IaC
CDKTF
Cloud Development Kit for Terraform (CDKTF) allows you to use familiar programming languages to define and provision infrastructure. This gives you access to the entire Terraform ecosystem without learning HashiCorp Configuration Language (HCL) and lets you leverage the power of your existing toolchain for testing, dependency management, etc.
License: https://github.com/hashicorp/terraform-cdk/blob/main/LICENSE (MPL)
Reference: https://developer.hashicorp.com/terraform/cdktf
Stacks
Overview
Terraform remote state will be stored in S3.
Networking
Includes:
- VPC
- Public Subnets
- Private Subnets
- Database Private Subnets
- Elastic IP (EIP)
- NAT Gateway
- Intenet Gateway
- Public Route Table
- Private Route Table
Computing
Includes:
- EKS Cluster
- Node Group
- IAM for EKS
- IAM for Node Group
- Security Group for EKS
- Security Group for Node Group
Dependencies:
- Networking Stack
- Storage Stack
- Helm Stack
- Helm Stack
Database
Includes:
- IAM for RDS PostgreSQL
- IAM for Redis
- Security Group for RDS PostgreSQL
- Security Group for Redis
Dependencies:
- Networking Stack
- EKS Security Group
Storage
Includes:
- Secrets Manager
- S3
- EFS
- CloudWatch
Helm
Includes:
- Load Balancer Controller
- ArgoCD
- ElasticSearch
- Kibana
- Fluent Bit
Other Services
Includes:
- Kafka Cluster (MSK)
- Grafana
- SES
- SNS
DEMO
Backend
In this demostration, we will
- Create Networking Stack
- Test creating variable for vpc id and store into GitHub
- Create EKS cluster that associate with the Networking Stack in step 1
- Create initial node group and IAM roles for the node group that associate with EKS cluster in step 2
- Install ArgoCD with Helm
- Install Karpenter with Helm
- Install Load Balancer Controller with Helm
- Test Karpenter auto scaling
- Test ArgoCD
Karpenter Provisioner
---
apiVersion: karpenter.sh/v1alpha5
kind: Provisioner
metadata:
name: default
spec:
labels:
nodeType: karpenter
ttlSecondsAfterEmpty: 60 # scale down nodes after 60 seconds without workloads (excluding daemons)
ttlSecondsUntilExpired: 604800 # expire nodes after 7 days (in seconds) = 7 * 60 * 60 * 24
limits:
resources:
cpu: 100 # limit to 100 CPU cores
requirements:
# Include general purpose instance families
- key: node.kubernetes.io/instance-type
operator: In
values: ["t3.small", "t3.medium"]
providerRef:
name: my-provider
---
apiVersion: karpenter.k8s.aws/v1alpha1
kind: AWSNodeTemplate
metadata:
name: my-provider
spec:
subnetSelector:
kubernetes.io/cluster/ob-eks-dev: owned
securityGroupSelector:
kubernetes.io/cluster/ob-eks-dev: owned
Handbook
Deploy vpc/eks stack
cdktf deploy vpc eks --auto-approve
Deploy nodegroup
cdktf deploy ng ng-iam eks vpc --auto-approve
Deploy karpenter
cdktf deploy karpenter ng-iam --auto-approve
Deploy karpenter provisioner
cdktf deploy provisioner --auto-approve
Deploy ArgoCD
cdktf deploy argo --auto-approve
Get ArgoCD Admin Default Password
kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath="{.data.password}" | base64 -d
Start ArgoCD in localhost
kubectl port-forward -n argocd svc/argocd-server 8000:80
Deploy load balancer controller
cdktf deploy lbc --auto-approve
Deploy Testing App
cdktf deploy app --auto-approve
DNS
cdktf deploy app lbc cfdns --auto-approve
Delete k8s context
kubectl config delete-context arn:aws:eks:ap-southeast-1:479397374389:cluster/obk-eks-uat
Update k8s context
aws eks update-kubeconfig --region ap-southeast-1 --name obk-eks-uat
Start Hello K8s app in localhost
kubectl port-forward svc/hello-k8s 8001:8080
Scale up apps
kubectl scale deploy/inflate --replicas=5
Spam traffic
ab -n 10000 -c 1000 https://ob-iac-demo.make-project.fun/
Cleanup
cdktf destroy cfdns --auto-approve
cdktf destroy app argo lbc provisioner karpenter --auto-approve
cdktf destroy vpc eks ng-iam ng karpenter --auto-approve