diff options
author | Vincent Ambo <mail@tazj.in> | 2019-09-03T15·26+0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2019-09-03T15·26+0100 |
commit | 628cec34331ea7ef94a71f562a0dc1f8d49e9ecf (patch) | |
tree | fe6be2f9756627ac09c3207f876430921789baec /infra/gcp | |
parent | be28462a8a29403128b39696cc632f70363efa6e (diff) | |
parent | 283951388c96e871c9c4a835eee6594fc27e08c0 (diff) |
Merge pull request #5 from tazjin/feat/cloud-kms-secrets r/80
Introduce secrets management via Google Cloud KMS
Diffstat (limited to 'infra/gcp')
-rw-r--r-- | infra/gcp/default.tf | 37 |
1 files changed, 26 insertions, 11 deletions
diff --git a/infra/gcp/default.tf b/infra/gcp/default.tf index 677e737a242e..d13345393bd4 100644 --- a/infra/gcp/default.tf +++ b/infra/gcp/default.tf @@ -27,24 +27,25 @@ resource "google_project_services" "primary" { "bigquerystorage.googleapis.com", "cloudapis.googleapis.com", "clouddebugger.googleapis.com", + "cloudkms.googleapis.com", "cloudtrace.googleapis.com", + "compute.googleapis.com", + "container.googleapis.com", + "containerregistry.googleapis.com", "datastore.googleapis.com", "dns.googleapis.com", + "iam.googleapis.com", + "iamcredentials.googleapis.com", "logging.googleapis.com", "monitoring.googleapis.com", + "oslogin.googleapis.com", + "pubsub.googleapis.com", "servicemanagement.googleapis.com", "serviceusage.googleapis.com", + "sourcerepo.googleapis.com", "sql-component.googleapis.com", "storage-api.googleapis.com", "storage-component.googleapis.com", - "container.googleapis.com", - "iam.googleapis.com", - "compute.googleapis.com", - "iamcredentials.googleapis.com", - "oslogin.googleapis.com", - "pubsub.googleapis.com", - "containerregistry.googleapis.com", - "sourcerepo.googleapis.com", ] } @@ -82,7 +83,21 @@ resource "google_service_account" "nixery" { display_name = "Nixery service account" } -# Configure a git repository in which to store my monorepo -resource "google_sourcerepo_repository" "monorepo" { - name = "monorepo" +# Configure Cloud KMS for secret encryption +resource "google_kms_key_ring" "tazjins_keys" { + name = "tazjins-keys" + location = "europe-north1" + + lifecycle { + prevent_destroy = true + } +} + +resource "google_kms_crypto_key" "kontemplate_key" { + name = "kontemplate-key" + key_ring = google_kms_key_ring.tazjins_keys.id + + lifecycle { + prevent_destroy = true + } } |