Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CES-68] Functions updated with ITN APIM for migration #1303

Draft
wants to merge 7 commits into
base: main
Choose a base branch
from
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions src/domains/citizen-auth-app/01_network.tf
Original file line number Diff line number Diff line change
Expand Up @@ -98,6 +98,12 @@ data "azurerm_subnet" "apim_v2_snet" {
resource_group_name = local.vnet_common_resource_group_name
}

data "azurerm_subnet" "apim_itn_snet" {
name = "io-p-itn-apim-pip-01"
virtual_network_name = local.vnet_common_name_itn
resource_group_name = local.vnet_common_resource_group_name_itn
}

data "azurerm_subnet" "azdoa_snet" {
count = var.enable_azdoa ? 1 : 0
name = "azure-devops"
Expand Down
2 changes: 1 addition & 1 deletion src/domains/citizen-auth-app/04_function_lollipop.tf
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
data "azurerm_key_vault_secret" "first_lollipop_consumer_subscription_key" {
name = "first-lollipop-consumer-pagopa-subscription-key-v2"
name = "first-lollipop-consumer-pagopa-subscription-key-itn"
key_vault_id = data.azurerm_key_vault.kv.id
}

Expand Down
252 changes: 252 additions & 0 deletions src/domains/citizen-auth-app/07_function_fast_login.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,252 @@
data "azurerm_key_vault_secret" "fast_login_subscription_key" {
name = "fast-login-subscription-key-itn"
key_vault_id = data.azurerm_key_vault.kv.id
}

data "azurerm_key_vault_secret" "backendli_api_key" {
name = "appbackend-PRE-SHARED-KEY"
key_vault_id = data.azurerm_key_vault.kv_common.id
}

data "azurerm_app_service" "app_backend_li" {
name = format("%s-app-appbackendli", local.product)
resource_group_name = format("%s-rg-linux", local.product)
}

locals {
function_fast_login = {
app_settings = {
NODE_ENV = "production"

// Keepalive fields are all optionals
FETCH_KEEPALIVE_ENABLED = "true"
FETCH_KEEPALIVE_SOCKET_ACTIVE_TTL = "110000"
FETCH_KEEPALIVE_MAX_SOCKETS = "40"
FETCH_KEEPALIVE_MAX_FREE_SOCKETS = "10"
FETCH_KEEPALIVE_FREE_SOCKET_TIMEOUT = "30000"
FETCH_KEEPALIVE_TIMEOUT = "60000"

FUNCTIONS_WORKER_PROCESS_COUNT = 8

# Redis
REDIS_URL = data.azurerm_redis_cache.redis_common_itn.hostname
REDIS_PORT = data.azurerm_redis_cache.redis_common_itn.ssl_port
REDIS_PASSWORD = data.azurerm_redis_cache.redis_common_itn.primary_access_key

# COSMOS
COSMOS_DB_NAME = "citizen-auth"
COSMOS_CONNECTION_STRING = format("AccountEndpoint=%s;AccountKey=%s;", data.azurerm_cosmosdb_account.cosmos_citizen_auth.endpoint, data.azurerm_cosmosdb_account.cosmos_citizen_auth.primary_key)

// --------------------------
// Config for getAssertion
// --------------------------
LOLLIPOP_GET_ASSERTION_BASE_URL = "https://api.io.pagopa.it"
LOLLIPOP_GET_ASSERTION_API_KEY = data.azurerm_key_vault_secret.fast_login_subscription_key.value

// --------------------------
// Fast login audit log storage
// --------------------------
FAST_LOGIN_AUDIT_CONNECTION_STRING = data.azurerm_storage_account.immutable_lv_audit_logs_storage.primary_connection_string


// --------------------------
// Config for backendli connection
// --------------------------
BACKEND_INTERNAL_API_KEY = data.azurerm_key_vault_secret.backendli_api_key.value
BACKEND_INTERNAL_BASE_URL = "https://${data.azurerm_app_service.app_backend_li.default_site_hostname}"

}
}
}


resource "azurerm_resource_group" "fast_login_rg_itn" {
name = format("%s-fast-login-rg-01", local.common_project_itn)
location = local.itn_location

tags = var.tags
}

## Create resources for fast-login on ITN Region

module "fast_login_snet_itn" {
source = "git::https://github.com/pagopa/terraform-azurerm-v3.git//subnet?ref=v8.22.0"
name = format("%s-fast-login-snet-01", local.project_itn)
address_prefixes = var.cidr_subnet_fnfastlogin_itn
resource_group_name = data.azurerm_virtual_network.common_vnet_italy_north.resource_group_name
virtual_network_name = data.azurerm_virtual_network.common_vnet_italy_north.name
private_endpoint_network_policies_enabled = true

service_endpoints = [
"Microsoft.Web",
"Microsoft.AzureCosmosDB",
"Microsoft.Storage",
]

delegation = {
name = "default"
service_delegation = {
name = "Microsoft.Web/serverFarms"
actions = ["Microsoft.Network/virtualNetworks/subnets/action"]
}
}
}

module "function_fast_login_itn" {
source = "git::https://github.com/pagopa/terraform-azurerm-v3.git//function_app?ref=v8.44.0"

resource_group_name = azurerm_resource_group.fast_login_rg_itn.name
name = format("%s-auth-lv-fn-01", local.common_project_itn)
location = local.itn_location
domain = "auth"
health_check_path = "/info"
health_check_maxpingfailures = "2"

enable_function_app_public_network_access = false

node_version = "18"
runtime_version = "~4"

always_on = "true"
application_insights_instrumentation_key = data.azurerm_application_insights.application_insights.instrumentation_key

app_service_plan_info = {
kind = var.function_fastlogin_kind
sku_size = var.function_fastlogin_sku_size
maximum_elastic_worker_count = 0
worker_count = null
zone_balancing_enabled = true
}

app_settings = local.function_fast_login.app_settings

sticky_app_setting_names = []

internal_storage = {
"enable" = true,
"private_endpoint_subnet_id" = data.azurerm_subnet.itn_pep.id,
"private_dns_zone_blob_ids" = [data.azurerm_private_dns_zone.privatelink_blob_core_windows_net.id],
"private_dns_zone_queue_ids" = [data.azurerm_private_dns_zone.privatelink_queue_core_windows_net.id],
"private_dns_zone_table_ids" = [data.azurerm_private_dns_zone.privatelink_table_core_windows_net.id],
"queues" = [],
"containers" = [],
"blobs_retention_days" = 0,
}

subnet_id = module.fast_login_snet_itn.id

allowed_subnets = [
]

# Action groups for alerts
action = [
{
action_group_id = data.azurerm_monitor_action_group.error_action_group.id
webhook_properties = {}
}
]

tags = var.tags
}

module "function_fast_login_staging_slot_itn" {
source = "git::https://github.com/pagopa/terraform-azurerm-v3.git//function_app_slot?ref=v8.44.0"

name = "staging"
location = local.itn_location
resource_group_name = azurerm_resource_group.fast_login_rg_itn.name
function_app_id = module.function_fast_login_itn.id
app_service_plan_id = module.function_fast_login_itn.app_service_plan_id
health_check_path = "/info"

storage_account_name = module.function_fast_login_itn.storage_account.name
storage_account_access_key = module.function_fast_login_itn.storage_account.primary_access_key
internal_storage_connection_string = module.function_fast_login_itn.storage_account_internal_function.primary_connection_string

node_version = "18"
always_on = "true"
runtime_version = "~4"
application_insights_instrumentation_key = data.azurerm_application_insights.application_insights.instrumentation_key

app_settings = local.function_fast_login.app_settings

subnet_id = module.fast_login_snet_itn.id

allowed_subnets = [
data.azurerm_subnet.azdoa_snet[0].id,
]

tags = var.tags
}

module "function_fast_login_itn_autoscale" {
source = "github.com/pagopa/dx//infra/modules/azure_app_service_plan_autoscaler?ref=main"

resource_group_name = azurerm_resource_group.fast_login_rg_itn.name
target_service = {
function_app_name = module.function_fast_login_itn.name
}

scheduler = {
high_load = {
name = "evening"
minimum = 4
default = 10
start = {
hour = 19
minutes = 30
}
end = {
hour = 22
minutes = 59
}
},
spot_load = {
name = "${module.common_values.scaling_gate.name}"
minimum = 6
default = 20
start_date = module.common_values.scaling_gate.start
end_date = module.common_values.scaling_gate.end
},
normal_load = {
minimum = 3
default = 10
},
maximum = 30
}

scale_metrics = {
requests = {
statistic_increase = "Max"
time_window_increase = 1
time_aggregation = "Maximum"
upper_threshold = 2500
increase_by = 2
cooldown_increase = 1
statistic_decrease = "Average"
time_window_decrease = 5
time_aggregation_decrease = "Average"
lower_threshold = 200
decrease_by = 1
cooldown_decrease = 1
}
cpu = {
upper_threshold = 35
lower_threshold = 15
increase_by = 3
decrease_by = 1
cooldown_increase = 1
cooldown_decrease = 20
statistic_increase = "Max"
statistic_decrease = "Average"
time_aggregation_increase = "Maximum"
time_aggregation_decrease = "Average"
time_window_increase = 1
time_window_decrease = 5
}
memory = null
}

tags = var.tags
}

6 changes: 4 additions & 2 deletions src/domains/citizen-auth-app/08_session_manager.tf
Original file line number Diff line number Diff line change
Expand Up @@ -271,7 +271,8 @@ module "session_manager_weu" {
allowed_subnets = [
data.azurerm_subnet.apim_v2_snet.id,
data.azurerm_subnet.appgateway_snet.id,
data.azurerm_subnet.fims_op_app_snet_01.id
data.azurerm_subnet.fims_op_app_snet_01.id,
data.azurerm_subnet.apim_itn_snet.id,
// TODO: add proxy subnet
]
allowed_ips = []
Expand Down Expand Up @@ -370,7 +371,8 @@ module "session_manager_weu_staging" {
data.azurerm_subnet.self_hosted_runner_snet.id,
#
data.azurerm_subnet.apim_v2_snet.id,
data.azurerm_subnet.appgateway_snet.id
data.azurerm_subnet.appgateway_snet.id,
data.azurerm_subnet.apim_itn_snet.id,
// TODO: add proxy subnet
]
allowed_ips = []
Expand Down
3 changes: 3 additions & 0 deletions src/domains/citizen-auth-app/99_locals.tf
Original file line number Diff line number Diff line change
Expand Up @@ -40,4 +40,7 @@ locals {
# auth n identity domain
short_domain = "auth"
short_project_itn = "${local.product}-${local.itn_location_short}-${local.short_domain}"

vnet_common_name_itn = "${local.common_project_itn}-common-vnet-01"
vnet_common_resource_group_name_itn = "${local.common_project_itn}-common-rg-01"
}
1 change: 1 addition & 0 deletions src/domains/functions/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -85,6 +85,7 @@
| [azurerm_storage_account.storage_api](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/data-sources/storage_account) | data source |
| [azurerm_storage_account.userbackups](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/data-sources/storage_account) | data source |
| [azurerm_storage_account.userdatadownload](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/data-sources/storage_account) | data source |
| [azurerm_subnet.apim_itn_snet](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/data-sources/subnet) | data source |
| [azurerm_subnet.apim_v2_snet](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/data-sources/subnet) | data source |
| [azurerm_subnet.azdoa_snet](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/data-sources/subnet) | data source |
| [azurerm_subnet.function_eucovidcert_snet](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/data-sources/subnet) | data source |
Expand Down
6 changes: 6 additions & 0 deletions src/domains/functions/data.tf
Original file line number Diff line number Diff line change
Expand Up @@ -117,6 +117,12 @@ data "azurerm_subnet" "apim_v2_snet" {
virtual_network_name = local.vnet_common_name
}

data "azurerm_subnet" "apim_itn_snet" {
name = "io-p-itn-apim-pip-01"
resource_group_name = local.vnet_common_resource_group_name_itn
virtual_network_name = local.vnet_common_name_itn
}

data "azurerm_subnet" "azdoa_snet" {
name = "azure-devops"
resource_group_name = local.rg_common_name
Expand Down
6 changes: 4 additions & 2 deletions src/domains/functions/function_admin.tf
Original file line number Diff line number Diff line change
Expand Up @@ -97,9 +97,9 @@ locals {

AssetsStorageConnection = data.azurerm_storage_account.assets_cdn.primary_connection_string

AZURE_APIM = "io-p-apim-v2-api"
AZURE_APIM = "io-p-itn-apim-01"
AZURE_APIM_HOST = local.apim_hostname_api_internal
AZURE_APIM_RESOURCE_GROUP = "io-p-rg-internal"
AZURE_APIM_RESOURCE_GROUP = "io-p-itn-common-rg-01"

MESSAGE_CONTAINER_NAME = local.message_content_container_name

Expand Down Expand Up @@ -241,6 +241,7 @@ module "function_admin" {
allowed_subnets = [
module.admin_snet.id,
data.azurerm_subnet.apim_v2_snet.id,
data.azurerm_subnet.apim_itn_snet.id,
]

# Action groups for alerts
Expand Down Expand Up @@ -292,6 +293,7 @@ module "function_admin_staging_slot" {
module.admin_snet.id,
data.azurerm_subnet.azdoa_snet.id,
data.azurerm_subnet.apim_v2_snet.id,
data.azurerm_subnet.apim_itn_snet.id,
]

tags = var.tags
Expand Down
2 changes: 2 additions & 0 deletions src/domains/functions/function_services.tf
Original file line number Diff line number Diff line change
Expand Up @@ -236,6 +236,7 @@ module "function_services" {
data.azurerm_subnet.azdoa_snet.id,
data.azurerm_subnet.apim_v2_snet.id,
data.azurerm_subnet.function_eucovidcert_snet.id,
data.azurerm_subnet.apim_itn_snet.id,
]

# Action groups for alerts
Expand Down Expand Up @@ -300,6 +301,7 @@ module "function_services_staging_slot" {
data.azurerm_subnet.azdoa_snet.id,
data.azurerm_subnet.apim_v2_snet.id,
data.azurerm_subnet.function_eucovidcert_snet.id,
data.azurerm_subnet.apim_itn_snet.id,
]

tags = var.tags
Expand Down
13 changes: 13 additions & 0 deletions src/domains/functions/locals.tf
Original file line number Diff line number Diff line change
Expand Up @@ -21,3 +21,16 @@ locals {

service_api_url = "https://api-app.internal.io.pagopa.it/"
}

# Region ITN
locals {
itn_location = "italynorth"
itn_location_short = "itn"
common_project_itn = "${local.project}-${local.itn_location_short}"

vnet_common_name_itn = "${local.common_project_itn}-common-vnet-01"
vnet_common_resource_group_name_itn = "${local.common_project_itn}-common-rg-01"

apim_itn_name = "${local.project}-${local.itn_location_short}-apim-01"
apim_itn_resource_group_name = "${local.project}-${local.itn_location_short}-common-rg-01"
}
6 changes: 6 additions & 0 deletions src/domains/ioweb-app/01_network.tf
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,12 @@ data "azurerm_subnet" "apim_v2_snet" {
resource_group_name = local.vnet_common_resource_group_name
}

data "azurerm_subnet" "apim_itn_snet" {
name = "io-p-itn-apim-pip-01"
virtual_network_name = local.vnet_common_name_itn
resource_group_name = local.vnet_common_resource_group_name_itn
}

data "azurerm_subnet" "azdoa_snet" {
count = var.enable_azdoa ? 1 : 0
name = "azure-devops"
Expand Down
Loading
Loading