Sign inSign up

simplemachines/ansible-template

By simplemachines

•Updated almost 9 years ago

Ansible-template build

Image
1

1.2K

simplemachines/ansible-template repository overview

⁠[DEPRECATED] Please move over to https://github.com/simple-machines/ansible-aws-infra-services⁠

⁠Getting Started

This template is supposed to live inside a deployable or infrastructure project and can self-update. To download and bootstrap a new template instance :

curl -L https://github.com/simple-machines/ansible-template/archive/master.tar.gz | tar zxv
mv ansible-template-master ansible
cd ansible
echo "12345" > .vaultpassword

⁠Running

Requires Docker to be installed (tested with Docker 1.12)

⁠Running playbooks after configuration

# Create a playbook (it will copy the roles/template folder to roles/<env>)
./create-role.sh dev
# Run the playbook
./run-playbook.sh dev

⁠Adding password file and edit the secret variables

echo "12345">.vaultpassword
./editvault.sh dev

⁠Configuration - Ansible Variables

infra vs env explanation

⁠Main Variables

variable namedefaultenv/infra guidanceimportancedescription
application_namemy-appinframandatoryYour application name. Letters (uppercase and lowercase), numbers, hyphens, and underscores are allowed
aws_regionenvmandatoryRegion where you application will be deployed
aws_profileenvmandatoryaws profile to use for deployment (in ~/.aws/credentials)
vpc_idenvmandatoryvpc the application will be deployed in
launch_config_key_nameenvmandatoryssh key name for your ec2 instances (existing key)

⁠ECS

⁠Service / Task Definition
variable namedefaultenv/infra guidanceimportancedescription
ecs_environment_variables[]define structure in infra, replace env specific in envhighUse this variable if your application requires environment variables
ecs_additional_port_mappings[]infrahighApplication port is opened by default. Array of extra port mappings to set (containerPort / hostPort). e.g. ecs_additional_port_mappings: - containerPort: 9999 hostPort: 9999
ecs_volumeinframediumoptional volume to mount. provide two keys from and to, e.g. "from": "/mnt", "to": "/etc"
ecs_service_desired_countasg_desired_capacity (1)inframediumManually set how many tasks you desire. Will default to the desired capacity of your asg by default
ecs_log_driverjson-fileenvlowlog options (replace this variable if you want to send logs to external aggregators e.g. splunk)
ecs_taskdefinition_cpumax it can use for the instancelowthe cpu for the task definition. By default utilise all available
ecs_taskdefinition_memorymax it can use for the instancelowthe memory for the task definition. By default utilise all available
ecs_cluster_nameapplication_namevery lowyour ecs cluster name is your application name
ecs_servicecomplexvery lowadvanced users only. Do not override unless you know what you're doing.
⁠Docker image

The AWS account ID where the docker images are stored (ECR). See docker_image_repo. Images are expected to be found at "{{ docker_image_repo }}/{{ application_name }}:{{ docker_image_tag }}".

variable namedefaultenv/infra guidanceimportancedescription
aws_account_idenvmandatoryThe AWS account ID where the docker images are stored (ECR). See docker_image_repo. Images is expected to be found at "{{ docker_image_repo }}/{{ application_name }}:{{ docker_image_tag }}"
docker_image_repo{{ aws_account_id }}.dkr.ecr.{{ aws_region }}.amazonaws.comenvlowrepository host name where images are stored
docker_image_name{{ application_name }}infralowimage name to look for
docker_image_taglatestenvmediumimage tag. Change this if you need to use a specific version instead of latest

⁠Autoscaling Group

To activate the creation of an ASG, place in infra/vars/main.yml the following:

  • create_auto_scaling_group: true
variable namedefaultenv/infra guidanceimportancedescription
asg_subnets[]envmandatoryList of subnets to deploy the application to
asg_additional_tags[{"Name":"{{ application_name }}"}]common structure in infra, env specific in envhighList of tags to apply to your asg and its ec2 instances
asg_min_size1envmediumminimum number of ec2 instances in your asg
asg_max_size1envmediummaximum number of ec2 instances in your asg
asg_desired_capacity1envmediumdesired number of ec2 instances in your asg
asg_override_desired_capacityfalseenvhighif false, asg_desired_capacity will be ignored if an asg already exists. if true, the asg will scale in or out to match asg_desired_capacity
launch_config_instance_sizet2.smallenvhighec2 instance size
launch_config_instance_profile_nameenvhighIAM instance profile name to define EC2 instances permissions
launch_config_assign_public_ipfalseenvmediumtrue means a public IP will be assigned to every new instance
application_port9000infrahighport that will be opened for your application
application_security_group_additional_open_ports[]inframediumlist of ports (from / port) to add to the security group
additional_user_data_bootcmddummy echo commands (see default/main.yml)inframediummultiline string that start by hyphens (-). Will be run at every boot.
additional_ecs_configvar=val (see default/main.yml)inframediummultiline string that allow you to configure the ECS agent (see ECS agent github)
additional_write_files(see default/main.yml)inframediumTo write more files on boot
additional_user_data_runcmd(see default/main.yml)inframediumcommands to run on first boot only
additional_cloud_config_commands(see default/main.yml)inframediumadditional commands for cloud config (see cloud config official doc)
additional_python_pip_packagesspace delimited listinframediumadditional python pip packages to install

⁠ELB

To activate the creation of an ELB, place in infra/vars/main.yml the following:

  • create_elb: true
variable namedefaultenv/infra guidanceimportancedescription
elb_inbound_ipsenvmandatoryarray of authorized IPs for ELB inbound traffic rules
application_port9000inframandatoryThe application port that the ELB will talk to
elb_secure_httpsfalseenvhighset to true if you'd like to authorise https traffic.
elb_ssl_certificate_nameenvhighif elb_secure_https is set to true, you need to provide the ssl certificate name
elb_tags[{"Name":"{{ application_name }}-elb"}]common structure in infra, env specific in envhighDict of tags to apply to your ELB
elb_health_check_ping_path/infrahighping path for health checks (your application need to have a health check route that returns 200 if healthy)
elb_connection_draining_timeout60inframediumsee aws doc
elb_health_check_response_timeout5inframediumsee aws doc
elb_health_check_interval15inframediumsee aws doc
elb_health_check_unhealthy_threshold6inframediumsee aws doc
elb_health_check_healthy_threshold2inframediumsee aws doc
elb_schemeinternet-facinginframediumsee aws doc

⁠EC2 Instances Shortcuts (alias and functions)

  • dps: shortcut for docker ps
  • dl : get the id of running docker container
  • dlog : get the log of the running container
  • dlogf : get the tailing log of the running container
  • dlogt : get the log with timestamps of the running container
  • dlog -ft : get the log of the running container with tailing and timestamps
  • dex <command> : docker execute command (interactive mode) on the running container (ex: dex bash)
  • dattach: print log as it streams (docker attach --no-stdin --sig-proxy=false)

⁠Directory Structure (aka what goes where)

  • ansible/: root folder
    • run-playbook.sh: script to run deployment. ex ./run-playbook.sh dev.yml

    • editvault.sh: script to change secret variables ex ./editvault.sh dev modifies the file: ./dev/vars/secret.yml. This requires .vaultpassword to be present.

    • .vaultpassword: contains the password to decrypt the vault. Do not commit this file!

    • dev.yml, prod.yml, test.yml: orchestrate deployment. They should only contain information about the environment (profile) and roles to execute. Example:

      - hosts: localhost
        gather_facts: yes
        environment:
          AWS_PROFILE: "my-company-dev"
        roles:
          - dev
          - infra
      
    • dev/, prod/, test/, etc: directory that contain environment specific variables

      • tasks/main.yml: File that should be edited to only include other variable files.
      • vars/: folder containing variables specific to the environment
        • secret.yml: encrypted variables (through editvault.sh)
        • main.yml: main variables
        • foo.yml: create as many as you want, but make sure to include them in your tasks/main.yml
    • infra/: directory that includes all the tasks. Could be seen as a "common" directory

      • vars/: define variables that are common. Can refer to your specific
      • tasks/: tasks that will be executed by ansible
        • main.yml: main file. references variables as defined in vars and then references other tasks in the same subfolder.
        • foo.yml: create as many as you want, but make sure to include them in your main.yml file.

Tag summary

Content type

Image

Digest

Size

295.5 MB

Last updated

almost 9 years ago

docker pull simplemachines/ansible-template