Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
82 changes: 82 additions & 0 deletions examples/big-peer-deployment/.env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,82 @@
# ---------------------------------------------------------------------------
# Example environment for the Makefile (Part 2 of this example).
#
# cp .env.example .env.local # then edit
#
# There are two files, and neither is committed:
#
# .env Generated by `terraform apply`. Holds DEPLOYMENT, CLUSTER and
# REGION only. Overwritten on every apply -- never edit it.
# Before the first apply the Makefile derives the same values
# from config.yaml instead.
#
# .env.local Yours. Loaded after .env, so anything here wins. Terraform
# never touches it.
#
# Anything you leave unset falls back to the default shown below. You can also
# override any of these per-invocation: make EXTERNAL=1 envoy
# ---------------------------------------------------------------------------

# --- AWS -------------------------------------------------------------------
# The profile used for `aws eks update-kubeconfig` and every AWS call. There is
# no sensible default, so set this unless you rely on ambient credentials.
AWS_PROFILE=my-aws-profile

# Normally these come from .env (Terraform) or config.yaml. Set them only to
# target a cluster this example did not build.
#CLUSTER=big-peer-dev
#REGION=us-east-1

# --- Big Peer --------------------------------------------------------------
# Namespace for the operator and the Big Peer instance.
NAMESPACE=ditto

# Name of the BigPeer resource, and the Ditto version it runs.
BIGPEER_NAME=example
BIGPEER_VERSION=1.59.0

# Playground anonymous-auth token. The quickstart uses abc123; it grants full
# read/write, so change it for anything that is not a throwaway cluster.
SHARED_TOKEN=abc123

# --- Networking ------------------------------------------------------------
# 0 = internal NLB only (default). 1 = also provision an internet-facing NLB.
# With no ACM certificate in the account the external gateway serves plaintext
# HTTP, so leave this off unless you understand the exposure.
EXTERNAL=0

# Envoy replicas per gateway. Raise once the cluster has more than one node.
ENVOY_REPLICAS=1

# Kafka's external listener is an `ingress`-type Strimzi listener, needed only
# for Kafka Data Bridges. This example installs Envoy Gateway, which implements
# the Gateway API and does NOT serve Ingress -- so with this on, Strimzi blocks
# forever waiting for an address and Big Peer never starts. Leave at 0 unless
# you have installed an Ingress controller.
KAFKA_EXTERNAL_LISTENER=0

# --- Portal (optional) -----------------------------------------------------
# Self-managed portal UI, shipped in the ditto-operator chart. 0 = not
# installed (default). 1 = install it and route it through the *internal*
# gateway -- it never gets its own load balancer or public address.
#
# The chart's portal.ingress / portal.operatorApiIngress are left disabled:
# Envoy Gateway does not serve Ingress. An HTTPRoute is used instead, serving
# the portal, the operator API and the Big Peer API from this one hostname so
# the browser stays same-origin and needs no CORS policy.
PORTAL=0

# Hostname the portal is served on. Nothing registers this in DNS -- add it to
# /etc/hosts, or point a private zone at the internal NLB.
PORTAL_HOST=portal.ditto.local

# Portal image tag (quay.io/ditto-external/portal-self-managed).
PORTAL_VERSION=0.3.0

# --- Chart versions --------------------------------------------------------
# Pinned so a re-run installs the same thing. cert-manager and Strimzi track
# the Ditto operator quickstart; gateway-helm tracks cloud-infra dev.
CERT_MANAGER_VERSION=v1.21.1
ENVOY_GATEWAY_VERSION=1.6.3
STRIMZI_VERSION=0.49.0
DITTO_OPERATOR_VERSION=0.17.2
14 changes: 14 additions & 0 deletions examples/big-peer-deployment/.gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# Generated by terraform (env.tf) and scripts/config.sh
.env
# Your local overrides -- copy from .env.example
.env.local
# Self-contained kubeconfig written by `make kubeconfig`
.kube/
# App ID and API key written by scripts/app.sh
.local/

# Terraform
.terraform/
*.tfstate
*.tfstate.backup
*.tfplan
194 changes: 194 additions & 0 deletions examples/big-peer-deployment/Makefile
Original file line number Diff line number Diff line change
@@ -0,0 +1,194 @@
#
# Part 2 of this example: deploy Big Peer and its dependencies onto the EKS
# cluster that Part 1 (Terraform) built. See README.md.
#
# make # list targets
# make all # kubeconfig -> bootstrap -> bigpeer -> app -> smoke
# make FORCE=1 … # reinstall components that are already healthy
#

SHELL := /usr/bin/env bash
.SHELLFLAGS := -euo pipefail -c
.DEFAULT_GOAL := help

# These steps are strictly ordered (CNI before nodes, gateways before routes,
# Big Peer before its app). -j would interleave them.
.NOTPARALLEL:

S := ./scripts
KUBEDIR := $(CURDIR)/.kube
KUBECFG := $(KUBEDIR)/config

# ---------------------------------------------------------------------------
# Configuration, in precedence order (lowest first):
#
# 1. the defaults below
# 2. .env - written by `terraform apply`, or derived from config.yaml
# 3. .env.local - yours, never touched by Terraform (see .env.example)
# 4. the command line, e.g. `make EXTERNAL=1 envoy`
#
# `-include` tolerates the files being absent. The `.env:` rule below creates
# it from config.yaml when Terraform has not run yet.
# ---------------------------------------------------------------------------

# Written atomically: a partial .env would be silently swallowed by -include
# and leave `make` pointed at the placeholder defaults below.
.env:
@echo "==> .env not found; deriving it from config.yaml"
@$(S)/config.sh > $@.tmp && mv $@.tmp $@ \
|| { rm -f $@.tmp; echo "ERROR: could not derive .env from config.yaml" >&2; exit 1; }

-include .env
-include .env.local

# Nothing above is required to be set: every value has a working default here.
CLUSTER ?= big-peer-dev
REGION ?= us-east-1
DEPLOYMENT ?= $(CLUSTER)
KUBE_CONTEXT ?= $(CLUSTER)

NAMESPACE ?= ditto
BIGPEER_NAME ?= example
BIGPEER_VERSION ?= 1.59.0
SHARED_TOKEN ?= abc123

EXTERNAL ?= 0
ENVOY_REPLICAS ?= 1

# Kafka's ingress-type external listener. Needs an Ingress controller, which
# this example does not install (Envoy Gateway is Gateway API only). Only
# required for Kafka Data Bridges.
KAFKA_EXTERNAL_LISTENER ?= 0

# Self-managed portal UI. Ships in the ditto-operator chart, off by default.
# Served from the internal gateway only -- no public load balancer.
PORTAL ?= 0
PORTAL_HOST ?= portal.ditto.local
PORTAL_VERSION ?= 0.3.0

CERT_MANAGER_VERSION ?= v1.21.1
ENVOY_GATEWAY_VERSION ?= 1.6.3
STRIMZI_VERSION ?= 0.49.0
DITTO_OPERATOR_VERSION ?= 0.17.2

# Scripts read all of this from the environment.
export CLUSTER REGION DEPLOYMENT KUBE_CONTEXT NAMESPACE BIGPEER_NAME
export BIGPEER_VERSION SHARED_TOKEN EXTERNAL ENVOY_REPLICAS FORCE
export KAFKA_EXTERNAL_LISTENER PORTAL PORTAL_HOST PORTAL_VERSION
export CERT_MANAGER_VERSION ENVOY_GATEWAY_VERSION STRIMZI_VERSION DITTO_OPERATOR_VERSION

# Self-contained kubeconfig: this example never touches ~/.kube/config, so it
# cannot disturb whatever cluster you have selected globally.
export KUBECONFIG := $(KUBECFG)

ifdef AWS_PROFILE
export AWS_PROFILE
endif

# ---------------------------------------------------------------------------

.PHONY: help
help: ## Show this help
@echo "Big Peer on EKS - Part 2 (deploy)"
@echo
@grep -hE '^[a-zA-Z_-]+:.*?## ' $(MAKEFILE_LIST) \
| awk 'BEGIN {FS = ":.*?## "}; {printf " \033[36m%-16s\033[0m %s\n", $$1, $$2}'
@echo
@echo "Cluster : $(CLUSTER) ($(REGION)) profile: $(or $(AWS_PROFILE),<ambient>)"
@echo "Big Peer: $(BIGPEER_NAME) v$(BIGPEER_VERSION) in ns/$(NAMESPACE) EXTERNAL=$(EXTERNAL)"
@echo "Config : $(if $(wildcard .env),.env,<none>) $(if $(wildcard .env.local),+ .env.local,)"
@echo "Kubecfg : $(KUBECFG)"

.PHONY: config
config: ## Print the resolved configuration
@printf ' %-24s %s\n' \
CLUSTER "$(CLUSTER)" REGION "$(REGION)" DEPLOYMENT "$(DEPLOYMENT)" \
AWS_PROFILE "$(or $(AWS_PROFILE),<ambient>)" KUBECONFIG "$(KUBECFG)" \
NAMESPACE "$(NAMESPACE)" BIGPEER_NAME "$(BIGPEER_NAME)" \
BIGPEER_VERSION "$(BIGPEER_VERSION)" EXTERNAL "$(EXTERNAL)" \
ENVOY_REPLICAS "$(ENVOY_REPLICAS)" \
KAFKA_EXTERNAL_LISTENER "$(KAFKA_EXTERNAL_LISTENER)" \
PORTAL "$(PORTAL)" PORTAL_HOST "$(PORTAL_HOST)" \
PORTAL_VERSION "$(PORTAL_VERSION)" \
CERT_MANAGER_VERSION "$(CERT_MANAGER_VERSION)" \
ENVOY_GATEWAY_VERSION "$(ENVOY_GATEWAY_VERSION)" \
STRIMZI_VERSION "$(STRIMZI_VERSION)" \
DITTO_OPERATOR_VERSION "$(DITTO_OPERATOR_VERSION)"

# File target: written once, then reused. `make kubeconfig` forces a refresh.
$(KUBECFG):
@mkdir -p $(KUBEDIR)
@echo "==> writing kubeconfig for $(CLUSTER) -> $(KUBECFG)"
@aws eks update-kubeconfig --region "$(REGION)" --name "$(CLUSTER)" \
--alias "$(KUBE_CONTEXT)" --kubeconfig "$(KUBECFG)"

.PHONY: kubeconfig
kubeconfig: ## (Re)write the local kubeconfig
@rm -f $(KUBECFG)
@$(MAKE) --no-print-directory $(KUBECFG)

.PHONY: preflight
preflight: $(KUBECFG) ## Verify tooling, cluster reachability and capacity
@$(S)/preflight.sh

.PHONY: storage
storage: $(KUBECFG) ## Default gp3 StorageClass (EBS CSI driver comes from Terraform)
@$(S)/storage.sh

.PHONY: cert-manager
cert-manager: $(KUBECFG) ## cert-manager + a self-signed ClusterIssuer
@$(S)/cert-manager.sh

.PHONY: envoy
envoy: $(KUBECFG) ## Envoy Gateway + internal (and optional external) gateways
@$(S)/envoy-gateway.sh

.PHONY: strimzi
strimzi: $(KUBECFG) ## Strimzi Kafka operator
@$(S)/strimzi.sh

.PHONY: operator
operator: $(KUBECFG) ## Ditto Operator
@$(S)/ditto-operator.sh

.PHONY: portal
portal: $(KUBECFG) ## Portal UI via the internal gateway (needs PORTAL=1)
@PORTAL=1 $(S)/ditto-operator.sh
@PORTAL=1 $(S)/portal.sh

.PHONY: bootstrap
bootstrap: preflight storage cert-manager envoy strimzi operator ## All cluster dependencies
@$(S)/portal.sh
@echo "==> bootstrap complete"

.PHONY: bigpeer
bigpeer: $(KUBECFG) ## BigPeer CR + its HTTPRoutes
@$(S)/bigpeer.sh

.PHONY: app
app: $(KUBECFG) ## Create an app + API key (writes .local/app.env)
@$(S)/app.sh

.PHONY: smoke
smoke: $(KUBECFG) ## Insert and query a document through the gateway
@$(S)/smoke.sh

.PHONY: all
all: kubeconfig bootstrap bigpeer app smoke ## Everything, end to end
@echo "==> all done"

.PHONY: status
status: $(KUBECFG) ## Show the state of every component
@$(S)/status.sh

.PHONY: endpoint
endpoint: $(KUBECFG) ## Print the gateway endpoints
@$(S)/status.sh endpoints

.PHONY: teardown
teardown: $(KUBECFG) ## Remove everything the Makefile installed (leaves Terraform alone)
@$(S)/teardown.sh

.PHONY: clean
clean: ## Remove generated local files (.env, .kube/, .local/)
rm -rf $(KUBEDIR) .local .env
Loading