷΠϯελϯε͕ ҙਤͤͣஔ͖ΘΔ • සൟʹΠϯελϯε͕ஔ͖ΘΔ ELB Terraform Ͱཧ͠ͳ͍͜ͱʹͨ͠ •
֎෦Ͱಈతͳมߋ͕͋Γ͏ΔϦιʔε ͋͑ͯཧ͠ͳ͍ • Terraform v0.6.4 Ͱ ignore_changes ͕ಋೖ resource "aws_elb" "foo" { lifecycle { ignore_changes = ["instances"] } }
IAM ϢʔβআͰࣦഊ • IAM ϢʔβࣗମΛফ͢લʹΫϨσϯγϟϧ ϩάΠϯϓϩϑΝΠϧΛফ͢ඞཁ͕͋Δ • Terraform ͦΜͳͷ͓ߏ͍ͳ͠ʹ delete-user
͠Α͏ͱ͢Δ • खಈͰґଘϦιʔεΛফ্ͨ͠Ͱ apply http://docs.aws.amazon.com/ja_jp/IAM/latest/UserGuide/Using_DeletingUserFromAccount.html
·ͱΊ
·ͱΊ • Wantedly ͷΠϯϑϥ Terraform Ͱཧ͞Ε͍ͯ·͢ʂ • ݱߦΠϯϑϥΛ Terraform Ͱཧ͢ΔͨΊʹ
Terraforming ͱ͍͏πʔϧΛ։ൃ͠·ͨ͠ • ͯ͢Λ Terraform ʹ͖ͤͬΓʹ͠ͳ͍