added service account for db backups and changed terraform to include bucket and service accounts

This commit is contained in:
sirius0xdev 2026-02-02 23:20:46 +00:00
parent 6abd076ed4
commit 995baa64cb
10 changed files with 167 additions and 44 deletions

View file

@ -27,4 +27,13 @@ spec:
owner: customer1 owner: customer1
secret: secret:
name: customer1-db-credentials name: customer1-db-credentials
serviceAccountTemplate:
metadata:
annotations:
iam.gke.io/gcp-service-account: cnpg-backup-sa@devops-lab-cluster.iam.gserviceaccount.com
backup:
barmanObjectStore:
destinationPath: "gs://customer1_db_backup/customer1-backups/"
googleCredentials:
gkeEnvironment: true

View file

@ -0,0 +1,8 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: cnpg-backup-sa
namespace: customer1
annotations:
iam.gke.io/gcp-service-account: cnpg-backup-sa@devops-lab-cluster.iam.gserviceaccount.com

View file

@ -1,5 +1,5 @@
[tools] [tools]
gcloud = "latest" gcloud = "latest"
k9s = "latest" kubectl = "latest"
sops = "latest" sops = "latest"
terraform = "latest" terraform = "latest"

View file

@ -1,27 +1,6 @@
# This file is maintained automatically by "terraform init". # This file is maintained automatically by "terraform init".
# Manual edits may be lost in future updates. # Manual edits may be lost in future updates.
provider "registry.terraform.io/fluxcd/flux" {
version = "1.7.6"
hashes = [
"h1:Zciva4ZlK4Oqg6cAnFoKUOVpEkJvZx/xbCvE4xbFSWY=",
"zh:08f1d43cc4d0d73beb26e433126ef68434ae1b88a945f3c7403e93ef8ce40b16",
"zh:0a27c7876f2399a66049deae0a2f0ba2233a8eddd3a45560eff6e20dac279317",
"zh:199ba361e9cbbb0289094480be7d1cdaae1796dcdbddb40bf5d3ee9c5aeb4483",
"zh:44ea3043649059b6884031b9e31016fad62dcb1e724dae29e5012a8ad4007039",
"zh:467f67a39b60ff247ead85d689cbdbaff2baac7693804a2a24857cb4824e2cc6",
"zh:4b910e6a1e4b65e838d4f2bb5965ff4b54ea315b35ae60ee5b17ceed1a75d11a",
"zh:5418c8ca39db1bb5e65edc4a976d3cb0140b30cbe63814287a3b7f36f14978ec",
"zh:6a2dad787674fd2219cb6a6d72d2e77500aba1c5b527db7c3e4d6fedb10d40db",
"zh:7cf60dc7fa3a7f9323aa8d036e931348482fb69340e6238caff21ec49e941bef",
"zh:8802c20134830ea46ef9214498c0539d3b63d7b0d0af82cfa6731ca7d41390c4",
"zh:9f20bcf0fda0ac6a3a162566537d8319bec377617cbec58d4c0805c9088d107c",
"zh:ace15c081c466984beecee05b9b072bfdf563020eccab6ed6ae7004238602f82",
"zh:d39a431d592629c23a4fb04ebc44c24b2bc68f03c5b85d5830fb21da0f025d9b",
"zh:fce784eb774155ccd9a87663d2dc9aa3e82e4fd495d8adb304301adf756a8f63",
]
}
provider "registry.terraform.io/hashicorp/google" { provider "registry.terraform.io/hashicorp/google" {
version = "7.14.1" version = "7.14.1"
hashes = [ hashes = [

42
modules/db-bucket.tf Normal file
View file

@ -0,0 +1,42 @@
resource "google_storage_bucket" "backup_bucket" {
name = "customer1_db_backup"
location = "US"
storage_class = "STANDARD"
uniform_bucket_level_access = true
versioning {
enabled = true
}
lifecycle {
prevent_destroy = true
}
}
resource "google_service_account" "cnpg_backup_sa" {
account_id = "cnpg-backup-sa"
display_name = "CNPG PostgreSQL GCS Backup SA"
description = "Used by CNPG operator pods for GCS backup access via Workload Identity"
}
# Grant minimal Storage permissions (adjust as needed)
resource "google_project_iam_member" "cnpg_backup_sa_storage" {
project = var.project_id
role = "roles/storage.objectAdmin" # Or finer: roles/storage.objectCreator + roles/storage.objectViewer + roles/storage.legacyBucketReader
member = "serviceAccount:${google_service_account.cnpg_backup_sa.email}"
}
resource "google_service_account_iam_binding" "workload_identity_binding" {
service_account_id = google_service_account.cnpg_backup_sa.name
role = "roles/iam.workloadIdentityUser"
members = [
"serviceAccount:${var.project_id}.svc.id.goog[${var.namespace}/${var.ksa_name}]"
]
}
# Outputs (useful for cross-reference or verification)
output "gcp_sa_email" {
value = google_service_account.cnpg_backup_sa.email
}

View file

@ -32,4 +32,59 @@ resource "google_container_cluster" "primary" {
enable_l4_ilb_subsetting = true enable_l4_ilb_subsetting = true
deletion_protection = false deletion_protection = false
lifecycle {
ignore_changes = [
enable_autopilot,
enable_tpu,
enable_intranode_visibility,
resource_labels,
addons_config,
anonymous_authentication_config,
binary_authorization,
cluster_autoscaling,
database_encryption,
default_snat_status,
gateway_api_config,
logging_config,
control_plane_endpoints_config,
cost_management_config,
enterprise_config,
gke_auto_upgrade_config,
identity_service_config,
node_config,
node_config[0].spot, # or node_config.spot if not indexed
node_config[0].preemptible, # sometimes shown as this
node_config[0].disk_size_gb,
node_config[0].disk_type,
node_config[0].metadata,
node_config[0].resource_labels,
node_config[0].boot_disk,
# IP policy sub-drift
ip_allocation_policy,
# Auth/cert drift
master_auth,
# Computed/read-only (removes warnings too)
endpoint,
self_link,
label_fingerprint,
operation,
cluster_ipv4_cidr,
services_ipv4_cidr,
node_locations,
default_max_pods_per_node,
networking_mode,
private_ipv6_google_access,
tpu_ipv4_cidr_block,
master_version,
node_version,
logging_service,
monitoring_service,
]
}
} }

View file

@ -10,27 +10,34 @@ provider "google" {
provider "helm" { provider "helm" {
kubernetes { kubernetes {
host = "https://${google_container_cluster.primary.endpoint}" host = "https://${google_container_cluster.primary.endpoint}"
token = data.google_client_config.default.access_token
cluster_ca_certificate = base64decode(google_container_cluster.primary.master_auth[0].cluster_ca_certificate) cluster_ca_certificate = base64decode(google_container_cluster.primary.master_auth[0].cluster_ca_certificate)
exec = {
api_version = "client.authentication.k8s.io/v1beta1"
command = "gke-gcloud-auth-plugin"
}
} }
} }
provider "flux" { ##provider "flux" {
kubernetes = { ##kubernetes = {
host = "https://${google_container_cluster.primary.endpoint}" ## host = "https://${google_container_cluster.primary.endpoint}"
token = data.google_client_config.default.access_token ## cluster_ca_certificate = base64decode(google_container_cluster.primary.master_auth[0].cluster_ca_certificate)
cluster_ca_certificate = base64decode(google_container_cluster.primary.master_auth[0].cluster_ca_certificate)
}
git = { ## exec = {
## api_version = "client.authentication.k8s.io/v1beta1"
## command = "gke-gcloud-auth-plugin"
## }
##}
url = "ssh://git@github.com/${var.github_org}/${var.github_repository}.git" ## git = {
## url = "ssh://git@github.com/${var.github_org}/${var.github_repository}.git"
## branch = "master"
## ssh = {
## username = "git"
## private_key = (file("~/.ssh/gcloud-lab"))
## }
##}
branch = "master"
ssh = {
username = "git"
private_key = (file("~/.ssh/gcloud-lab"))
}
}
}

View file

@ -16,3 +16,23 @@ variable "github_repository" {
type = string type = string
default = "" default = ""
} }
variable "project_id" {
type = string
description = "Gcloud project id"
}
variable "namespace" {
type = string
default = "cnpg-system"
}
variable "ksa_name" {
type = string
default = "cnpg-backup-sa"
}
variable "gcs_bucket_name" {
type = string
}

View file

@ -1,3 +1,6 @@
#!/bin/bash #!/bin/bash
/usr/local/bin/mise trust /workspaces/gcloud-lab/mise.toml && /usr/local/bin/mise install /usr/local/bin/mise trust /workspaces/gcloud-lab/mise.toml && /usr/local/bin/mise install
curl -sSfL \
https://github.com/cloudnative-pg/cloudnative-pg/raw/main/hack/install-cnpg-plugin.sh | \
sudo sh -s -- -b /usr/local/bin