mirror of
https://github.com/Hestia-Homes/Model.git
synced 2026-06-30 13:10:47 +00:00
update fast-api terraform
This commit is contained in:
parent
6632e6fcdc
commit
dcb3efdb7e
3 changed files with 118 additions and 53 deletions
|
|
@ -7,43 +7,101 @@ data "terraform_remote_state" "shared" {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
module "lambda" {
|
data "aws_secretsmanager_secret_version" "db_credentials" {
|
||||||
source = "../../modules/lambda_with_sqs"
|
secret_id = "${var.stage}/assessment_model/db_credentials"
|
||||||
|
}
|
||||||
|
|
||||||
name = REPLACE ME #"address2uprn" for example
|
locals {
|
||||||
stage = var.stage
|
db_credentials = jsondecode(data.aws_secretsmanager_secret_version.db_credentials.secret_string)
|
||||||
|
}
|
||||||
|
|
||||||
image_uri = local.image_uri
|
|
||||||
|
|
||||||
# Optional: Set maximum_concurrency to limit concurrent SQS-triggered invocations (2-1000)
|
data "aws_ssm_parameter" "certificate_arn" {
|
||||||
maximum_concurrency = var.maximum_concurrency
|
name = "/ssl_certificate_arn"
|
||||||
|
}
|
||||||
|
|
||||||
batch_size = var.batch_size
|
data "aws_route53_zone" "this" {
|
||||||
|
name = var.domain_name
|
||||||
|
}
|
||||||
|
|
||||||
environment = {
|
############################################
|
||||||
STAGE = var.stage
|
# Install Python requirements
|
||||||
LOG_LEVEL = "info"
|
############################################
|
||||||
|
resource "null_resource" "pip_install" {
|
||||||
|
triggers = {
|
||||||
|
requirements_hash = filemd5("${path.root}/../../../../backend/app/requirements/requirements.txt")
|
||||||
|
}
|
||||||
|
|
||||||
|
provisioner "local-exec" {
|
||||||
|
command = <<EOT
|
||||||
|
pip install \
|
||||||
|
-r ${path.root}/../../../../backend/app/requirements/requirements.txt \
|
||||||
|
-t ${path.root}/../../../../backend/app/packages \
|
||||||
|
--platform manylinux2014_x86_64 \
|
||||||
|
--implementation cp \
|
||||||
|
--python-version 3.11 \
|
||||||
|
--only-binary=:all: \
|
||||||
|
--upgrade
|
||||||
|
EOT
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
# ======================================================================
|
############################################
|
||||||
# OPTIONAL: Attach S3 IAM policy to Lambda execution role
|
# FastAPI Lambda + API Gateway
|
||||||
# ======================================================================
|
############################################
|
||||||
# Uncomment and configure the resource below to attach S3 permissions
|
module "fastapi" {
|
||||||
#
|
depends_on = [null_resource.pip_install]
|
||||||
# Example 1: Attach existing policy from shared state
|
source = "../../modules/lambda_with_api_gateway"
|
||||||
# resource "aws_iam_role_policy_attachment" "lambda_s3_policy" {
|
|
||||||
# role = module.lambda.role_name
|
name = "fastapi"
|
||||||
# policy_arn = data.terraform_remote_state.shared.outputs.YOUR_POLICY_OUTPUT_NAME_arn
|
stage = var.stage
|
||||||
# }
|
source_dir = "${path.root}/../../../../backend"
|
||||||
#
|
handler = "app.main.handler"
|
||||||
# Example 2: Attach multiple policies
|
runtime = "python3.11"
|
||||||
# resource "aws_iam_role_policy_attachment" "lambda_read_policy" {
|
timeout = 600
|
||||||
# role = module.lambda.role_name
|
memory_size = 512
|
||||||
# policy_arn = data.terraform_remote_state.shared.outputs.postcode_splitter_s3_read_arn
|
|
||||||
# }
|
domain_name = "api.${var.domain_name}"
|
||||||
#
|
certificate_arn = data.aws_ssm_parameter.certificate_arn.value
|
||||||
# resource "aws_iam_role_policy_attachment" "lambda_write_policy" {
|
route53_zone_id = data.aws_route53_zone.this.zone_id
|
||||||
# role = module.lambda.role_name
|
|
||||||
# policy_arn = data.terraform_remote_state.shared.outputs.another_policy_arn
|
environment = {
|
||||||
# }
|
ENVIRONMENT = var.stage
|
||||||
|
API_KEY = var.api_key
|
||||||
|
SECRET_KEY = var.secret_key
|
||||||
|
DOMAIN_NAME = var.domain_name
|
||||||
|
EPC_AUTH_TOKEN = var.epc_auth_token
|
||||||
|
GOOGLE_SOLAR_API_KEY = var.google_solar_api_key
|
||||||
|
|
||||||
|
DB_HOST = var.db_host
|
||||||
|
DB_NAME = var.db_name
|
||||||
|
DB_PORT = var.db_port
|
||||||
|
DB_USERNAME = local.db_credentials.db_assessment_model_username
|
||||||
|
DB_PASSWORD = local.db_credentials.db_assessment_model_password
|
||||||
|
|
||||||
|
PLAN_TRIGGER_BUCKET = data.terraform_remote_state.shared.outputs.retrofit_plan_trigger_bucket_name
|
||||||
|
DATA_BUCKET = data.terraform_remote_state.shared.outputs.retrofit_sap_data_bucket_name
|
||||||
|
SAP_PREDICTIONS_BUCKET = data.terraform_remote_state.shared.outputs.retrofit_sap_predictions_bucket_name
|
||||||
|
CARBON_PREDICTIONS_BUCKET = data.terraform_remote_state.shared.outputs.retrofit_carbon_predictions_bucket_name
|
||||||
|
HEAT_PREDICTIONS_BUCKET = data.terraform_remote_state.shared.outputs.retrofit_heat_predictions_bucket_name
|
||||||
|
HEATING_KWH_PREDICTIONS_BUCKET = data.terraform_remote_state.shared.outputs.retrofit_heating_kwh_predictions_bucket_name
|
||||||
|
HOTWATER_KWH_PREDICTIONS_BUCKET = data.terraform_remote_state.shared.outputs.retrofit_hotwater_kwh_predictions_bucket_name
|
||||||
|
ENERGY_ASSESSMENTS_BUCKET = data.terraform_remote_state.shared.outputs.retrofit_energy_assessments_bucket_name
|
||||||
|
|
||||||
|
ENGINE_SQS_URL = data.terraform_remote_state.shared.outputs.engine_queue_url
|
||||||
|
CATEGORISATION_SQS_URL = "https://sqs.eu-west-2.amazonaws.com/337213553626/categorisation-queue-dev"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
############################################
|
||||||
|
# IAM policy attachments
|
||||||
|
############################################
|
||||||
|
resource "aws_iam_role_policy_attachment" "fastapi_s3_read" {
|
||||||
|
role = module.fastapi.role_name
|
||||||
|
policy_arn = data.terraform_remote_state.shared.outputs.fastapi_s3_read_arn
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_iam_role_policy_attachment" "fastapi_sqs_send" {
|
||||||
|
role = module.fastapi.role_name
|
||||||
|
policy_arn = data.terraform_remote_state.shared.outputs.fastapi_sqs_send_arn
|
||||||
|
}
|
||||||
|
|
@ -7,7 +7,7 @@ terraform {
|
||||||
}
|
}
|
||||||
|
|
||||||
backend "s3" {
|
backend "s3" {
|
||||||
bucket = REPLACE_ME
|
bucket = "ara-fast-api-terraform-state"
|
||||||
key = "terraform.tfstate"
|
key = "terraform.tfstate"
|
||||||
region = "eu-west-2"
|
region = "eu-west-2"
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -4,34 +4,41 @@ variable "lambda_name" {
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "stage" {
|
variable "stage" {
|
||||||
description = "Deployment stage (e.g. dev, prod)"
|
type = string
|
||||||
type = string
|
|
||||||
}
|
|
||||||
variable "ecr_repo_url" {
|
|
||||||
type = string
|
|
||||||
description = "ECR repository URL (no tag, no digest)"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "image_digest" {
|
variable "db_host" {
|
||||||
type = string
|
type = string
|
||||||
description = "Image digest (sha256:...)"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "maximum_concurrency" {
|
variable "db_name" {
|
||||||
type = number
|
type = string
|
||||||
default = null
|
|
||||||
description = "Maximum number of concurrent Lambda invocations from SQS (2-1000). null = no limit."
|
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "batch_size" {
|
variable "db_port" {
|
||||||
type = number
|
type = string
|
||||||
default = 1
|
|
||||||
}
|
}
|
||||||
|
|
||||||
locals {
|
variable "api_key" {
|
||||||
image_uri = "${var.ecr_repo_url}@${var.image_digest}"
|
type = string
|
||||||
|
sensitive = true
|
||||||
}
|
}
|
||||||
|
|
||||||
output "resolved_image_uri" {
|
variable "secret_key" {
|
||||||
value = local.image_uri
|
type = string
|
||||||
|
sensitive = true
|
||||||
}
|
}
|
||||||
|
|
||||||
|
variable "domain_name" {
|
||||||
|
type = string
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "epc_auth_token" {
|
||||||
|
type = string
|
||||||
|
sensitive = true
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "google_solar_api_key" {
|
||||||
|
type = string
|
||||||
|
sensitive = true
|
||||||
|
}
|
||||||
Loading…
Add table
Reference in a new issue