Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .trivyignore.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,8 @@ misconfigurations:
- docker/osv-scanner/Dockerfile
- docker/semgrep/Dockerfile
- docker/trivy/Dockerfile
# Container runs as non-root (user 65532) via the ECS task definition; the image is a thin version-pin for dependabot.
- docker/victoriametrics/Dockerfile
Comment thread
cubic-dev-ai[bot] marked this conversation as resolved.
- docker/zap/Dockerfile
- id: AVD-AWS-0053 # Public ALB intentional for nest.owasp.dev
paths:
Expand Down Expand Up @@ -43,6 +45,9 @@ misconfigurations:
- id: AVD-AWS-0176 # IAM DB auth deferred; app uses Secrets Manager credentials today
paths:
- infrastructure/modules/database/main.tf
- id: AVD-AWS-0178 # Throwaway VPC fixture for module tests; flow logs are not applicable
paths:
- infrastructure/modules/observability/tests/setup/main.tf
- id: AVD-AWS-0342 # EventBridge PassRole required to run ECS tasks
paths:
- infrastructure/modules/tasks/main.tf
1 change: 1 addition & 0 deletions docker-compose/infrastructure/compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,7 @@ services:
network_mode: service:localstack
pull_policy: never
volumes:
- ../../docker:/home/owasp/docker:ro
- ../../infrastructure/bootstrap:/home/owasp/infrastructure/bootstrap
- ../../infrastructure/modules:/home/owasp/infrastructure/modules
- ../../infrastructure/scripts:/home/owasp/infrastructure/scripts:ro
Expand Down
4 changes: 3 additions & 1 deletion docker-compose/local/compose.o11y.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,9 @@ services:
command:
- -retentionPeriod=5y
- -storageDataPath=/data
image: victoriametrics/victoria-metrics:v1.145.0@sha256:c014fb5a711d38cb24fd0673197592cd1394bb903dbb16aea565620c9c8a3d70
build:
context: ../../docker/victoriametrics
dockerfile: Dockerfile
Comment thread
rudransh-shrivastava marked this conversation as resolved.
healthcheck:
interval: 5s
retries: 5
Expand Down
1 change: 1 addition & 0 deletions docker/victoriametrics/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
FROM victoriametrics/victoria-metrics:v1.145.0@sha256:c014fb5a711d38cb24fd0673197592cd1394bb903dbb16aea565620c9c8a3d70
2 changes: 2 additions & 0 deletions infrastructure/live/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,7 @@ No providers.
| <a name="module_frontend_build_cache"></a> [frontend\_build\_cache](#module\_frontend\_build\_cache) | ../modules/ecr-cache | n/a |
| <a name="module_kms"></a> [kms](#module\_kms) | ../modules/kms | n/a |
| <a name="module_networking"></a> [networking](#module\_networking) | ../modules/networking | n/a |
| <a name="module_observability"></a> [observability](#module\_observability) | ../modules/observability | n/a |
| <a name="module_parameters"></a> [parameters](#module\_parameters) | ../modules/parameters | n/a |
| <a name="module_security"></a> [security](#module\_security) | ../modules/security | n/a |
| <a name="module_storage"></a> [storage](#module\_storage) | ../modules/storage | n/a |
Expand Down Expand Up @@ -102,6 +103,7 @@ No resources.
| <a name="input_domain_name"></a> [domain\_name](#input\_domain\_name) | The domain name for the site. | `string` | n/a | yes |
| <a name="input_enable_additional_parameters"></a> [enable\_additional\_parameters](#input\_enable\_additional\_parameters) | Whether to enable additional parameters (e.g. for production). | `bool` | `false` | no |
| <a name="input_enable_cron_tasks"></a> [enable\_cron\_tasks](#input\_enable\_cron\_tasks) | Whether to enable scheduled cron tasks. | `bool` | n/a | yes |
| <a name="input_enable_observability"></a> [enable\_observability](#input\_enable\_observability) | Whether to create the observability stack. | `bool` | `false` | no |
| <a name="input_enable_rds_proxy"></a> [enable\_rds\_proxy](#input\_enable\_rds\_proxy) | Whether to create an RDS proxy. | `bool` | `false` | no |
| <a name="input_enable_vpc_cloudwatch_logs_endpoint"></a> [enable\_vpc\_cloudwatch\_logs\_endpoint](#input\_enable\_vpc\_cloudwatch\_logs\_endpoint) | Whether to create CloudWatch Logs VPC endpoint. | `bool` | `false` | no |
| <a name="input_enable_vpc_ecr_api_endpoint"></a> [enable\_vpc\_ecr\_api\_endpoint](#input\_enable\_vpc\_ecr\_api\_endpoint) | Whether to create ECR API VPC endpoint. | `bool` | `false` | no |
Expand Down
21 changes: 21 additions & 0 deletions infrastructure/live/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@ locals {
Project = var.project_name
}
fixtures_bucket_name = coalesce(var.fixtures_bucket_name, "${var.project_name}-${var.environment}-fixtures")
observability_image = regex("(?m)^FROM (victoriametrics/victoria-metrics:\\S+)", file("${path.root}/../../docker/victoriametrics/Dockerfile"))[0]
}

module "alb" {
Expand Down Expand Up @@ -175,6 +176,26 @@ module "networking" {
vpc_cidr = var.vpc_cidr
}

module "observability" {
count = var.enable_observability ? 1 : 0
source = "../modules/observability"

app_security_group_ids = [
module.security.backend_sg_id,
module.security.frontend_sg_id,
module.security.tasks_sg_id,
]
assign_public_ip = false
aws_region = var.aws_region
common_tags = local.common_tags
environment = var.environment
kms_key_arn = module.kms.key_arn
project_name = var.project_name
subnet_ids = module.networking.private_subnet_ids
image = local.observability_image
vpc_id = module.networking.vpc_id
}

module "parameters" {
source = "../modules/parameters"

Expand Down
6 changes: 6 additions & 0 deletions infrastructure/live/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -193,6 +193,12 @@ variable "enable_cron_tasks" {
type = bool
}

variable "enable_observability" {
description = "Whether to create the observability stack."
type = bool
default = false
}

variable "enable_rds_proxy" {
description = "Whether to create an RDS proxy."
type = bool
Expand Down
1 change: 1 addition & 0 deletions infrastructure/make/test.mk
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ infrastructure-test-image-build:
infrastructure-test-unit:
@$(MAKE) infrastructure-test-image-build
@docker run --rm \
-v "$(CURDIR)/docker:/home/owasp/docker:ro" \
-v "$(CURDIR)/infrastructure/bootstrap:/home/owasp/infrastructure/bootstrap" \
-v "$(CURDIR)/infrastructure/live:/home/owasp/infrastructure/live" \
-v "$(CURDIR)/infrastructure/modules:/home/owasp/infrastructure/modules" \
Expand Down
28 changes: 28 additions & 0 deletions infrastructure/modules/observability/.terraform.lock.hcl

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

69 changes: 69 additions & 0 deletions infrastructure/modules/observability/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
<!-- BEGIN_TF_DOCS -->
## Requirements

| Name | Version |
| ---- | ------- |
| <a name="requirement_terraform"></a> [terraform](#requirement\_terraform) | ~> 1.15.0 |
| <a name="requirement_aws"></a> [aws](#requirement\_aws) | ~> 6.58.0 |

## Providers

| Name | Version |
| ---- | ------- |
| <a name="provider_aws"></a> [aws](#provider\_aws) | 6.58.0 |

## Modules

No modules.

## Resources

| Name | Type |
| ---- | ---- |
| [aws_cloudwatch_log_group.vm](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudwatch_log_group) | resource |
| [aws_ecs_cluster.vm](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecs_cluster) | resource |
| [aws_ecs_cluster_capacity_providers.vm](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecs_cluster_capacity_providers) | resource |
| [aws_ecs_service.vm](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecs_service) | resource |
| [aws_ecs_task_definition.vm](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecs_task_definition) | resource |
| [aws_efs_access_point.vm](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/efs_access_point) | resource |
| [aws_efs_file_system.vm](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/efs_file_system) | resource |
| [aws_efs_mount_target.vm](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/efs_mount_target) | resource |
| [aws_iam_policy.ecs_task_execution_policy](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_policy) | resource |
| [aws_iam_role.ecs_task_execution_role](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role) | resource |
| [aws_iam_role_policy_attachment.ecs_task_execution_policy_attachment](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/iam_role_policy_attachment) | resource |
| [aws_security_group.efs](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group) | resource |
| [aws_security_group.vm](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group) | resource |
| [aws_security_group_rule.efs_from_vm](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group_rule) | resource |
| [aws_security_group_rule.vm_egress_https](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group_rule) | resource |
| [aws_security_group_rule.vm_ingest_from_apps](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group_rule) | resource |
| [aws_security_group_rule.vm_to_efs](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group_rule) | resource |

## Inputs

| Name | Description | Type | Default | Required |
| ---- | ----------- | ---- | ------- | :------: |
| <a name="input_app_security_group_ids"></a> [app\_security\_group\_ids](#input\_app\_security\_group\_ids) | Security group IDs of the application tasks allowed to send metrics to the observability backend. | `list(string)` | n/a | yes |
| <a name="input_assign_public_ip"></a> [assign\_public\_ip](#input\_assign\_public\_ip) | Whether to assign a public IP to the observability task. | `bool` | `false` | no |
| <a name="input_aws_region"></a> [aws\_region](#input\_aws\_region) | The AWS region where the module is deployed. | `string` | n/a | yes |
| <a name="input_common_tags"></a> [common\_tags](#input\_common\_tags) | A map of common tags to apply to all resources. | `map(string)` | `{}` | no |
| <a name="input_cpu"></a> [cpu](#input\_cpu) | The CPU units for the observability Fargate task. | `number` | `512` | no |
| <a name="input_desired_count"></a> [desired\_count](#input\_desired\_count) | The number of observability tasks to run (0 or 1; the current backend is a single-node store). | `number` | `1` | no |
| <a name="input_environment"></a> [environment](#input\_environment) | The environment (e.g., staging, production). | `string` | n/a | yes |
| <a name="input_image"></a> [image](#input\_image) | The observability backend container image (including digest). | `string` | n/a | yes |
| <a name="input_kms_key_arn"></a> [kms\_key\_arn](#input\_kms\_key\_arn) | The ARN of the KMS key used to encrypt the EFS file system. | `string` | n/a | yes |
| <a name="input_log_retention_in_days"></a> [log\_retention\_in\_days](#input\_log\_retention\_in\_days) | The number of days to retain observability container logs. | `number` | `90` | no |
| <a name="input_memory"></a> [memory](#input\_memory) | The memory (in MiB) for the observability Fargate task. | `number` | `1024` | no |
| <a name="input_port"></a> [port](#input\_port) | The port the observability backend listens on for ingest and queries. | `number` | `8428` | no |
| <a name="input_project_name"></a> [project\_name](#input\_project\_name) | The name of the project. | `string` | n/a | yes |
| <a name="input_retention_period"></a> [retention\_period](#input\_retention\_period) | The VictoriaMetrics data retention period. A value without a suffix is in months, so the default "12" means 12 months (duration suffixes like 1y, 30d, 1w are also supported). | `string` | `"12"` | no |
| <a name="input_subnet_ids"></a> [subnet\_ids](#input\_subnet\_ids) | The private subnet IDs for the EFS mount targets and the observability task. | `list(string)` | n/a | yes |
| <a name="input_vpc_id"></a> [vpc\_id](#input\_vpc\_id) | The VPC ID where the observability backend security group is created. | `string` | n/a | yes |

## Outputs

| Name | Description |
| ---- | ----------- |
| <a name="output_cluster_name"></a> [cluster\_name](#output\_cluster\_name) | The name of the ECS cluster running the observability backend. |
| <a name="output_efs_file_system_id"></a> [efs\_file\_system\_id](#output\_efs\_file\_system\_id) | The ID of the EFS file system backing observability storage. |
| <a name="output_security_group_id"></a> [security\_group\_id](#output\_security\_group\_id) | The ID of the observability backend security group. |
<!-- END_TF_DOCS -->
Loading
Loading