Files
doczyai-pipelines/streamlit-server/main.tf
T
2024-05-06 19:28:00 -05:00

189 lines
5.7 KiB
Terraform

provider "aws" {
region = "us-east-2"
profile = "temp_cred"
}
# data "aws_acm_certificate" "cert_global" {
# domain = "doczy.aarete.com"
# statuses = ["ISSUED"]
# }
locals {
region_map = {
us-east-1 = "use1"
us-east-2 = "use2"
us-west-1 = "usw1"
us-west-2 = "usw2"
}
environment_map = {
prod = "p"
uat = "u"
qa = "q"
dev = "d"
}
# region abbreviation
region_short_name = local.region_map[var.aws_region]
# environment abbreviation
environment_short_name = local.environment_map[var.environment]
# global prefix
global_prefix = "${var.project_name}-${local.region_short_name}-${local.environment_short_name}"
# Resource prefix
iam_policy_prefix = "${local.global_prefix}-pol"
# # Resource prefix
iam_role_prefix = "${local.global_prefix}-rol"
# IAM role name
ec2_role_name = "${local.iam_role_prefix}-streamlit"
ec2_instance_name = "${local.global_prefix}-ec2-infra-streamlit-server"
}
# get the subnet id using data source
data "aws_subnets" "subnets" {
filter {
name = "vpc-id"
values = [var.vpc_id]
}
}
# vpc security groups
data "aws_security_groups" "security_groups" {
filter {
name = "group-name"
values = ["*default*"]
}
filter {
name = "vpc-id"
values = [var.vpc_id]
}
}
# instance profile for ec2 using the ec2_role
resource "aws_iam_instance_profile" "ec2_instance_profile" {
name = "${local.ec2_role_name}-instance-profile"
role = aws_iam_role.ec2_role.name
}
resource "aws_instance" "streamlit_server" {
ami = var.ubuntu_ami
instance_type = var.ec2_instance_type
subnet_id = data.aws_subnets.subnets.ids[0]
vpc_security_group_ids = data.aws_security_groups.security_groups.ids
iam_instance_profile = aws_iam_instance_profile.ec2_instance_profile.name
associate_public_ip_address = false
key_name = "tf-test-key" # Created using TF and uploaded to S3. Prerequisite
root_block_device {
volume_size = 30 # Variable
encrypted = true # Mandatory
}
# Setup SSH authentication for bitbucket access to pull code
# Setup SSL certificate for HTTPS access for SSO to work
user_data = <<-EOF
#!/bin/bash
echo '${file("${path.module}/requirements.txt")}' > /tmp/requirements.txt
apt-get update
apt-get install -y python3 python3-pip
python3 -m pip install $(cat /tmp/requirements.txt)
sudo apt install openssh-client
# Create UI0 systemd service
cat <<EOT > /etc/systemd/system/streamlit-ui0.service
[Unit]
Description=Streamlit Server Service
[Service]
User=ubuntu
Type=simple
Restart=always
WorkingDirectory=/home/ubuntu/doczy.ai/streamlit
ExecStart=/home/ubuntu/.local/bin/streamlit run /home/ubuntu/doczy.ai/streamlit/interface_0.py --server.port 8500
[Install]
WantedBy=multi-user.target
EOT
# Enable and start the service
systemctl enable streamlit-ui0.service
systemctl start streamlit-ui0.service
# Create UI1 systemd service
cat <<EOT > /etc/systemd/system/streamlit-ui1.service
[Unit]
Description=Streamlit Server Service
[Service]
User=ubuntu
Type=simple
Restart=always
WorkingDirectory=/home/ubuntu/doczy.ai/streamlit
ExecStart=/home/ubuntu/.local/bin/streamlit run /home/ubuntu/doczy.ai/streamlit/interface_1.py --server.port 8501
[Install]
WantedBy=multi-user.target
EOT
# Enable and start the service
systemctl enable streamlit-ui1.service
systemctl start streamlit-ui1.service
# Create UI2 systemd service
cat <<EOT > /etc/systemd/system/streamlit-ui2.service
[Unit]
Description=Streamlit Server Service
[Service]
User=ubuntu
Type=simple
Restart=always
WorkingDirectory=/home/ubuntu/doczy.ai/streamlit
ExecStart=/home/ubuntu/.local/bin/streamlit run /home/ubuntu/doczy.ai/streamlit/interface_2.py --server.port 8502
[Install]
WantedBy=multi-user.target
EOT
# Enable and start the service
systemctl enable streamlit-ui2.service
systemctl start streamlit-ui2.service
# Create UI3 systemd service
cat <<EOT > /etc/systemd/system/streamlit-ui3.service
[Unit]
Description=Streamlit Server Service
[Service]
User=ubuntu
Type=simple
Restart=always
WorkingDirectory=/home/ubuntu/doczy.ai/streamlit
ExecStart=/home/ubuntu/.local/bin/streamlit run /home/ubuntu/doczy.ai/streamlit/interface_3.py --server.port 8503
[Install]
WantedBy=multi-user.target
EOT
# Enable and start the service
systemctl enable streamlit-ui3.service
systemctl start streamlit-ui3.service
EOF
metadata_options {
http_endpoint = "enabled"
http_put_response_hop_limit = 2
http_tokens = "required"
}
tags = {
Terraform = "true"
Environment = "dev"
}
}