Infrastructure is using Terraform to manage Azure resources.
- IaC: Infrastructure as code
- Replicable infrastructure (Teams interested on using IaC can take this repo and adapt it to their requirements)
- Centralized and easy to maintain with peer review for increased visiblity regarding changes.
- State aware (Which means that it can be run automatically in pipelines without worrying of the existent recources being duplicated)
- These terraform scripts create 2 AKS clusters in westus2 and eastus2
- Init (Needs to be ran every time we add a new provider)
terraform init
- Plan (Describe all the actions that will take place, it is recommended to have an output file)
terraform plan -out tf.plan
- Apply ()
terraform apply tf.plan
- Scripts in
aks-shared-resources
folder create common azure resources for AKS- Resource Group for AKS clusters
- Azure Container Registry
- Front Door
- Log Analytics Workspace
- Application Insights
- Scripts in
aks-cluster
folder create various AKS resources- AKS Cluster
- Public Ip
- Namespaces
- AKS Dashboard
- Cert Manager
- Ingress Controller
- Ingress Rules
- Horizontal Pod Autoscaler
- Keyvault AKS Access Policy
- ACR AKS Role Assignment
- Resource group with name
terraform-storage-rg
- Storage account
- Storage account with name
terraformstate12
in the above resource group - Container within the above storage account with name
tfstatefiles
- Storage account with name
- Key vault
- Key vault with name
terraform-integration-1
in the above resource group
- Key vault with name
- Storage account
-
In
terraform-manifests/aks-shared-resources/variable.tf
, change the following variables default values to unique names.- log_analytics_workspace_name
- acr_prefix
- application_insights_name
- proj_id
-
In
terraform-manifests/aks-cluster/variable.tf
, change the following variables default values to unique names.
-
Provide access to a Service Principal Name which would be used to run the pipeline to create azure resources
-
Replace
aadGroupId
in theazure-pipelines.yml
which is required to integrate Azure Active Directory with Azure Kubernetes Service. -
Create a CI/CD pipeline with
azure-pipelines.yml
file. Run this pipeline to create multiple aks clusters as configured in the scripts.
This project welcomes contributions and suggestions. Most contributions require you to agree to a Contributor License Agreement (CLA) declaring that you have the right to, and actually do, grant us the rights to use your contribution. For details, visit https://cla.opensource.microsoft.com.
When you submit a pull request, a CLA bot will automatically determine whether you need to provide a CLA and decorate the PR appropriately (e.g., status check, comment). Simply follow the instructions provided by the bot. You will only need to do this once across all repos using our CLA.
This project has adopted the Microsoft Open Source Code of Conduct. For more information see the Code of Conduct FAQ or contact opencode@microsoft.com with any additional questions or comments.
This project may contain trademarks or logos for projects, products, or services. Authorized use of Microsoft trademarks or logos is subject to and must follow Microsoft's Trademark & Brand Guidelines. Use of Microsoft trademarks or logos in modified versions of this project must not cause confusion or imply Microsoft sponsorship. Any use of third-party trademarks or logos are subject to those third-party's policies.