terraform-contour-mirror/modules/rabbitmq/main.tf

252 lines
7.0 KiB
HCL
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

locals {
rabbitmq_enabled = length(var.vhosts) + length(var.users) + length(var.permissions) + length(var.topic_permissions) + length(var.exchanges) + length(var.queues) + length(var.bindings) + length(var.policies) > 0
management_endpoint = local.rabbitmq_enabled ? var.management_endpoint : "http://127.0.0.1:15672"
management_username = local.rabbitmq_enabled ? var.management_username : "noop"
management_password = local.rabbitmq_enabled ? var.management_password : "noop"
vhosts = {
for vhost in var.vhosts : vhost.name => {
name = vhost.name
description = try(vhost.description, null)
tracing = try(vhost.tracing, false)
}
}
users = {
for user in var.users : user.name => {
name = user.name
tags = try(user.tags, [])
# Строгий optional(number) без схемного дефолта отдаёт null, а не "нет
# ключа" - try() ловит только ошибки вычисления, не null-значения.
# Нужен coalesce, а не try, чтобы null действительно падал на дефолт.
password_length = coalesce(try(tonumber(user.password_length), null), var.default_user_password_length)
password_special = try(user.password_special, false)
}
}
permissions = {
for permission in var.permissions : "${permission.vhost}:${permission.user}" => {
vhost = permission.vhost
user = permission.user
configure = tostring(try(permission.configure, ""))
write = tostring(try(permission.write, ""))
read = tostring(try(permission.read, ""))
}
}
topic_permissions = {
for permission in var.topic_permissions : "${permission.vhost}:${permission.user}" => {
vhost = permission.vhost
user = permission.user
permissions = try(permission.permissions, [])
}
}
exchanges = {
for exchange in var.exchanges : "${exchange.vhost}:${exchange.name}" => {
name = exchange.name
vhost = exchange.vhost
type = try(exchange.type, "topic")
durable = try(exchange.durable, true)
auto_delete = try(exchange.auto_delete, false)
arguments = try(exchange.arguments, {})
}
}
queues = {
for queue in var.queues : "${queue.vhost}:${queue.name}" => {
name = queue.name
vhost = queue.vhost
durable = try(queue.durable, true)
auto_delete = try(queue.auto_delete, false)
arguments = try(queue.arguments, {})
}
}
bindings = {
# properties_key - optional(string) без схемного дефолта: при отсутствии
# приходит null, а не "нет ключа", поэтому coalesce, не try.
for binding in var.bindings : "${binding.vhost}:${binding.source}:${binding.destination_type}:${binding.destination}:${coalesce(binding.properties_key, format("%s:%s", try(binding.routing_key, ""), sha1(jsonencode(try(binding.arguments, {})))))}" => {
vhost = binding.vhost
source = binding.source
destination = binding.destination
destination_type = binding.destination_type
routing_key = try(binding.routing_key, "")
arguments = try(binding.arguments, {})
}
}
policies = {
for policy in var.policies : "${policy.vhost}:${policy.name}" => {
name = policy.name
vhost = policy.vhost
pattern = policy.pattern
apply_to = try(policy.apply_to, "all")
priority = try(tonumber(policy.priority), 0)
definition = policy.definition
}
}
user_vhosts = {
for item in distinct([
for permission in values(local.permissions) : "${permission.vhost}:${permission.user}"
]) : item => {
vhost = split(":", item)[0]
user = split(":", item)[1]
}
}
}
provider "rabbitmq" {
endpoint = local.management_endpoint
username = local.management_username
password = local.management_password
}
resource "rabbitmq_vhost" "this" {
for_each = local.vhosts
name = each.value.name
description = each.value.description
tracing = each.value.tracing
lifecycle {
prevent_destroy = true
}
}
resource "random_password" "user" {
for_each = local.users
length = each.value.password_length
special = each.value.password_special
upper = true
lower = true
numeric = true
lifecycle {
ignore_changes = all
}
}
resource "rabbitmq_user" "this" {
for_each = local.users
name = each.value.name
password = random_password.user[each.key].result
tags = each.value.tags
lifecycle {
prevent_destroy = true
ignore_changes = [password]
}
}
resource "rabbitmq_permissions" "this" {
for_each = local.permissions
user = rabbitmq_user.this[each.value.user].name
vhost = rabbitmq_vhost.this[each.value.vhost].name
permissions {
configure = each.value.configure
write = each.value.write
read = each.value.read
}
lifecycle {
prevent_destroy = true
}
}
resource "rabbitmq_topic_permissions" "this" {
for_each = local.topic_permissions
user = rabbitmq_user.this[each.value.user].name
vhost = rabbitmq_vhost.this[each.value.vhost].name
dynamic "permissions" {
for_each = each.value.permissions
content {
exchange = permissions.value.exchange
write = tostring(try(permissions.value.write, ""))
read = tostring(try(permissions.value.read, ""))
}
}
lifecycle {
prevent_destroy = true
}
}
resource "rabbitmq_exchange" "this" {
for_each = local.exchanges
name = each.value.name
vhost = rabbitmq_vhost.this[each.value.vhost].name
settings {
type = each.value.type
durable = each.value.durable
auto_delete = each.value.auto_delete
arguments = each.value.arguments
}
lifecycle {
prevent_destroy = true
}
}
resource "rabbitmq_queue" "this" {
for_each = local.queues
name = each.value.name
vhost = rabbitmq_vhost.this[each.value.vhost].name
settings {
durable = each.value.durable
auto_delete = each.value.auto_delete
arguments = each.value.arguments
}
lifecycle {
prevent_destroy = true
}
}
resource "rabbitmq_binding" "this" {
for_each = local.bindings
source = each.value.source
vhost = rabbitmq_vhost.this[each.value.vhost].name
destination = each.value.destination
destination_type = each.value.destination_type
routing_key = each.value.routing_key
arguments = each.value.arguments
lifecycle {
prevent_destroy = true
}
depends_on = [rabbitmq_exchange.this, rabbitmq_queue.this]
}
resource "rabbitmq_policy" "this" {
for_each = local.policies
name = each.value.name
vhost = rabbitmq_vhost.this[each.value.vhost].name
policy {
pattern = each.value.pattern
priority = each.value.priority
apply_to = each.value.apply_to
definition = each.value.definition
}
lifecycle {
prevent_destroy = true
}
}