Deploy Sample using Terraform

Prerequisites

Unix environment

Make sure you have a Unix-like environment (Linux or WSL on Windows) to run the Terraform commands.

Terraform

To install Terraform cli, see Install Terraform

For provider documentation, see Open Telekom Cloud Provider

Adapt environment variables used in provider.tf

Environment variables

Environment variable name

Value

Remark

TF_VAR_OTC_SDK_AK

<your_access_key>

see: Generating an AK and SK in API usage guide.

TF_VAR_OTC_SDK_SK

<your_secret_key>

see: Generating an AK and SK in API usage guide.

TF_VAR_OTC_SDK_DOMAIN_NAME

<your_domain_name>

Domain Name, eg. OTC-EU-DE-000000000010000XXXXX, see Obtaining Required Information.

TF_VAR_OTC_SDK_PROJECTID

<your_project_id>

Project Id, see Obtaining Required Information.

TF_VAR_OTC_SDK_PROJECTNAME

<your_project_name>

Project Name, eg. eu-de_MYPROJECT

TF_VAR_OTC_SDK_REGION

<your_region_name>

Region Name, eg. “eu-de”, for available regions, see: Regions.

AWS_ACCESS_KEY_ID

<your_access_key>

same as TF_VAR_OTC_SDK_AK

AWS_SECRET_ACCESS_KEY

<your_secret_key>

same as TF_VAR_OTC_SDK_SK

AWS_REQUEST_CHECKSUM_CALCULATION

“when_required”

see note below

AWS_RESPONSE_CHECKSUM_VALIDATION

“when_required”

see note below

Note

There is an issue (see GitHub , Problem - Remote State OBS - Terraform >=v1.6) which causes the s3 backend to fail as it doesn’t respect the skip_s3_checksum setting properly due to a newer AWX Go SDK in the TF code.

As a workaround set these environment variables:

export AWS_REQUEST_CHECKSUM_CALCULATION="when_required"
export AWS_RESPONSE_CHECKSUM_VALIDATION="when_required"

Create OBS Bucket for .tfstate files

Terraform must store state about your managed infrastructure and configuration.

This state is used by Terraform to map real world resources to your configuration, keep track of metadata, and to improve performance for large infrastructures.

See: Terraform state

Create OBS bucket for terraform state file either:

  • using OpenTelekomCloud OBS console with bucket name as defined in provider.tf file for terraform.backend.s3.bucket.

  • using the OpenTelekomCloud CLI with command s3cmd (replace <bucket_name>):

    s3cmd \
      --access_key=${AWS_ACCESS_KEY_ID} \
      --secret_key=${AWS_SECRET_ACCESS_KEY} \
      --no-ssl \
      mb s3://<bucket_name>
    

    Note

    In provider.tf, the bucket name is sample-tf-backend

Adapt provider.tf file

Check and adapt following values in provider.tf (see comments there).

  • terraform.backend.s3.endpoints

  • terraform.backend.s3.bucket

  • terraform.backend.s3.key

  • terraform.backend.s3.region

  • provider.opentelekomcloud.auth_url

Adapt variables.tf file

Check and adapt values in variables.tf.

Adapt apigw.tf file

Adapt apigw.tf according to your needs (e.g. IP addresses).

Deploy

In folder terraform run following commands:

# change folder
cd terraform

# initialize provider
terraform init

# plan changes
terraform plan

# apply changes
terraform apply

# destroy all deployed resources on OpenTelekomCloud
terraform destroy

Note

Deployment of resources may take several minutes.

Terraform apply script will output the URLs to test endpoints (APIGWGROUPID and REGION will be replaced with real values):

URL = "https://APIGWGROUPID.apic.REGION.otc.t-systems.com"
URL_APIItems = "https://APIGWGROUPID.apic.REGION.otc.t-systems.com/api/v1/items/100?q=20"
URL_Root = "https://APIGWGROUPID.apic.REGION.otc.t-systems.com/"
URL_docs = "https://APIGWGROUPID.apic.REGION.otc.t-systems.com/docs"
URL_openapi = "https://APIGWGROUPID.apic.REGION.otc.t-systems.com/openapi.json"
URL_redocs = "https://APIGWGROUPID.apic.REGION.otc.t-systems.com/redoc"