Konga with secrets management using Chamber
2.3K
This project creates two containers for deployment in AWS ECS:
aws-vault is used to generate temporary AWS credentials throughout the documentation. If you aren't using aws-vault, remove everything before "--" for each command.
KONG_ADMIN_ACCESS_LOG="/dev/stdout"
KONG_ADMIN_ERROR_LOG="/dev/stderr"
KONG_ADMIN_LISTEN="0.0.0.0:8001"
KONG_LOG_LEVEL="error"
KONG_PG_DATABASE="kong"
KONG_PG_HOST="DATABASE_HOST"
KONG_PG_PASSWORD="DATABASE_PASSWORD"
KONG_PG_USER="DATABASE_USER"
KONG_PROXY_ACCESS_LOG="/dev/stdout"
KONG_PROXY_ERROR_LOG="/dev/stderr"
KONG_PROXY_LISTEN="0.0.0.0:8000"
KONG_STATUS_LISTEN="0.0.0.0:8100"
KONG_TRUSTED_IPS="0.0.0.0/0,::/0"
DB_ADAPTER="postgres"
DB_DATABASE="konga"
DB_HOST="DATABASE_HOST"
DB_PASSWORD="DATABASE_PASSWORD"
DB_USER="DATABASE_USER"
KONG_LOG_LEVEL="info"
NODE_ENV="production"
TOKEN_SECRET="TOKEN"
ENV is the name of the aws-vault profile to use. If you aren't using aws-vault, remove everything before "--" for each command.
aws-vault exec ${ENV} -- chamber write kong VARIABLE_NAME VALUE
Example:
aws-vault exec ${ENV} -- chamber write kong kong_proxy_listen 0.0.0.0:8000
aws-vault exec ${ENV} -- chamber write konga VARIABLE_NAME VALUE
Example:
aws-vault exec ${ENV} -- chamber write konga node_env production
Before first execution, both the kong and konga databases need to be prepared.
Apply Kong migrations
aws-vault exec ${ENV} -- docker run --env-file .env -e AWS_REGION -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY -e AWS_SESSION_TOKEN -e AWS_SECURITY_TOKEN driftwood/kong-gateway-deo kong migrations bootstrap
Apply Konga migrations
aws-vault exec ${ENV} -- docker run --env-file .env -e AWS_REGION -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY -e AWS_SESSION_TOKEN -e AWS_SECURITY_TOKEN driftwood/konga-deo -c prepare -a postgres -u postgresql://${DB_USER}:${DB_PASSWORD}@${DB_HOST}:${DB_PORT}/${DB_DATABASE}
Example Makefile (assumes jq is installed):
ENV:=prod
run-kong:
# run the kong container with temporary credentials
aws-vault exec ${ENV} -- docker run -e AWS_REGION -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY -e AWS_SESSION_TOKEN -e AWS_SECURITY_TOKEN driftwood/kong-gateway-deo
run-konga:
# run the konga container with temporary credentials
aws-vault exec ${ENV} -- docker run -e AWS_REGION -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY -e AWS_SESSION_TOKEN -e AWS_SECURITY_TOKEN driftwood/konga-deo
ssm-export-kong:
# Export all SSM parameters associated with this service to the console as son
aws-vault exec ${ENV} -- chamber export kong | jq
ssm-export-konga:
# Export all SSM parameters associated with this service to the console as json
aws-vault exec ${ENV} -- chamber export konga | jq
view-credentials:
# print the current temporary credentials from aws-vault
aws-vault exec ${ENV} -- env | grep AWS
ssm-export-kong:
# Export all SSM parameters associated with this service to the console as json
aws-vault exec ${ENV} -- chamber export kong | jq
ssm-export-konga:
# Export all SSM parameters associated with this service to the console as json
aws-vault exec ${ENV} -- chamber export konga | jq
ssm-export-dotenv-kong: # Export all SSM parameters associated with this service to a dotenv file
aws-vault exec ${ENV} -- chamber export --format=dotenv kong | tee .env.kong
ssm-export-dotenv-konga: # Export all SSM parameters associated with this service to a dotenv file
aws-vault exec ${ENV} -- chamber export --format=dotenv kong | tee .env.konga
ssm-update-kong:
# Update SSM environment variables using a local dotenv file (.env.kong by default)
# Python is used to convert the uppercased keys to lowercase. The chamber "import" command currently doesnt do this.
python3 -c 'import json, os, dotenv; values={k.lower():v for k,v in dotenv.dotenv_values(".env.kong").items()}; print(json.dumps(values))' | jq | aws-vault exec ${ENV} -- chamber import kong -
ssm-update-konga:
# Update SSM environment variables using a local dotenv file (.env.kong by default)
# Python is used to convert the uppercased keys to lowercase. The chamber "import" command currently doesnt do this.
python3 -c 'import json, os, dotenv; values={k.lower():v for k,v in dotenv.dotenv_values(".env.konga").items()}; print(json.dumps(values))' | jq | aws-vault exec ${ENV} -- chamber import konga -
Content type
Image
Digest
Size
149.7 MB
Last updated
almost 7 years ago
docker pull driftwood/konga-deo