Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 0 additions & 22 deletions layers/api-gateway/00-backend.tf

This file was deleted.

39 changes: 0 additions & 39 deletions layers/api-gateway/00-datasources.tf

This file was deleted.

26 changes: 0 additions & 26 deletions layers/api-gateway/00-providers.tf

This file was deleted.

2 changes: 0 additions & 2 deletions layers/api-gateway/tfvars/env.tfvars.example

This file was deleted.

15 changes: 15 additions & 0 deletions main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -252,3 +252,18 @@ module "keycloak" {
}
}
}

module "api_gateway" {
source = "./modules/api-gateway"

namespace = var.namespace
environment = var.environment
project_name = "api-gateway"

lambda_authorizer_invoke_arn = var.lambda_authorizer_invoke_arn
lambda_authorizer_function_name = var.lambda_authorizer_function_name
scanner_sqs_queue_name = module.lambda_cur.scanner_sqs_cur_name
scanner_sqs_queue_arn = module.lambda_cur.scanner_sqs_cur_arn

depends_on = [module.lambda_cur]
}
Original file line number Diff line number Diff line change
Expand Up @@ -14,13 +14,10 @@
#
# SPDX-License-Identifier: Apache-2.0

terraform {
required_version = "~> 1.0"
data "aws_region" "current" {}

required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.0"
}
}
data "aws_caller_identity" "current" {}

data "aws_sqs_queue" "scanner_sqs_queue" {
name = var.scanner_sqs_queue_name
}
Original file line number Diff line number Diff line change
Expand Up @@ -15,5 +15,16 @@
# SPDX-License-Identifier: Apache-2.0

output "base_url" {
value = aws_api_gateway_deployment.api_deployment_test.invoke_url
}
value = aws_api_gateway_deployment.api_deployment_test.invoke_url
description = "The base URL of the API Gateway deployment"
}

output "rest_api_id" {
value = aws_api_gateway_rest_api.Scanner_API.id
description = "The ID of the REST API"
}

output "stage_name" {
value = aws_api_gateway_stage.api_stage_test.stage_name
description = "The name of the API Gateway stage"
}
Original file line number Diff line number Diff line change
Expand Up @@ -28,23 +28,25 @@ variable "environment" {
variable "project_name" {
type = string
description = "Project's name"
default = "api-gateway-infrastructure"
default = "api-gateway"
}

variable "project_type" {
variable "lambda_authorizer_invoke_arn" {
type = string
description = "The type of project."
default = "application"
description = "Invoke ARN of the lambda authorizer"
}

variable "aws_lambda_payload_cur_part_function_name" {
description = "Name of the lambda (in the outputs of the payload-cur-part lambda repository)"
variable "lambda_authorizer_function_name" {
type = string
description = "Name of the lambda authorizer function"
}

variable "aws_lambda_payload_cur_part_invoke_arn" {
description = "Invoke ARN of the lambda (in the outputs of the payload-cur-part lambda repository)"
variable "scanner_sqs_queue_name" {
type = string
description = "Name of the scanner SQS queue"
}
variable "tfstate_bucket" {

variable "scanner_sqs_queue_arn" {
type = string
description = "The tfstate bucket where to fetch some information from the other layers."
description = "ARN of the scanner SQS queue"
}
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ resource "aws_api_gateway_resource" "payload_cur_part_api_resource" {
resource "aws_api_gateway_authorizer" "lambda_authorizer" {
name = "lambda-authorizer"
rest_api_id = aws_api_gateway_rest_api.Scanner_API.id
authorizer_uri = data.terraform_remote_state.lambda_authorizer.outputs.aws_lambda_invoke_arn
authorizer_uri = var.lambda_authorizer_invoke_arn
authorizer_result_ttl_in_seconds = 300
identity_source = "method.request.header.Authorization"
type = "TOKEN"
Expand All @@ -54,10 +54,6 @@ resource "aws_api_gateway_method" "payload_cur_part_post_method" {
}

# Integration with SQS
data "aws_sqs_queue" "scanner_sqs_queue" {
name = data.terraform_remote_state.cur_service.outputs.scanner_sqs_cur_name
}

resource "aws_api_gateway_integration" "payload_cur_part_sqs_integration" {
rest_api_id = aws_api_gateway_rest_api.Scanner_API.id
resource_id = aws_api_gateway_resource.payload_cur_part_api_resource.id
Expand All @@ -79,7 +75,7 @@ resource "aws_api_gateway_integration" "payload_cur_part_sqs_integration" {
resource "aws_lambda_permission" "authorizer_aws_permission" {
statement_id = "AllowAPIGatewayInvokeAuthorizer"
action = "lambda:InvokeFunction"
function_name = data.terraform_remote_state.lambda_authorizer.outputs.aws_lambda_function_name
function_name = var.lambda_authorizer_function_name
principal = "apigateway.amazonaws.com"
source_arn = "arn:aws:execute-api:${data.aws_region.current.name}:${data.aws_caller_identity.current.account_id}:${aws_api_gateway_rest_api.Scanner_API.id}/authorizers/${aws_api_gateway_authorizer.lambda_authorizer.id}"
}
Expand All @@ -100,7 +96,7 @@ data "aws_iam_policy_document" "api_gateway_permissions" {
statement {
effect = "Allow"
actions = ["sqs:SendMessage"]
resources = [data.aws_sqs_queue.scanner_sqs_queue.arn]
resources = [var.scanner_sqs_queue_arn]
}
}

Expand Down Expand Up @@ -157,6 +153,6 @@ resource "aws_api_gateway_stage" "api_stage_test" {
deployment_id = aws_api_gateway_deployment.api_deployment_test.id

lifecycle {
ignore_changes = [deployment_id] # Prevents dependency cycle
ignore_changes = [deployment_id]
}
}
5 changes: 5 additions & 0 deletions modules/lambdas/iroco2-cur-analyzer/00-outputs.tf
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,11 @@ output "scanner_sqs_cur_url" {
description = "The url of the SQS queue for the scanner"
}

output "scanner_sqs_cur_arn" {
value = aws_sqs_queue.scanner_sqs_queue.arn
description = "The ARN of the SQS queue for the scanner"
}

output "s3_cur_bucket_id" {
value = aws_s3_bucket.cur_s3_bucket.id
description = "The ID of the S3 bucket for the CUR"
Expand Down
11 changes: 11 additions & 0 deletions variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -215,3 +215,14 @@ variable "container_desired_count" {
error_message = "You should have at least one instance running."
}
}

## ---------------------- API GATEWAY ------------------------------
variable "lambda_authorizer_invoke_arn" {
type = string
description = "Invoke ARN of the lambda authorizer function"
}

variable "lambda_authorizer_function_name" {
type = string
description = "Name of the lambda authorizer function"
}
Loading