diff --git a/.github/workflows/dogfood-deploy.yml b/.github/workflows/dogfood-deploy.yml index 7fb072cf97..fe0b2d6553 100644 --- a/.github/workflows/dogfood-deploy.yml +++ b/.github/workflows/dogfood-deploy.yml @@ -10,6 +10,10 @@ on: description: Dry run only? No "terraform apply" type: boolean default: false + skip_free: + description: Skip "Terraform Apply Free" and only run the dogfood apply? + type: boolean + default: false # This allows a subsequently queued workflow run to interrupt previous runs concurrency: @@ -75,7 +79,7 @@ jobs: - uses: hashicorp/setup-terraform@633666f66e0061ca3b725c73b2ec20cd13a8fdd1 # v2.0.3 with: - terraform_version: 1.10.2 + terraform_version: 1.12.0 terraform_wrapper: false - name: Terraform Init id: init @@ -113,7 +117,7 @@ jobs: SLACK_WEBHOOK_TYPE: INCOMING_WEBHOOK # Note: This will cause the geolite2 image to be built twice, but that cannot be avoided without refactoring the terraform to not tag it based upon timestamp. - name: Terraform Apply Free - if: inputs.dry_run == false + if: inputs.dry_run == false && inputs.skip_free == false id: apply-free run: terraform apply -target=module.free -target=module.migrations_free -target=module.geolite2 -auto-approve - name: Terraform Apply diff --git a/.github/workflows/loadtest-infra.yml b/.github/workflows/loadtest-infra.yml index dc200d736d..ced05dc7d3 100644 --- a/.github/workflows/loadtest-infra.yml +++ b/.github/workflows/loadtest-infra.yml @@ -108,7 +108,7 @@ jobs: go-version-file: 'go.mod' - uses: hashicorp/setup-terraform@633666f66e0061ca3b725c73b2ec20cd13a8fdd1 # v2.0.3 with: - terraform_version: 1.10.2 + terraform_version: 1.12.0 terraform_wrapper: false - name: Terraform Init id: init diff --git a/.github/workflows/loadtest-osquery-perf.yml b/.github/workflows/loadtest-osquery-perf.yml index d383db0a7d..310e427d54 100644 --- a/.github/workflows/loadtest-osquery-perf.yml +++ b/.github/workflows/loadtest-osquery-perf.yml @@ -93,7 +93,7 @@ jobs: go-version-file: 'go.mod' - uses: hashicorp/setup-terraform@633666f66e0061ca3b725c73b2ec20cd13a8fdd1 # v2.0.3 with: - terraform_version: 1.10.2 + terraform_version: 1.12.0 terraform_wrapper: false - name: Terraform Init id: init diff --git a/.github/workflows/loadtest-shared.yml b/.github/workflows/loadtest-shared.yml index 261e56ac04..e23ee141d4 100644 --- a/.github/workflows/loadtest-shared.yml +++ b/.github/workflows/loadtest-shared.yml @@ -56,7 +56,7 @@ jobs: go-version-file: 'go.mod' - uses: hashicorp/setup-terraform@633666f66e0061ca3b725c73b2ec20cd13a8fdd1 # v2.0.3 with: - terraform_version: 1.10.2 + terraform_version: 1.12.0 terraform_wrapper: false - name: Terraform Init id: init diff --git a/.github/workflows/tfvalidate.yml b/.github/workflows/tfvalidate.yml index 885b164f1f..35d20bf072 100644 --- a/.github/workflows/tfvalidate.yml +++ b/.github/workflows/tfvalidate.yml @@ -41,7 +41,7 @@ jobs: - name: Install terraform uses: hashicorp/setup-terraform@633666f66e0061ca3b725c73b2ec20cd13a8fdd1 # v2.0.3 with: - terraform_version: 1.10.4 + terraform_version: 1.12.0 # If we want to test more of these, consider using a matrix. With a matrix of directories, all terraform modules could be fully tested and potentially in parallel. - name: Validate loadtesting working-directory: ./infrastructure/loadtesting/terraform diff --git a/infrastructure/dogfood/terraform/aws-tf-module/.terraform.lock.hcl b/infrastructure/dogfood/terraform/aws-tf-module/.terraform.lock.hcl index 0f01fda983..348a2bf9e7 100644 --- a/infrastructure/dogfood/terraform/aws-tf-module/.terraform.lock.hcl +++ b/infrastructure/dogfood/terraform/aws-tf-module/.terraform.lock.hcl @@ -21,25 +21,25 @@ provider "registry.terraform.io/hashicorp/archive" { } provider "registry.terraform.io/hashicorp/aws" { - version = "6.32.1" - constraints = ">= 2.67.0, >= 3.0.0, >= 4.6.0, >= 4.8.0, >= 4.9.0, >= 4.18.0, >= 4.27.0, >= 4.30.0, >= 4.40.0, >= 4.52.0, >= 5.0.0, >= 5.68.0, >= 5.99.0, >= 5.100.0, >= 6.0.0" + version = "6.40.0" + constraints = ">= 2.67.0, >= 3.0.0, >= 4.8.0, >= 4.9.0, >= 4.40.0, >= 4.52.0, >= 5.0.0, >= 5.68.0, >= 5.73.0, >= 5.89.0, >= 5.99.0, >= 5.100.0, >= 6.34.0, >= 6.37.0, >= 6.39.0" hashes = [ - "h1:j691GxEePvwjhYV08mwgTLD/CiCG4YHdZOXL+gV6qt0=", - "zh:024d2cc116c8c83bb63b71623e3654109948791b250929449f4533b06678d574", - "zh:0ee944eb1c0b28957ad04541546ebac66f81b74ae811d20bcd7043d0313722e1", - "zh:43f1b6bcc2d6ba34dd4f02aab2ef3923281cf82455e608ac1ea493374dbb132d", - "zh:52e91c66c3d946d9d24ecf6684e23337abbe7e93a7e8d927f8b7cc69d096215e", - "zh:5d8030a02b61256fb6ee51efe70c1ddfc0d57b4dc0f25c621afddab81575a9c2", - "zh:67b25c8732af678af5772cf57bfb68937bdb535ef06f7f353202e272d843f52c", - "zh:6e846e85e55d7c49820410fb3db338e2d2adf19e3481558e3bec0d63b953c521", - "zh:8d4922a86a39cb2788c14f430008fcaf236b0023260439bc95cc7758d5b76f4a", + "h1:Li1WiMXyFcGfuph9iGIdTScJFNjhkSR/MkuvpapGYYg=", + "zh:05171de71e4236b41740c6a4d4145cc38399b344535e7768e5380d0fdcb95609", + "zh:17910a059ac677c21b61ed5da94cffba40f7cb13ddd78c818458d122cf3ef9a9", + "zh:2f072f335d3f422bbe0f3fd46eba70a52caf43e09ee97599c26f713dbac48fed", + "zh:316da833674982910718aae754f4db0fcc89f0466ca2ca66219fe7fa435950be", + "zh:3fcdde0076bebfaeb0c61960b3e03cf3e2c5a978f7a4ebb0aa42e6b36209044a", + "zh:48cecf9748a3354ccd08275da8b34a42b3367247fc2de398e03ae4e8463299aa", + "zh:4ae0f7e76c61a4820405bd3f340b156f42f7f4480715865b008636c61fbbfa30", + "zh:5add497a7ff7063425c65460c6bc40701cf0e59e09b379e7f535fa37c8ebd80a", + "zh:7a26b4507c99382cefba2b189d4c5ebed939de8fb663a193b65d37934603804d", "zh:9b12af85486a96aedd8d7984b0ff811a4b42e3d88dad1a3fb4c0b580d04fa425", - "zh:9e3d4d1848fc6675c6bd88087188f229c4ec98b1a35de97c2697a0160fb76678", - "zh:b21c1b932c896c21988baac3b1cbc8b51843581b8fabf5e396952a329c9e6a12", - "zh:df8e5b1a2713880e2b3c489cc22ad3b14490e1702a1637273f91747bf091c071", - "zh:ec66785d40f7c04f138bb94fec55b8ddaae6fcc9cb25cc388989150bfaf2de4c", - "zh:f1ecb00fcfdb0c2aec3622549c023f469db401f395bc25bbddfe5cf8b51cd046", - "zh:fca78bf28897c8077130ce8d0f4d67900dbd77619adb1326bcd017ef421e5f1f", + "zh:bad959d58660f6a0b0f950b038c76f378cfe045ba8560a0c3bbf8886f62d81be", + "zh:cf7af6468288a36b02d009045dd4a67c24ad99bbcad406bab0f9c12776d5d99c", + "zh:cfb683320d6d8bc1a5640538af62a5f9da285e28d0daca9e91d667d6e25585d9", + "zh:de7d26ac15362942f590175e425160a2fbf0fe0960afec40b4af78076d4fb9fb", + "zh:fe2fd136b68ea1941da60d8991d3857dd721b180d49502121f3ea8688a812704", ] } @@ -64,22 +64,22 @@ provider "registry.terraform.io/hashicorp/external" { } provider "registry.terraform.io/hashicorp/local" { - version = "2.7.0" + version = "2.8.0" constraints = ">= 1.0.0" hashes = [ - "h1:sSwlfp2etjCaE9hIF7bJBDjRIhDCVFglEOVyiCI7vgs=", - "zh:261fec71bca13e0a7812dc0d8ae9af2b4326b24d9b2e9beab3d2400fab5c5f9a", - "zh:308da3b5376a9ede815042deec5af1050ec96a5a5410a2206ae847d82070a23e", - "zh:3d056924c420464dc8aba10e1915956b2e5c4d55b11ffff79aa8be563fbfe298", - "zh:643256547b155459c45e0a3e8aab0570db59923c68daf2086be63c444c8c445b", + "h1:3jWHVwO5QUIS9V1NsK10ZzdpkK2ABuB4G+UIWrVeGp4=", + "zh:05f18164beab4a84753e5fedf463771ee0c6eca8e90346b8766f1e1c186dec1e", + "zh:563a0702e3711e25ba8930120899b681378b50cbb957fd204b37745c7c9b5f40", + "zh:5b56ab2ed70ed92721febb4a070af0837f1084c44825c18e4b95f7efb1d45d26", + "zh:6cbedc09b67a5cdb9501ff1b18a315fa46a38e0530424cab1c7f4b3acc75f489", + "zh:71b3bd50f89fb385a42a436ba2ce2b8e00f9de53535ce956deff1477b0b117dc", "zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3", - "zh:7aa4d0b853f84205e8cf79f30c9b2c562afbfa63592f7231b6637e5d7a6b5b27", - "zh:7dc251bbc487d58a6ab7f5b07ec9edc630edb45d89b761dba28e0e2ba6b1c11f", - "zh:7ee0ca546cd065030039168d780a15cbbf1765a4c70cd56d394734ab112c93da", - "zh:b1d5d80abb1906e6c6b3685a52a0192b4ca6525fe090881c64ec6f67794b1300", - "zh:d81ea9856d61db3148a4fc6c375bf387a721d78fc1fea7a8823a027272a47a78", - "zh:df0a1f0afc947b8bfc88617c1ad07a689ce3bd1a29fd97318392e6bdd32b230b", - "zh:dfbcad800240e0c68c43e0866f2a751cff09777375ec701918881acf67a268da", + "zh:9d45ac0a00b85cabdd398b859349d17f124c598b6e6bf272f1bb01321ce708a8", + "zh:a453efe8641a8f31fe806b597bf2b34d7b78b971a8e3919061ea89d61fda7b8d", + "zh:ac692bacb8c3dca8b5b37e5383168aca1f87d3cd7b40615efd300defb76494f5", + "zh:bda9e90c8547d90c9c573206985c5675cc1406047605af037a5069942c3c5966", + "zh:c30a1967de040d00f5038086dd53cdbfb78cc05d1dbc75037410f011bf2a20d8", + "zh:c80bbd1c3f56b3c836d80cf93ac0e8809305c2642f0c98b54bf5d05d3b12718c", ] } @@ -123,6 +123,26 @@ provider "registry.terraform.io/hashicorp/random" { ] } +provider "registry.terraform.io/hashicorp/time" { + version = "0.13.1" + constraints = ">= 0.13.0" + hashes = [ + "h1:ZT5ppCNIModqk3iOkVt5my8b8yBHmDpl663JtXAIRqM=", + "zh:02cb9aab1002f0f2a94a4f85acec8893297dc75915f7404c165983f720a54b74", + "zh:04429b2b31a492d19e5ecf999b116d396dac0b24bba0d0fb19ecaefe193fdb8f", + "zh:26f8e51bb7c275c404ba6028c1b530312066009194db721a8427a7bc5cdbc83a", + "zh:772ff8dbdbef968651ab3ae76d04afd355c32f8a868d03244db3f8496e462690", + "zh:78d5eefdd9e494defcb3c68d282b8f96630502cac21d1ea161f53cfe9bb483b3", + "zh:898db5d2b6bd6ca5457dccb52eedbc7c5b1a71e4a4658381bcbb38cedbbda328", + "zh:8de913bf09a3fa7bedc29fec18c47c571d0c7a3d0644322c46f3aa648cf30cd8", + "zh:9402102c86a87bdfe7e501ffbb9c685c32bbcefcfcf897fd7d53df414c36877b", + "zh:b18b9bb1726bb8cfbefc0a29cf3657c82578001f514bcf4c079839b6776c47f0", + "zh:b9d31fdc4faecb909d7c5ce41d2479dd0536862a963df434be4b16e8e4edc94d", + "zh:c951e9f39cca3446c060bd63933ebb89cedde9523904813973fbc3d11863ba75", + "zh:e5b773c0d07e962291be0e9b413c7a22c044b8c7b58c76e8aa91d1659990dfb5", + ] +} + provider "registry.terraform.io/hashicorp/tls" { version = "4.2.1" hashes = [ diff --git a/infrastructure/dogfood/terraform/aws-tf-module/free.tf b/infrastructure/dogfood/terraform/aws-tf-module/free.tf index 7cd21c8e95..510d9deab8 100644 --- a/infrastructure/dogfood/terraform/aws-tf-module/free.tf +++ b/infrastructure/dogfood/terraform/aws-tf-module/free.tf @@ -6,6 +6,8 @@ locals { FLEET_LOGGING_TRACING_ENABLED = "true" FLEET_LOGGING_TRACING_TYPE = "elasticapm" FLEET_MYSQL_MAX_OPEN_CONNS = "25" + FLEET_MYSQL_CONN_MAX_LIFETIME = "14400" + FLEET_MYSQL_READ_REPLICA_CONN_MAX_LIFETIME = "14400" FLEET_VULNERABILITIES_DATABASES_PATH = "/home/fleet" FLEET_OSQUERY_ENABLE_ASYNC_HOST_PROCESSING = "false" # ELASTIC_APM_SERVER_URL = var.elastic_url @@ -61,7 +63,7 @@ locals { } module "free" { - source = "github.com/fleetdm/fleet-terraform//byo-vpc?ref=tf-mod-byo-vpc-v1.18.3" + source = "github.com/fleetdm/fleet-terraform//byo-vpc?ref=tf-mod-byo-vpc-v1.27.1" vpc_config = { name = local.customer_free vpc_id = module.main.vpc.vpc_id @@ -90,7 +92,10 @@ module "free" { } } redis_config = { - name = local.customer_free + name = local.customer_free + engine = "redis" + engine_version = "7.1" + family = "redis7" log_delivery_configuration = [ { destination = "dogfood-free-redis-logs" @@ -106,6 +111,17 @@ module "free" { } ecs_cluster = { cluster_name = local.customer_free + cluster_configuration = { + execute_command_configuration = { + logging = "OVERRIDE" + log_configuration = { + cloud_watch_log_group_name = "/aws/ecs/${local.customer_free}" + } + } + } + cloudwatch_log_group = { + retention_in_days = 365 + } } fleet_config = { image = local.geolite2_image @@ -193,7 +209,7 @@ resource "aws_route53_record" "free" { } module "ses-free" { - source = "github.com/fleetdm/fleet-terraform//addons/ses?ref=tf-mod-addon-ses-v1.4.0" + source = "github.com/fleetdm/fleet-terraform//addons/ses?ref=tf-mod-addon-ses-v1.4.1" zone_id = aws_route53_zone.free.zone_id domain = "free.fleetdm.com" extra_txt_records = [] @@ -207,7 +223,7 @@ module "migrations_free" { depends_on = [ module.geolite2 ] - source = "github.com/fleetdm/fleet-terraform//addons/migrations?ref=tf-mod-addon-migrations-v2.2.1" + source = "github.com/fleetdm/fleet-terraform//addons/migrations?ref=tf-mod-addon-migrations-v2.2.2" ecs_cluster = module.free.byo-db.byo-ecs.service.cluster task_definition = module.free.byo-db.byo-ecs.task_definition.family task_definition_revision = module.free.byo-db.byo-ecs.task_definition.revision diff --git a/infrastructure/dogfood/terraform/aws-tf-module/imports.tf b/infrastructure/dogfood/terraform/aws-tf-module/imports.tf new file mode 100644 index 0000000000..f856f4d458 --- /dev/null +++ b/infrastructure/dogfood/terraform/aws-tf-module/imports.tf @@ -0,0 +1,4 @@ +import { + to = module.monitoring.aws_cloudwatch_log_group.cron_monitoring_lambda[0] + id = "/aws/lambda/${local.customer}_cron_monitoring" +} \ No newline at end of file diff --git a/infrastructure/dogfood/terraform/aws-tf-module/main.tf b/infrastructure/dogfood/terraform/aws-tf-module/main.tf index fc960553e0..e72222a109 100644 --- a/infrastructure/dogfood/terraform/aws-tf-module/main.tf +++ b/infrastructure/dogfood/terraform/aws-tf-module/main.tf @@ -71,6 +71,8 @@ locals { FLEET_LOGGING_ENABLE_TOPICS = "deprecated-field-names" FLEET_MYSQL_MAX_OPEN_CONNS = "10" FLEET_MYSQL_READ_REPLICA_MAX_OPEN_CONNS = "10" + FLEET_MYSQL_CONN_MAX_LIFETIME = "14400" + FLEET_MYSQL_READ_REPLICA_CONN_MAX_LIFETIME = "14400" FLEET_VULNERABILITIES_DATABASES_PATH = "/home/fleet" FLEET_OSQUERY_ENABLE_ASYNC_HOST_PROCESSING = "false" FLEET_OSQUERY_POLICY_UPDATE_INTERVAL = "30m" @@ -145,7 +147,7 @@ locals { } module "main" { - source = "github.com/fleetdm/fleet-terraform?ref=tf-mod-root-v1.21.0" + source = "github.com/fleetdm/fleet-terraform?ref=tf-mod-root-v1.26.1" certificate_arn = module.acm.acm_certificate_arn vpc = { name = local.customer @@ -175,7 +177,10 @@ module "main" { } } redis_config = { - name = local.customer + name = local.customer + engine = "redis" + engine_version = "7.1" + family = "redis7" log_delivery_configuration = [{ destination = "dogfood-redis-logs" destination_type = "cloudwatch-logs" @@ -185,6 +190,17 @@ module "main" { } ecs_cluster = { cluster_name = local.customer + cluster_configuration = { + execute_command_configuration = { + logging = "OVERRIDE" + log_configuration = { + cloud_watch_log_group_name = "/aws/ecs/${local.customer}" + } + } + } + cloudwatch_log_group = { + retention_in_days = 365 + } } fleet_config = { image = local.geolite2_image @@ -250,6 +266,7 @@ module "main" { bucket_prefix = "${local.customer}-software-installers-" create_kms_key = true kms_alias = "${local.customer}-software-installers" + cloudfront_distribution_arn = "arn:aws:cloudfront::160035666661:distribution/E3T927IDMQ7AE4" enable_bucket_versioning = true expire_noncurrent_versions = true noncurrent_version_expiration_days = 30 @@ -486,7 +503,7 @@ module "migrations" { depends_on = [ module.geolite2 ] - source = "github.com/fleetdm/fleet-terraform//addons/migrations?ref=tf-mod-addon-migrations-v2.2.1" + source = "github.com/fleetdm/fleet-terraform//addons/migrations?ref=tf-mod-addon-migrations-v2.2.2" ecs_cluster = module.main.byo-vpc.byo-db.byo-ecs.service.cluster task_definition = module.main.byo-vpc.byo-db.byo-ecs.task_definition.family task_definition_revision = module.main.byo-vpc.byo-db.byo-ecs.task_definition.revision @@ -509,7 +526,7 @@ module "mdm" { } module "firehose-logging" { - source = "github.com/fleetdm/fleet-terraform//addons/byo-firehose-logging-destination/firehose?ref=tf-mod-addon-byo-firehose-logging-destination-firehose-v2.0.3" + source = "github.com/fleetdm/fleet-terraform//addons/byo-firehose-logging-destination/firehose?ref=tf-mod-addon-byo-firehose-logging-destination-firehose-v2.0.4" firehose_results_name = "osquery_results" firehose_status_name = "osquery_status" firehose_audit_name = "fleet_audit" @@ -518,14 +535,14 @@ module "firehose-logging" { } module "osquery-carve" { - source = "github.com/fleetdm/fleet-terraform//addons/osquery-carve?ref=tf-mod-addon-osquery-carve-v1.1.1" + source = "github.com/fleetdm/fleet-terraform//addons/osquery-carve?ref=tf-mod-addon-osquery-carve-v1.3.1" osquery_carve_s3_bucket = { name = "fleet-${local.customer}-osquery-carve" } } module "monitoring" { - source = "github.com/fleetdm/fleet-terraform//addons/monitoring?ref=tf-mod-addon-monitoring-v1.9.0" + source = "github.com/fleetdm/fleet-terraform//addons/monitoring?ref=tf-mod-addon-monitoring-v1.12.0" customer_prefix = local.customer fleet_ecs_service_name = module.main.byo-vpc.byo-db.byo-ecs.service.name albs = [ @@ -603,7 +620,7 @@ module "monitoring" { } module "logging_alb" { - source = "github.com/fleetdm/fleet-terraform//addons/logging-alb?ref=tf-mod-addon-logging-alb-v1.4.0" + source = "github.com/fleetdm/fleet-terraform/addons/logging-alb?depth=1&ref=tf-mod-addon-logging-alb-v2.2.2" prefix = local.customer enable_athena = true } @@ -686,7 +703,7 @@ module "notify_slack_p2" { } module "ses" { - source = "github.com/fleetdm/fleet-terraform//addons/ses?ref=tf-mod-addon-ses-v1.4.0" + source = "github.com/fleetdm/fleet-terraform//addons/ses?ref=tf-mod-addon-ses-v1.4.1" zone_id = aws_route53_zone.main.zone_id domain = "dogfood.fleetdm.com" extra_txt_records = [] @@ -746,7 +763,7 @@ module "geolite2" { } module "vuln-processing" { - source = "github.com/fleetdm/fleet-terraform//addons/external-vuln-scans?ref=tf-mod-addon-external-vuln-scans-v2.3.0" + source = "github.com/fleetdm/fleet-terraform//addons/external-vuln-scans?ref=tf-mod-addon-external-vuln-scans-v2.5.0" ecs_cluster = module.main.byo-vpc.byo-db.byo-ecs.service.cluster execution_iam_role_arn = module.main.byo-vpc.byo-db.byo-ecs.execution_iam_role_arn subnets = module.main.byo-vpc.byo-db.byo-ecs.service.network_configuration[0].subnets @@ -807,10 +824,9 @@ resource "aws_iam_policy" "osquery_sidecar" { } module "cloudfront-software-installers" { - source = "github.com/fleetdm/fleet-terraform//addons/cloudfront-software-installers?ref=tf-mod-addon-cloudfront-software-installers-v1.1.0" + source = "github.com/fleetdm/fleet-terraform//addons/cloudfront-software-installers?ref=tf-mod-addon-cloudfront-software-installers-v2.0.0" customer = local.customer s3_bucket = module.main.byo-vpc.byo-db.byo-ecs.fleet_s3_software_installers_config.bucket_name - s3_kms_key_id = module.main.byo-vpc.byo-db.byo-ecs.fleet_s3_software_installers_config.kms_key_id public_key = var.cloudfront_public_key private_key = var.cloudfront_private_key enable_logging = true diff --git a/infrastructure/loadtesting/terraform/infra/locals.tf b/infrastructure/loadtesting/terraform/infra/locals.tf index 70e96e2e98..1730657188 100644 --- a/infrastructure/loadtesting/terraform/infra/locals.tf +++ b/infrastructure/loadtesting/terraform/infra/locals.tf @@ -39,6 +39,8 @@ locals { FLEET_FILESYSTEM_RESULT_LOG_FILE = "/dev/null" FLEET_MYSQL_MAX_OPEN_CONNS = "10" FLEET_MYSQL_READ_REPLICA_MAX_OPEN_CONNS = "10" + FLEET_MYSQL_CONN_MAX_LIFETIME = "14400" + FLEET_MYSQL_READ_REPLICA_CONN_MAX_LIFETIME = "14400" FLEET_OSQUERY_ASYNC_HOST_REDIS_SCAN_KEYS_COUNT = "10000" FLEET_REDIS_MAX_OPEN_CONNS = "500" FLEET_REDIS_MAX_IDLE_CONNS = "500" diff --git a/infrastructure/loadtesting/terraform/infra/main.tf b/infrastructure/loadtesting/terraform/infra/main.tf index f68b7137f7..1d36875f8f 100644 --- a/infrastructure/loadtesting/terraform/infra/main.tf +++ b/infrastructure/loadtesting/terraform/infra/main.tf @@ -30,7 +30,7 @@ resource "aws_route53_record" "main" { } module "loadtest" { - source = "github.com/fleetdm/fleet-terraform//byo-vpc?ref=tf-mod-root-v1.18.3" + source = "github.com/fleetdm/fleet-terraform//byo-vpc?ref=tf-mod-root-v1.26.1" vpc_config = { name = local.customer vpc_id = data.terraform_remote_state.shared.outputs.vpc.vpc_id @@ -58,6 +58,9 @@ module "loadtest" { } redis_config = { name = local.customer + engine = "redis" + engine_version = "7.1" + family = "redis7" instance_type = var.redis_instance_size cluster_size = var.redis_instance_count subnets = data.terraform_remote_state.shared.outputs.vpc.private_subnets @@ -192,7 +195,7 @@ module "acm" { } module "ses" { - source = "github.com/fleetdm/fleet-terraform//addons/ses?ref=tf-mod-addon-ses-v1.4.0" + source = "github.com/fleetdm/fleet-terraform//addons/ses?ref=tf-mod-addon-ses-v1.4.1" zone_id = data.aws_route53_zone.main.id domain = "${terraform.workspace}.loadtest.fleetdm.com" extra_txt_records = [] @@ -203,7 +206,7 @@ module "ses" { } module "migrations" { - source = "github.com/fleetdm/fleet-terraform//addons/migrations?ref=tf-mod-addon-migrations-v2.2.1" + source = "github.com/fleetdm/fleet-terraform//addons/migrations?ref=tf-mod-addon-migrations-v2.2.2" ecs_cluster = module.loadtest.byo-db.byo-ecs.service.cluster task_definition = module.loadtest.byo-db.byo-ecs.task_definition.family task_definition_revision = module.loadtest.byo-db.byo-ecs.task_definition.revision @@ -221,7 +224,7 @@ module "migrations" { } module "vuln-processing" { - source = "github.com/fleetdm/fleet-terraform//addons/external-vuln-scans?ref=tf-mod-addon-external-vuln-scans-v2.3.0" + source = "github.com/fleetdm/fleet-terraform//addons/external-vuln-scans?ref=tf-mod-addon-external-vuln-scans-v2.5.0" ecs_cluster = module.loadtest.byo-db.byo-ecs.service.cluster execution_iam_role_arn = module.loadtest.byo-db.byo-ecs.execution_iam_role_arn subnets = module.loadtest.byo-db.byo-ecs.service.network_configuration[0].subnets @@ -247,14 +250,14 @@ module "mdm" { } module "osquery-carve" { - source = "github.com/fleetdm/fleet-terraform//addons/osquery-carve?ref=tf-mod-addon-osquery-carve-v1.1.1" + source = "github.com/fleetdm/fleet-terraform//addons/osquery-carve?ref=tf-mod-addon-osquery-carve-v1.3.1" osquery_carve_s3_bucket = { name = "${local.customer}-osquery-carve" } } module "logging_alb" { - source = "github.com/fleetdm/fleet-terraform//addons/logging-alb?ref=tf-mod-addon-logging-alb-v1.6.2" + source = "github.com/fleetdm/fleet-terraform//addons/logging-alb?ref=tf-mod-addon-logging-alb-v2.2.2" prefix = local.customer alt_path_prefix = local.customer enable_athena = true diff --git a/infrastructure/loadtesting/terraform/infra/template/cloudfront.tf.disabled b/infrastructure/loadtesting/terraform/infra/template/cloudfront.tf.disabled index 33774f338d..4eb1637786 100644 --- a/infrastructure/loadtesting/terraform/infra/template/cloudfront.tf.disabled +++ b/infrastructure/loadtesting/terraform/infra/template/cloudfront.tf.disabled @@ -1,8 +1,7 @@ module "cloudfront-software-installers" { - source = "github.com/fleetdm/fleet-terraform/addons/cloudfront-software-installers?ref=tf-mod-addon-cloudfront-software-installers-v1.2.0" + source = "github.com/fleetdm/fleet-terraform/addons/cloudfront-software-installers?ref=tf-mod-addon-cloudfront-software-installers-v2.0.0" customer = terraform.workspace s3_bucket = module.loadtest.byo-db.byo-ecs.fleet_s3_software_installers_config.bucket_name - s3_kms_key_id = module.loadtest.byo-db.byo-ecs.fleet_s3_software_installers_config.kms_key_id public_key = tls_private_key.cloudfront_key.public_key_pem private_key = tls_private_key.cloudfront_key.private_key_pem_pkcs8 enable_logging = true diff --git a/infrastructure/loadtesting/terraform/infra/template/firehose.tf.disabled b/infrastructure/loadtesting/terraform/infra/template/firehose.tf.disabled index 1df913e7c5..9a3333b628 100644 --- a/infrastructure/loadtesting/terraform/infra/template/firehose.tf.disabled +++ b/infrastructure/loadtesting/terraform/infra/template/firehose.tf.disabled @@ -1,5 +1,5 @@ module "logging_firehose" { - source = "github.com/fleetdm/fleet-terraform//addons/logging-destination-firehose?ref=tf-mod-addon-logging-destination-firehose-v1.2.4" + source = "github.com/fleetdm/fleet-terraform//addons/logging-destination-firehose?ref=tf-mod-addon-logging-destination-firehose-v1.2.6" prefix = local.customer osquery_results_s3_bucket = { name = "${local.customer}-osquery-results-firehose-policy"