-
Couldn't load subscription status.
- Fork 323
Terraform sync tool #290
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Terraform sync tool #290
Changes from 50 commits
cf9653f
fbca216
313418f
c1ccc83
1a69c02
feb176f
7c42756
d94c55b
345ab63
3cfcbc2
8ae5b48
4d5ac73
7c8e1d1
8b690c3
c2fc146
dd75e1f
2a354f0
376b7fd
7a33b29
9a5fe09
5c36be7
d330bb9
252dcab
abcf98f
2422a88
3fca695
485bde1
52467af
9211697
5dabf46
e85bd21
073e192
f699fdd
c89fee7
1e65ae7
ec2d139
90cb7da
23f1701
993bffa
d31e25f
1e7a6fc
67505be
69a2df3
9cd0da7
1c4fc9f
d2e5e0e
815bee4
2bf25ea
4e1bb73
2b20ed5
7f469e4
5496102
34f1461
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,159 @@ | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| # Terraform Sync Tool | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| This directory contains the setup for the Terraform Sync Tool. Terraform Sync Tool was designed to address the schema drifts in BigQuery tables and keep the | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Terraform schemas up-to-date with the BigQuery table schemas in production environment. Schema drifts occurred when BigQuery Table schemas are updated by newly | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ingested data while Terraform schema files contain the outdated schemas. Therefore, this tool will detect the schema drifts, trace the origins of the drifts, and alert | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| developers/data engineers. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| The Terraform Schema Sync Tool fails the build attemps if resource drifts are detected and notifies the latest resource information. Developers and data engineers should be able to update the Terraform resources accordingly. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| The Terraform Schema Sync Tool fails the build attemps if resource drifts are detected and notifies the latest resource information. Developers and data engineers should be able to update the Terraform resources accordingly. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updated in 7f469e4
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| - Step 0: Use Terraform/erragrunt command to detect resource drifts and write output into a JSON file | |
| - Step 0: Run the Terraform plan command (using either Terraform/Terragrunt) with the `-json` option and write the output into a JSON file using the caret operator `> output.json` |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updated in 7f469e4
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| ## How to run Terraform Schema Sync Tool | |
| ## How to run Terraform Schema Sync Tool | |
| ```bash | |
| ############### | |
| # Using Terragrunt | |
| ############### | |
| terragrunt run-all plan -json --terragrunt-non-interactive > plan_output.json | |
| python3 terraform_sync.py plan_output.json | |
| ############## | |
| # Using Terraform | |
| ############## | |
| terraform plan -json > plan_output.json | |
| python3 terraform_sync.py plan_output.json |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
All these should be 3rd level headers (###), not 4 (####)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updated in 5496102
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| Terragrunt/Terraform commands: | |
| ``` | |
| terragrunt run-all plan -json --terragrunt-non-interactive | |
| # Terraform Command | |
| terraform plan -json | |
| ``` | |
| After running the Terrform plan command, **the event type "resource_drift"("type": "resource_drift") indicates a drift has occurred**. | |
| If drifts detected, please update your terraform configurations and address the resource drifts based on the event outputs. | |
| #### Add Could Build Steps to your configuration file | |
| Please check cloud build steps in `cloudbuild.yaml` file, and add these steps to your Cloud Build Configuration File. | |
| - step 0: run terraform commands in `deploy.sh` to detects drifts | |
| Add `deploy.sh` to your project directory. | |
| - step 1: run python scripts to investigate terraform output | |
| Add `requirements.txt` and `terraform_sync.py` to your project directory. | |
| #### (Optional if you haven't created Cloud Build Trigger) Create and configure a new Trigger in Cloud Build | |
| Make sure to indicate your cloud configuration file location correctly. | |
| #### That's all you need! Let's commit and test in CLoud Build! |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
These are not required to run this tool. This is more related to running the example you provide with this tool.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updated in 5496102
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
All of these should go inside an example/ directory
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updated in 5496102
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,15 @@ | ||
| steps: | ||
| # step 0: run terraform commands in deploy.sh to detects drifts | ||
| - name: 'alpine/terragrunt' | ||
| entrypoint: 'bash' | ||
| dir: './tools/terraform_sync_tool/' | ||
| args: ['deploy.sh', 'qa', 'terraform-sync-tool'] | ||
|
|
||
| # step 1: run python scripts to investigate terraform output | ||
| - name: python:3.7 | ||
| entrypoint: 'bash' | ||
| dir: './tools/terraform_sync_tool/' | ||
| args: | ||
| - -c | ||
| - 'pip install -r ./requirements.txt' | ||
| - 'python terraform_sync.py plan_out.json <GCP_PROJECT_ID>' |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,6 @@ | ||
| #!/bin/bash | ||
|
|
||
| env=$1 | ||
| tool=$2 | ||
|
|
||
| terragrunt run-all plan -json --terragrunt-non-interactive --terragrunt-working-dir="${env}"/"${tool}" > plan_out.json |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,55 @@ | ||
| locals { | ||
| datasets = { for dataset in var.datasets : dataset["dataset_id"] => dataset } | ||
| tables = { for table in var.tables : table["table_id"] => table } | ||
|
|
||
| iam_to_primitive = { | ||
| "roles/bigquery.dataOwner" : "OWNER" | ||
| "roles/bigquery.dataEditor" : "WRITER" | ||
| "roles/bigquery.dataViewer" : "READER" | ||
| } | ||
| } | ||
|
|
||
| #this is the test for dataset list creation | ||
| resource "google_bigquery_dataset" "bq_dataset" { | ||
| for_each = local.datasets | ||
| friendly_name = each.value["friendly_name"] | ||
| dataset_id = each.key | ||
| location = each.value["location"] | ||
| project = var.project_id | ||
| } | ||
|
|
||
| resource "google_bigquery_table" "bq_table" { | ||
| for_each = local.tables | ||
| dataset_id = each.value["dataset_id"] | ||
| friendly_name = each.key | ||
| table_id = each.key | ||
| labels = each.value["labels"] | ||
| schema = file(each.value["schema"]) | ||
| clustering = each.value["clustering"] | ||
| expiration_time = each.value["expiration_time"] | ||
| project = var.project_id | ||
| deletion_protection = each.value["deletion_protection"] | ||
| depends_on = [google_bigquery_dataset.bq_dataset] | ||
|
|
||
| dynamic "time_partitioning" { | ||
| for_each = each.value["time_partitioning"] != null ? [each.value["time_partitioning"]] : [] | ||
| content { | ||
| type = time_partitioning.value["type"] | ||
| expiration_ms = time_partitioning.value["expiration_ms"] | ||
| field = time_partitioning.value["field"] | ||
| require_partition_filter = time_partitioning.value["require_partition_filter"] | ||
| } | ||
| } | ||
|
|
||
| dynamic "range_partitioning" { | ||
| for_each = each.value["range_partitioning"] != null ? [each.value["range_partitioning"]] : [] | ||
| content { | ||
| field = range_partitioning.value["field"] | ||
| range { | ||
| start = range_partitioning.value["range"].start | ||
| end = range_partitioning.value["range"].end | ||
| interval = range_partitioning.value["range"].interval | ||
| } | ||
| } | ||
| } | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,56 @@ | ||
| variable "location" { | ||
| description = "The regional location for the dataset only US and EU are allowed in module" | ||
| type = string | ||
| default = "US" | ||
| } | ||
|
|
||
| variable "deletion_protection" { | ||
| description = "Whether or not to allow Terraform to destroy the instance. Unless this field is set to false in Terraform state, a terraform destroy or terraform apply that would delete the instance will fail." | ||
| type = bool | ||
| default = true | ||
| } | ||
|
|
||
| variable "project_id" { | ||
| description = "Project where the dataset and table are created" | ||
| type = string | ||
| } | ||
|
|
||
| variable "datasets" { | ||
| description = "this is a test DS" | ||
| default = [] | ||
| type = list(object({ | ||
| dataset_id = string | ||
| friendly_name = string | ||
| location = string | ||
| } | ||
| )) | ||
| } | ||
|
|
||
| variable "tables" { | ||
| description = "A list of objects which include table_id, schema, clustering, time_partitioning, expiration_time and labels." | ||
| default = [] | ||
| type = list(object({ | ||
| table_id = string, | ||
| dataset_id = string, #added to test creating multi dataset | ||
| schema = string, | ||
| clustering = list(string), | ||
| deletion_protection=bool, | ||
| time_partitioning = object({ | ||
| expiration_ms = string, | ||
| field = string, | ||
| type = string, | ||
| require_partition_filter = bool, | ||
| }), | ||
| range_partitioning = object({ | ||
| field = string, | ||
| range = object({ | ||
| start = string, | ||
| end = string, | ||
| interval = string, | ||
| }), | ||
| }), | ||
| expiration_time = string, | ||
| labels = map(string), | ||
| } | ||
| )) | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,62 @@ | ||
| [ | ||
| { | ||
| "description": "Col1", | ||
| "mode": "NULLABLE", | ||
| "name": "Col1", | ||
| "type": "STRING" | ||
| }, | ||
| { | ||
| "description": "Col2", | ||
| "mode": "NULLABLE", | ||
| "name": "Col2", | ||
| "type": "STRING" | ||
| }, | ||
| { | ||
| "description": "Col3", | ||
| "mode": "NULLABLE", | ||
| "name": "Col3", | ||
| "type": "STRING" | ||
| }, | ||
| { | ||
| "description": "Col4", | ||
| "mode": "NULLABLE", | ||
| "name": "Col4", | ||
| "type": "STRING" | ||
| }, | ||
| { | ||
| "description": "Col5", | ||
| "mode": "NULLABLE", | ||
| "name": "Col5", | ||
| "type": "STRING" | ||
| }, | ||
| { | ||
| "description": "Col6", | ||
| "mode": "NULLABLE", | ||
| "name": "Col6", | ||
| "type": "STRING" | ||
| }, | ||
| { | ||
| "description": "Col7", | ||
| "mode": "NULLABLE", | ||
| "name": "Col7", | ||
| "type": "STRING" | ||
| }, | ||
| { | ||
| "description": "Col8", | ||
| "mode": "NULLABLE", | ||
| "name": "Col8", | ||
| "type": "STRING" | ||
| }, | ||
| { | ||
| "description": "Col9", | ||
| "mode": "NULLABLE", | ||
| "name": "Col9", | ||
| "type": "STRING" | ||
| }, | ||
| { | ||
| "description": "Col10", | ||
| "mode": "NULLABLE", | ||
| "name": "Col10", | ||
| "type": "STRING" | ||
| } | ||
| ] |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,26 @@ | ||
| [ | ||
| { | ||
| "description": "Col1", | ||
| "mode": "NULLABLE", | ||
| "name": "Col1", | ||
| "type": "STRING" | ||
| }, | ||
| { | ||
| "description": "Col2", | ||
| "mode": "NULLABLE", | ||
| "name": "Col2", | ||
| "type": "STRING" | ||
| }, | ||
| { | ||
| "description": "Col3", | ||
| "mode": "NULLABLE", | ||
| "name": "Col3", | ||
| "type": "STRING" | ||
| }, | ||
| { | ||
| "description": "Col4", | ||
| "mode": "NULLABLE", | ||
| "name": "Col4", | ||
| "type": "STRING" | ||
| } | ||
| ] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
updated in 7f469e4