Add postgres

This commit is contained in:
2025-04-12 09:27:16 +10:00
parent ac253d76c5
commit f16a167d42
3 changed files with 192 additions and 518 deletions
+95
View File
@@ -1,6 +1,101 @@
# This file is maintained automatically by "terraform init".
# Manual edits may be lost in future updates.
provider "registry.terraform.io/gavinbunney/kubectl" {
version = "1.14.0"
constraints = "1.14.0"
hashes = [
"h1:mX2AOFIMIxJmW5kM8DT51gloIOKCr9iT6W8yodnUyfs=",
"zh:0350f3122ff711984bbc36f6093c1fe19043173fad5a904bce27f86afe3cc858",
"zh:07ca36c7aa7533e8325b38232c77c04d6ef1081cb0bac9d56e8ccd51f12f2030",
"zh:0c351afd91d9e994a71fe64bbd1662d0024006b3493bb61d46c23ea3e42a7cf5",
"zh:39f1a0aa1d589a7e815b62b5aa11041040903b061672c4cfc7de38622866cbc4",
"zh:428d3a321043b78e23c91a8d641f2d08d6b97f74c195c654f04d2c455e017de5",
"zh:4baf5b1de2dfe9968cc0f57fd4be5a741deb5b34ee0989519267697af5f3eee5",
"zh:6131a927f9dffa014ab5ca5364ac965fe9b19830d2bbf916a5b2865b956fdfcf",
"zh:c62e0c9fd052cbf68c5c2612af4f6408c61c7e37b615dc347918d2442dd05e93",
"zh:f0beffd7ce78f49ead612e4b1aefb7cb6a461d040428f514f4f9cc4e5698ac65",
]
}
provider "registry.terraform.io/hashicorp/helm" {
version = "2.12.1"
constraints = "2.12.1"
hashes = [
"h1:7wfYOAeSEchHB8idNl+2jf+OkFi9zFSOLWkEZFuTCik=",
"zh:1d623fb1662703f2feb7860e3c795d849c77640eecbc5a776784d08807b15004",
"zh:253a5bc62ba2c4314875139e3fbd2feaad5ef6b0fb420302a474ab49e8e51a38",
"zh:282358f4ad4f20d0ccaab670b8645228bfad1c03ac0d0df5889f0aea8aeac01a",
"zh:4fd06af3091a382b3f0d8f0a60880f59640d2b6d9d6a31f9a873c6f1bde1ec50",
"zh:6816976b1830f5629ae279569175e88b497abbbac30ee809948a1f923c67a80d",
"zh:7d82c4150cdbf48cfeec867be94c7b9bd7682474d4df0ebb7e24e148f964844f",
"zh:83f062049eea2513118a4c6054fb06c8600bac96196f25aed2cc21898ec86e93",
"zh:a79eec0cf4c08fca79e44033ec6e470f25ff23c3e2c7f9bc707ed7771c1072c0",
"zh:b2b2d904b2821a6e579910320605bc478bbef063579a23fbfdd6fcb5871b81f8",
"zh:e91177ca06a15487fc570cb81ecef6359aa399459ea2aa7c4f7367ba86f6fcad",
"zh:e976bcb82996fc4968f8382bbcb6673efb1f586bf92074058a232028d97825b1",
"zh:f569b65999264a9416862bca5cd2a6177d94ccb0424f3a4ef424428912b9cb3c",
]
}
provider "registry.terraform.io/hashicorp/kubernetes" {
version = "2.27.0"
constraints = "2.27.0"
hashes = [
"h1:/3kLyOR2jTaWS1MKso4xAztrocGBMxi8yVadWiqSWOg=",
"zh:3bdba30ae67c55dc7e9a317ac0da3b208ea7926fe9c2f0ae6587ee88dcc58d1f",
"zh:3f35138a831c00b188d2ffee27111dd0cf59afad2dd5653ed9e67d59646de12c",
"zh:64066d18f6ae9a316c2bc840ef3e641d7ab94e1ea3a41d12523e77345ad442ef",
"zh:653063d44b44881af3a480f7f8eaa94fa300e0229df2072d30f606bddcc9f025",
"zh:87f306e37efb61d13efa6da53a1e45e97e5996ebc0568b1caf8c3c5e54c05809",
"zh:8c428b9708f9634391e52300218771eab3fe942bb1295d8c0ad50ca4b33db3d9",
"zh:a44e87119a0337ded15479851786a13f412b413d9a463ba550d1210249206b0f",
"zh:aa2c4d110b0de6ef997c0d45f3f23f8a98f5530753095d6eff439a6d91a8ea31",
"zh:eb15ed8781ac6a0dec2f7d03cf090e23cfa05e3225806c6231ff2c574662fd63",
"zh:eb81c563f93bd3303f9620d11cd49f21f3f89ac3475c6d3e821b239feb9c217d",
"zh:f1a344a7f16131123577e4ec994d04a34ea458ec16c1ccac53fe7946bd817b18",
"zh:f569b65999264a9416862bca5cd2a6177d94ccb0424f3a4ef424428912b9cb3c",
]
}
provider "registry.terraform.io/hashicorp/local" {
version = "2.5.2"
hashes = [
"h1:p99F1AoV9z51aJ4EdItxz/vLwWIyhx/0Iw7L7sWSH1o=",
"zh:136299545178ce281c56f36965bf91c35407c11897f7082b3b983d86cb79b511",
"zh:3b4486858aa9cb8163378722b642c57c529b6c64bfbfc9461d940a84cd66ebea",
"zh:4855ee628ead847741aa4f4fc9bed50cfdbf197f2912775dd9fe7bc43fa077c0",
"zh:4b8cd2583d1edcac4011caafe8afb7a95e8110a607a1d5fb87d921178074a69b",
"zh:52084ddaff8c8cd3f9e7bcb7ce4dc1eab00602912c96da43c29b4762dc376038",
"zh:71562d330d3f92d79b2952ffdda0dad167e952e46200c767dd30c6af8d7c0ed3",
"zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3",
"zh:805f81ade06ff68fa8b908d31892eaed5c180ae031c77ad35f82cb7a74b97cf4",
"zh:8b6b3ebeaaa8e38dd04e56996abe80db9be6f4c1df75ac3cccc77642899bd464",
"zh:ad07750576b99248037b897de71113cc19b1a8d0bc235eb99173cc83d0de3b1b",
"zh:b9f1c3bfadb74068f5c205292badb0661e17ac05eb23bfe8bd809691e4583d0e",
"zh:cc4cbcd67414fefb111c1bf7ab0bc4beb8c0b553d01719ad17de9a047adff4d1",
]
}
provider "registry.terraform.io/hashicorp/null" {
version = "3.2.3"
hashes = [
"h1:nKUqWEza6Lcv3xRlzeiRQrHtqvzX1BhIzjaOVXRYQXQ=",
"zh:22d062e5278d872fe7aed834f5577ba0a5afe34a3bdac2b81f828d8d3e6706d2",
"zh:23dead00493ad863729495dc212fd6c29b8293e707b055ce5ba21ee453ce552d",
"zh:28299accf21763ca1ca144d8f660688d7c2ad0b105b7202554ca60b02a3856d3",
"zh:55c9e8a9ac25a7652df8c51a8a9a422bd67d784061b1de2dc9fe6c3cb4e77f2f",
"zh:756586535d11698a216291c06b9ed8a5cc6a4ec43eee1ee09ecd5c6a9e297ac1",
"zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3",
"zh:9d5eea62fdb587eeb96a8c4d782459f4e6b73baeece4d04b4a40e44faaee9301",
"zh:a6355f596a3fb8fc85c2fb054ab14e722991533f87f928e7169a486462c74670",
"zh:b5a65a789cff4ada58a5baffc76cb9767dc26ec6b45c00d2ec8b1b027f6db4ed",
"zh:db5ab669cf11d0e9f81dc380a6fdfcac437aea3d69109c7aef1a5426639d2d65",
"zh:de655d251c470197bcbb5ac45d289595295acb8f829f6c781d4a75c8c8b7c7dd",
"zh:f5c68199f2e6076bce92a12230434782bf768103a427e9bb9abee99b116af7b5",
]
}
provider "registry.terraform.io/loafoe/ssh" {
version = "2.6.0"
constraints = "2.6.0"
+97
View File
@@ -0,0 +1,97 @@
# Create a local file with the PostgreSQL installation script
resource "local_file" "postgres_install_script" {
filename = "${path.module}/tmp/install_postgres.sh"
content = <<-EOT
#!/bin/bash
set -e
echo "Checking PostgreSQL installation..."
sudo apt-get update
sudo apt-get install -y postgresql postgresql-contrib
# Stop PostgreSQL before configuration
echo "Stopping PostgreSQL service..."
sudo systemctl stop postgresql
# Configure PostgreSQL data directory
POSTGRES_DATA_DIR="/mnt/k8s/postgres"
POSTGRES_VERSION=14 # Hardcoding to version 14 as that's what's installed
POSTGRES_CONF_DIR="/etc/postgresql/$POSTGRES_VERSION/main"
echo "PostgreSQL version: $POSTGRES_VERSION"
echo "Config directory: $POSTGRES_CONF_DIR"
# Clean up and create new data directory
echo "Setting up fresh data directory..."
sudo rm -rf "$POSTGRES_DATA_DIR"
sudo mkdir -p "$POSTGRES_DATA_DIR"
# Set initial permissions
echo "Setting initial permissions on $POSTGRES_DATA_DIR"
sudo chown postgres:postgres "$POSTGRES_DATA_DIR"
sudo chmod 700 "$POSTGRES_DATA_DIR"
# Initialize PostgreSQL cluster
echo "Initializing new PostgreSQL cluster..."
sudo -u postgres /usr/lib/postgresql/$POSTGRES_VERSION/bin/initdb -D "$POSTGRES_DATA_DIR"
# Configure PostgreSQL to listen on all interfaces
echo "Configuring postgresql.conf..."
echo "listen_addresses = '*'" | sudo -u postgres tee -a "$POSTGRES_DATA_DIR/postgresql.conf"
# Configure remote access
echo "Configuring pg_hba.conf..."
echo "host all all 0.0.0.0/0 md5" | sudo -u postgres tee -a "$POSTGRES_DATA_DIR/pg_hba.conf"
# Update system service configuration
echo "Updating system service configuration..."
sudo sed -i "s|^data_directory.*|data_directory = '$POSTGRES_DATA_DIR'|" "$POSTGRES_CONF_DIR/postgresql.conf"
# Start PostgreSQL
echo "Starting PostgreSQL service..."
sudo systemctl start postgresql
sleep 5
sudo systemctl status postgresql --no-pager || true
# Set password for postgres user
echo "Setting password for postgres user..."
sudo -u postgres psql -c "ALTER USER postgres PASSWORD 'postgres';"
# Verify PostgreSQL is running and accessible
echo "Checking PostgreSQL status..."
sudo -u postgres psql -c "\l"
echo "PostgreSQL installation completed!"
EOT
file_permission = "0755"
}
# Create the scripts directory if it doesn't exist
resource "null_resource" "create_scripts_dir_postgres" {
provisioner "local-exec" {
command = "mkdir -p ${path.module}/scripts"
}
}
# Upload and execute the PostgreSQL installation script
resource "ssh_resource" "postgres_install" {
depends_on = [local_file.postgres_install_script, null_resource.create_scripts_dir_postgres]
host = local.ssh_host
user = local.ssh_user
port = local.ssh_port
private_key = local.ssh_private_key
timeout = "4m"
when = "create"
file {
source = local_file.postgres_install_script.filename
destination = "/tmp/install_postgres.sh"
permissions = "0755"
}
commands = [
"bash /tmp/install_postgres.sh"
]
}
-518
View File
@@ -1,518 +0,0 @@
{
"version": 4,
"terraform_version": "1.5.7",
"serial": 65,
"lineage": "0a6a74be-5948-1b78-61c9-d523dd42e97c",
"outputs": {
"argocd_access": {
"value": "ArgoCD has been installed! To access the UI:\n\n1. Get the admin password:\n kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath=\"{.data.password}\" | base64 -d\n\n2. Access ArgoCD:\n https://argo.junv.cc\n\n3. Login with:\n Username: admin\n Password: (from step 1)\n",
"type": "string"
},
"k3s_token": {
"value": "ssh -p 22422 junv@192.168.1.2 'sudo cat /var/lib/rancher/k3s/server/node-token'",
"type": "string"
},
"kubeconfig_command": {
"value": "scp -P 22422 junv@192.168.1.2:/etc/rancher/k3s/k3s.yaml ~/.kube/config \u0026\u0026 sed -i '' 's/127.0.0.1/192.168.1.2/g' ~/.kube/config",
"type": "string"
},
"next_steps": {
"value": "K3s cluster setup complete! Next steps:\n\n1. Get your kubeconfig:\n scp -P 22422 junv@192.168.1.2:/etc/rancher/k3s/k3s.yaml ~/.kube/config \u0026\u0026 sed -i '' 's/127.0.0.1/192.168.1.2/g' ~/.kube/config\n\n2. Test the connection:\n kubectl get nodes\n\n3. To add worker nodes, get the node token:\n ssh -p 22422 junv@192.168.1.2 'sudo cat /var/lib/rancher/k3s/server/node-token'\n",
"type": "string"
}
},
"resources": [
{
"mode": "managed",
"type": "helm_release",
"name": "argocd",
"provider": "provider[\"registry.terraform.io/hashicorp/helm\"]",
"instances": [
{
"schema_version": 1,
"attributes": {
"atomic": false,
"chart": "argo-cd",
"cleanup_on_fail": false,
"create_namespace": false,
"dependency_update": false,
"description": null,
"devel": null,
"disable_crd_hooks": false,
"disable_openapi_validation": false,
"disable_webhooks": false,
"force_update": false,
"id": "argocd",
"keyring": null,
"lint": false,
"manifest": null,
"max_history": 0,
"metadata": [
{
"app_version": "v2.10.0",
"chart": "argo-cd",
"name": "argocd",
"namespace": "argocd",
"revision": 4,
"values": "{\"server\":{\"extraArgs\":[\"--insecure\"],\"ingress\":{\"annotations\":{\"cert-manager.io/cluster-issuer\":\"letsencrypt-prod\"},\"enabled\":true,\"hosts\":[\"argo.junv.cc\"],\"ingressClassName\":\"nginx\",\"tls\":[{\"hosts\":[\"argo.junv.cc\"],\"secretName\":\"argocd-server-tls\"}]},\"insecure\":true,\"service\":{\"type\":\"ClusterIP\"}}}",
"version": "5.55.0"
}
],
"name": "argocd",
"namespace": "argocd",
"pass_credentials": false,
"postrender": [],
"recreate_pods": true,
"render_subchart_notes": true,
"replace": false,
"repository": "https://argoproj.github.io/argo-helm",
"repository_ca_file": null,
"repository_cert_file": null,
"repository_key_file": null,
"repository_password": null,
"repository_username": null,
"reset_values": false,
"reuse_values": false,
"set": [
{
"name": "server.extraArgs[0]",
"type": "",
"value": "--insecure"
},
{
"name": "server.ingress.annotations.cert-manager\\.io/cluster-issuer",
"type": "",
"value": "letsencrypt-prod"
},
{
"name": "server.ingress.enabled",
"type": "",
"value": "true"
},
{
"name": "server.ingress.hosts[0]",
"type": "",
"value": "argo.junv.cc"
},
{
"name": "server.ingress.ingressClassName",
"type": "",
"value": "nginx"
},
{
"name": "server.ingress.tls[0].hosts[0]",
"type": "",
"value": "argo.junv.cc"
},
{
"name": "server.ingress.tls[0].secretName",
"type": "",
"value": "argocd-server-tls"
},
{
"name": "server.insecure",
"type": "",
"value": "true"
},
{
"name": "server.service.type",
"type": "",
"value": "ClusterIP"
}
],
"set_list": [],
"set_sensitive": [],
"skip_crds": false,
"status": "deployed",
"timeout": 900,
"values": [],
"verify": false,
"version": "5.55.0",
"wait": true,
"wait_for_jobs": false
},
"sensitive_attributes": [],
"private": "eyJzY2hlbWFfdmVyc2lvbiI6IjEifQ==",
"dependencies": [
"helm_release.cert_manager",
"helm_release.ingress_nginx",
"kubernetes_namespace.argocd"
]
}
]
},
{
"mode": "managed",
"type": "helm_release",
"name": "cert_manager",
"provider": "provider[\"registry.terraform.io/hashicorp/helm\"]",
"instances": [
{
"schema_version": 1,
"attributes": {
"atomic": false,
"chart": "cert-manager",
"cleanup_on_fail": false,
"create_namespace": true,
"dependency_update": false,
"description": null,
"devel": null,
"disable_crd_hooks": false,
"disable_openapi_validation": false,
"disable_webhooks": false,
"force_update": false,
"id": "cert-manager",
"keyring": null,
"lint": false,
"manifest": null,
"max_history": 0,
"metadata": [
{
"app_version": "v1.14.3",
"chart": "cert-manager",
"name": "cert-manager",
"namespace": "cert-manager",
"revision": 1,
"values": "{\"installCRDs\":true}",
"version": "v1.14.3"
}
],
"name": "cert-manager",
"namespace": "cert-manager",
"pass_credentials": false,
"postrender": [],
"recreate_pods": false,
"render_subchart_notes": true,
"replace": false,
"repository": "https://charts.jetstack.io",
"repository_ca_file": null,
"repository_cert_file": null,
"repository_key_file": null,
"repository_password": null,
"repository_username": null,
"reset_values": false,
"reuse_values": false,
"set": [
{
"name": "installCRDs",
"type": "",
"value": "true"
}
],
"set_list": [],
"set_sensitive": [],
"skip_crds": false,
"status": "deployed",
"timeout": 300,
"values": null,
"verify": false,
"version": "v1.14.3",
"wait": true,
"wait_for_jobs": false
},
"sensitive_attributes": [],
"private": "eyJzY2hlbWFfdmVyc2lvbiI6IjEifQ=="
}
]
},
{
"mode": "managed",
"type": "helm_release",
"name": "ingress_nginx",
"provider": "provider[\"registry.terraform.io/hashicorp/helm\"]",
"instances": [
{
"schema_version": 1,
"attributes": {
"atomic": false,
"chart": "ingress-nginx",
"cleanup_on_fail": false,
"create_namespace": true,
"dependency_update": false,
"description": null,
"devel": null,
"disable_crd_hooks": false,
"disable_openapi_validation": false,
"disable_webhooks": false,
"force_update": false,
"id": "ingress-nginx",
"keyring": null,
"lint": false,
"manifest": null,
"max_history": 0,
"metadata": [
{
"app_version": "1.9.6",
"chart": "ingress-nginx",
"name": "ingress-nginx",
"namespace": "ingress-nginx",
"revision": 1,
"values": "{\"controller\":{\"hostPort\":{\"enabled\":true},\"ingressClassResource\":{\"default\":true},\"service\":{\"externalTrafficPolicy\":\"Local\",\"nodePorts\":{\"http\":80,\"https\":443},\"type\":\"NodePort\"},\"watchIngressWithoutClass\":true}}",
"version": "4.9.1"
}
],
"name": "ingress-nginx",
"namespace": "ingress-nginx",
"pass_credentials": false,
"postrender": [],
"recreate_pods": false,
"render_subchart_notes": true,
"replace": false,
"repository": "https://kubernetes.github.io/ingress-nginx",
"repository_ca_file": null,
"repository_cert_file": null,
"repository_key_file": null,
"repository_password": null,
"repository_username": null,
"reset_values": false,
"reuse_values": false,
"set": [
{
"name": "controller.hostPort.enabled",
"type": "",
"value": "true"
},
{
"name": "controller.ingressClassResource.default",
"type": "",
"value": "true"
},
{
"name": "controller.service.externalTrafficPolicy",
"type": "",
"value": "Local"
},
{
"name": "controller.service.nodePorts.http",
"type": "",
"value": "80"
},
{
"name": "controller.service.nodePorts.https",
"type": "",
"value": "443"
},
{
"name": "controller.service.type",
"type": "",
"value": "NodePort"
},
{
"name": "controller.watchIngressWithoutClass",
"type": "",
"value": "true"
}
],
"set_list": [],
"set_sensitive": [],
"skip_crds": false,
"status": "deployed",
"timeout": 300,
"values": null,
"verify": false,
"version": "4.9.1",
"wait": true,
"wait_for_jobs": false
},
"sensitive_attributes": [],
"private": "eyJzY2hlbWFfdmVyc2lvbiI6IjEifQ=="
}
]
},
{
"mode": "managed",
"type": "kubernetes_namespace",
"name": "argocd",
"provider": "provider[\"registry.terraform.io/hashicorp/kubernetes\"]",
"instances": [
{
"schema_version": 0,
"attributes": {
"id": "argocd",
"metadata": [
{
"annotations": {},
"generate_name": "",
"generation": 0,
"labels": {},
"name": "argocd",
"resource_version": "1404",
"uid": "ca66b674-dafb-452b-86ab-826013b403b5"
}
],
"timeouts": null,
"wait_for_default_service_account": false
},
"sensitive_attributes": [],
"private": "eyJlMmJmYjczMC1lY2FhLTExZTYtOGY4OC0zNDM2M2JjN2M0YzAiOnsiZGVsZXRlIjozMDAwMDAwMDAwMDB9fQ=="
}
]
},
{
"mode": "managed",
"type": "local_file",
"name": "redis_install_script",
"provider": "provider[\"registry.terraform.io/hashicorp/local\"]",
"instances": [
{
"schema_version": 0,
"attributes": {
"content": "#!/bin/bash\nset -e\n\necho \"Installing Redis...\"\nsudo apt-get update\nsudo apt-get install -y redis-server\n\n# Stop Redis before configuration\necho \"Stopping Redis service...\"\nsudo systemctl stop redis-server\n\n# Configure Redis\nsudo chown redis:redis /mnt/k8s/redis\necho \"Configuring Redis...\"\n\n# Find and copy the latest RDB and AOF files from Bitnami directory\necho \"Finding and copying latest Redis data files...\"\nLATEST_RDB=$(sudo find /mnt/k8s/redis/appendonlydir -name \"*.base.rdb\" | sort -V | tail -1)\nLATEST_AOF=$(sudo find /mnt/k8s/redis/appendonlydir -name \"*.incr.aof\" | sort -V | tail -1)\n\n# Create a backup directory\nBACKUP_DIR=\"/mnt/k8s/redis/backup_$(date +%Y%m%d%H%M%S)\"\nsudo mkdir -p \"$BACKUP_DIR\"\n\n# Backup existing files\nif [ -f \"/mnt/k8s/redis/dump.rdb\" ]; then \n sudo mv \"/mnt/k8s/redis/dump.rdb\" \"$BACKUP_DIR/\"\nfi\n\nif [ -f \"/mnt/k8s/redis/appendonly.aof\" ]; then \n sudo mv \"/mnt/k8s/redis/appendonly.aof\" \"$BACKUP_DIR/\"\nfi\n\n# Copy the latest files\necho \"Copying $LATEST_RDB to /mnt/k8s/redis/dump.rdb\"\nsudo cp \"$LATEST_RDB\" \"/mnt/k8s/redis/dump.rdb\"\necho \"Copying $LATEST_AOF to /mnt/k8s/redis/appendonly.aof\"\nsudo cp \"$LATEST_AOF\" \"/mnt/k8s/redis/appendonly.aof\"\n\n# Set permissions\nsudo chown redis:redis \"/mnt/k8s/redis/dump.rdb\"\nsudo chown redis:redis \"/mnt/k8s/redis/appendonly.aof\"\nsudo chmod 640 \"/mnt/k8s/redis/dump.rdb\"\nsudo chmod 640 \"/mnt/k8s/redis/appendonly.aof\"\n\n# Create Redis configuration\nsudo bash -c 'cat \u003e /etc/redis/redis.conf \u003c\u003c EOF\nbind 0.0.0.0\nprotected-mode no\nport 6379\ndir /mnt/k8s/redis\nappendonly yes\nappendfilename \"appendonly.aof\"\nappendfsync everysec\nsave 900 1\nsave 300 10\nsave 60 10000\naof-use-rdb-preamble yes\naof-load-truncated yes\naof-rewrite-incremental-fsync yes\nEOF'\n\n# Update systemd service file to allow access to appendonlydir\nif ! sudo grep -q \"ReadWritePaths=-/mnt/k8s/redis/appendonlydir\" /etc/systemd/system/redis-server.service; then\n sudo sed -i '/ReadWritePaths=-\\/mnt\\/k8s\\/redis/a ReadWritePaths=-\\/mnt\\/k8s\\/redis\\/appendonlydir' /etc/systemd/system/redis-server.service || true\nfi\n\n# Ensure proper permissions\nsudo chown redis:redis /etc/redis/redis.conf\nsudo chmod 640 /etc/redis/redis.conf\nsudo chown -R redis:redis /mnt/k8s/redis\nsudo chmod -R 750 /mnt/k8s/redis\n\n# Reload systemd and restart Redis\nsudo systemctl daemon-reload\nsudo systemctl restart redis-server\necho \"Waiting for Redis to start...\"\nsleep 5\nsudo systemctl status redis-server --no-pager || true\n\n# Verify Redis data was loaded\necho \"Checking Redis data...\"\nsudo redis-cli dbsize\nsudo redis-cli keys '*' | head -5 || true\necho \"Redis installation completed!\"\n",
"content_base64": null,
"content_base64sha256": "C0GB8DHE7zi2vofR5aTfq/g0YpvmOxK9vOZuoBICiag=",
"content_base64sha512": "lHOvQShQ11KagOluatFerZPvk/wztgFebfSJ8zCV0sD4Dqn2/sb0KbTpQHxipf1gbp1vOnUp95UHa+UZAFDRXA==",
"content_md5": "afe1845a85de90b6c170851e2b1df11a",
"content_sha1": "7d54c3016d142084655fcc098c56f7853e9bf340",
"content_sha256": "0b4181f031c4ef38b6be87d1e5a4dfabf834629be63b12bdbce66ea0120289a8",
"content_sha512": "9473af412850d7529a80e96e6ad15ead93ef93fc33b6015e6df489f33095d2c0f80ea9f6fec6f429b4e9407c62a5fd606e9d6f3a7529f795076be5190050d15c",
"directory_permission": "0777",
"file_permission": "0755",
"filename": "./tmp/install_redis.sh",
"id": "7d54c3016d142084655fcc098c56f7853e9bf340",
"sensitive_content": null,
"source": null
},
"sensitive_attributes": []
}
]
},
{
"mode": "managed",
"type": "null_resource",
"name": "create_scripts_dir",
"provider": "provider[\"registry.terraform.io/hashicorp/null\"]",
"instances": [
{
"schema_version": 0,
"attributes": {
"id": "8265566036880216262",
"triggers": null
},
"sensitive_attributes": []
}
]
},
{
"mode": "managed",
"type": "null_resource",
"name": "wait_for_cert_manager_crds",
"provider": "provider[\"registry.terraform.io/hashicorp/null\"]",
"instances": [
{
"schema_version": 0,
"attributes": {
"id": "6787282006457738648",
"triggers": null
},
"sensitive_attributes": [],
"dependencies": [
"helm_release.cert_manager"
]
}
]
},
{
"mode": "managed",
"type": "ssh_resource",
"name": "k3s_install",
"provider": "provider[\"registry.terraform.io/loafoe/ssh\"]",
"instances": [
{
"schema_version": 4,
"attributes": {
"agent": false,
"bastion_host": null,
"bastion_password": null,
"bastion_port": "22",
"bastion_private_key": null,
"bastion_user": null,
"commands": [
"echo 'Installing k3s...'",
"curl -sfL https://get.k3s.io \u003e install.sh",
"chmod +x install.sh",
"INSTALL_K3S_EXEC='--tls-san 192.168.1.2 --kube-apiserver-arg service-node-port-range=80-32767 --disable traefik' sudo -E ./install.sh",
"echo 'Waiting for k3s to start (60s)...'",
"sleep 60",
"sudo chmod 644 /etc/rancher/k3s/k3s.yaml",
"echo 'Checking node status...'",
"sudo kubectl --kubeconfig=/etc/rancher/k3s/k3s.yaml get nodes -o wide",
"echo 'K3s installation completed!'"
],
"commands_after_file_changes": true,
"file": [],
"host": "192.168.1.2",
"host_private_key": null,
"host_user": null,
"id": "5405818983794944734",
"password": null,
"port": "22422",
"pre_commands": null,
"private_key": "-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW\nQyNTUxOQAAACD7YuJqOLvMPWLaf+eiT9LX5TsmlggcdKJp847296SISAAAAJijIGOvoyBj\nrwAAAAtzc2gtZWQyNTUxOQAAACD7YuJqOLvMPWLaf+eiT9LX5TsmlggcdKJp847296SISA\nAAAEAVgAUPk0hwoiFwnlQOhSL3iZ+qboim1OQNtsHnj3Khp/ti4mo4u8w9Ytp/56JP0tfl\nOyaWCBx0omnzjvb3pIhIAAAAEHdhaHlkNEBnbWFpbC5jb20BAgMEBQ==\n-----END OPENSSH PRIVATE KEY-----\n",
"result": "K3s installation completed!\n",
"retry_delay": "10s",
"timeout": "15m",
"triggers": null,
"user": "junv",
"when": "create"
},
"sensitive_attributes": [],
"private": "eyJzY2hlbWFfdmVyc2lvbiI6IjQifQ=="
}
]
},
{
"mode": "managed",
"type": "ssh_resource",
"name": "redis_install",
"provider": "provider[\"registry.terraform.io/loafoe/ssh\"]",
"instances": [
{
"schema_version": 4,
"attributes": {
"agent": false,
"bastion_host": null,
"bastion_password": null,
"bastion_port": "22",
"bastion_private_key": null,
"bastion_user": null,
"commands": [
"bash /tmp/install_redis.sh"
],
"commands_after_file_changes": true,
"file": [
{
"content": "",
"destination": "/tmp/install_redis.sh",
"group": "",
"owner": "",
"permissions": "0755",
"source": "./tmp/install_redis.sh"
}
],
"host": "192.168.1.2",
"host_private_key": null,
"host_user": null,
"id": "4618730231472137946",
"password": null,
"port": "22422",
"pre_commands": null,
"private_key": "-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW\nQyNTUxOQAAACD7YuJqOLvMPWLaf+eiT9LX5TsmlggcdKJp847296SISAAAAJijIGOvoyBj\nrwAAAAtzc2gtZWQyNTUxOQAAACD7YuJqOLvMPWLaf+eiT9LX5TsmlggcdKJp847296SISA\nAAAEAVgAUPk0hwoiFwnlQOhSL3iZ+qboim1OQNtsHnj3Khp/ti4mo4u8w9Ytp/56JP0tfl\nOyaWCBx0omnzjvb3pIhIAAAAEHdhaHlkNEBnbWFpbC5jb20BAgMEBQ==\n-----END OPENSSH PRIVATE KEY-----\n",
"result": "Installing Redis...\nHit:1 http://au.archive.ubuntu.com/ubuntu jammy InRelease\nHit:2 http://au.archive.ubuntu.com/ubuntu jammy-updates InRelease\nHit:3 http://au.archive.ubuntu.com/ubuntu jammy-backports InRelease\nHit:4 http://au.archive.ubuntu.com/ubuntu jammy-security InRelease\nHit:5 https://prod-cdn.packages.k8s.io/repositories/isv:/kubernetes:/core:/stable:/v1.32/deb InRelease\nHit:6 https://packages.redis.io/deb jammy InRelease\nReading package lists...\nReading package lists...\nBuilding dependency tree...\nReading state information...\nredis-server is already the newest version (6:7.4.2-1rl1~jammy1).\nThe following packages were automatically installed and are no longer required:\n libjemalloc2 liblua5.1-0 liblzf1 lua-bitop lua-cjson\nUse 'sudo apt autoremove' to remove them.\n0 upgraded, 0 newly installed, 0 to remove and 1 not upgraded.\nStopping Redis service...\nConfiguring Redis...\nFinding and copying latest Redis data files...\nCopying /mnt/k8s/redis/appendonlydir/appendonly.aof.149903.base.rdb to /mnt/k8s/redis/dump.rdb\nCopying /mnt/k8s/redis/appendonlydir/appendonly.aof.149903.incr.aof to /mnt/k8s/redis/appendonly.aof\nWaiting for Redis to start...\n● redis-server.service - Advanced key-value store\n Loaded: loaded (/etc/systemd/system/redis-server.service; enabled; vendor preset: enabled)\n Active: active (running) since Fri 2025-04-11 14:17:24 UTC; 5s ago\n Docs: http://redis.io/documentation,\n man:redis-server(1)\n Main PID: 116750 (redis-server)\n Status: \"Ready to accept connections\"\n Tasks: 6 (limit: 38378)\n Memory: 8.3M\n CPU: 1.505s\n CGroup: /system.slice/redis-server.service\n └─116750 \"/usr/bin/redis-server 0.0.0.0:6379\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\" \"\"\nApr 11 14:17:24 server-3 redis-server[116750]: 116750:M 11 Apr 2025 14:17:24.570 * RDB age 24438 seconds\nApr 11 14:17:24 server-3 redis-server[116750]: 116750:M 11 Apr 2025 14:17:24.570 * RDB memory usage when created 5.15 Mb\nApr 11 14:17:24 server-3 redis-server[116750]: 116750:M 11 Apr 2025 14:17:24.570 * RDB is base AOF\nApr 11 14:17:24 server-3 redis-server[116750]: 116750:M 11 Apr 2025 14:17:24.578 * Done loading RDB, keys loaded: 167, keys expired: 0.\nApr 11 14:17:24 server-3 redis-server[116750]: 116750:M 11 Apr 2025 14:17:24.578 * DB loaded from base file appendonly.aof.149903.base.rdb: 0.008 seconds\nApr 11 14:17:24 server-3 redis-server[116750]: 116750:M 11 Apr 2025 14:17:24.602 * DB loaded from incr file appendonly.aof.149903.incr.aof: 0.024 seconds\nApr 11 14:17:24 server-3 redis-server[116750]: 116750:M 11 Apr 2025 14:17:24.602 * DB loaded from append only file: 0.032 seconds\nApr 11 14:17:24 server-3 redis-server[116750]: 116750:M 11 Apr 2025 14:17:24.602 * Opening AOF incr file appendonly.aof.149903.incr.aof on server start\nApr 11 14:17:24 server-3 redis-server[116750]: 116750:M 11 Apr 2025 14:17:24.602 * Ready to accept connections tcp\nApr 11 14:17:24 server-3 systemd[1]: Started Advanced key-value store.\nChecking Redis data...\n154\nmfst|argocd.argoproj.io/instance|db|4200c3d72a6d88f3201170bfb4d07ad83e3ec46c|db|2325489594|1.8.3.gz\ncelery-task-meta-e2ce837b-c55f-452e-8773-9cd4a91ff8cd\ncelery-task-meta-c365c427-5d06-4937-935c-cf2961e199f2\ncelery-task-meta-a7ba9d37-0ef1-4c58-ab89-34459f3270f9\ncelery-task-meta-3fb6f83b-114b-493b-8052-9bf098618d13\nRedis installation completed!\n",
"retry_delay": "10s",
"timeout": "5m",
"triggers": null,
"user": "junv",
"when": "create"
},
"sensitive_attributes": [],
"private": "eyJzY2hlbWFfdmVyc2lvbiI6IjQifQ==",
"dependencies": [
"local_file.redis_install_script",
"null_resource.create_scripts_dir"
]
}
]
}
],
"check_results": null
}