about summary refs log tree commit diff
path: root/corp/ops/yandex/main.tf
blob: cd8fa6e4cc67b3bb26eec235c8f34b3c84c1dc1c (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
# Terraform configuration for TVL corp infrastructure (on Yandex
# Cloud).

terraform {
  required_providers {
    yandex = {
      source = "yandex-cloud/yandex"
    }
  }

  # Credentials need to be sourced from creds.fish
  backend "s3" {
    endpoint = "storage.yandexcloud.net"
    bucket   = "su-tvl-terraform-state"
    region   = "ru-central1"
    key      = "corp/ops/terraform.tfstate"

    skip_region_validation      = true
    skip_credentials_validation = true
  }
}

provider "yandex" {
  zone = "ru-central1-b"
}

locals {
  tvl_cloud_id  = "b1ggu5m1btue982app12"
  tvl_folder_id = "b1gmbeqt9o5kbl7rclln"
  rih_cloud_id  = "b1glccvcqggi2ruibgvt"
  rih_folder_id = "b1gsavcrsjn059d1sbh9"
}

# Storage state bucket configuration

resource "yandex_iam_service_account" "tf_state_sa" {
  folder_id = local.tvl_folder_id
  name      = "terraform-state"
}

resource "yandex_resourcemanager_folder_iam_member" "tf_state_sa_storage" {
  folder_id = local.tvl_folder_id
  role      = "storage.editor"
  member    = "serviceAccount:${yandex_iam_service_account.tf_state_sa.id}"
}

resource "yandex_iam_service_account_static_access_key" "tf_state_sa_key" {
  service_account_id = yandex_iam_service_account.tf_state_sa.id
  description        = "Static access key for Terraform state"
}

resource "yandex_storage_bucket" "tf_state" {
  access_key = yandex_iam_service_account_static_access_key.tf_state_sa_key.access_key
  secret_key = yandex_iam_service_account_static_access_key.tf_state_sa_key.secret_key
  bucket     = "su-tvl-terraform-state"
}

# Secret management configuration

resource "yandex_kms_symmetric_key" "tvl_credentials_key" {
  name              = "tvl-credentials"
  folder_id         = local.tvl_folder_id
  default_algorithm = "AES_256"
  rotation_period   = "2160h" # 90 days
}

resource "yandex_kms_secret_ciphertext" "tf_state_key" {
  key_id    = yandex_kms_symmetric_key.tvl_credentials_key.id
  plaintext = yandex_iam_service_account_static_access_key.tf_state_sa_key.secret_key
}