🔧 chore(terraform): update security group rules to allow ingress and egress traffic on port 8080
🔧 chore(terraform): modify user data script for manager instance to fetch instance metadata with token and start a netcat server on port 8080 to provide join token 🔧 chore(terraform): modify user data script for worker instance to fetch manager IP and join the swarm using the join token obtained from the manager on port 8080
This commit is contained in:
parent
3fe30671d9
commit
d13771d8c9
2 changed files with 36 additions and 9 deletions
|
|
@ -89,4 +89,18 @@ resource "aws_security_group" "swarm-sg" {
|
||||||
protocol = "-1"
|
protocol = "-1"
|
||||||
cidr_blocks = ["0.0.0.0/0"]
|
cidr_blocks = ["0.0.0.0/0"]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
ingress {
|
||||||
|
from_port = 8080
|
||||||
|
to_port = 8080
|
||||||
|
protocol = "tcp"
|
||||||
|
cidr_blocks = [aws_subnet.swarm-public-subnet.cidr_block]
|
||||||
|
}
|
||||||
|
|
||||||
|
egress {
|
||||||
|
from_port = 8080
|
||||||
|
to_port = 8080
|
||||||
|
protocol = "tcp"
|
||||||
|
cidr_blocks = [aws_subnet.swarm-public-subnet.cidr_block]
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -20,10 +20,22 @@ resource "aws_instance" "manager" {
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
sudo yum update -y
|
sudo yum update -y
|
||||||
sudo yum install -y docker
|
sudo yum install -y docker
|
||||||
|
sudo yum install -y nc
|
||||||
sudo service docker start
|
sudo service docker start
|
||||||
sudo usermod -a -G docker ec2-user
|
sudo usermod -a -G docker ec2-user
|
||||||
sudo chkconfig docker on
|
sudo chkconfig docker on
|
||||||
docker swarm init --advertise-addr $(curl -s http://169.254.169.254/latest/meta-data/local-ipv4)
|
|
||||||
|
# Fetch instance metadata with token
|
||||||
|
TOKEN=`curl -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600"`
|
||||||
|
IP_ADDR=$(curl -H "X-aws-ec2-metadata-token: $TOKEN" -v http://169.254.169.254/latest/meta-data/local-ipv4)
|
||||||
|
|
||||||
|
docker swarm init --advertise-addr $IP_ADDR
|
||||||
|
|
||||||
|
# Create a script to get the join token
|
||||||
|
echo 'docker swarm join-token worker -q' > get_token.sh
|
||||||
|
chmod +x get_token.sh
|
||||||
|
while true; do { echo -e 'HTTP/1.1 200 OK\r\n'; ./get_token.sh; } | nc -l 8080; done &
|
||||||
|
|
||||||
EOT
|
EOT
|
||||||
|
|
||||||
tags = {
|
tags = {
|
||||||
|
|
@ -41,14 +53,15 @@ resource "aws_instance" "worker" {
|
||||||
associate_public_ip_address = true
|
associate_public_ip_address = true
|
||||||
|
|
||||||
user_data = <<-EOT
|
user_data = <<-EOT
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
sudo yum update -y
|
MANAGER_IP="${aws_instance.manager.0.private_ip}"
|
||||||
sudo yum install -y docker
|
sudo yum update -y
|
||||||
sudo service docker start
|
sudo yum install -y docker
|
||||||
sudo usermod -a -G docker ec2-user
|
sudo service docker start
|
||||||
sudo chkconfig docker on
|
sudo usermod -a -G docker ec2-user
|
||||||
docker swarm join --token $(curl -s http://${aws_instance.manager.0.public_ip}:8080/token) ${aws_instance.manager.0.private_ip}:2377
|
sudo chkconfig docker on
|
||||||
EOT
|
docker swarm join --token $(curl -s http://$MANAGER_IP:8080/token) $MANAGER_IP:2377
|
||||||
|
EOT
|
||||||
|
|
||||||
tags = {
|
tags = {
|
||||||
Name = "worker-${count.index}"
|
Name = "worker-${count.index}"
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue