Sign inSign up

driftwood/konga-deo

By driftwood

•Updated almost 7 years ago

Konga with secrets management using Chamber

Image
0

2.3K

driftwood/konga-deo repository overview

⁠kong-gateway-deo

⁠About

This project creates two containers for deployment in AWS ECS:

  1. Kong Gateway⁠ container with secrets management using Chamber⁠
  2. Konga⁠ UI container with secrets management using Chamber⁠

aws-vault⁠ is used to generate temporary AWS credentials throughout the documentation. If you aren't using aws-vault, remove everything before "--" for each command.

⁠Configuration

⁠Kong
KONG_ADMIN_ACCESS_LOG="/dev/stdout"
KONG_ADMIN_ERROR_LOG="/dev/stderr"
KONG_ADMIN_LISTEN="0.0.0.0:8001"
KONG_LOG_LEVEL="error"
KONG_PG_DATABASE="kong"
KONG_PG_HOST="DATABASE_HOST"
KONG_PG_PASSWORD="DATABASE_PASSWORD"
KONG_PG_USER="DATABASE_USER"
KONG_PROXY_ACCESS_LOG="/dev/stdout"
KONG_PROXY_ERROR_LOG="/dev/stderr"
KONG_PROXY_LISTEN="0.0.0.0:8000"
KONG_STATUS_LISTEN="0.0.0.0:8100"
KONG_TRUSTED_IPS="0.0.0.0/0,::/0"
⁠Konga
DB_ADAPTER="postgres"
DB_DATABASE="konga"
DB_HOST="DATABASE_HOST"
DB_PASSWORD="DATABASE_PASSWORD"
DB_USER="DATABASE_USER"
KONG_LOG_LEVEL="info"
NODE_ENV="production"
TOKEN_SECRET="TOKEN"

⁠Add secrets to SSM Parameter Store

⁠Kong

ENV is the name of the aws-vault profile to use. If you aren't using aws-vault, remove everything before "--" for each command.

aws-vault exec ${ENV} -- chamber write kong VARIABLE_NAME VALUE

Example:

aws-vault exec ${ENV} -- chamber write kong kong_proxy_listen 0.0.0.0:8000
⁠Konga
aws-vault exec ${ENV} -- chamber write konga VARIABLE_NAME VALUE

Example:

aws-vault exec ${ENV} -- chamber write konga node_env production

⁠Database Migration

Before first execution, both the kong and konga databases need to be prepared.

  1. Apply Kong migrations

    aws-vault exec ${ENV} -- docker run --env-file .env -e AWS_REGION -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY -e AWS_SESSION_TOKEN -e AWS_SECURITY_TOKEN driftwood/kong-gateway-deo kong migrations bootstrap
    
  2. Apply Konga migrations

    aws-vault exec ${ENV} -- docker run --env-file .env -e AWS_REGION -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY -e AWS_SESSION_TOKEN -e AWS_SECURITY_TOKEN driftwood/konga-deo -c prepare -a postgres -u postgresql://${DB_USER}:${DB_PASSWORD}@${DB_HOST}:${DB_PORT}/${DB_DATABASE}
    

Example Makefile (assumes jq⁠ is installed):


ENV:=prod

run-kong:
    # run the kong container with temporary credentials
	aws-vault exec ${ENV} -- docker run -e AWS_REGION -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY -e AWS_SESSION_TOKEN -e AWS_SECURITY_TOKEN driftwood/kong-gateway-deo

run-konga:
    # run the konga container with temporary credentials
	aws-vault exec ${ENV} -- docker run -e AWS_REGION -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY -e AWS_SESSION_TOKEN -e AWS_SECURITY_TOKEN driftwood/konga-deo

ssm-export-kong:
	# Export all SSM parameters associated with this service to the console as son
	aws-vault exec ${ENV} -- chamber export kong | jq

ssm-export-konga:
	# Export all SSM parameters associated with this service to the console as json
	aws-vault exec ${ENV} -- chamber export konga | jq

view-credentials:
	# print the current temporary credentials from aws-vault
	aws-vault exec ${ENV} -- env | grep AWS

ssm-export-kong:
    # Export all SSM parameters associated with this service to the console as json
    aws-vault exec ${ENV} -- chamber export kong | jq

ssm-export-konga:
    # Export all SSM parameters associated with this service to the console as json
    aws-vault exec ${ENV} -- chamber export konga | jq

ssm-export-dotenv-kong: # Export all SSM parameters associated with this service to a dotenv file
    aws-vault exec ${ENV} -- chamber export --format=dotenv kong | tee .env.kong

ssm-export-dotenv-konga: # Export all SSM parameters associated with this service to a dotenv file
    aws-vault exec ${ENV} -- chamber export --format=dotenv kong | tee .env.konga

ssm-update-kong:
    # Update SSM environment variables using a local dotenv file (.env.kong by default)
    # Python is used to convert the uppercased keys to lowercase. The chamber "import" command currently doesnt do this.
    python3 -c 'import json, os, dotenv; values={k.lower():v for k,v in dotenv.dotenv_values(".env.kong").items()}; print(json.dumps(values))' | jq | aws-vault exec ${ENV} -- chamber import kong -

ssm-update-konga:
    # Update SSM environment variables using a local dotenv file (.env.kong by default)
    # Python is used to convert the uppercased keys to lowercase. The chamber "import" command currently doesnt do this.
    python3 -c 'import json, os, dotenv; values={k.lower():v for k,v in dotenv.dotenv_values(".env.konga").items()}; print(json.dumps(values))' | jq | aws-vault exec ${ENV} -- chamber import konga -

Tag summary

Content type

Image

Digest

Size

149.7 MB

Last updated

almost 7 years ago

docker pull driftwood/konga-deo