Skip to content

Latest commit

Β 

History

History
332 lines (257 loc) Β· 12 KB

File metadata and controls

332 lines (257 loc) Β· 12 KB

AKS Terraform Foundation

A production-ready Azure Kubernetes Service (AKS) infrastructure with Crossplane, ArgoCD, and Vault, managed entirely with Terraform.

πŸš€ Quick Start

# Clone and navigate to the project
cd 03-plat-eng-aks-foundation

# Initialize and deploy
make init ENV=dev
make plan
make apply

# Get AKS credentials
az aks get-credentials --name aks-test --resource-group aks-test-rg

For detailed setup instructions, see the Quickstart Guide.

πŸ“‹ Table of Contents

✨ Features

Infrastructure

  • Azure Kubernetes Service (AKS): Production-ready Kubernetes cluster
  • Multi-environment Support: Separate workspaces for dev and production
  • Infrastructure as Code: Complete Terraform configuration
  • Azure Integration: Workload Identity, Azure CNI, managed identities

Platform Services

  • ArgoCD: GitOps continuous delivery
    • Public endpoint with Azure Public IP
    • DNS: luciano-argocd.eastus.cloudapp.azure.com
  • Crossplane: Cloud-native control plane
    • Azure AD Service Principal authentication
    • Provider Family Azure and Provider Azure Cache
  • Azure Service Operator (ASO): Cloud-native Azure resource management (v2.17.0)
  • Vault: Secrets management (HashiCorp Vault)

Operations

  • Makefile Commands: Simplified infrastructure management
  • Terraform Workspaces: Environment isolation
  • Namespaced Resources: Organized by system component
  • Logging & Monitoring: Azure Log Analytics integration

πŸ—οΈ Architecture

This project implements a modern cloud-native platform on Azure:

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                         Azure Cloud                             β”‚
β”‚                                                                 β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚  β”‚                    AKS Cluster                             β”‚ β”‚
β”‚  β”‚                                                            β”‚ β”‚
β”‚  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”      β”‚ β”‚
β”‚  β”‚  β”‚   ArgoCD     β”‚  β”‚ Crossplane+ASOβ”‚  β”‚    Vault     β”‚      β”‚ β”‚
β”‚  β”‚  β”‚ devops-systemβ”‚  β”‚resources-sys β”‚  β”‚ devops-systemβ”‚      β”‚ β”‚
β”‚  β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜      β”‚ β”‚
β”‚  β”‚                                                            β”‚ β”‚
β”‚  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚ β”‚
β”‚  β”‚  β”‚              Application Namespaces                  β”‚  β”‚ β”‚
β”‚  β”‚  β”‚ jarvix β€’ gateway β€’ observability β€’ pipeline β€’ security β”‚  β”‚ β”‚
β”‚  β”‚  β”‚            test β€’ storage β€’ ai                       β”‚  β”‚ β”‚
β”‚  β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚ β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β”‚                                                                 β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€-─┐  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”‚
β”‚  β”‚   Public IP   β”‚  β”‚ Service Principalβ”‚  β”‚  Log Analytics  β”‚   β”‚
β”‚  β”‚   (ArgoCD)    β”‚  β”‚(Crossplane + ASO)β”‚  β”‚   Workspace     β”‚   β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  └─────────────────-β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜   β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

For detailed architecture documentation, see:

πŸ“¦ Prerequisites

  • Azure CLI: Authenticated with appropriate subscription
  • Terraform: >= 1.3
  • kubectl: For Kubernetes cluster management
  • make: For using Makefile commands
  • Azure Subscription: With contributor permissions

Required Environment Variables

export ARM_SUBSCRIPTION_ID="your-subscription-id"

πŸ“š Documentation

Setup & Getting Started

Guides

Architecture & Design

Reference

πŸ“ Project Structure

03-plat-eng-aks-foundation/
β”œβ”€β”€ README.md                      # This file
β”œβ”€β”€ makefile                       # Infrastructure management commands
β”œβ”€β”€ .devcontainer/                 # Dev container configuration
β”œβ”€β”€ .github/                       # CI/CD workflows
β”œβ”€β”€ .checkov_config.yaml           # Checkov configuration
β”œβ”€β”€ docs/                          # Documentation
β”‚   β”œβ”€β”€ setup/                     # Setup and installation guides
β”‚   β”‚   └── quickstart.md
β”‚   β”œβ”€β”€ guides/                    # How-to guides
β”‚   β”‚   β”œβ”€β”€ argocd-public-endpoint.md
β”‚   β”‚   └── namespace-update.md
β”‚   β”œβ”€β”€ architecture/              # Architecture documentation
β”‚   β”‚   β”œβ”€β”€ crossplane-azure-workload-identity.md
β”‚   β”‚   └── crossplane-implementation-summary.md
β”‚   └── reference/                 # Reference documentation
β”‚       β”œβ”€β”€ makefile.md
β”‚       └── crossplane-readme.md
β”œβ”€β”€ aks-foundation/                # Terraform configuration
β”‚   β”œβ”€β”€ main.tf                    # Main AKS cluster configuration
β”‚   β”œβ”€β”€ variables.tf               # Input variables
β”‚   β”œβ”€β”€ outputs.tf                 # Output values
β”‚   β”œβ”€β”€ aks_addons_argocd.tf      # ArgoCD Helm installation
β”‚   β”œβ”€β”€ aks_cluster_namespaces.tf # Kubernetes namespaces
β”‚   β”œβ”€β”€ argocd_public_ingress.tf  # ArgoCD public endpoint
β”‚   β”œβ”€β”€ aso_argocd.tf             # Azure Service Operator deployment
β”‚   β”œβ”€β”€ crossplane_*.tf           # Crossplane configuration
β”‚   β”œβ”€β”€ crossplane_managed_resources.tf
β”‚   β”œβ”€β”€ extra_node_pool.tf
β”‚   β”œβ”€β”€ role_assignments.tf
β”‚   β”œβ”€β”€ locals.tf
β”‚   β”œβ”€β”€ providers.tf
β”‚   β”œβ”€β”€ versions.tf
β”‚   β”œβ”€β”€ log_analytics.tf
β”‚   β”œβ”€β”€ vault.tf                   # Vault installation
β”‚   β”œβ”€β”€ unit-test-fixture/         # Unit test fixtures
β”‚   └── ...                        # Additional configuration files

⚑ Quick Reference

Common Commands

# Initialize for dev environment
make init

# Plan changes
make plan

# Apply changes
make apply

# Full upgrade cycle
make upgrade

# Switch to production
make init ENV=prd

# Destroy infrastructure (⚠️ careful!)
make destroy

Access Services

# ArgoCD
URL: http://luciano-argocd.eastus.cloudapp.azure.com
Username: admin
Password: kubectl -n devops-system get secret argocd-initial-admin-secret \
  -o jsonpath="{.data.password}" | base64 -d

# Get AKS credentials
az aks get-credentials --name aks-test --resource-group aks-test-rg

# Check cluster status
kubectl get nodes
kubectl get pods -A

Terraform Outputs

# View all outputs
terraform -chdir=./aks-foundation output

# Specific outputs
terraform -chdir=./aks-foundation output argocd_public_fqdn
terraform -chdir=./aks-foundation output crossplane_identity_client_id # App Registration Client ID
terraform -chdir=./aks-foundation output aks_name

πŸ”§ Configuration

Customize Variables

Edit aks-foundation/terraform.tfvars or create your own:

# Environment
location = "eastus"
resource_group_name = "aks-test-rg"

# AKS Configuration
kubernetes_version = "1.34"
agents_count = 3
agents_size = "Standard_D2s_v3"

# Crossplane
crossplane_version = "2.1.3"
crossplane_provider_family_azure_version = "v2.3.0"

# ArgoCD
# Configured via Helm values in aks_addons_argocd.tf

πŸ› οΈ Development

Local Development

  1. Clone the repository

    git clone <repository-url>
    cd 03-plat-eng-aks-foundation
  2. Set up Azure authentication

    az login
    export ARM_SUBSCRIPTION_ID=$(az account show --query id -o tsv)
  3. Initialize Terraform

    make init ENV=dev
  4. Make changes and test

    make plan
    # Review changes
    make apply

Testing Changes

# Validate Terraform configuration
terraform -chdir=./aks-foundation validate

# Format Terraform files
terraform -chdir=./aks-foundation fmt -recursive

# Check for issues with checkov
checkov -d aks-foundation/

πŸ” Security Considerations

  • Service Principal: Crossplane and ASO use Azure AD Service Principal with client secret stored as Kubernetes Secret
  • RBAC: Kubernetes RBAC enabled with Azure AD integration
  • Network Policies: Configure as needed for your security requirements
  • Secrets Management: Vault for application secrets
  • Public Endpoints: ArgoCD exposed publicly - consider adding authentication/TLS

For production:

  1. Enable TLS for ArgoCD
  2. Configure network security groups
  3. Implement Azure Firewall or Application Gateway
  4. Enable Azure Policy for AKS
  5. Configure backup and disaster recovery

πŸ“– Additional Resources

🀝 Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

  1. Fork the repository
  2. Create your feature branch (git checkout -b feature/amazing-feature)
  3. Commit your changes (git commit -m 'Add some amazing feature')
  4. Push to the branch (git push origin feature/amazing-feature)
  5. Open a Pull Request

πŸ“ License

This project is licensed under the MIT License - see the LICENSE file for details.

πŸ‘₯ Authors

  • Luciano Silva

πŸ™ Acknowledgments

  • Azure AKS team for excellent Kubernetes service
  • Crossplane community for cloud-native infrastructure management
  • ArgoCD community for GitOps excellence
  • Terraform community for infrastructure as code

Note: This is a reference implementation. Customize according to your organization's requirements and security policies.